COMPLIANCE_REGISTRY
Legal & Regulatory Framework
All protocols governing data handling, service delivery, and operational governance.
Privacy Policy
Effective Date: 1 January 2026
1. Data Controller Identity
The data controller responsible for processing personal data collected through this platform is IcefieldKernel, registered at Boulevarden 14, 9000 Aalborg, Denmark. All data processing activities are conducted in accordance with the EU General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679.
2. Categories of Personal Data Processed
We collect and process the following categories of personal data:
- — Identity Data: Full name, professional designation, and organizational affiliation provided through contact forms or service inquiries.
- — Contact Data: Email address, telephone number, and postal address submitted for communication and service delivery purposes.
- — Technical Data: IP address, browser type and version, operating system, device identifiers, and access timestamps collected automatically through server logs.
- — Usage Data: Page navigation patterns, interaction events, session duration, and feature engagement metrics gathered through first-party analytics.
- — Financial Data: Transaction records and payment confirmations processed exclusively through our PCI DSS-compliant payment processor. We do not store credit card numbers or banking credentials on our servers.
3. Legal Basis for Processing
Each data processing activity is grounded in one or more of the following legal bases as defined in Article 6(1) GDPR:
- — Consent (Art. 6(1)(a)): Where you have given explicit, informed, and freely given consent for specific processing purposes, such as receiving marketing communications.
- — Contractual Necessity (Art. 6(1)(b)): Processing required for the performance of a contract to which you are a party, or for taking pre-contractual steps at your request.
- — Legitimate Interest (Art. 6(1)(f)): Processing necessary for our legitimate interests, such as fraud prevention, network security, and service improvement, provided these interests are not overridden by your fundamental rights.
4. Data Retention Periods
Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law:
- — Contact form submissions: Retained for 24 months from the date of submission, after which they are irreversibly deleted.
- — Contractual and financial records: Retained for a minimum of 5 years in compliance with Danish bookkeeping legislation (Bogføringsloven).
- — Server access logs: Retained for a maximum of 90 days for security monitoring purposes, then automatically purged.
- — Cookie consent records: Retained for the duration of the consent validity period plus 3 years for audit compliance.
5. Data Recipients and Third-Party Transfers
Your personal data may be shared with the following categories of recipients:
- — Infrastructure Providers: Cloud hosting and CDN services operating within the European Economic Area (EEA) or in jurisdictions providing adequate data protection as determined by the European Commission.
- — Payment Processors: PCI DSS-compliant payment gateways that process transaction data under their own data processing agreements and security certifications.
- — Legal Authorities: Government agencies, courts, or regulatory bodies where disclosure is required by law, regulation, or binding legal process.
We do not sell, rent, or trade personal data to third parties for their own marketing purposes under any circumstances.
6. International Data Transfers
Where personal data is transferred outside the EEA, we ensure adequate protection through one or more of the following safeguards:
- — European Commission adequacy decisions for the destination country.
- — Standard Contractual Clauses (SCCs) approved by the European Commission.
- — Binding Corporate Rules (BCRs) where applicable within corporate groups.
7. Your Data Subject Rights
Under the GDPR, you have the following rights regarding your personal data:
- — Right of Access (Art. 15): Request a copy of all personal data we hold about you.
- — Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
- — Right to Erasure (Art. 17): Request deletion of your personal data where there is no compelling reason for continued processing.
- — Right to Restrict Processing (Art. 18): Request limitation of processing in specific circumstances.
- — Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, and machine-readable format.
- — Right to Object (Art. 21): Object to processing based on legitimate interests, including direct marketing.
- — Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, contact our data protection officer at [email protected]. We will respond to all requests within 30 days.
8. Right to Lodge a Complaint
If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet):
Datatilsynet
Borgergade 28, 1300 Copenhagen K, Denmark
Phone: +45 33 19 32 00
Email: [email protected]
9. Data Security Measures
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include but are not limited to:
- — TLS 1.3 encryption for all data in transit.
- — AES-256 encryption for data at rest.
- — Role-based access controls with principle of least privilege enforcement.
- — Regular security audits and penetration testing.
- — Automated vulnerability scanning and patch management.
10. Changes to This Policy
We reserve the right to update this Privacy Policy to reflect changes in our data processing practices or legal requirements. Material changes will be communicated through prominent notice on this platform and, where appropriate, via direct notification to affected data subjects.
Refund Policy
Effective Date: 1 January 2026
1. Service Delivery Model
IcefieldKernel delivers custom digital engineering services on a project-by-project basis. Each engagement begins with a scoping and discovery phase, followed by defined delivery milestones. All service specifications, timelines, and deliverables are documented in a mutually signed Statement of Work (SOW) prior to commencement.
2. Milestone-Based Refund Structure
Refund eligibility is assessed on a milestone-by-milestone basis according to the following framework:
- — Pre-Commencement Cancellation: If you cancel the engagement before any work has commenced, 100% of any advance payment is refunded within 14 business days.
- — During Active Milestone: If cancellation occurs during an active milestone, payment for the current milestone is non-refundable as resources have been allocated and work has been initiated. All previously paid milestones for completed phases remain non-refundable.
- — Completed Milestones: Payments for completed milestones that have been accepted and signed off are non-refundable.
3. Quality Assurance Disputes
If deliverables materially fail to meet the specifications documented in the signed SOW, you may raise a formal dispute within 14 days of delivery. Upon receipt of a valid dispute:
- — We will conduct an internal review within 5 business days.
- — If the dispute is substantiated, we will either remediate the deficiency at no additional cost or issue a proportional refund for the affected deliverable.
- — If the dispute is not substantiated, we will provide a detailed technical response with evidence of compliance.
4. Payment Processor Refunds
Refunds are processed through the original payment method within 14 business days of approval. Stripe processing fees are non-refundable and will be deducted from the refund amount where applicable.
5. Force Majeure
Neither party shall be liable for delays or failures in performance resulting from causes beyond reasonable control, including but not limited to acts of God, government regulations, natural disasters, or infrastructure failures. In such cases, both parties will negotiate in good faith to reach an equitable resolution.
Terms of Service
Effective Date: 1 January 2026
1. Acceptance of Terms
By accessing, browsing, or using any services provided by IcefieldKernel, registered at Boulevarden 14, 9000 Aalborg, Denmark, you agree to be bound by these Terms of Service. If you do not agree to these terms, you must immediately cease use of our platform and services.
2. Scope of Services
IcefieldKernel provides custom digital engineering services including but not limited to web development, platform architecture, API integration, infrastructure engineering, and consulting. The specific scope, deliverables, timelines, and pricing for each engagement are defined in a separate Statement of Work (SOW) signed by both parties.
3. Client Obligations
The client agrees to:
- — Provide accurate, complete, and timely information necessary for project execution.
- — Designate an authorized representative with decision-making authority for the engagement.
- — Review and provide feedback on deliverables within the timeframes specified in the SOW.
- — Ensure that all content, data, and materials provided do not infringe upon the intellectual property rights of third parties.
- — Make payments in accordance with the payment schedule defined in the SOW.
4. Intellectual Property
Upon receipt of full payment for a completed engagement, all intellectual property rights for custom-developed code, designs, and documentation created specifically for the client are transferred to the client. IcefieldKernel retains the right to use anonymized, non-client-identifying technical methodologies, frameworks, and general-purpose tools developed during the engagement for future projects.
5. Confidentiality
Both parties agree to maintain the confidentiality of all proprietary information disclosed during the engagement. This obligation survives the termination of the agreement for a period of 3 years. Confidential information shall not be disclosed to third parties without prior written consent, except as required by law.
6. Limitation of Liability
To the maximum extent permitted by applicable law, IcefieldKernel's total aggregate liability for any claims arising out of or related to these terms or any engagement shall not exceed the total fees paid by the client for the specific engagement giving rise to the claim. In no event shall IcefieldKernel be liable for any indirect, incidental, special, consequential, or punitive damages.
7. Indemnification
Each party agrees to indemnify, defend, and hold harmless the other party from and against any claims, losses, damages, liabilities, and expenses (including reasonable legal fees) arising from: (a) a breach of these Terms; (b) violation of applicable law; or (c) infringement of third-party intellectual property rights by the indemnifying party's provided materials.
8. Termination
Either party may terminate an engagement with 30 days' written notice. Termination does not relieve either party of obligations accrued prior to the termination date. Upon termination, the client shall pay for all work completed up to the termination date, and IcefieldKernel shall deliver all completed deliverables in its possession.
9. Governing Law and Dispute Resolution
These Terms are governed by the laws of the Kingdom of Denmark. Any disputes arising from these Terms or any engagement shall first be subject to mediation. If mediation fails within 60 days, disputes shall be submitted to the exclusive jurisdiction of the courts of Aalborg, Denmark.
10. Amendments
IcefieldKernel reserves the right to amend these Terms of Service at any time. Material changes will be communicated at least 30 days before they take effect. Continued use of the platform after the effective date constitutes acceptance of the amended terms.
11. Severability
If any provision of these Terms is found to be invalid, illegal, or unenforceable by a court of competent jurisdiction, the remaining provisions shall remain in full force and effect. The invalid provision shall be modified to the minimum extent necessary to make it valid and enforceable while preserving the original intent.
For questions regarding these terms, contact: [email protected]
Address correspondence to: IcefieldKernel, Boulevarden 14, 9000 Aalborg, Denmark