IcefieldKernel

COMPLIANCE_REGISTRY

Legal & Regulatory Framework

All protocols governing data handling, service delivery, and operational governance.

01

Privacy Policy

Effective Date: 1 January 2026

1. Data Controller Identity

The data controller responsible for processing personal data collected through this platform is IcefieldKernel, registered at Boulevarden 14, 9000 Aalborg, Denmark. All data processing activities are conducted in accordance with the EU General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679.

2. Categories of Personal Data Processed

We collect and process the following categories of personal data:

  • Identity Data: Full name, professional designation, and organizational affiliation provided through contact forms or service inquiries.
  • Contact Data: Email address, telephone number, and postal address submitted for communication and service delivery purposes.
  • Technical Data: IP address, browser type and version, operating system, device identifiers, and access timestamps collected automatically through server logs.
  • Usage Data: Page navigation patterns, interaction events, session duration, and feature engagement metrics gathered through first-party analytics.
  • Financial Data: Transaction records and payment confirmations processed exclusively through our PCI DSS-compliant payment processor. We do not store credit card numbers or banking credentials on our servers.

3. Legal Basis for Processing

Each data processing activity is grounded in one or more of the following legal bases as defined in Article 6(1) GDPR:

  • Consent (Art. 6(1)(a)): Where you have given explicit, informed, and freely given consent for specific processing purposes, such as receiving marketing communications.
  • Contractual Necessity (Art. 6(1)(b)): Processing required for the performance of a contract to which you are a party, or for taking pre-contractual steps at your request.
  • Legitimate Interest (Art. 6(1)(f)): Processing necessary for our legitimate interests, such as fraud prevention, network security, and service improvement, provided these interests are not overridden by your fundamental rights.

4. Data Retention Periods

Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law:

  • Contact form submissions: Retained for 24 months from the date of submission, after which they are irreversibly deleted.
  • Contractual and financial records: Retained for a minimum of 5 years in compliance with Danish bookkeeping legislation (Bogføringsloven).
  • Server access logs: Retained for a maximum of 90 days for security monitoring purposes, then automatically purged.
  • Cookie consent records: Retained for the duration of the consent validity period plus 3 years for audit compliance.

5. Data Recipients and Third-Party Transfers

Your personal data may be shared with the following categories of recipients:

  • Infrastructure Providers: Cloud hosting and CDN services operating within the European Economic Area (EEA) or in jurisdictions providing adequate data protection as determined by the European Commission.
  • Payment Processors: PCI DSS-compliant payment gateways that process transaction data under their own data processing agreements and security certifications.
  • Legal Authorities: Government agencies, courts, or regulatory bodies where disclosure is required by law, regulation, or binding legal process.

We do not sell, rent, or trade personal data to third parties for their own marketing purposes under any circumstances.

6. International Data Transfers

Where personal data is transferred outside the EEA, we ensure adequate protection through one or more of the following safeguards:

  • European Commission adequacy decisions for the destination country.
  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Binding Corporate Rules (BCRs) where applicable within corporate groups.

7. Your Data Subject Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of Access (Art. 15): Request a copy of all personal data we hold about you.
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
  • Right to Erasure (Art. 17): Request deletion of your personal data where there is no compelling reason for continued processing.
  • Right to Restrict Processing (Art. 18): Request limitation of processing in specific circumstances.
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interests, including direct marketing.
  • Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

To exercise any of these rights, contact our data protection officer at [email protected]. We will respond to all requests within 30 days.

8. Right to Lodge a Complaint

If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet):

Datatilsynet
Borgergade 28, 1300 Copenhagen K, Denmark
Phone: +45 33 19 32 00
Email: [email protected]

9. Data Security Measures

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include but are not limited to:

  • TLS 1.3 encryption for all data in transit.
  • AES-256 encryption for data at rest.
  • Role-based access controls with principle of least privilege enforcement.
  • Regular security audits and penetration testing.
  • Automated vulnerability scanning and patch management.

10. Changes to This Policy

We reserve the right to update this Privacy Policy to reflect changes in our data processing practices or legal requirements. Material changes will be communicated through prominent notice on this platform and, where appropriate, via direct notification to affected data subjects.

02

Cookies Policy

Effective Date: 1 January 2026

1. What Are Cookies

Cookies are small text files placed on your device by websites you visit. They are widely used to make websites function efficiently, provide usage analytics, and deliver personalized experiences. Cookies may be "first-party" (set by our domain) or "third-party" (set by external services integrated into our platform).

2. Categories of Cookies We Use

Strictly Necessary Cookies

Essential for platform operation. These cookies enable core functionality such as session management, security token validation, and load balancing. They cannot be disabled without compromising platform integrity. No consent is required for these cookies under Article 5(3) of the ePrivacy Directive.

Performance & Analytics Cookies

Collect anonymized usage data including page load times, navigation patterns, and error rates. All analytics data is aggregated and does not personally identify individual users. These cookies are only activated with your explicit consent.

Preference Cookies

Remember your settings and choices (such as language, display preferences, or consent selections) to provide a more personalized experience on subsequent visits.

Marketing & Targeting Cookies

Used to deliver relevant advertisements and track campaign effectiveness. These cookies may be set by third-party advertising partners and may share data across domains. We currently do not deploy marketing cookies unless explicitly activated through a separate consent mechanism.

3. Managing Cookie Consent

When you first access this platform, a cookie consent banner is presented allowing you to accept or decline non-essential cookies. Your choice is stored in your browser's localStorage and will persist until you clear it or change your preference. You may review and modify your cookie preferences at any time by clearing your browser's localStorage for this domain and reloading the page.

4. Third-Party Cookie Providers

The following third-party services may set cookies on your device through this platform:

  • Google Maps: When the contact page map is loaded, Google may set cookies for map functionality and usage analytics. See Google's Privacy Policy for details.
  • Stripe: Payment processing cookies set during checkout and payment flows. These are strictly necessary for transaction security.

5. Cookie Retention Periods

  • Session Cookies: Automatically deleted when you close your browser.
  • Persistent Cookies: Remain on your device for a defined period or until manually deleted. Maximum retention: 13 months from the date of placement.

6. Browser-Level Controls

Most browsers allow you to block or delete cookies through their settings. Note that disabling cookies may affect platform functionality. Refer to your browser's help documentation for specific instructions on managing cookie settings.

03

Refund Policy

Effective Date: 1 January 2026

1. Service Delivery Model

IcefieldKernel delivers custom digital engineering services on a project-by-project basis. Each engagement begins with a scoping and discovery phase, followed by defined delivery milestones. All service specifications, timelines, and deliverables are documented in a mutually signed Statement of Work (SOW) prior to commencement.

2. Milestone-Based Refund Structure

Refund eligibility is assessed on a milestone-by-milestone basis according to the following framework:

  • Pre-Commencement Cancellation: If you cancel the engagement before any work has commenced, 100% of any advance payment is refunded within 14 business days.
  • During Active Milestone: If cancellation occurs during an active milestone, payment for the current milestone is non-refundable as resources have been allocated and work has been initiated. All previously paid milestones for completed phases remain non-refundable.
  • Completed Milestones: Payments for completed milestones that have been accepted and signed off are non-refundable.

3. Quality Assurance Disputes

If deliverables materially fail to meet the specifications documented in the signed SOW, you may raise a formal dispute within 14 days of delivery. Upon receipt of a valid dispute:

  • We will conduct an internal review within 5 business days.
  • If the dispute is substantiated, we will either remediate the deficiency at no additional cost or issue a proportional refund for the affected deliverable.
  • If the dispute is not substantiated, we will provide a detailed technical response with evidence of compliance.

4. Payment Processor Refunds

Refunds are processed through the original payment method within 14 business days of approval. Stripe processing fees are non-refundable and will be deducted from the refund amount where applicable.

5. Force Majeure

Neither party shall be liable for delays or failures in performance resulting from causes beyond reasonable control, including but not limited to acts of God, government regulations, natural disasters, or infrastructure failures. In such cases, both parties will negotiate in good faith to reach an equitable resolution.

04

Terms of Service

Effective Date: 1 January 2026

1. Acceptance of Terms

By accessing, browsing, or using any services provided by IcefieldKernel, registered at Boulevarden 14, 9000 Aalborg, Denmark, you agree to be bound by these Terms of Service. If you do not agree to these terms, you must immediately cease use of our platform and services.

2. Scope of Services

IcefieldKernel provides custom digital engineering services including but not limited to web development, platform architecture, API integration, infrastructure engineering, and consulting. The specific scope, deliverables, timelines, and pricing for each engagement are defined in a separate Statement of Work (SOW) signed by both parties.

3. Client Obligations

The client agrees to:

  • Provide accurate, complete, and timely information necessary for project execution.
  • Designate an authorized representative with decision-making authority for the engagement.
  • Review and provide feedback on deliverables within the timeframes specified in the SOW.
  • Ensure that all content, data, and materials provided do not infringe upon the intellectual property rights of third parties.
  • Make payments in accordance with the payment schedule defined in the SOW.

4. Intellectual Property

Upon receipt of full payment for a completed engagement, all intellectual property rights for custom-developed code, designs, and documentation created specifically for the client are transferred to the client. IcefieldKernel retains the right to use anonymized, non-client-identifying technical methodologies, frameworks, and general-purpose tools developed during the engagement for future projects.

5. Confidentiality

Both parties agree to maintain the confidentiality of all proprietary information disclosed during the engagement. This obligation survives the termination of the agreement for a period of 3 years. Confidential information shall not be disclosed to third parties without prior written consent, except as required by law.

6. Limitation of Liability

To the maximum extent permitted by applicable law, IcefieldKernel's total aggregate liability for any claims arising out of or related to these terms or any engagement shall not exceed the total fees paid by the client for the specific engagement giving rise to the claim. In no event shall IcefieldKernel be liable for any indirect, incidental, special, consequential, or punitive damages.

7. Indemnification

Each party agrees to indemnify, defend, and hold harmless the other party from and against any claims, losses, damages, liabilities, and expenses (including reasonable legal fees) arising from: (a) a breach of these Terms; (b) violation of applicable law; or (c) infringement of third-party intellectual property rights by the indemnifying party's provided materials.

8. Termination

Either party may terminate an engagement with 30 days' written notice. Termination does not relieve either party of obligations accrued prior to the termination date. Upon termination, the client shall pay for all work completed up to the termination date, and IcefieldKernel shall deliver all completed deliverables in its possession.

9. Governing Law and Dispute Resolution

These Terms are governed by the laws of the Kingdom of Denmark. Any disputes arising from these Terms or any engagement shall first be subject to mediation. If mediation fails within 60 days, disputes shall be submitted to the exclusive jurisdiction of the courts of Aalborg, Denmark.

10. Amendments

IcefieldKernel reserves the right to amend these Terms of Service at any time. Material changes will be communicated at least 30 days before they take effect. Continued use of the platform after the effective date constitutes acceptance of the amended terms.

11. Severability

If any provision of these Terms is found to be invalid, illegal, or unenforceable by a court of competent jurisdiction, the remaining provisions shall remain in full force and effect. The invalid provision shall be modified to the minimum extent necessary to make it valid and enforceable while preserving the original intent.

For questions regarding these terms, contact: [email protected]

Address correspondence to: IcefieldKernel, Boulevarden 14, 9000 Aalborg, Denmark