KERBRUS LLC
Privacy Policy
This policy explains what Kerbrus LLC ("Kerbrus", "we", "us") does with personal information. Kerbrus LLC is a limited liability company and is the controller of the personal information described here.
Contact: [email protected]. Postal address: published at kerbrus.com/legal.
1. WHO THIS POLICY COVERS
This policy covers three groups, and what we hold differs for each.
- Visitors
- People who browse kerbrus.com or our documentation.
- Account holders
- People who register for a Kerbrus account, buy a licence, start a trial, download software or contact support.
- Installs
- Deployments of the Software that check in to us. Section 3 covers this and Schedule 1 lists every field.
2. VISITORS AND ACCOUNT HOLDERS
2.1 What we collect from you
- Given by you
- Name, business email, company name, job title, country, and anything you write to us in a form, an email or a support request.
- Payment
- Handled by our payment provider, which is the merchant of record. We receive a transaction record, the billing country and the last four digits of a card. We never receive full card numbers.
- Account
- Which licences you hold, which tier, which releases you downloaded, and your support history.
- Automatic
- IP address, browser and operating system, pages requested, referring page, and dates and times.
2.2 Why, and the legal basis
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Provide the account, licence and downloads you asked for | Contract |
| Take payment and meet tax and accounting obligations | Legal obligation |
| Answer support requests | Contract, legitimate interests |
| Send service messages about your licence, renewal or a security issue | Contract |
| Send marketing email | Consent, withdrawable at any time |
| Keep the site and the portal secure, prevent fraud and abuse | Legitimate interests |
| Understand how the site and the product are used, in aggregate | Consent, through the cookie banner, where cookies are used |
2.3 Cookies
Our sites use cookies that are strictly necessary to serve the page and keep a session. Anything beyond that -- analytics -- runs only if you accept it in the banner, and you may change your mind at any time from the same banner. We do not use advertising cookies and we do not permit third-party advertising networks on our sites.
3. WHAT AN INSTALL SENDS US
3.1 What is sent. The fields are listed in Schedule 1 and they are: a random install identifier, the licence identifier, the Software version, the measured flow rate, and a small number of operational counts.
3.2 What is not sent. The check-in carries no flow records, no IP addresses observed on your network, no host names, no interface or device names, no user names or identities, no credentials, no configuration, and no dashboard, query or report content.
3.3 Whether it is personal information. The install identifier is generated randomly by your Install and is not derived from your network, your hardware or your account. On its own it identifies nobody. Where an Install holds a licence, the licence identifier links the check-in to your account, and your account has a named contact -- so we treat check-in data as personal information relating to that contact, and this policy governs it.
3.4 Why we do it. To revoke a licence that must be revoked, to renew your licence without an annual chore, to tell you when your Install has outgrown its tier, to support you, and in aggregate to understand how the Software performs in the field. Legal basis: contract, for the first three; legitimate interests, for the last two.
3.5 Turning it off. There is no setting that disables the check-in. You do not need one: blocking it at your firewall is a supported configuration, and a check-in that fails -- for any reason, for any length of time -- never limits what the Software collects, never expires a licence and never disables any part of the Software.
3.6 Changes. We will not add a category of information to the check-in without documenting it in the release that makes the change, and we will not add your traffic data to it at all. Section 3.2 is a commitment, not a snapshot of what this release happens to send.
4. WHAT WE DO NOT RECEIVE
The Software records metadata about network traffic. That data is written to databases you run, on infrastructure you control. It does not reach us.
We are not a controller and not a processor of it. There is no data processing agreement to sign for it, because there is no processing by us to agree about. You do not need to name Kerbrus in a record of processing activities for your flow data, and a transfer impact assessment for it has no transfer to assess.
As between you and us, you are the controller of any personal data in the traffic your Install records, and you are responsible for the lawfulness of collecting it -- including any notice, consent or works-council approval required where you operate.
Two exceptions, both of which you initiate:
Support diagnostics. If you send us a diagnostic bundle, packet capture, screenshot or database extract, you have disclosed that data to us deliberately. We use it only to answer your request, hold it in confidence, and delete it on request. Please redact what you do not need to send.
Hosted Services. If a future feature is performed by infrastructure we operate, it is optional, inactive until you enable it, and we will tell you what it sends before you turn it on. Section 3.2 does not limit what such a feature submits, and its own terms will say what it does.
5. WHO ELSE PROCESSES IT
We use service providers who process personal information on our instructions, under contract, and only for us. We do not sell personal information and we do not share it for cross-context behavioural advertising.
The categories are: hosting and content delivery for our sites and portal; account sign-in; payment, invoicing and tax; licence issuing and the check-in; email delivery; customer and support record-keeping; and drafting assistance for support replies, which a person at Kerbrus reads and sends.
If you need the current list of named providers, write to [email protected] and we will send it.
6. INTERNATIONAL TRANSFERS
Kerbrus is in the United States, and our service providers are in the United States, the United Kingdom and the European Union.
Where we move personal information out of the United Kingdom or the European Economic Area, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK is the exporter, and we assess whether additional safeguards are needed. You may request a copy of the clauses we rely on.
7. YOUR RIGHTS
Wherever you are, you may ask us to give you a copy of what we hold, correct it, delete it, restrict or object to what we do with it, or send it to another provider in a portable form. You may withdraw consent at any time, which does not affect what we did before you withdrew it.
If you are in the UK or the EEA, these are your rights under the GDPR, and you may complain to your supervisory authority. If you are in California, you may also ask what we collected, used and disclosed in the past twelve months, ask us to delete or correct it, and ask us to limit the use of sensitive personal information -- we do not collect any -- and we will not discriminate against you for asking.
Email [email protected]. We answer within one month, and will tell you if we need longer. We may ask you to confirm who you are, and we will not use what you send for that purpose for anything else.
8. HOW LONG WE KEEP IT
We keep personal information for as long as we need it for the purpose we collected it, and then for as long as tax, accounting and limitation periods require. In practice:
- Account and licence records
- While your account is open, and afterwards for the period tax and contract records must be kept.
- Support correspondence
- While it remains useful for supporting you.
- Support diagnostics you send
- Deleted when the request is closed, or sooner if you ask.
- Check-in records
- Long enough to answer a licensing or renewal question. Aggregate figures derived from them, which identify no Install, are kept without a limit.
- Site logs
- A short period, for security and troubleshooting.
Where a claim, an investigation or a legal obligation requires it, we keep what is relevant for as long as that requires and no longer.
9. SECURITY
Personal information is encrypted in transit. Access is limited to those who need it and is protected by multi-factor authentication. Payment card details never reach our systems. If a breach affects your personal information and the law requires us to tell you, we will, without undue delay.
To report a vulnerability, write to [email protected].
10. CHILDREN
The Software and our services are for organisations. They are not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe we have, write to [email protected] and we will delete it.
11. CHANGES TO THIS POLICY
We will post any change here and update the version date. Where a change materially affects what we do with information we already hold, we will tell account holders by email before it takes effect. Earlier versions are available on request.
SCHEDULE 1 -- CHECK-IN FIELDS
These are the fields section 3.1 refers to. They match Schedule B of the End User License Agreement and the check-in page of the Administrator Guide; if the three ever disagree, that is a defect, and reports of it go to [email protected].
- installId
- A random identifier generated by your Install. Not derived from your network, hardware or account.
- licenceId
- The identifier of your Licence Key.
- version
- The Software version running.
- meteredRate
- The measured flow rate -- one number.
- counts
- Operational totals: exporters seen, collector instances, records limited by the capacity ceiling, days since the last successful check-in.
NO FLOW RECORDS. NO IP ADDRESSES FROM YOUR NETWORK. NO HOST NAMES, INTERFACE NAMES OR DEVICE NAMES. NO USER IDENTITIES. NO CREDENTIALS. NO CONFIGURATION. NO DASHBOARD, QUERY OR REPORT CONTENT.
END OF POLICY