Table of Contents
GDPR Privacy Policy & Data Handling Framework
This Privacy Policy outlines how Kernax Asset Architecture manages, processes, and cryptographically secures corporate and personal data. We are committed to absolute transparency and strict adherence to the General Data Protection Regulation (GDPR) of the European Union and the regulatory mandates of the IFSCA.
Welcome to the Kernax Institutional Portal (www.kernax.de). Protecting your corporate and personal data is fundamental to our operational architecture. As an enterprise utilizing Distributed Ledger Technology (DLT) and AI-driven Carbon Border Adjustment Mechanism (CBAM) auditing tools, we enforce stringent data governance protocols.
1. Data Controller & EU Representation
For the purposes of the General Data Protection Regulation (GDPR) and the Indian Digital Personal Data Protection Act (DPDPA), the primary Data Controller is:
Processing Area, GIFT SEZ, Gandhinagar
Gujarat 382355, India.
Email: privacy@kernax.de
EU Representative (Art. 27 GDPR): Because our primary operational infrastructure services European institutional clients, we have appointed a localized representative within the European Union. Legal inquiries and regulatory communications from EU supervisory authorities may be directed to our nominated trustee services operating in Berlin, Germany.
2. Scope of Data Collection
We collect data strictly necessary to fulfill our institutional regulatory requirements, anti-money laundering (AML) obligations, and the generation of Scope 3 CBAM declarations. The data we collect includes:
- Corporate Identifiers: Entity names, EORI numbers, CBAM Registry IDs, and registered addresses.
- Executive Contact Data: Corporate email addresses, full names of authorized signatories, business telephone numbers, and LinkedIn URLs (submitted via our gated Institutional Access portal).
- KYC/AML Documentation: Passports, Director Identification Numbers (DIN), and proof of corporate beneficial ownership required under IFSCA FinTech Sandbox regulations.
- Technical Telemetry: IP addresses, browser types, and cryptographic wallet addresses (Public Keys) interacting with our ERC-3643 compliant smart contracts.
3. Legal Basis for Processing (Art. 6 GDPR)
Our data processing activities are anchored in the following legal bases:
- Contractual Necessity (Art. 6(1)(b)): To provide access to the Kernax Institutional Data Room, issue digital tokens, and facilitate fractional asset acquisition.
- Legal Obligation (Art. 6(1)(c)): To comply with strict AML/KYC mandates dictated by the International Financial Services Centres Authority (IFSCA) and to generate accurate customs schema for European Commission CBAM declarations.
- Legitimate Interests (Art. 6(1)(f)): To monitor the security of our IT infrastructure and protect our smart contracts against cyber-exploits and fraud.
4. Cross-Border Data Transfers
Kernax operates a cross-border infrastructure bridging the EU and the GIFT City Special Economic Zone (India). Data submitted via kernax.de is processed in the EU and may be securely transferred to our central servers in India.
To ensure an adequate level of data protection in compliance with Chapter V of the GDPR, all such cross-border transfers are safeguarded by Standard Contractual Clauses (SCCs) approved by the European Commission, combined with robust, end-to-end encryption protocols in transit and at rest.
5. Crucial Notice: Blockchain Immutability & GDPR
Kernax utilizes public/permissioned distributed ledgers (e.g., the Polygon network) to record the fractional ownership of real-world assets and retire carbon credits.
It is a fundamental technological characteristic of blockchain networks that data written to the ledger is immutable and cannot be deleted, altered, or destroyed.
Our Compliance Strategy:To reconcile immutability with the GDPR "Right to Erasure" (Art. 17), Kernax never writes Personally Identifiable Information (PII) or plaintext corporate data to the public blockchain. We utilize a dual-layer architecture:
• Off-Chain (Erasable): All KYC data, names, and contact details are stored in highly secure, off-chain, centralized databases. This data can be modified or deleted upon request.
• On-Chain (Immutable): Only cryptographic hashes, anonymous wallet addresses (0x...), and specific asset metrics (e.g., Carat weight, tCO₂e offset) are recorded on the ledger.
6. Data Retention Policy
We adhere to the principle of storage limitation. However, as a regulated financial infrastructure operating within the IFSCA Sandbox, we are subject to statutory retention mandates:
- KYC and Transactional Data: Retained for a mandatory period of seven (7) years following the termination of the business relationship or the expiration of the Limited Use Authorisation (LUA) to comply with anti-money laundering legislation.
- General Inquiry Data: Email addresses and profiles submitted for un-executed inquiries are purged 12 months after the last point of contact.
7. Data Subject Rights (EU Users)
Under the GDPR, individuals and authorized corporate representatives possess the following rights regarding their personal data:
- Right of Access (Art. 15): Request a copy of the data we hold concerning your entity.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Right to Erasure / "Right to be Forgotten" (Art. 17): Request deletion of your off-chain data, subject to overriding statutory retention laws (see Section 6).
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to Lodge a Complaint (Art. 77): If you believe our processing infringes data protection laws, you retain the right to lodge a complaint with a supervisory authority in your EU Member State.
To exercise these rights, please submit a formal request from an authorized corporate email to privacy@kernax.de.
8. Cryptographic & Operational Security
Kernax deploys institutional-grade security architectures. All sensitive documents (e.g., IGI certificates, Settlement Deeds) utilized in our Schedule III transparency dashboards are anchored via IPFS (InterPlanetary File System) to prevent unauthorized tampering. Off-chain database architectures are safeguarded by strict Role-Based Access Controls (RBAC), multi-factor authentication (MFA) for all internal engineering nodes, and routine Vulnerability Assessment and Penetration Testing (VAPT).