Kerbes LogoKerbesBack to home

Privacy Policy

Last updated: January 15, 2026

Introduction

Kerbes ("we", "our", "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our Endpoint Detection and Response (EDR) service enhanced by artificial intelligence. By using our Service, you accept the practices described in this policy.

1. Information We Collect

1.1 Account Information

When creating your account, we collect:

  • Full name and contact information (professional email address)
  • Company information (name, size, industry sector)
  • Billing and payment information
  • Login credentials (username, encrypted password)

1.2 System Monitoring Data

To provide our EDR protection services, we collect and analyze:

  • System process metadata (name, PID, execution path, timestamp)
  • Network activities (incoming/outgoing connections, IP addresses, ports)
  • File and system registry modifications
  • Security events and alerts generated by our system
  • File analysis results and detected suspicious behaviors

Important: We do NOT collect the content of your personal files, your passwords, your sensitive financial data, or the content of your communications. We only analyze metadata and behaviors necessary for threat detection.

1.3 Usage Data

We collect information about your use of the Service:

  • Access and authentication logs
  • Interactions with the user interface and AI advisor
  • Configuration preferences and settings
  • Reports and alerts viewed

1.4 Technical Data

  • IP address and approximate location information
  • Operating system type and version
  • Hardware information (processor, memory, disk)
  • Installed EDR agent version
  • Cookies and similar tracking technologies

2. Use of Information

We use your information to:

  • Provide and improve the Service: Real-time monitoring, threat detection, report generation, and AI advisor operation
  • Security and fraud prevention: Detection and prevention of malicious activities, protection of your system and our infrastructure
  • Communication: Sending security alerts, important notifications, and responses to your support requests
  • Billing and account management: Payment processing, subscription management, and account administration
  • Legal compliance: Compliance with legal and regulatory obligations, response to legitimate judicial requests
  • AI improvement: Training and improvement of our threat detection AI models (with data anonymization)

3. Information Sharing

We never sell your personal data. We may share your information only in the following cases:

  • Service providers: With trusted third-party providers who help us operate the Service (hosting, payment, support), under strict confidentiality agreements
  • Legal obligations: When required by law, court order, or legitimate government request
  • Protection of our rights: To protect our rights, property, security, or that of our users
  • With your consent: In any other case, only with your explicit consent

4. Data Security

We implement robust technical and organizational security measures to protect your data:

  • Encryption: Encryption in transit (TLS 1.3) and at rest (AES-256) for all sensitive data
  • Restricted access: Data access limited to authorized employees requiring this information for their functions
  • Continuous monitoring: 24/7 monitoring of our systems to detect and prevent unauthorized access
  • Strong authentication: Multi-factor authentication for administrative access
  • Regular audits: Penetration testing and periodic security audits
  • Secure backups: Regular backups with geographic replication

Despite our efforts, no system is completely secure. We cannot guarantee absolute security, but we commit to promptly notifying affected users in case of data breach in accordance with applicable regulations.

5. Your Rights

In accordance with GDPR and data protection laws, you have the following rights:

  • Right of access: Obtain a copy of your personal data that we hold
  • Right to rectification: Correct your inaccurate or incomplete data
  • Right to erasure: Request deletion of your data under certain circumstances
  • Right to portability: Receive your data in a structured and commonly used format
  • Right to object: Object to the processing of your data for certain purposes
  • Right to restriction: Request limitation of the processing of your data
  • Right to withdraw consent: Withdraw your consent at any time when processing is based on consent

To exercise these rights, contact us at privacy@kerbes.us. We will respond to your request within one month.

6. Data Retention

We retain your personal data for as long as necessary to provide the Service and comply with our legal obligations. System monitoring data is retained for a maximum period of 12 months, unless legal obligation requires longer retention. Account data is retained for the duration of your subscription and up to 3 years after termination, in accordance with accounting and legal obligations. You may request early deletion of your data, subject to legal retention obligations.

7. Cookies and Tracking Technologies

We use cookies and similar technologies to improve your experience, analyze Service usage, and ensure security. Essential cookies are necessary for the Service to function and cannot be disabled. You can manage your cookie preferences through your browser settings.

8. International Transfers

Your data may be transferred and stored in countries outside your country of residence. We ensure that these transfers are carried out in accordance with applicable data protection laws, including through the use of standard contractual clauses approved by the European Commission or other appropriate protection mechanisms.

9. Children

Our Service is not intended for persons under 18 years of age. We do not knowingly collect personal data from children. If we learn that we have collected data from a child, we will take steps to delete this information.

10. Modifications to This Policy

We may modify this Privacy Policy from time to time. Significant modifications will be communicated by email or via a notification in the Service. The "Last updated" date at the top of this page indicates when the policy was last revised. We encourage you to regularly consult this page.

11. Contact

For any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

Kerbes - Data Protection Department

Email: privacy@kerbes.us

Contact page: /contact

You also have the right to file a complaint with the data protection authority of your country if you believe that the processing of your personal data violates applicable laws.

© 2026 Kerbes. All rights reserved.

Terms of UseHome