KESTREL ADVANCED SYSTEMS PTE. LTD.
COOKIE AND SIMILAR TECHNOLOGIES POLICY
Effective Date: 4 October 2026
Last Updated: 4 October 2026
01ABOUT THIS POLICY
This Cookie and Similar Technologies Policy (the “Cookie Policy”) explains how Kestrel Advanced Systems Pte. Ltd. (“Kestrel”, “we”, “us”, or “our”) uses cookies, browser storage and other similar technologies in connection with our websites, enterprise dashboard and other browser-based interfaces.
This Cookie Policy explains, among other things:
- what cookies and similar technologies are;
- which technologies Kestrel currently uses;
- why those technologies are used;
- what information may be stored, accessed or otherwise processed through them;
- how long they remain on a device;
- when consent may or may not be required;
- how users can control cookies and browser storage;
- when information may be disclosed to service providers or other recipients; and
- how to contact us about our use of these technologies.
This Cookie Policy is intended to provide detailed technical and privacy information for visitors, authorised users, enterprise customers, security teams, procurement teams, privacy professionals and other persons who interact with Kestrel's online services.
The mere inclusion of a category or type of technology in this Cookie Policy does not mean that Kestrel currently uses that technology. Where we describe technologies that may be used in the future, we expressly distinguish those technologies from our verified current implementation.
02ABOUT KESTREL
Kestrel Advanced Systems Pte. Ltd. is a private company limited by shares incorporated in Singapore.
Legal entity: Kestrel Advanced Systems Pte. Ltd.
UEN: 202644596C
Registered office and business address:
Blk 31, #01-16C
535 Clementi Road
Singapore 599489
Primary website: https://kestreladvanced.com
Enterprise dashboard: https://kestreladvanced.com/admin
Privacy Policy: https://kestreladvanced.com/privacy
Master Terms of Service: https://kestreladvanced.com/terms
Cookie Policy: https://kestreladvanced.com/cookies
General enquiries: contact@kestreladvanced.com
Legal notices: legal@kestreladvanced.com
Privacy and data-protection enquiries: privacy@kestreladvanced.com
Our Data Processing Agreement and Security Addendum are available upon request from legal@kestreladvanced.com until their public URLs are deployed.
Information regarding our subprocessors is available upon request from privacy@kestreladvanced.com until a public subprocessor list is deployed.
03OUR SERVICES
Kestrel provides a business-to-business enterprise AI governance and security control plane.
Depending on the applicable deployment and configuration, the Kestrel platform may support governance and security functions relating to AI prompts, model responses, agents, tool actions, models, data, policies, approvals, runtime enforcement, audit evidence, governance workflows, continuous assurance and executive oversight.
Our Services may include:
- our public marketing website;
- authenticated enterprise dashboards;
- APIs;
- gateways;
- administrative interfaces;
- demonstrations;
- pilots;
- support interactions; and
- production deployments.
Kestrel is designed for enterprise and organisational use and is not offered for personal, family or household consumer use.
Our Services are not directed to children. No person under 18 years of age may establish or administer a Kestrel Account.
Customer-specific API endpoints, gateway domains and deployment environments may be specified in an applicable Order Form, statement of work or deployment documentation.
API or gateway traffic does not necessarily involve browser cookies. Browser-based access to the Kestrel administrative dashboard, however, uses browser technologies for authentication and security as described below.
04SCOPE OF THIS COOKIE POLICY
This Cookie Policy applies to cookies and similar technologies used by or on behalf of Kestrel through browser-accessible Kestrel properties, including, as applicable:
- kestreladvanced.com;
- kestreladvanced.com/admin;
- other Kestrel-controlled web interfaces; and
- browser-accessible customer deployment interfaces where Kestrel controls the relevant technology.
The current Kestrel-controlled production browser origin is kestreladvanced.com. Any customer-specific browser-accessible deployment origin will be documented before use and added to this Policy where Kestrel controls the relevant technology.
This Cookie Policy does not automatically describe technologies independently deployed by an enterprise customer on systems or domains controlled solely by that customer.
Where a customer determines why and how personal data is processed through the Kestrel Services, that customer may have separate responsibilities relating to cookies, browser storage and privacy notices.
05RELATIONSHIP WITH OUR OTHER LEGAL DOCUMENTS
This Cookie Policy should be read together with our:
- Privacy Policy;
- Master Terms of Service;
- applicable Order Form;
- Data Processing Agreement, where applicable;
- Security Addendum, where applicable; and
- applicable customer deployment documentation.
Our Privacy Policy explains more broadly how Kestrel collects, uses, discloses, protects, retains and transfers personal data.
This Cookie Policy provides more specific information about browser storage and similar technologies.
If a technology described in this Cookie Policy processes personal data, the processing of that personal data is also subject to our Privacy Policy and applicable data-protection law.
Nothing in this Cookie Policy is intended to limit any non-waivable right or remedy available under applicable law.
06TERRITORIAL AVAILABILITY
6.1 EU & EEA Availability
EU & EEA Availability. Kestrel is not currently available for deployment within the European Union or European Economic Area as we continue our work toward supporting applicable requirements under the EU Artificial Intelligence Act. EU and EEA availability will be introduced once the necessary compliance requirements have been addressed. Please refer to our legal terms for current territorial restrictions.
This deployment restriction does not necessarily mean that Kestrel's public website is outside the territorial scope of European privacy, electronic communications or similar laws.
Website accessibility and availability of the Kestrel enterprise product for deployment are separate matters.
Applicable legal requirements may depend on factors including the visitor's location, Kestrel's activities, targeting, the nature of the processing, applicable statutory thresholds and applicable rules concerning extraterritorial jurisdiction.
07WHAT IS A COOKIE?
A cookie is a small piece of information that a website or web application causes a browser to store.
Cookies may allow a website or application to recognise a browser or session, maintain authentication, protect transactions, remember a user's selections, provide requested functionality or perform other functions.
A cookie may contain or reference identifiers or other information.
A cookie should not be assumed to be anonymous merely because it does not contain a person's name. Depending on the information stored, associated systems and context, a cookie identifier may constitute or become associated with personal data.
08FIRST-PARTY AND THIRD-PARTY COOKIES
A first-party cookie is generally a cookie set in connection with the domain or service that the user is directly accessing.
A third-party cookie is generally associated with another organisation, domain or third-party service integrated into a website or application.
Kestrel's currently verified authentication and security cookies described in Section 16 are first-party technologies.
No non-essential third-party cookie has presently been verified in the application inventory underlying this Policy.
That statement is limited to the technology that has been reviewed. It is not a representation that no third-party cookie, request or similar technology can exist anywhere in Kestrel's production infrastructure.
CONFIRM BEFORE PUBLICATION: complete a production scan covering website code, deployed assets, CDN, DNS, reverse proxies, WAF, load balancers, support tools, forms, embedded media, analytics, monitoring and marketing integrations before stating that no other third-party cookies are deployed.
09SESSION AND PERSISTENT TECHNOLOGIES
Cookies are sometimes described as session cookies or persistent cookies.
A session cookie is generally removed when the relevant browser session ends.
A persistent cookie may remain until its configured expiration time, until the browser removes it, or until the user manually deletes it.
Separately, an authentication session maintained on Kestrel's servers may expire or be invalidated independently of whether browser-side information remains.
Accordingly, the existence or deletion of a browser cookie does not necessarily determine whether related server-side records exist.
10BROWSER STORAGE IS NOT THE SAME AS A COOKIE
Modern browsers provide storage technologies such as localStorage and sessionStorage.
These technologies are not HTTP cookies.
They nevertheless permit a website or application to store information on a user's device and may therefore be subject to privacy, device-access or electronic communications laws in certain jurisdictions.
Kestrel currently uses both localStorage and sessionStorage for certain verified dashboard and interface functions described in this Policy.
localStorage
Information placed in localStorage may remain after a browser tab or browser window is closed. It ordinarily remains until it is overwritten, removed by the application or cleared through browser or device controls.
sessionStorage
Information placed in sessionStorage is ordinarily scoped to a browser tab or browser session and is generally removed when that browser session ends.
Actual browser behaviour can vary by browser, privacy mode, browser extension, configuration and device.
11OTHER SIMILAR TECHNOLOGIES
Technologies that may fall within the broader concept of cookies or similar device-access technologies can include:
- localStorage;
- sessionStorage;
- tracking pixels;
- web beacons;
- SDK identifiers;
- scripts;
- tags;
- cache-based identifiers;
- link-decoration technologies;
- embedded content;
- device identifiers;
- browser or device fingerprinting technologies; and
- other technologies that store information on, or access information from, a user's device.
The inclusion of a technology in this definition does not mean Kestrel currently deploys it.
Unless otherwise identified in the current technology tables below, Kestrel has not verified the deployment of advertising pixels, behavioural advertising technologies, fingerprinting technologies or equivalent tracking systems.
12CURRENT IMPLEMENTATION AT A GLANCE
Based on Kestrel's current verified application inventory, Kestrel uses:
Cookies
kestrel_session— authentication and account security;kestrel_csrf— cross-site request forgery protection;kestrel_oidc_state— OpenID Connect authentication transaction security;kestrel_auth_transaction— direct sign-in transaction security; andkestrel_signup_grant— temporary proof of completed email verification during sign-up.- Browser storage
kestrel_active_tenant— localStorage;kestrel_sso_session— sessionStorage;kestrel-landing-seen— sessionStorage; andkestrel.audit.filters.open— localStorage.
A development workflow has also been identified that uses:
kestrel_admin_key— localStorage in the current development workflow only.
The kestrel_admin_key entry is not represented as an intended production browser-storage practice.
CONFIRM BEFORE PUBLICATION: Security and Engineering must verify that
kestrel_admin_keyis not stored in browser localStorage in any production deployment and document the production authentication mechanism.
A legacy kestrel_registry_tenant storage key is removed during tenant-context migration and is not created by the current application source. It is therefore not listed as an active Kestrel storage technology.
13CATEGORIES OF TECHNOLOGIES
13.1 Strictly Necessary Technologies
Strictly necessary technologies support functionality required to deliver a service requested by the user or to maintain essential security.
They may include technologies used for:
- authentication;
- session management;
- CSRF protection;
- fraud prevention;
- account security;
- transaction integrity;
- secure routing; and
- other functionality without which the requested service cannot operate securely.
Kestrel currently uses technologies in this category.
13.2 Authentication Technologies
Authentication technologies allow Kestrel to determine whether a user has successfully completed an authorised sign-in process and to maintain the resulting authenticated session.
Kestrel currently uses authentication technologies.
13.3 Security and Fraud-Prevention Technologies
Security technologies can assist with preventing unauthorised access, cross-site request forgery, session misuse, authentication attacks and similar security risks.
Kestrel currently uses technologies in this category.
13.4 Load-Balancing Technologies
Load-balancing technologies can be used to route network traffic or maintain session affinity across infrastructure.
CONFIRM BEFORE PUBLICATION: Infrastructure must determine whether any production load balancer, reverse proxy, CDN or edge provider currently sets a browser cookie or other device identifier for load balancing, routing or affinity.
No load-balancing cookie is listed as verified in the current inventory.
13.5 Preference and Functionality Technologies
Preference technologies may remember interface selections or application state.
Kestrel currently uses limited browser-storage entries for functionality such as:
- remembering the active enterprise tenant or workspace;
- recording browser-session SSO state;
- remembering whether the user has seen the initial landing experience; and
- remembering whether audit-filter controls are open.
13.6 Performance Technologies
Performance technologies may measure application responsiveness, page performance or other operational characteristics.
No non-essential performance cookie or browser-storage technology has been verified in the current application inventory.
CONFIRM BEFORE PUBLICATION: Engineering and Infrastructure must verify whether production application-performance monitoring, real-user monitoring, error monitoring or observability software stores or accesses information on user devices.
13.7 Analytics Technologies
Analytics technologies may be used to measure how people interact with a website or application.
No Google Analytics, Google Tag Manager, Mixpanel, Segment, PostHog, Microsoft Clarity, Hotjar or equivalent analytics/tracking integration has been identified in the current application code reviewed for this Policy.
This statement is not a guarantee that no analytics technology exists elsewhere in the production environment.
CONFIRM BEFORE PUBLICATION: Marketing, Engineering and Infrastructure must verify all production website, deployment, tag-management, analytics, observability and integration configurations.
13.8 Advertising Technologies
Advertising technologies may be used to deliver, attribute, measure or personalise advertising, including behavioural or cross-context advertising.
No advertising network or behavioural-advertising pixel has been identified in the current application code.
Kestrel does not represent that this conclusion is final until the production audit described in this Policy is completed.
Kestrel must not deploy non-essential advertising or cross-context tracking technologies without first implementing any notice, consent and user-control mechanisms required by applicable law.
13.9 Social-Media Technologies
Social-media platforms may offer widgets, embedded content or tracking technologies that allow social functionality or measurement.
No social-media tracking technology has been verified in the current inventory.
CONFIRM BEFORE PUBLICATION: Marketing and Engineering must verify whether any social-media embed, conversion tag, social login integration or tracking script is deployed on any Kestrel-controlled production page.
13.10 Unclassified Technologies
A technology may temporarily be classified as unclassified while its function or legal treatment is being evaluated.
Kestrel should not intentionally deploy an unclassified non-essential technology to production without determining its purpose, data use, retention period, responsible provider and consent requirements.
14INFORMATION THAT MAY BE PROCESSED
Depending on the technology, configuration and context, Kestrel's current browser technologies may process information such as:
- opaque session identifiers;
- authentication state;
- authentication transaction information;
- CSRF security values;
- tenant or workspace selections;
- browser-session state;
- interface-state information;
- timestamps;
- requested URLs;
- IP addresses;
- browser and device information;
- user-agent information;
- HTTP referrer information;
- security events; and
- information needed to protect or administer authenticated sessions.
A particular item of information does not necessarily identify an individual by itself. However, information may constitute personal data where an individual can be identified from the information alone or together with other information to which the relevant organisation has or is likely to have access.
We do not describe cookie identifiers or technical identifiers as “anonymous” merely because they do not contain a person's name.
15WHY WE USE THESE TECHNOLOGIES
We may use the verified technologies described in this Policy for purposes including:
15.1 Authenticating authorised users
We use authentication technologies to establish and maintain authorised dashboard sessions following successful authentication.
15.2 Protecting user accounts and Kestrel systems
We use security technologies to reduce the risk of unauthorised access, session misuse, cross-site request forgery and related attacks.
15.3 Validating authentication transactions
Temporary authentication-state technologies are used to protect OpenID Connect login flows and validate the integrity of authentication transactions.
15.4 Providing requested enterprise functionality
Browser storage can remember the active enterprise tenant or workspace and limited interface state.
15.5 Maintaining session-related application state
Browser storage may identify whether an SSO session is active in the current browser session and whether a particular landing experience has already been displayed.
15.6 Operating, protecting and troubleshooting the Services
Technical request information may also be processed through ordinary network communications, server logs, security systems and infrastructure necessary to operate and defend the Services.
The processing of server logs and other server-side data is addressed principally in our Privacy Policy and other applicable documentation rather than solely by this Cookie Policy.
16DETAILED CURRENT COOKIE AND BROWSER-STORAGE REGISTER
The table below describes the technologies currently identified in Kestrel's application inventory.
| Name | Provider / Controller | Domain / Origin | Path | Technology | Party | Category | Purpose | Data stored or accessed | When set | Duration | Session / Persistent | HttpOnly | Secure | SameSite | Consent position | Recipients | Transfer considerations | Verification |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
kestrel_session | Kestrel Advanced Systems Pte. Ltd. | Host-only on kestreladvanced.com in the current production architecture | / | HTTP cookie | First-party | Strictly necessary; authentication; security | Maintains authenticated SSO dashboard session and supports account security | Opaque session token. Kestrel's server stores only the token hash. | After successful authentication | 8 hours absolute duration, with a server-side 2-hour inactivity timeout | Persistent browser cookie with Expires and Max-Age attributes | Yes | Yes | Strict | Used as a necessary authentication/security technology. Applicability of any consent exemption depends on jurisdiction. | Kestrel systems and authorised service providers only as operationally necessary. [CONFIRM BEFORE PUBLICATION: verify relevant infrastructure/service-provider recipients.] | [CONFIRM BEFORE PUBLICATION: identify countries from which supporting infrastructure may process associated technical data.] | Cookie purpose, host-only scope, duration and attributes verified in source, production configuration and production authentication-transaction testing. |
kestrel_csrf | Kestrel Advanced Systems Pte. Ltd. | Host-only on kestreladvanced.com in the current production architecture | / | HTTP cookie | First-party | Strictly necessary; security | Protects authenticated state-changing requests against cross-site request forgery | CSRF verification token/value read by the dashboard and submitted in the X-Kestrel-CSRF request header | During authenticated session establishment/security flow | 8 hours absolute duration, aligned with the authenticated session | Persistent browser cookie with Expires and Max-Age attributes | No, because the dashboard must read the value | Yes | Strict | Used as a necessary security technology. Applicability of any consent exemption depends on jurisdiction. | Kestrel systems and authorised operational service providers where applicable. [CONFIRM BEFORE PUBLICATION: verify provider recipients.] | [CONFIRM BEFORE PUBLICATION: verify relevant cross-border infrastructure.] | Purpose, host-only scope, duration and attributes verified in source and production configuration. |
kestrel_oidc_state | Kestrel Advanced Systems Pte. Ltd. | Host-only on kestreladvanced.com in the current production architecture | / | HTTP cookie | First-party | Strictly necessary; authentication; security | Binds and validates the OpenID Connect login transaction, including state, nonce, PKCE and return-path handling | Temporary authentication-transaction state | During initiation of an OpenID Connect authentication transaction | 10 minutes; cleared after authentication callback processing | Persistent browser cookie with Expires and Max-Age attributes | Yes | Yes | Lax | Used as a necessary authentication/security technology. Applicability of any consent exemption depends on jurisdiction. | Kestrel systems. Authentication flows may separately interact with the applicable identity provider. [CONFIRM BEFORE PUBLICATION: verify production identity-provider arrangements.] | [CONFIRM BEFORE PUBLICATION: verify whether authentication infrastructure involves processing outside Singapore.] | Purpose, duration, host-only scope and attributes verified in source and production configuration. |
kestrel_auth_transaction | Kestrel Advanced Systems Pte. Ltd. | Host-only on kestreladvanced.com | / | HTTP cookie | First-party | Strictly necessary; authentication; security | Binds the direct Cognito sign-in transaction to the browser and protects the return path | Opaque temporary authentication-transaction token; the server stores only a token hash and transaction metadata | When direct sign-in, sign-up or invitation authentication begins | 15 minutes; cleared when the direct authentication transaction completes | Persistent browser cookie with Expires and Max-Age attributes | Yes | Yes | Strict | Used as a necessary authentication/security technology. Applicability of any consent exemption depends on jurisdiction. | Kestrel systems and Amazon Cognito as required for authentication | [CONFIRM BEFORE PUBLICATION: verify the final Cognito processing and support locations.] | Name, purpose, host-only scope, duration and attributes verified in source and against the production endpoint on 4 October 2026. |
kestrel_signup_grant | Kestrel Advanced Systems Pte. Ltd. | Host-only on kestreladvanced.com in the current production architecture | / | HTTP cookie | First-party | Strictly necessary; authentication; security | Temporarily proves that the browser completed email verification before continuing an authorised sign-up | Opaque temporary grant token; the server stores only a token hash and verified email binding | After successful email verification during an authorised sign-up | 20 minutes; consumed when the sign-up authentication flow continues | Persistent browser cookie with Expires and Max-Age attributes | Yes | Yes | Lax | Used as a necessary authentication/security technology. Applicability of any consent exemption depends on jurisdiction. | Kestrel systems and Amazon Cognito as required for sign-up | [CONFIRM BEFORE PUBLICATION: verify the final Cognito processing and support locations.] | Name, purpose, host-only scope, duration and attributes verified in source and production configuration. |
kestrel_active_tenant | Kestrel | [CONFIRM BEFORE PUBLICATION: identify every production web origin on which this localStorage key is used.] | N/A | localStorage | First-party browser storage | Functionality / workspace state | Remembers the user's currently active enterprise tenant or workspace | Tenant/workspace selection identifier | When an applicable tenant/workspace is selected or application state is established | Retained until changed, removed, the user signs out, or browser storage is cleared | Persistent browser storage | N/A | N/A | N/A | Depends on applicable law and whether treatment as necessary/requested functionality is available. | Kestrel application code; [CONFIRM BEFORE PUBLICATION: verify whether the value is transmitted to any service provider.] | [CONFIRM BEFORE PUBLICATION: verify associated server/API destinations and transfer locations.] | Use and purpose verified in current application inventory. |
kestrel_sso_session | Kestrel | [CONFIRM BEFORE PUBLICATION: identify applicable production origin.] | N/A | sessionStorage | First-party browser storage | Authentication / functionality | Records that an SSO session is active in the current browser session | SSO session-state indicator | During SSO/authenticated application use | Until logout or browser-session end | Session browser storage | N/A | N/A | N/A | Generally associated with requested authentication functionality; jurisdiction-specific treatment must be confirmed. | Kestrel application; [CONFIRM BEFORE PUBLICATION: verify any external disclosure.] | [CONFIRM BEFORE PUBLICATION: verify associated transfer locations.] | Verified in current application inventory. |
kestrel-landing-seen | Kestrel | [CONFIRM BEFORE PUBLICATION: identify applicable production origin.] | N/A | sessionStorage | First-party browser storage | Functionality | Prevents repetition of the initial landing experience during the same browser session | Indicator that the initial landing experience has been displayed | When the landing experience is displayed | Browser session | Session browser storage | N/A | N/A | N/A | [CONFIRM BEFORE PUBLICATION: Legal/Privacy to classify consent or statutory-exemption position for jurisdictions in which this technology is accessible.] | Kestrel application | Ordinarily local browser state unless transmitted. [CONFIRM BEFORE PUBLICATION: verify no transmission to third parties.] | Verified in current application inventory. |
kestrel.audit.filters.open | Kestrel | [CONFIRM BEFORE PUBLICATION: identify applicable production origin.] | N/A | localStorage | First-party browser storage | Preference / functionality | Remembers whether audit-filter controls are open | Interface preference/state | When the user changes or uses the relevant audit-filter interface | Until changed or browser storage is cleared | Persistent browser storage | N/A | N/A | N/A | [CONFIRM BEFORE PUBLICATION: Legal/Privacy to determine applicable jurisdiction-specific consent or exemption treatment.] | Kestrel application | Ordinarily local browser state unless transmitted. [CONFIRM BEFORE PUBLICATION: verify no transmission to third parties.] | Verified in current application inventory. |
17DEVELOPMENT-ONLY STORAGE
The following technology has been identified in Kestrel's current development workflow:
kestrel_admin_key
kestrel_admin_key uses localStorage in the current development workflow.
It is not described as an intended production storage practice.
CONFIRM BEFORE PUBLICATION: Security and Engineering must verify that production builds do not store privileged administrative credentials, administrative API keys or equivalent secrets in browser localStorage under
kestrel_admin_keyor another key.
If production architecture does use browser-accessible administrative credentials, this Policy and the relevant security design must be reassessed before publication.
18LEGACY STORAGE
A legacy storage key identified as kestrel_registry_tenant may be removed during migration.
It is not currently identified as being actively set and is therefore not included in the active technology register.
Current source review confirms that kestrel_registry_tenant is removed during tenant-context migration and is not actively set. Production runtime verification remains part of Kestrel's release audit.
19THIRD-PARTY TECHNOLOGIES AND EXTERNAL RESOURCES
Kestrel's current application review has not identified an active integration with:
- Google Analytics;
- Google Tag Manager;
- Meta Pixel;
- Hotjar;
- Microsoft Clarity;
- Mixpanel;
- Segment;
- PostHog;
- HubSpot;
- Intercom;
- an advertising network; or
- an equivalent analytics or behavioural-tracking system.
These are examples of technologies specifically checked in the current application review. Their inclusion here does not imply that Kestrel has used or contracted with those providers.
A complete production audit remains necessary because technologies may also be introduced through deployment configuration, infrastructure, DNS, CDN configuration, reverse proxies, customer-support systems, marketing tooling or other systems outside the reviewed application source code.
20THIRD-PARTY / EXTERNAL TECHNOLOGY REGISTER
| Technology / Provider | Current status | Type | Purpose | Cookies verified? | Information potentially disclosed | Consent position | Action required |
|---|---|---|---|---|---|---|---|
| Google Fonts through fonts.googleapis.com | External request identified in current website/application implementation | Externally loaded web resource; not itself characterised here as a cookie | Delivers the Inter font used by the interface | No cookie has been verified from this integration in the reviewed implementation | An external resource request may expose technical network information such as IP address, user agent, referrer and request time to the recipient of the request | A network request is not automatically equivalent to placement of a cookie. Applicable privacy/data-transfer requirements depend on the final implementation and jurisdiction. | [CONFIRM BEFORE PUBLICATION: determine whether Inter will be self-hosted before publication. If Google Fonts remains externally loaded, document the complete request chain, applicable provider, data processing, transfer implications and legal basis.] |
| Advertising networks | Not currently identified | Potential future third-party technology | Advertising | None verified | Not applicable to verified current implementation | Non-essential advertising/tracking must not be activated without required legal controls | Production audit required |
| Behavioural advertising pixels | Not currently identified | Potential future tracking technology | Cross-site/cross-context measurement or advertising | None verified | Not applicable to verified current implementation | Consent or other controls may be required depending on applicable law | Production audit required |
| Analytics platforms | Not currently identified | Potential future analytics technology | Analytics/measurement | None verified | Not applicable to verified current implementation | Jurisdiction-dependent; consent or an applicable statutory exception may be required | Production audit required |
| Social-media tracking technologies | Not currently identified | Potential future third-party technology | Social integration/measurement | None verified | Not applicable to verified current implementation | Jurisdiction-dependent | Production audit required |
21GOOGLE FONTS
Kestrel's current website implementation requests the Inter font through fonts.googleapis.com.
The retrieval of an externally hosted web resource normally requires a network request to the external host.
As part of an ordinary network request, technical information may be available to the receiving service, potentially including information such as:
- the requesting IP address;
- browser or user-agent information;
- the requested resource;
- referral information where transmitted; and
- request timing.
The existence of such a request does not, by itself, mean that a cookie is set.
CONFIRM BEFORE PUBLICATION: determine whether Kestrel will self-host the Inter font before launch/publication. If the font remains externally hosted, Privacy, Legal and Engineering must validate the final data flow and update the Privacy Policy, subprocessor disclosures and this Policy where required.
22INFRASTRUCTURE TECHNOLOGIES
Web infrastructure can itself introduce cookies or similar technologies.
Examples can include:
- content-delivery networks;
- web-application firewalls;
- bot-management systems;
- DDoS-protection providers;
- reverse proxies;
- load balancers;
- identity systems;
- error-monitoring tools;
- application-performance monitoring;
- support widgets;
- embedded video providers;
- online form providers; and
- other hosting or security services.
Their inclusion in this paragraph does not mean Kestrel currently uses a particular provider or that the provider places cookies.
CONFIRM BEFORE PUBLICATION: Infrastructure, Security and Engineering must audit production hosting, CDN, WAF, DDoS protection, load balancing, logging, monitoring, identity infrastructure and all externally loaded resources and add any storage/access technology discovered to this Policy.
23EMAIL AND LINK TRACKING
Some organisations use tracking parameters, redirect links or pixels in email communications.
Kestrel does not state in this Policy that such technologies are currently used.
CONFIRM BEFORE PUBLICATION: Marketing and Engineering must verify whether Kestrel's production email delivery systems use open-tracking pixels, click tracking, redirect tracking, link decoration or equivalent technologies.
If such technologies are introduced or confirmed, Kestrel must assess their disclosure and consent requirements and update the relevant notices before use where required.
24HOW SINGAPORE DATA-PROTECTION LAW APPLIES
Kestrel is established in Singapore and this Policy is drafted principally with reference to Singapore's Personal Data Protection Act 2012 (“PDPA”).
Where information collected, used or disclosed through cookies or similar technologies constitutes personal data, Kestrel manages that information in accordance with the PDPA to the extent the PDPA applies.
Depending on the circumstances, relevant obligations may include:
- accountability;
- notification of purposes;
- consent or a legally available form of deemed consent;
- purpose limitation;
- protection;
- retention limitation;
- access and correction;
- withdrawal of consent;
- transfer limitation; and
- data-breach notification.
Not every cookie or browser-storage value necessarily constitutes personal data.
Similarly, Singapore law does not require the same standalone opt-in mechanism for every use of a cookie.
Whether consent is required depends on the relevant information, purpose, circumstances and legal basis.
For functionality clearly requested by a user, Singapore law may in appropriate circumstances permit reliance on consent, deemed consent or another applicable legal basis without requiring a separate cookie-banner interaction.
Kestrel nevertheless provides this Policy to promote transparency regarding technologies used by our Services.
25LAWS OUTSIDE SINGAPORE
Persons may access Kestrel's public website from jurisdictions outside Singapore.
Where another jurisdiction's laws apply to Kestrel's use of cookies or similar technologies, we intend to apply legally required controls applicable to that processing.
Depending on the jurisdiction, this may include requirements relating to:
- prior consent;
- granular consent choices;
- strictly necessary technologies;
- statistical or analytics technologies;
- preference technologies;
- advertising technologies;
- third-party tracking;
- device storage and access;
- withdrawal of consent;
- records of consent; and
- disclosures concerning third parties.
For example, where the European ePrivacy framework, GDPR-standard consent requirements, the United Kingdom's Privacy and Electronic Communications Regulations or comparable laws apply, certain storage or access technologies may require prior consent unless an applicable statutory exemption is available.
Applicable exceptions and requirements vary by jurisdiction and may change over time.
Kestrel does not, by publishing this Policy, represent that every Kestrel service is offered in every jurisdiction or that every foreign privacy regime applies to Kestrel.
26STRICTLY NECESSARY TECHNOLOGIES AND CONSENT
Kestrel's presently verified cookies are principally used for authentication and security.
Where applicable law permits a strictly necessary or equivalent exemption for technologies required to authenticate a user, secure an account, protect an online service or provide functionality specifically requested by the user, Kestrel may use those technologies without asking the user to opt in to them separately.
Such technologies remain described transparently in this Policy.
Because an authenticated Kestrel dashboard depends on certain authentication and security controls, blocking them may prevent successful login or make it impossible for Kestrel to provide the requested authenticated service securely.
27OPTIONAL TECHNOLOGIES
Kestrel must not intentionally deploy a non-essential analytics, advertising, behavioural-tracking, cross-context tracking or optional-personalisation technology without first:
- identifying the technology;
- identifying its provider;
- documenting its purposes;
- determining what information it stores or accesses;
- determining its duration;
- determining whether personal data is processed;
- analysing applicable consent requirements;
- updating this Cookie Policy and other applicable notices;
- configuring any required consent-management controls; and
- verifying technically that the technology does not activate before any legally required consent has been obtained.
Where applicable law requires prior consent, optional technologies will not be activated merely because a user:
- continues browsing;
- closes a notice;
- has browser settings that accept cookies by default;
- agrees generally to Terms of Service;
- has been presented with a pre-selected control; or
- has accepted another unrelated processing purpose.
28COOKIE BANNERS AND PREFERENCE CENTRES
Based solely on the presently verified implementation, Kestrel has not identified a non-essential cookie that necessarily requires deployment of a general consent banner solely because of that cookie.
Whether Kestrel should display a notice, consent banner or preference centre nevertheless depends on the final production environment, applicable visitor jurisdictions and any additional technologies discovered during the required production audit.
CONFIRM BEFORE PUBLICATION: Legal and Privacy must determine whether the final production website requires a cookie banner, preference centre, jurisdiction-specific notice or geographic consent configuration.
If Kestrel introduces technologies for which consent is legally required, Kestrel will implement an appropriate mechanism designed to:
- prevent applicable optional technologies from activating before consent;
- provide meaningful information before the choice;
- permit purpose-level or category-level choices where required;
- allow acceptance and rejection without manipulative design;
- make withdrawal accessible;
- maintain appropriate records of consent;
- distinguish different versions of the applicable consent notice; and
- request fresh consent where a material change in technology or purpose requires it.
29GLOBAL PRIVACY CONTROL, DO NOT TRACK AND SIMILAR SIGNALS
Browsers and extensions may transmit signals such as Global Privacy Control (“GPC”), Do Not Track (“DNT”) or similar preference signals.
Standards and legal requirements governing these signals vary between jurisdictions.
Kestrel does not state that it currently interprets or honours a particular browser privacy signal unless that behaviour has been technically verified.
CONFIRM BEFORE PUBLICATION: Engineering, Privacy and Legal must test and document production handling of Global Privacy Control, Do Not Track and other legally recognised browser/device privacy signals.
Where applicable law requires Kestrel to recognise a valid privacy preference signal, Kestrel will implement the controls required by that law.
30HOW LONG TECHNOLOGIES REMAIN
Kestrel uses different retention periods depending on the function of the technology.
The presently verified browser-side periods are:
kestrel_session
Production authentication duration: 8 hours absolute, with server-side expiry after 2 hours of inactivity. Automated background activity must not be treated as user activity for purposes of extending the inactivity period.
kestrel_csrf
Aligned with the authenticated session; 8 hours absolute in production and invalidated when the associated server-side session expires.
kestrel_oidc_state
Approximately 10 minutes, and cleared after processing of the authentication callback.
kestrel_auth_transaction
15 minutes, and cleared after processing of the direct authentication transaction.
kestrel_signup_grant
20 minutes, and consumed when the authorised sign-up flow continues.
kestrel_active_tenant
Stored until it is changed, removed, the user signs out, or browser storage is cleared.
kestrel_sso_session
Stored for the current browser session and removed on logout or session end.
kestrel-landing-seen
Stored for the browser session.
kestrel.audit.filters.open
Stored until changed or the relevant browser storage is cleared.
These periods describe browser-side technologies.
Separate server-side authentication, operational, audit, security or legal records may have different retention periods under Kestrel's data-retention policies.
Deleting a cookie or clearing local browser storage does not necessarily delete related server-side records.
Please refer to our Privacy Policy for broader information regarding retention of personal data.
31LOGOUT, REVOCATION AND EXPIRY
Depending on the technology:
- logging out may remove authentication-related cookies or browser-storage entries;
- an authentication session may be invalidated server-side;
- a temporary authentication-state cookie may be removed after the login callback;
- a cookie may expire according to its configured lifetime;
- sessionStorage may disappear when the relevant browser session ends;
- localStorage may remain until application logic or the user removes it; and
- clearing browser data may remove cookies and browser-storage values.
A user's browser, extension or privacy settings may modify these behaviours.
Logout or deletion of browser-side information does not necessarily erase server-side security, audit, compliance or operational records.
32HOW TO CONTROL COOKIES
Most browsers provide controls that allow users to inspect, block or delete cookies.
Depending on the browser, users may be able to:
- view stored cookies;
- remove individual cookies;
- clear cookies for a particular website;
- block all cookies;
- block certain third-party cookies;
- restrict cross-site tracking; or
- configure site-specific storage permissions.
Browser interfaces and terminology differ between browser providers and versions.
Users should consult the privacy or security settings of their browser for the controls available on their device.
33HOW TO CLEAR BROWSER STORAGE
Browsers may also permit users to clear:
- localStorage;
- sessionStorage;
- site data;
- cached files; and
- other locally stored website information.
Clearing localStorage or sessionStorage may remove Kestrel interface or authentication state.
Depending on what is removed, the user may need to:
- authenticate again;
- reselect an enterprise tenant or workspace;
- repeat interface choices; or
- reload the application.
34CONSEQUENCES OF BLOCKING STRICTLY NECESSARY TECHNOLOGIES
If a browser blocks technologies required for authentication or security, some or all of the authenticated Kestrel Services may not operate correctly.
For example:
- the dashboard may be unable to maintain authentication;
- sign-in transactions may fail;
- security checks may fail;
- state-changing requests may be rejected;
- tenant or workspace selection may not persist; or
- security protections may be unable to operate as designed.
Kestrel does not recommend disabling technologies required to securely deliver an authenticated service if the user intends to use that service.
35PRIVATE OR INCOGNITO BROWSING
Private browsing, incognito mode and similar browser features may reduce or modify local persistence.
These modes do not necessarily prevent:
- all cookies;
- all local browser storage;
- all network requests;
- IP-address processing;
- server logs;
- security monitoring; or
- information processing by a service the user deliberately accesses.
Users should consult their browser provider for the precise behaviour of the privacy mode they use.
36WITHDRAWING CONSENT
Where Kestrel relies on consent for a technology, a user may withdraw that consent using the mechanism made available for that purpose.
CONFIRM BEFORE PUBLICATION: if a consent-management platform or preference centre is deployed, insert the direct method or link through which users can reopen Cookie Settings.
Withdrawal of consent does not retroactively invalidate processing that was lawful before consent was withdrawn.
After withdrawal, Kestrel will cease the relevant consent-based use to the extent required by applicable law, subject to any independent legal basis that lawfully applies.
Technologies that are strictly necessary or otherwise legally exempt from consent requirements may continue to operate where permitted by law and necessary for the applicable purpose.
37RECIPIENTS OF INFORMATION
Information associated with cookies and similar technologies may be available to:
- Kestrel personnel who require access for legitimate operational, security, support or legal functions;
- Kestrel-controlled systems;
- service providers acting on Kestrel's behalf;
- relevant infrastructure providers;
- enterprise customers or their administrators where the processing relates to their organisation and such access is authorised;
- advisers and professional service providers where necessary;
- parties involved in a legitimate corporate transaction;
- government authorities, courts or regulators where disclosure is required or permitted by law; and
- parties involved in investigating fraud, security incidents, abuse or unlawful activity where disclosure is legally permitted.
This provision does not mean that every recipient category receives every category of information.
CONFIRM BEFORE PUBLICATION: reconcile the final provider/recipient list with the Privacy Policy, DPA, Security Addendum, production architecture and current subprocessor inventory.
38THIRD-PARTY SERVICE PROVIDERS
Where Kestrel uses a service provider to process personal data on Kestrel's behalf, Kestrel seeks to establish appropriate contractual and security arrangements as required by applicable law.
Where the service provider independently determines purposes or means of processing, its own privacy documentation may also apply.
CONFIRM BEFORE PUBLICATION: verify the final production provider list and legal role of each provider relevant to website/browser data.
Current subprocessor information may be requested from privacy@kestreladvanced.com until a public list is deployed.
39CROSS-BORDER PROCESSING
The operation of an Internet service can involve processing in more than one jurisdiction.
Where personal data subject to the Singapore PDPA is transferred outside Singapore, Kestrel will take steps required under applicable law regarding overseas transfers.
Where another data-protection regime applies, additional transfer requirements may apply.
CONFIRM BEFORE PUBLICATION: map the countries in which hosting, CDN, security, authentication, logging, monitoring, support and other relevant providers process browser-derived personal data.
Kestrel does not represent that all browser-related data remains exclusively in Singapore unless that fact has been verified for the applicable deployment.
40ENTERPRISE CUSTOMERS AND ADMINISTRATORS
Kestrel's dashboard is designed for organisational users.
An enterprise customer may administer user accounts, authentication configuration, tenant access and other aspects of its Kestrel environment.
Depending on the circumstances and contractual arrangement, an enterprise customer may determine certain purposes and means of processing personal data associated with authorised users.
Users should therefore also consult the relevant enterprise customer's internal policies where applicable.
Nothing in this section changes the allocation of legal responsibilities contained in an applicable Data Processing Agreement, Order Form or other contractual documentation.
41AUTHENTICATION AND IDENTITY PROVIDERS
Kestrel uses OpenID Connect-based authentication flows in connection with the authenticated dashboard.
Such flows may involve an identity provider selected, configured or otherwise applicable to the relevant environment.
The kestrel_oidc_state cookie is used by Kestrel for protection of the authentication transaction.
The broader authentication transaction may involve direct communications between the browser, Kestrel and an applicable identity provider.
CONFIRM BEFORE PUBLICATION: identify production identity-provider configurations, determine which providers are Kestrel-selected versus customer-selected, and ensure related disclosures are consistent across this Policy, the Privacy Policy and subprocessor documentation.
42SECURITY
Kestrel uses technical and organisational safeguards designed to protect information processed through its Services.
For the presently identified cookies:
kestrel_sessionis configured as HttpOnly;kestrel_csrfis intentionally readable by the application because the dashboard submits the token through the X-Kestrel-CSRF header;kestrel_oidc_stateis configured as HttpOnly;- the three cookies are configured as Secure in production; and
- the three cookies use SameSite=Lax.
Development configuration may differ from production where secure transport or other production infrastructure is unavailable.
These controls are security measures, not guarantees.
Attributes such as Secure, HttpOnly and SameSite reduce particular categories of risk but do not make a system immune from attack.
Similarly, token hashing, encryption, access control or other technical safeguards do not eliminate all security risk.
Users must also maintain appropriate security over their own browsers, devices and account credentials.
43CHILDREN
Kestrel is a business-to-business enterprise service.
The Services are not designed or marketed for personal, family or household consumer use and are not directed to children.
If Kestrel becomes aware that its browser technologies are being used in a context requiring additional protections for children or minors, Kestrel will assess and implement applicable requirements.
44CHANGES TO OUR TECHNOLOGY
Our technical environment may evolve.
We may add, remove or change cookies and similar technologies when we:
- develop new functionality;
- modify authentication or security architecture;
- change infrastructure;
- add or remove service providers;
- improve application functionality;
- comply with legal requirements; or
- modify our websites or Services.
A new technology will not automatically be treated as permissible merely because a similar technology appears in this Policy.
Before introducing a materially different non-essential technology, Kestrel should assess its purpose, data use, duration, provider and applicable notice or consent requirements.
45CHANGES TO THIS COOKIE POLICY
We may amend this Cookie Policy from time to time to reflect:
- changes to our Services;
- changes to our use of cookies or similar technologies;
- changes in infrastructure or service providers;
- security developments;
- changes in applicable law, regulatory guidance or industry practice; or
- improvements to our transparency disclosures.
When we update the Policy, we will update the “Last Updated” date above.
We will publish an updated version on the Website. Where a change is material, we will also provide notice by email or through the authenticated Platform dashboard. Where required by applicable law, we will obtain new consent before applying a materially changed non-essential technology.
46VERSION HISTORY
| Version | Date | Description |
|---|---|---|
| 1.0 | 4 October 2026 | Initial public Cookie and Similar Technologies Policy |
Future material revisions may be added to this table.
47GOVERNING LANGUAGE
This Cookie Policy is prepared in English.
If Kestrel provides a translation, it is intended for convenience unless applicable law requires otherwise. To the extent permitted by applicable law, the English version controls in the event of inconsistency.
Nothing in this section limits rights that cannot lawfully be excluded or restricted.
48QUESTIONS, REQUESTS AND COMPLAINTS
For questions or requests relating to this Cookie Policy, privacy or Kestrel's handling of personal data, contact:
- Privacy and data-protection enquiries
- privacy@kestreladvanced.com
Legal notices
legal@kestreladvanced.com
General enquiries
contact@kestreladvanced.com
Postal address
Kestrel Advanced Systems Pte. Ltd.
Blk 31, #01-16C
535 Clementi Road
Singapore 599489
Where applicable, an individual may also have the right to raise a complaint with a competent privacy or data-protection regulator.
Nothing in this Policy restricts any right to contact the Personal Data Protection Commission of Singapore or another competent regulator where applicable law provides such a right.
49SUMMARY
Kestrel's currently verified browser technologies are primarily designed to:
- authenticate authorised enterprise users;
- secure authentication transactions;
- protect state-changing requests;
- maintain limited session and workspace state; and
- remember limited user-interface state.
No behavioural-advertising platform, advertising network, Google Analytics, Google Tag Manager, Meta Pixel, Hotjar, Microsoft Clarity, Mixpanel, Segment, PostHog, HubSpot, Intercom or equivalent tracking integration has been identified in the application code reviewed for this Policy.
That statement remains subject to the mandatory production environment audit identified throughout this Policy.
Kestrel will not characterise a technology as absent, necessary, anonymous, consent-exempt or confined to a particular jurisdiction unless the relevant technical and legal basis has been verified.
© Kestrel Advanced Systems Pte. Ltd. All rights reserved.