KESTREL ADVANCED SYSTEMS PTE. LTD.
PRIVACY POLICY
Effective Date: 1 September 2026
Last Updated: 4 October 2026
Kestrel Advanced Systems Pte. Ltd. (“Kestrel”, “we”, “us”, or “our”) takes the protection of personal data seriously.
This Privacy Policy explains how we collect, use, disclose, process, store, retain and protect personal data in connection with our websites, enterprise software, customer relationships, business operations and related services.
Kestrel provides business-to-business enterprise artificial intelligence governance, security and control-plane software, including capabilities relating to runtime enforcement, governance operations, continuous assurance, security controls, auditability, accountability, evidence management and executive oversight.
Because Kestrel provides infrastructure that may process information on behalf of enterprise customers, an important distinction exists between:
- personal data that Kestrel processes for our own business purposes; and
- personal data contained within Customer Data that Kestrel processes on behalf of an enterprise customer.
This Privacy Policy explains that distinction.
01WHO WE ARE
The organisation responsible for this Privacy Policy is:
Kestrel Advanced Systems Pte. Ltd.
Registered Office:
Blk 31, #01-16C
535 Clementi Road
Singapore 599489
Singapore UEN / Company Registration Number:
202644596C
Website:
kestreladvanced.com
General Contact:
contact@kestreladvanced.com
Data Protection Officer
Kestrel's Data Protection Officer may be contacted at:
Rai Krish Kumar
Chief Executive Officer
Kestrel Advanced Systems Pte. Ltd.
Email: privacy@kestreladvanced.com
Postal Address:
Blk 31, #01-16C
535 Clementi Road
Singapore 599489
02SCOPE OF THIS PRIVACY POLICY
This Privacy Policy applies to personal data handled by Kestrel in connection with:
- kestreladvanced.com;
- Kestrel-operated web applications;
- enquiries;
- requests for information;
- product demonstrations;
- pilots;
- evaluations;
- enterprise sales activities;
- procurement processes;
- contractual negotiations;
- customer onboarding;
- account registration;
- user administration;
- authentication;
- use of the Kestrel platform;
- customer support;
- technical support;
- security monitoring;
- fraud and misuse prevention;
- subscriptions;
- billing;
- customer relationship management;
- vendor relationships;
- partner relationships;
- corporate governance;
- regulatory and legal compliance;
- business communications; and
- other interactions with Kestrel.
This Privacy Policy also explains Kestrel's general role when enterprise customers use the Kestrel platform to process information relating to their personnel, users, customers, systems or other individuals.
03KESTREL'S DIFFERENT DATA-PROTECTION ROLES
Kestrel may have different legal responsibilities depending on why particular personal data is being processed.
3.1 Information Kestrel processes for its own purposes
Kestrel generally determines the purposes for processing information relating to matters such as:
- website enquiries;
- prospective customers;
- business contacts;
- customer representatives;
- account administration;
- security;
- fraud prevention;
- billing;
- contracting;
- customer relationships;
- Kestrel's corporate activities;
- legal compliance;
- marketing preferences; and
- communications sent directly to Kestrel.
In these circumstances, Kestrel may act as an organisation, controller, business or equivalent party responsible for determining the relevant processing purposes under applicable law.
3.2 Information Kestrel processes on behalf of customers
Enterprise customers may transmit, configure, store, generate or otherwise process information through Kestrel's platform.
We refer to this information as “Customer Data”.
Where Customer Data contains personal data and Kestrel processes that data solely to provide services to an enterprise customer pursuant to that customer's instructions and our agreement with that customer, Kestrel generally acts as a data intermediary, processor, service provider or equivalent processing party.
In those circumstances, the enterprise customer generally determines:
- why the personal data is processed;
- whose personal data is processed;
- what personal data is submitted;
- which systems are connected;
- which applications are monitored;
- which models are connected;
- which agents are connected;
- which tools are controlled;
- what policies are applied;
- what governance rules are configured;
- what retention configuration is selected where configurable;
- which integrations are enabled; and
- what lawful authority permits the processing.
Kestrel processes that Customer Data in accordance with the relevant customer agreement, applicable Data Processing Addendum, documented customer instructions and applicable law.
04CUSTOMER RESPONSIBILITY FOR CUSTOMER DATA
Kestrel's enterprise customers remain responsible for their own collection and use of personal data.
Customers are responsible for determining, among other things:
- whether personal data should be submitted to Kestrel;
- whether such processing is lawful;
- whether notice must be given to affected individuals;
- whether consent is required;
- whether another lawful authority permits processing;
- what categories of personal data may be processed;
- how long information should be retained where customer-controlled;
- whether particular automated decisions require human oversight;
- whether particular data is subject to heightened legal protections; and
- whether their use of Kestrel complies with applicable laws and regulations.
Kestrel's Privacy Policy does not replace a customer's own privacy notice.
05WHAT WE MEAN BY PERSONAL DATA
For purposes of this Privacy Policy, “personal data” generally means information relating to an identified or identifiable individual or information otherwise treated as personal data, personal information or personally identifiable information under applicable law.
Personal data does not necessarily need to contain someone's name.
Depending on the circumstances, personal data may include:
- names;
- email addresses;
- telephone numbers;
- account identifiers;
- IP addresses;
- device identifiers;
- authentication information;
- employment information;
- communications;
- usage information;
- security records;
- online identifiers;
- AI interaction information; and
- other information capable of being associated with an individual.
Different jurisdictions may define personal data differently.
06INFORMATION WE COLLECT FOR OUR OWN BUSINESS PURPOSES
The categories described below identify information that Kestrel may process for our own legitimate business operations.
Not every category is collected from every individual.
07BUSINESS AND CONTACT INFORMATION
We may collect information including:
- name;
- business email address;
- business telephone number;
- employer;
- job title;
- department;
- organisation;
- business location;
- professional role;
- professional contact information;
- relationship with Kestrel; and
- other information you choose to provide.
08SALES, DEMONSTRATION AND CUSTOMER-RELATIONSHIP INFORMATION
When an organisation communicates with Kestrel regarding our services, we may process information including:
- enquiries;
- product requirements;
- demo requests;
- meeting information;
- proof-of-concept requirements;
- pilot information;
- procurement information;
- security requirements;
- technical requirements;
- commercial requirements;
- correspondence;
- proposals;
- contract negotiations;
- meeting notes;
- customer feedback;
- implementation discussions; and
- customer relationship records.
09ACCOUNT AND USER-ADMINISTRATION INFORMATION
Where an individual is authorised to access Kestrel on behalf of an organisation, we may process information such as:
- name;
- business email address;
- user identifier;
- organisation;
- tenant membership;
- workspace membership;
- user role;
- permissions;
- administrative privileges;
- authentication state;
- authentication events;
- account status;
- SSO-related attributes;
- identity-provider attributes;
- account configurations;
- administrative actions;
- login information;
- session information; and
- other information reasonably necessary to administer access to the platform.
10CONTRACTUAL AND COMMERCIAL INFORMATION
We may process information relating to commercial relationships, including:
- authorised company representatives;
- names;
- titles;
- contact information;
- signatures;
- contracts;
- purchase orders;
- subscription information;
- billing contacts;
- invoices;
- transaction references;
- payment status;
- renewal information;
- procurement records; and
- related commercial records.
Where third-party payment or billing providers are used, those providers may separately process payment information in accordance with their applicable terms and privacy practices.
11COMMUNICATIONS AND SUPPORT INFORMATION
If you communicate with Kestrel, we may process:
- emails;
- support requests;
- troubleshooting requests;
- correspondence;
- attachments;
- screenshots;
- error reports;
- technical information;
- meeting notes;
- feedback; and
- other information contained in communications you send to us.
Customers should avoid providing personal data in support communications where that information is unnecessary for resolving the relevant issue.
12TECHNICAL, SECURITY AND OPERATIONAL INFORMATION
When Kestrel systems are accessed or used, technical information may be generated.
This may include:
- IP addresses;
- timestamps;
- browser information;
- device information;
- operating-system information;
- user-agent information;
- request metadata;
- authentication events;
- API activity;
- API-key identifiers;
- tenant identifiers;
- workspace identifiers;
- session identifiers;
- security events;
- access logs;
- administrative events;
- error logs;
- diagnostic information;
- performance information;
- operational telemetry;
- suspected abuse;
- rate-limit events;
- integrity events;
- suspicious activity;
- policy events; and
- other information reasonably necessary to operate and secure the service.
13CUSTOMER DATA PROCESSED THROUGH KESTREL
Kestrel is an enterprise AI governance and security platform.
Depending on customer configuration, Customer Data processed through Kestrel may include information associated with:
- AI applications;
- artificial intelligence models;
- large language models;
- AI agents;
- autonomous or semi-autonomous systems;
- agentic workflows;
- prompts;
- model requests;
- model responses;
- system instructions;
- agent instructions;
- contextual information;
- API requests;
- tool calls;
- tool results;
- connected applications;
- datasets;
- identity information;
- user identifiers;
- agent identifiers;
- sessions;
- governance systems;
- policies;
- integrations; and
- other enterprise systems configured by the customer.
Customer Data may contain personal data where such information is submitted by a customer, user, AI system, application, dataset, connected service or other source.
14SECURITY AND GOVERNANCE INFORMATION GENERATED BY KESTREL
Kestrel may generate security, governance, policy and assurance information while providing the service.
Such information may include:
- threat scores;
- security findings;
- risk scores;
- detected personal-data categories;
- detected PII categories;
- PII counts;
- sensitivity labels;
- sensitivity classifications;
- intent classifications;
- policy findings;
- policy traces;
- enforcement reasons;
- response findings;
- security evidence;
- tool-risk findings;
- session-risk signals;
- adversarial-risk indicators;
- governance findings;
- policy outcomes; and
- enforcement actions.
Depending on customer configuration, enforcement actions may include outcomes such as:
- allow;
- audit;
- hold; or
- deny.
Security and evidence records may contain limited extracts of underlying information where reasonably necessary to identify, explain, investigate or evidence a security or governance finding.
Kestrel seeks to minimise unnecessary reproduction of Customer Data when generating such information.
15GOVERNANCE, ASSURANCE AND EVIDENCE RECORDS
Customers may use Kestrel to maintain enterprise AI governance information.
This may include records concerning:
- AI systems;
- models;
- agents;
- datasets;
- tools;
- vendors;
- deployments;
- system owners;
- business purposes;
- system relationships;
- lifecycle status;
- criticality;
- risk classifications;
- data sensitivity;
- PII indicators;
- review schedules;
- governance policies;
- assessments;
- workflow cases;
- findings;
- incidents;
- exceptions;
- remediation plans;
- risk acceptances;
- approvals;
- business justifications;
- audit reviews;
- evidence references; and
- exported governance or assurance reports.
Such records may identify customer personnel or other individuals where customers choose to enter personal data into those records.
16WHERE PERSONAL DATA COMES FROM
Kestrel may obtain information from several sources.
16.1 Directly from you
For example, when you:
- contact us;
- email us;
- submit a form;
- request a demonstration;
- participate in a meeting;
- negotiate an agreement;
- register an account;
- use the service;
- request support; or
- otherwise communicate with Kestrel.
16.2 From your organisation
Your employer or organisation may provide information necessary to:
- establish your account;
- authenticate you;
- identify you as an authorised user;
- assign roles;
- administer permissions;
- configure SSO;
- administer its relationship with Kestrel; or
- manage its use of the service.
16.3 From customer systems
Information may be received from:
- customer applications;
- AI systems;
- AI agents;
- identity providers;
- models;
- datasets;
- tools;
- APIs; and
- customer-authorised integrations.
16.4 Automatically
Certain technical and operational information may be generated automatically through interactions with our website and platform.
16.5 From third parties
Where appropriate and lawful, Kestrel may receive business information from service providers, professional sources, partners or publicly available business sources.
17WHY WE USE PERSONAL DATA
Where Kestrel processes personal data for our own purposes, we may use that information for the purposes described below.
18RESPONDING TO ENQUIRIES AND SALES REQUESTS
We may use personal data to:
- respond to enquiries;
- arrange demonstrations;
- communicate with prospective customers;
- evaluate business requirements;
- evaluate technical requirements;
- conduct pilots;
- prepare proposals;
- conduct procurement processes;
- respond to security questionnaires;
- negotiate agreements; and
- administer prospective customer relationships.
19PROVIDING AND ADMINISTERING THE SERVICE
We may use personal data to:
- establish accounts;
- authenticate users;
- authenticate agents;
- configure access;
- enforce permissions;
- administer tenants;
- administer workspaces;
- operate the platform;
- deliver contracted services;
- maintain customer configurations;
- provide support;
- troubleshoot issues; and
- administer customer relationships.
20SECURITY AND FRAUD PREVENTION
We may process information to:
- protect Kestrel;
- protect customers;
- protect users;
- authenticate users and systems;
- prevent unauthorised access;
- detect suspicious activity;
- detect misuse;
- prevent fraud;
- investigate security incidents;
- protect credentials;
- maintain tenant separation;
- detect abuse;
- enforce access restrictions;
- maintain system integrity;
- investigate policy violations; and
- secure infrastructure.
21SERVICE OPERATION AND RELIABILITY
We may process information to:
- maintain service availability;
- troubleshoot faults;
- investigate errors;
- monitor system performance;
- improve reliability;
- manage capacity;
- resolve technical incidents;
- maintain infrastructure; and
- understand operational performance.
22CONTRACTING, BILLING AND BUSINESS ADMINISTRATION
We may process personal data to:
- enter into contracts;
- administer contracts;
- manage subscriptions;
- issue invoices;
- process payments;
- administer renewals;
- maintain accounting records;
- maintain corporate records;
- communicate with authorised representatives; and
- manage commercial relationships.
23LEGAL, REGULATORY AND COMPLIANCE PURPOSES
We may process personal data where reasonably necessary to:
- comply with applicable law;
- comply with regulatory requirements;
- meet tax obligations;
- meet accounting obligations;
- conduct audits;
- respond to lawful legal process;
- protect legal rights;
- investigate misconduct;
- enforce contracts;
- resolve disputes;
- establish legal claims;
- exercise legal claims;
- defend legal claims; and
- meet corporate-governance obligations.
24BUSINESS COMMUNICATIONS AND MARKETING
Where permitted by applicable law, Kestrel may communicate with business contacts about:
- Kestrel products;
- Kestrel services;
- product developments;
- enterprise AI governance;
- security developments;
- events;
- demonstrations;
- pilots;
- company announcements; and
- other information reasonably relevant to the recipient's professional role.
Where legally required or otherwise appropriate, marketing communications will provide a method to unsubscribe or opt out.
An individual who opts out of marketing communications may continue receiving:
- security communications;
- service notices;
- administrative messages;
- contractual communications;
- billing communications; and
- other non-marketing communications necessary for our business relationship.
We may retain limited suppression information after an opt-out so that we can continue respecting that preference.
25HOW WE PROCESS CUSTOMER DATA
Kestrel processes Customer Data principally for the purpose of providing, securing, operating and supporting the services purchased or enabled by the relevant customer.
Depending on customer configuration, these functions may include:
- runtime inspection;
- request inspection;
- response inspection;
- prompt-security controls;
- PII detection;
- PII redaction;
- PII tokenisation;
- sensitivity classification;
- intent classification;
- policy enforcement;
- tool-action controls;
- tool-call firewalling;
- response controls;
- session-risk analysis;
- adversarial-state analysis;
- risk scoring;
- model-routing controls;
- agent identity;
- role-based access controls;
- governance workflows;
- AI-system registries;
- model registries;
- dataset registries;
- vendor registries;
- tool registries;
- risk assessments;
- continuous assurance;
- accountability workflows;
- audit functions;
- evidence management;
- incident management;
- exception management;
- remediation tracking;
- risk acceptance;
- governance approvals;
- reporting; and
- executive oversight.
Kestrel does not acquire ownership of Customer Data merely because Customer Data is transmitted through or processed by our systems.
Customer Data remains subject to the applicable agreement between Kestrel and the enterprise customer.
26CUSTOMER DATA, MODEL TRAINING AND PRODUCT DEVELOPMENT
Kestrel's rights to use Customer Data are limited by the applicable customer agreement, Data Processing Addendum, documented customer instructions and applicable law.
Kestrel does not treat access to Customer Data as a general or unrestricted licence to use that information for unrelated purposes.
Kestrel does not use Customer Content to train general-purpose Kestrel models or models made available to other customers.
Kestrel may use properly de-identified and aggregated operational information for security, reliability, analytics, abuse prevention and product improvement, subject to applicable law and contractual restrictions. Kestrel will not represent information as de-identified or aggregated where an individual remains reasonably identifiable in the relevant context.
Any other use of Customer Data for machine-learning training, model fine-tuning, model evaluation, benchmarking, product development, service improvement or human review must be expressly authorised by the applicable customer agreement, documented customer instructions and applicable law.
27AI MODEL PROVIDERS AND CUSTOMER-CONNECTED SERVICES
Depending on customer configuration, Kestrel may facilitate communication between customer systems and AI models, model providers, tools, identity systems or other integrations.
Where information is transmitted to a third-party service selected or authorised by a customer, that information may also be processed by the relevant third party.
Kestrel's contractual relationship with such providers, the categories of information transmitted and applicable processing restrictions depend on the particular service and architecture involved.
Customers should review relevant service documentation and contractual terms when configuring integrations involving third parties.
28LEGAL AUTHORITY FOR PROCESSING
28.1 Singapore
Where Singapore's Personal Data Protection Act 2012 applies, Kestrel collects, uses and discloses personal data in accordance with applicable requirements of that legislation.
Depending on the circumstances, processing may occur pursuant to:
- consent;
- deemed consent where recognised by law;
- an applicable statutory exception permitting processing without consent; or
- another lawful authority provided under applicable law.
Kestrel seeks to collect, use and disclose personal data only for purposes that are reasonable and appropriate in the circumstances.
Nothing in this Privacy Policy should be interpreted as meaning that publication of a privacy policy itself creates consent for processing.
28.2 Customer Data
Where Kestrel acts as a data intermediary or processor, the relevant enterprise customer generally determines the lawful authority or legal basis for the underlying processing.
28.3 Other jurisdictions
Where another privacy or data-protection law applies to Kestrel, we will process personal data in accordance with the requirements applicable to that processing.
29AUTOMATED SECURITY AND POLICY DECISIONS
Kestrel's platform is designed to automatically analyse AI requests, responses, agent actions, tool actions, sessions and related activity.
Depending on customer configuration, Kestrel may automatically:
- identify security indicators;
- identify potentially sensitive information;
- classify data;
- classify intent;
- calculate risk signals;
- evaluate policy conditions;
- identify policy violations;
- generate findings;
- route requests;
- trigger alerts;
- require additional controls; or
- produce an enforcement outcome.
Such outcomes may include:
- allow;
- audit;
- hold; or
- deny.
Enterprise customers generally determine:
- which policies apply;
- relevant thresholds;
- applicable enforcement actions;
- how automated outcomes are used;
- whether human review is required; and
- how an outcome affects the customer's downstream systems.
Customers are responsible for assessing whether their use of automated Kestrel functionality creates additional transparency, human-review, fairness, appeal or other obligations under laws applicable to the customer's use case.
30WHEN WE DISCLOSE INFORMATION
Kestrel may disclose personal data where reasonably necessary for the purposes described in this Privacy Policy and subject to applicable legal and contractual restrictions.
Recipients may include the following categories where applicable.
31INFRASTRUCTURE AND TECHNOLOGY SERVICE PROVIDERS
Kestrel may use service providers to support infrastructure necessary to operate the business and provide the service.
Depending on Kestrel's current architecture, these may include providers supporting:
- hosting;
- infrastructure;
- networking;
- content delivery;
- authentication;
- communications;
- security;
- monitoring;
- billing;
- customer support;
- business administration; and
- related functions.
Such providers are authorised to process information only to the extent appropriate for the relevant service and subject to applicable contractual and legal requirements.
32AI AND MODEL PROVIDERS
Where a customer-authorised workflow involves an external model or AI provider, information necessary to perform that request may be transmitted to the relevant service.
The exact information transmitted depends on the customer's configuration and the architecture of the relevant deployment.
33PROFESSIONAL ADVISERS
Kestrel may provide information where reasonably necessary to professional advisers, including:
- legal advisers;
- accountants;
- auditors;
- tax advisers;
- insurers;
- consultants; and
- other professional service providers.
Such disclosures may be subject to professional, contractual or statutory confidentiality obligations.
34CORPORATE TRANSACTIONS
If Kestrel is involved in a proposed or completed:
- financing;
- investment;
- merger;
- acquisition;
- restructuring;
- reorganisation;
- asset sale;
- insolvency process;
- due-diligence exercise; or
- similar corporate transaction,
relevant information may be disclosed to actual or prospective investors, purchasers, advisers, lenders or transaction counterparties.
Where appropriate, such disclosures will be subject to confidentiality and data-protection requirements.
35LEGAL AND REGULATORY DISCLOSURES
Kestrel may preserve, access or disclose information where reasonably necessary to:
- comply with applicable law;
- comply with a court order;
- comply with lawful regulatory requirements;
- respond to valid legal process;
- cooperate with law-enforcement authorities where legally required;
- investigate fraud;
- investigate security incidents;
- protect Kestrel;
- protect customers;
- protect individuals;
- prevent unlawful activity; or
- establish, exercise or defend legal claims.
Kestrel does not treat every third-party request for information as automatically valid.
Requests may be assessed for appropriate legal authority, scope and validity.
36CUSTOMER-AUTHORISED INTEGRATIONS
Customers may choose to connect Kestrel with third-party systems, models, services or tools.
Where they do so, Customer Data may be transmitted to or received from those third parties in accordance with the customer's configuration.
Customers are responsible for assessing independently selected third-party integrations.
37SUBPROCESSORS
Kestrel may engage third parties to process Customer Data where reasonably necessary to provide the enterprise service.
Where such parties constitute subprocessors or equivalent processing parties under applicable law or contract, Kestrel will manage those relationships in accordance with applicable contractual and legal requirements.
Where appropriate, Kestrel may maintain a customer-facing subprocessor list identifying relevant service providers and processing locations.
38SALE OF PERSONAL DATA AND ADVERTISING
Kestrel is a business-to-business enterprise software provider.
Personal data collected in connection with Kestrel's services is used for purposes connected with operating, securing, administering and developing Kestrel's business and services as described in this Privacy Policy.
Kestrel does not sell personal data and does not share personal data for cross-context behavioural advertising.
Where laws applicable to Kestrel create specific obligations concerning targeted advertising, sale or sharing of personal data, Kestrel will provide any legally required disclosures and controls.
39INTERNATIONAL DATA TRANSFERS
Kestrel is headquartered in Singapore.
Personal data may be processed in countries other than the country in which the relevant individual is located where Kestrel's infrastructure, service providers, enterprise customers or customer-authorised integrations require such processing.
Where Kestrel transfers personal data outside Singapore and Singapore law requires Kestrel to ensure an appropriate standard of protection, Kestrel will take measures required under applicable law.
Where another applicable data-protection law requires a particular international-transfer mechanism or safeguard, Kestrel will implement the mechanism applicable to that processing.
40DATA RETENTION
Kestrel does not retain personal data indefinitely merely because retaining it is technically possible.
The period for which information is retained depends on factors including:
- the reason the information was collected;
- customer instructions;
- customer configuration;
- the type of Kestrel service involved;
- contractual requirements;
- technical requirements;
- security requirements;
- audit requirements;
- governance requirements;
- operational requirements;
- legal obligations;
- regulatory requirements;
- tax obligations;
- accounting requirements;
- applicable limitation periods;
- dispute requirements;
- litigation holds; and
- other legitimate business requirements.
Where personal data is no longer required for an applicable legal or business purpose, Kestrel will take appropriate steps concerning deletion, disposal, anonymisation or cessation of retention in accordance with applicable requirements.
41CUSTOMER DATA RETENTION
Retention of Customer Data may depend on:
- the feature involved;
- the customer's service configuration;
- customer-selected retention settings;
- the applicable enterprise agreement;
- security requirements;
- audit requirements;
- governance requirements;
- technical architecture; and
- applicable law.
Upon termination of a customer relationship, Customer Data will be handled in accordance with Kestrel's contractual commitments, applicable retention requirements and technical deletion procedures.
Certain information may remain temporarily within backup, recovery, security, audit or legal-hold systems after deletion from active systems where continued retention is reasonably necessary and legally permitted.
42TAMPER-EVIDENT AUDIT RECORDS
Certain Kestrel functionality may create tamper-evident governance, evidence or audit records.
Kestrel may use cryptographic integrity techniques designed to make unauthorised alteration of audit history detectable.
These controls may include mechanisms such as:
- cryptographic hashing;
- digital signatures;
- chained records; and
- cryptographic checkpoints.
The existence of tamper-evident records can affect how correction or deletion requests are technically implemented.
Where personal data contained within such records is subject to a valid correction, restriction or deletion requirement, Kestrel and the relevant enterprise customer will determine the appropriate treatment in accordance with:
- applicable law;
- Kestrel's role;
- customer instructions;
- security requirements;
- evidentiary requirements;
- audit integrity; and
- contractual obligations.
Kestrel does not promise physical deletion from every cryptographically protected record where continued retention is legally permitted or required.
43COOKIES AND BROWSER STORAGE
Kestrel's website and application may use cookies and browser-storage technologies where reasonably necessary to operate, secure or administer the service.
These technologies may include:
- security cookies;
- CSRF protections;
- authentication state;
- session storage;
- local browser storage;
- interface preferences;
- tenant or workspace state; and
- similar technologies.
Where Kestrel uses technologies that require additional consent under applicable law, appropriate consent or preference controls will be provided.
A separate Cookie Policy or storage notice may provide additional details concerning technologies used on Kestrel's production services.
44WEBSITE TECHNOLOGIES AND THIRD-PARTY RESOURCES
Kestrel webpages may use third-party resources necessary for website presentation, security, infrastructure or functionality.
When a browser connects directly to a third-party resource, the third-party provider may receive technical information associated with that connection, such as an IP address and browser request information.
Where practicable and appropriate, Kestrel may minimise unnecessary third-party website requests.
45ANALYTICS
Kestrel may use operational, security or website analytics where appropriate to understand system operation, service performance, reliability, security or website usage.
Where analytics technologies are not strictly necessary and applicable law requires consent, Kestrel will implement appropriate consent controls.
Kestrel does not treat analytics information as automatically anonymous merely because an individual's name is not present.
46SECURITY
Kestrel implements technical and organisational safeguards designed to protect information against risks such as:
- unauthorised access;
- unauthorised collection;
- unauthorised use;
- unauthorised disclosure;
- accidental loss;
- improper alteration;
- unauthorised destruction;
- compromise; and
- other security risks.
Depending on deployment architecture and feature configuration, Kestrel's systems may include safeguards such as:
- protected network communications;
- authentication controls;
- API-key authentication;
- OIDC-based authentication;
- role-based access controls;
- tenant separation;
- workspace separation;
- policy enforcement;
- PII detection;
- PII redaction or tokenisation features;
- bounded session state;
- structured logging;
- cryptographic integrity mechanisms;
- digital signatures;
- hash chains;
- Merkle-based integrity mechanisms; and
- other administrative, technical and organisational controls.
Security is a risk-management process.
No software service, communication mechanism, network or storage system can be guaranteed to be completely secure.
Kestrel therefore does not represent that its systems are “unhackable”, “breach-proof” or otherwise immune from all security risks.
47SECURITY CERTIFICATIONS
Kestrel will only represent that it holds a particular certification, attestation, audit result or independent security assurance where that representation is accurate, current and capable of being substantiated.
A technical feature or security control should not be interpreted as meaning that Kestrel holds a certification unless Kestrel expressly states that the certification has been obtained.
48SECURITY INCIDENTS AND PERSONAL-DATA BREACHES
Kestrel maintains processes intended to identify, investigate, contain and respond to security incidents.
Where Kestrel is responsible for assessing a personal-data breach under applicable law, we will determine whether regulatory or individual notification requirements apply.
Where Kestrel processes Customer Data as a data intermediary or processor and becomes aware of a relevant personal-data breach, Kestrel will communicate with the affected enterprise customer in accordance with applicable legal and contractual requirements.
Enterprise customers remain responsible for regulatory or individual notifications that applicable law places upon them as the organisation or controller, subject to any assistance obligations undertaken by Kestrel.
49PRIVACY RIGHTS
The privacy rights available to an individual depend on:
- applicable law;
- the individual's location;
- the nature of the information;
- the purposes of processing;
- Kestrel's legal role;
- the identity of the relevant enterprise customer; and
- applicable exceptions.
This Privacy Policy does not represent that every privacy right exists in every jurisdiction or every circumstance.
50ACCESS
Where applicable, you may request access to personal data Kestrel holds about you for our own purposes and information regarding how that personal data has been used or disclosed, subject to applicable law and exceptions.
51CORRECTION
Where applicable, you may request correction of an error or omission in personal data relating to you that is held by Kestrel.
52WITHDRAWAL OF CONSENT
Where Kestrel relies upon your consent and applicable law permits withdrawal, you may withdraw your consent by providing reasonable notice.
We may explain the likely consequences of withdrawal before completing the request.
Withdrawal of consent does not prevent processing independently authorised or required under applicable law.
53DELETION
You may request deletion of personal data relating to you.
Whether Kestrel is required or permitted to delete particular information depends on:
- applicable law;
- Kestrel's role;
- customer instructions;
- contractual requirements;
- legal retention requirements;
- audit requirements;
- security requirements;
- evidentiary requirements; and
- applicable exceptions.
A deletion request does not automatically require deletion of information that Kestrel or a customer is legally entitled or required to retain.
54OBJECTION, RESTRICTION AND SIMILAR RIGHTS
Certain privacy laws may provide rights to:
- object to processing;
- restrict processing;
- challenge particular automated processing;
- request human intervention;
- appeal certain decisions; or
- exercise related controls.
Kestrel will recognise such rights where they apply.
55DATA PORTABILITY
Where applicable law provides an enforceable right to data portability that applies to Kestrel's processing, Kestrel will respond in accordance with the relevant legal requirements.
Nothing in this Privacy Policy should be interpreted as representing that a portability right currently applies to every individual or every Kestrel processing activity.
56MARKETING OPT-OUTS
Individuals may opt out of eligible marketing communications by using the unsubscribe mechanism provided in the relevant communication or by contacting Kestrel.
Marketing opt-outs do not prevent Kestrel from sending communications that are necessary for:
- security;
- service administration;
- billing;
- contractual matters;
- account administration; or
- other non-marketing business purposes.
57REQUESTS CONCERNING CUSTOMER DATA
If your personal data was submitted to Kestrel by your employer or another Kestrel enterprise customer, Kestrel may process that information solely on behalf of that organisation.
In those circumstances, you should ordinarily direct your request to the relevant enterprise customer.
Where appropriate, Kestrel may:
- refer the request to the customer;
- notify the customer;
- forward the request;
- assist the customer; or
- take another action required by applicable contract or law.
Kestrel will not ordinarily disclose Customer Data directly to an individual where doing so would:
- circumvent the enterprise customer's responsibilities;
- compromise security;
- disclose another person's information;
- violate contractual obligations;
- create an unauthorised disclosure; or
- conflict with applicable law.
58HOW TO MAKE A PRIVACY REQUEST
Requests relating to personal data Kestrel processes for our own purposes may be directed to:
Data Protection Officer
Rai Krish Kumar
Chief Executive Officer
Kestrel Advanced Systems Pte. Ltd.
Email: privacy@kestreladvanced.com
Postal Address:
Blk 31, #01-16C
535 Clementi Road
Singapore 599489
Please provide sufficient information for us to understand:
- your identity;
- your relationship with Kestrel;
- the information concerned; and
- what you are requesting.
Kestrel may take reasonable steps to verify the identity and authority of a person making a request.
This protects individuals against fraudulent or unauthorised access to personal data.
59RESPONSE TO PRIVACY REQUESTS
Kestrel will respond to valid privacy requests within the period required by applicable law.
Where legally permitted or necessary, we may request additional information in order to:
- verify identity;
- identify relevant records;
- identify the relevant enterprise customer;
- protect another individual's personal data;
- assess whether an exception applies; or
- securely fulfil the request.
A request may be restricted or refused where permitted under applicable law.
60COMPLAINTS
If you have concerns about Kestrel's processing of personal data, you are encouraged to contact our Data Protection Officer.
We will assess privacy complaints and take appropriate action where required.
Where applicable, individuals may also have a right to lodge a complaint with the competent privacy or data-protection authority.
For matters governed by Singapore's Personal Data Protection Act, the relevant regulator is the Personal Data Protection Commission of Singapore.
61CHILDREN
Kestrel is a business-to-business enterprise software provider.
The Kestrel platform is intended for organisations and authorised business users.
No person under 18 years of age may establish or administer a Kestrel Account. Kestrel is not designed or offered as a consumer service directed at children.
Enterprise customers that process personal data concerning children through Kestrel remain responsible for determining whether that processing is permitted and what additional safeguards are required.
62SENSITIVE AND HIGH-RISK INFORMATION
Because Kestrel processes enterprise AI activity, Customer Data may potentially contain information subject to heightened legal or security protections.
Enterprise customers are responsible for determining whether particular categories of information may lawfully be submitted to Kestrel.
Customers should avoid submitting personal data that is unnecessary for the relevant processing purpose.
Kestrel may provide controls intended to assist customers with:
- PII detection;
- data classification;
- redaction;
- tokenisation;
- access control;
- policy enforcement;
- risk analysis; and
- security governance.
These technical controls do not eliminate an enterprise customer's underlying legal obligations.
63ANONYMISED AND AGGREGATED INFORMATION
Kestrel may generate or use aggregated or anonymised information where the information no longer constitutes personal data under applicable law.
Such information may be used for legitimate purposes including:
- security analysis;
- reliability analysis;
- capacity planning;
- statistical analysis;
- service operation;
- performance analysis;
- research; and
- business planning.
Kestrel will not describe information as anonymous where individuals remain reasonably identifiable from the information in the relevant context.
64THIRD-PARTY WEBSITES
Our website or communications may contain links to third-party websites or services.
Kestrel is not responsible for an independently operated third party's privacy practices merely because Kestrel links to that service.
Individuals should review the applicable third party's privacy information before providing personal data.
This provision does not limit Kestrel's responsibility for a third party that processes personal data on Kestrel's behalf.
65BUSINESS TRANSFERS
If ownership or control of all or part of Kestrel changes as part of a merger, acquisition, investment, reorganisation, financing, restructuring, asset sale or similar transaction, relevant information may form part of that transaction.
Where applicable, Kestrel will take appropriate steps concerning confidentiality and data protection.
Any successor's processing of personal data remains subject to applicable law.
66TERRITORIAL AVAILABILITY
Subject to applicable sanctions, export controls and other legal restrictions, Kestrel is available for purchase and deployment worldwide, including by organisations in the United States and California, except that Kestrel is not currently available for deployment within the European Union or European Economic Area as we continue our work toward supporting applicable requirements under the EU Artificial Intelligence Act.
EU and EEA availability will be introduced once the necessary compliance requirements have been addressed.
Please refer to our legal terms for current territorial restrictions.
This deployment restriction relates to availability of the Kestrel service.
The European Union Artificial Intelligence Act and European data-protection legislation are separate legal regimes.
The deployment restriction should therefore not be interpreted as a statement that European data-protection laws could never apply to other interactions involving Kestrel.
67DATA PROCESSING ADDENDUM
Enterprise customers may enter into a Data Processing Addendum (“DPA”) with Kestrel governing Kestrel's processing of Customer Data.
A DPA may address matters including:
- processing instructions;
- processing purposes;
- confidentiality;
- security;
- subprocessors;
- international transfers;
- data-subject requests;
- security incidents;
- audits;
- return of data;
- deletion of data; and
- other data-protection obligations.
Where an enterprise agreement or DPA contains more specific contractual commitments concerning Customer Data, those contractual commitments are governed by the applicable agreement.
This Privacy Policy does not replace the DPA.
68RELATIONSHIP WITH OTHER KESTREL POLICIES
This Privacy Policy should be read together with other applicable Kestrel documents, which may include:
- Terms of Service;
- enterprise agreements;
- Cookie Policy;
- Data Processing Addendum;
- security documentation;
- subprocessor information; and
- other applicable notices.
These documents serve different purposes.
This Privacy Policy principally explains how personal data is handled and is not intended to silently replace contractual provisions that appropriately belong within another agreement.
69CHANGES TO THIS PRIVACY POLICY
Kestrel may update this Privacy Policy from time to time.
Changes may be made to reflect:
- changes to our services;
- changes to our processing activities;
- changes to our technology;
- changes to our service providers;
- security developments;
- organisational changes;
- legal developments;
- regulatory developments; or
- other relevant circumstances.
When this Privacy Policy is updated, Kestrel will update the Last Updated date shown at the beginning of the document.
Kestrel will publish an updated version on the Website. Where a change materially affects the way personal data is processed, Kestrel will also provide notice by email or through the authenticated Platform dashboard where required by applicable law or contractual commitment.
An amendment to this Privacy Policy does not retroactively make unlawful processing lawful.
70CONTACT US
Questions, requests, concerns or complaints relating to this Privacy Policy or Kestrel's handling of personal data may be directed to:
Data Protection Officer
Rai Krish Kumar
Chief Executive Officer
Kestrel Advanced Systems Pte. Ltd.
Blk 31, #01-16C
535 Clementi Road
Singapore 599489
Privacy Contact:
privacy@kestreladvanced.com
General Contact:
contact@kestreladvanced.com
Website:
kestreladvanced.com
Singapore UEN:
202644596C