Privacy Policy

Effective July 24, 2026

1. Scope and information we collect

This notice explains how Kernl Systems Inc. handles information submitted through the informational pre-launch site and private waitlist.

The waitlist collects your name, email, farm or company, and any optional role, province, operation range, operational problem, or early-access preference you choose to provide.

Kernl may also receive source and referrer details, including limited campaign parameters and the referring page, to understand how people find the waitlist. The private prototype ref parameter is used only for prototype visibility and is not stored as waitlist attribution.

Kernl briefly processes your network address to prevent abuse; it is not stored with your lead.

2. Why we use it and who processes it

Kernl uses this information to manage the private waitlist, understand referrals, respond to an optional founder-conversation request, and contact you about private early access. Joining does not promise timing or access.

Kernl's hosting and email service providers process information only to support the waitlist and its messages on Kernl's behalf. Kernl does not sell waitlist information or use it for third-party advertising.

3. Consent, withdrawal, and your requests

You may withdraw consent and unsubscribe from waitlist email at any time through the link in a Kernl message. Messaging stops immediately after a valid unsubscribe request.

You may ask to access the information linked to your public waitlist identifier, correct current profile information, or request verified deletion. To protect the record, Kernl verifies privacy requests before acting on them.

Send access, correction, deletion, or other privacy questions to kernlfounders@gmail.com or write to Kernl Systems Inc., 4646 Curtiss Avenue, Regina, Saskatchewan, Canada S4W 0A4.

4. Retention while the waitlist operates

An active lead is retained only while the private waitlist is operating and its consent remains active. At least every 12 months, Kernl identifies active records due for review. A review records the database time but does not renew consent.

For an unresolved active duplicate, unsubscribe review, or suppression review, submitted personal information is removed after 30 days. This includes name, email forms, farm or company, optional answers, attribution, and the accepted-payload hash; the immutable consent-event core and non-content timestamps remain.

For an active lead, an email render snapshot and payload hash are cleared 30 days after a sent result or a definitive or reconciled non-retryable failed result. Pending or uncertain attempts retain that material only until the delivery decision is resolved or the program-close rule applies.

5. Retention after unsubscribe or deletion

On unsubscribe, messaging stops immediately. Within 30 days, Kernl clears original email, name or company, qualification details, lead and submission attribution, accepted-payload hashes, and email render snapshots and payload hashes, unless a recorded verified privacy request or documented legal hold temporarily requires that material.

While the waitlist email program remains active, Kernl keeps only normalized email, minimal consent and unsubscribe event evidence, and non-content provider-attempt metadata to honour suppression and demonstrate consent history.

On a verified deletion request, personal profile and address fields are cleared within 30 days. A one-way suppression digest and minimal consent, unsubscribe, and provider-attempt evidence may remain. That evidence cannot be used for marketing or profile reconstruction.

6. Program closure, evidence, and holds

Within 90 days after the waitlist program closes, remaining qualification, attribution, accepted-payload hashes, and email render snapshot or payload-hash information is deleted or anonymized, regardless of provider status.

Minimal consent, unsubscribe, suppression, and delivery evidence is retained for 36 months after the later of program closure or the latest unsubscribe, reviewed annually, and then deleted unless a documented legal hold applies.

A verified privacy request or legal hold must have an owner and future expiry. It pauses only destructive retention steps; it never pauses unsubscribe or no-send enforcement, access export, provider reconciliation, annual review reporting, or program closure. Expired or incomplete holds do not block retention.

The final eligible purge removes linked token, email, event, submission, action, and lead evidence together in one controlled transaction. If any step fails, the transaction rolls back so partial deletion cannot corrupt the retained evidence.

7. Security and contact

Kernl uses reasonable administrative, technical, and organizational safeguards to protect waitlist information against unauthorized access, loss, misuse, or alteration. No internet or storage system can be guaranteed completely secure.

Kernl Systems Inc. can be contacted at kernlfounders@gmail.com or 4646 Curtiss Avenue, Regina, Saskatchewan, Canada S4W 0A4.