Cerebellum engineers its open-source intelligence and due diligence frameworks to operate outside the regulatory perimeter of consumer privacy and employment screening mandates. Our intelligence modules rely exclusively on publicly available data, maintaining operational compliance with state, federal and European data frameworks.
Continuing to use this site is consenting to the data-processing practices described below. If you do not consent, close this page. Accepting the banner stores only a local consent state; no personal data is collected.
§ 00Operating principles
Public vectors only
Government records, widely distributed media, and statements subjects have intentionally made public.
Outside the perimeter
Structured to sit outside consumer privacy and employment-screening mandates by design, not by workaround.
Documented basis
Lawful-basis memos and balancing tests maintained per framework, per engagement.
§ 01-03Statutory frameworks
California Consumer Privacy Act exemption
- Statutory exemption
- Under Cal. Civ. Code § 1798.140, information a business has a reasonable basis to believe is lawfully made available from government records, widely distributed media, or statements the consumer has intentionally made available to the general public is expressly excluded from the definition of "Personal Information."
- Operational structure
- Cerebellum restricts intelligence gathering entirely to those open-source vectors. Because we do not aggregate hidden commercial profiles, private purchase histories or non-public telemetry, the data processed in our commercial assessments is categorically exempt from CCPA deletion, opt-out and portability mandates.
Fair Credit Reporting Act non-applicability
- Commercial scope constraint
- The FCRA regulates consumer reports used as a factor in establishing eligibility for employment, credit, insurance or housing. Cerebellum operates exclusively as a corporate risk consultancy and is not a Consumer Reporting Agency (CRA).
- Binding disclaimers
- Our products evaluate B2B commercial risk, brand contagion and corporate alignment. Binding disclaimers are embedded in every Master Services Agreement and dossier footer, expressly prohibiting use of our reports in hiring, retention, reassignment or termination decisions.
General Data Protection Regulation framework
- Article 6, lawful basis
- Public intelligence is processed under Article 6(1)(f), on the basis that a client's commercial risk and brand-safety requirements constitute a legitimate interest. Documented balancing tests are maintained verifying that this processing does not override the fundamental rights of the subject.
- Article 9, special category data
- Where a commercial assessment documents political opinions, religious beliefs or other protected classes, processing is executed strictly under the Article 9(2)(e) exception, which permits processing of special category data the subject has manifestly made public themselves.
- Minimization & retention
- In accordance with GDPR storage-limitation principles, baseline commercial assessment data is retained for a standard operational window of three years unless a client mandate specifies otherwise.
§ 04Collection boundary
The compliance position holds only because the collection boundary is fixed. What follows is the operative definition of that boundary, applied identically to every mandate.
Corporate registries and beneficial-ownership filings, court and insolvency dockets, regulatory and enforcement registers, sanctions and PEP lists, property and vessel registries, procurement and lobbying disclosures, licensed news and archival media, published academic and professional credentials, and statements the subject has published to the general public.
Intrusion, credential use, pretexting against a subject's own people, purchased non-public telemetry, private purchase histories, covert interception and consumer credit files are out of scope unless expressly authorised in writing.
Every material assertion carries a source, a capture date and a confidence grade of confirmed, corroborated or unresolved. Where a source is open but ephemeral, the artefact is timestamped and hashed so the record survives challenge.
§ 05Permissible purpose
B2B counterparty and vendor risk, pre-transaction diligence, brand-contagion and contract-liability analysis, corporate governance review, and litigation or enforcement support conducted through counsel.
Any use as a factor in an individual's eligibility for employment, credit, insurance, housing, or any other purpose regulated by the FCRA. Prohibited uses are recited in the MSA, restated in every dossier footer, and are grounds for immediate termination of the engagement.
The client warrants in writing that the engagement serves a B2B commercial purpose and no FCRA-regulated purpose.
Reports are confidential to the named recipients. Redistribution beyond the recipient list requires written consent.
Clients may not use our work product as a factor in hiring, retention, reassignment or termination decisions.
On termination, work product is returned or destroyed on request, with certification.
§ 06Data subject rights
- Access and copy
- A data subject may request confirmation of whether commercial assessment material referencing them is held, and a copy of that material, subject to client confidentiality, legal privilege and third-party rights.
- Rectification
- Factual inaccuracies are corrected at source and, where a report has been issued, a corrected addendum is circulated to the original recipients.
- Objection
- Where processing rests on Article 6(1)(f), a subject may object. A fresh balancing test is run and processing ceases unless compelling legitimate grounds are documented.
- Erasure
- Applied where no overriding legal, contractual or defence-of-claims basis remains. Legal-hold material is retained until the hold lifts.
- 01 · Receipt
Requests are submitted to support@cerebellum.online and logged with a reference on the day of receipt.
- 02 · Verification
Identity is verified proportionately to the sensitivity of the material, without collecting more data than the verification requires.
- 03 · Determination
Scope, applicable framework and any exemption are assessed and recorded in a written determination.
- 04 · Response
Substantive response within thirty calendar days for GDPR requests and forty-five for CCPA requests, extendable once where permitted and notified.
§ 07Retention schedule
Three years from delivery, unless a client mandate specifies a shorter or longer window.
Three years, aligned to the associated work product, then destroyed with a certificate on request.
Six years, retained for defence of legal claims and professional-obligation audit.
Retained for the duration of the hold, segregated and excluded from routine destruction cycles.
Twelve months for intake correspondence; consent state is stored locally in the visitor's browser only.
§ 08Security, vendors and transfers
Encrypted in transit and at rest. PGP available for correspondence; Signal for voice and message traffic once identity is established.
Minimum-necessary case teams, role-based access, and client identity treated internally as material non-public information.
Jurisdiction-controlled data residency by contract, including EU-resident processing where a mandate requires it.
Subprocessors are diligence-screened before engagement, bound by written processing terms, and reviewed on a standing cycle.
International transfers rely on Standard Contractual Clauses with a documented transfer impact assessment.
Confirmed personal-data breaches are notified to the controller without undue delay and within seventy-two hours of confirmation.
§ 09Jurisdictional coverage
FCRA non-applicability by commercial scope; CCPA/CPRA publicly-available exemption; state consumer privacy statutes tracked as they take effect.
GDPR Articles 6(1)(f) and 9(2)(e), with documented balancing tests and SCC-based transfers.
UK GDPR and the Data Protection Act 2018, on the same legitimate-interests architecture.
Local counsel is engaged where a mandate touches a jurisdiction with restrictive investigation or data-localisation rules.
§ 10Analytical governance
No automated system issues a finding. Machine assistance is limited to collection, translation and clustering; every conclusion is reached and signed by a named analyst.
We do not perform automated decision-making producing legal or similarly significant effects within the meaning of GDPR Article 22.
Client material and subject data are not used to train third-party models.
§ 11Standing disclosures
Cerebellum.online provides open-source intelligence for B2B commercial risk, brand contagion and contract liability analysis. Cerebellum is not a Consumer Reporting Agency (CRA) as defined by the Fair Credit Reporting Act (FCRA). The intelligence and assessments provided on this platform do not constitute consumer reports and may not be utilized, in whole or in part, as a factor in establishing an individual's eligibility for employment, credit, insurance, housing, or any other purpose regulated by the FCRA.
Cerebellum.online limits its data processing to information lawfully and manifestly made available to the general public by the data subject, or derived from widely distributed media and government records. This publicly available data is exempt from California Consumer Privacy Act (CCPA) categorizations of personal information. For jurisdictions governed by the GDPR, Cerebellum relies on the Legitimate Interests processing basis (Article 6(1)(f)) and the Manifestly Made Public exception (Article 9(2)(e)) to conduct corporate due diligence and commercial risk evaluations.