Legal & Regulatory

Compliance architecture

Cerebellum engineers its open-source intelligence and due diligence frameworks to operate outside the regulatory perimeter of consumer privacy and employment screening mandates. Our intelligence modules rely exclusively on publicly available data, maintaining operational compliance with state, federal and European data frameworks.

CCPA / CPRA · Cal. Civ. Code § 1798.140
FCRA · Non-CRA commercial scope
GDPR · Art. 6(1)(f) / Art. 9(2)(e)
Consent notice

Continuing to use this site is consenting to the data-processing practices described below. If you do not consent, close this page. Accepting the banner stores only a local consent state; no personal data is collected.

§ 00Operating principles

CI
Regulatory Perimeter
FCRA · GDPR · CCPA aligned
P-01

Public vectors only

Government records, widely distributed media, and statements subjects have intentionally made public.

P-02

Outside the perimeter

Structured to sit outside consumer privacy and employment-screening mandates by design, not by workaround.

P-03

Documented basis

Lawful-basis memos and balancing tests maintained per framework, per engagement.

§ 01-03Statutory frameworks

CCPA / CPRA§ 01

California Consumer Privacy Act exemption

Statutory exemption
Under Cal. Civ. Code § 1798.140, information a business has a reasonable basis to believe is lawfully made available from government records, widely distributed media, or statements the consumer has intentionally made available to the general public is expressly excluded from the definition of "Personal Information."
Operational structure
Cerebellum restricts intelligence gathering entirely to those open-source vectors. Because we do not aggregate hidden commercial profiles, private purchase histories or non-public telemetry, the data processed in our commercial assessments is categorically exempt from CCPA deletion, opt-out and portability mandates.
FCRA§ 02

Fair Credit Reporting Act non-applicability

Commercial scope constraint
The FCRA regulates consumer reports used as a factor in establishing eligibility for employment, credit, insurance or housing. Cerebellum operates exclusively as a corporate risk consultancy and is not a Consumer Reporting Agency (CRA).
Binding disclaimers
Our products evaluate B2B commercial risk, brand contagion and corporate alignment. Binding disclaimers are embedded in every Master Services Agreement and dossier footer, expressly prohibiting use of our reports in hiring, retention, reassignment or termination decisions.
GDPR§ 03

General Data Protection Regulation framework

Article 6, lawful basis
Public intelligence is processed under Article 6(1)(f), on the basis that a client's commercial risk and brand-safety requirements constitute a legitimate interest. Documented balancing tests are maintained verifying that this processing does not override the fundamental rights of the subject.
Article 9, special category data
Where a commercial assessment documents political opinions, religious beliefs or other protected classes, processing is executed strictly under the Article 9(2)(e) exception, which permits processing of special category data the subject has manifestly made public themselves.
Minimization & retention
In accordance with GDPR storage-limitation principles, baseline commercial assessment data is retained for a standard operational window of three years unless a client mandate specifies otherwise.

§ 04Collection boundary

The compliance position holds only because the collection boundary is fixed. What follows is the operative definition of that boundary, applied identically to every mandate.

In scopeC-01

Corporate registries and beneficial-ownership filings, court and insolvency dockets, regulatory and enforcement registers, sanctions and PEP lists, property and vessel registries, procurement and lobbying disclosures, licensed news and archival media, published academic and professional credentials, and statements the subject has published to the general public.

Requires written authorisationC-02

Intrusion, credential use, pretexting against a subject's own people, purchased non-public telemetry, private purchase histories, covert interception and consumer credit files are out of scope unless expressly authorised in writing.

ProvenanceC-03

Every material assertion carries a source, a capture date and a confidence grade of confirmed, corroborated or unresolved. Where a source is open but ephemeral, the artefact is timestamped and hashed so the record survives challenge.

§ 05Permissible purpose

PermittedU-01

B2B counterparty and vendor risk, pre-transaction diligence, brand-contagion and contract-liability analysis, corporate governance review, and litigation or enforcement support conducted through counsel.

ProhibitedU-02

Any use as a factor in an individual's eligibility for employment, credit, insurance, housing, or any other purpose regulated by the FCRA. Prohibited uses are recited in the MSA, restated in every dossier footer, and are grounds for immediate termination of the engagement.

Purpose warranty

The client warrants in writing that the engagement serves a B2B commercial purpose and no FCRA-regulated purpose.

Onward disclosure

Reports are confidential to the named recipients. Redistribution beyond the recipient list requires written consent.

No adverse action

Clients may not use our work product as a factor in hiring, retention, reassignment or termination decisions.

Return and destruction

On termination, work product is returned or destroyed on request, with certification.

§ 06Data subject rights

Rights honoured§ 06.1
Access and copy
A data subject may request confirmation of whether commercial assessment material referencing them is held, and a copy of that material, subject to client confidentiality, legal privilege and third-party rights.
Rectification
Factual inaccuracies are corrected at source and, where a report has been issued, a corrected addendum is circulated to the original recipients.
Objection
Where processing rests on Article 6(1)(f), a subject may object. A fresh balancing test is run and processing ceases unless compelling legitimate grounds are documented.
Erasure
Applied where no overriding legal, contractual or defence-of-claims basis remains. Legal-hold material is retained until the hold lifts.
Request handling§ 06.2
  1. 01 · Receipt

    Requests are submitted to support@cerebellum.online and logged with a reference on the day of receipt.

  2. 02 · Verification

    Identity is verified proportionately to the sensitivity of the material, without collecting more data than the verification requires.

  3. 03 · Determination

    Scope, applicable framework and any exemption are assessed and recorded in a written determination.

  4. 04 · Response

    Substantive response within thirty calendar days for GDPR requests and forty-five for CCPA requests, extendable once where permitted and notified.

support@cerebellum.online

§ 07Retention schedule

Commercial assessment work productR-01

Three years from delivery, unless a client mandate specifies a shorter or longer window.

Source artefacts and capture recordsR-02

Three years, aligned to the associated work product, then destroyed with a certificate on request.

Engagement and conflicts recordsR-03

Six years, retained for defence of legal claims and professional-obligation audit.

Legal-hold materialR-04

Retained for the duration of the hold, segregated and excluded from routine destruction cycles.

Website and intake dataR-05

Twelve months for intake correspondence; consent state is stored locally in the visitor's browser only.

§ 08Security, vendors and transfers

EncryptionS-01

Encrypted in transit and at rest. PGP available for correspondence; Signal for voice and message traffic once identity is established.

Access controlS-02

Minimum-necessary case teams, role-based access, and client identity treated internally as material non-public information.

ResidencyS-03

Jurisdiction-controlled data residency by contract, including EU-resident processing where a mandate requires it.

Vendor KYCS-04

Subprocessors are diligence-screened before engagement, bound by written processing terms, and reviewed on a standing cycle.

TransfersS-05

International transfers rely on Standard Contractual Clauses with a documented transfer impact assessment.

IncidentsS-06

Confirmed personal-data breaches are notified to the controller without undue delay and within seventy-two hours of confirmation.

§ 09Jurisdictional coverage

United StatesJ-01

FCRA non-applicability by commercial scope; CCPA/CPRA publicly-available exemption; state consumer privacy statutes tracked as they take effect.

European Union / EEAJ-02

GDPR Articles 6(1)(f) and 9(2)(e), with documented balancing tests and SCC-based transfers.

United KingdomJ-03

UK GDPR and the Data Protection Act 2018, on the same legitimate-interests architecture.

Rest of worldJ-04

Local counsel is engaged where a mandate touches a jurisdiction with restrictive investigation or data-localisation rules.

§ 10Analytical governance

Human determinationG-01

No automated system issues a finding. Machine assistance is limited to collection, translation and clustering; every conclusion is reached and signed by a named analyst.

No automated decisionsG-02

We do not perform automated decision-making producing legal or similarly significant effects within the meaning of GDPR Article 22.

Model boundariesG-03

Client material and subject data are not used to train third-party models.

§ 11Standing disclosures

FCRA / B2B commercial disclaimerD-01

Cerebellum.online provides open-source intelligence for B2B commercial risk, brand contagion and contract liability analysis. Cerebellum is not a Consumer Reporting Agency (CRA) as defined by the Fair Credit Reporting Act (FCRA). The intelligence and assessments provided on this platform do not constitute consumer reports and may not be utilized, in whole or in part, as a factor in establishing an individual's eligibility for employment, credit, insurance, housing, or any other purpose regulated by the FCRA.

GDPR & CCPA OSINT processing noticeD-02

Cerebellum.online limits its data processing to information lawfully and manifestly made available to the general public by the data subject, or derived from widely distributed media and government records. This publicly available data is exempt from California Consumer Privacy Act (CCPA) categorizations of personal information. For jurisdictions governed by the GDPR, Cerebellum relies on the Legitimate Interests processing basis (Article 6(1)(f)) and the Manifestly Made Public exception (Article 9(2)(e)) to conduct corporate due diligence and commercial risk evaluations.

§ 12Statutory references