GDPR · UK GDPR · CCPA / CPRA

What we process, the lawful basis for each purpose, how long it is kept and how to exercise your rights. Last updated 8 September 2026.

§ 01Who is responsible

Controller

Cerebellum Intel Group, a Delaware limited liability company, is the controller for data processed through this website and for research conducted on its own account. Where we conduct an engagement on a client's instructions, the client is the controller and we act as processor under written terms.

Contact

Privacy correspondence, including rights requests, should be sent to support@cerebellum.online with 'Privacy request' in the subject line.

§ 02What we process and why

Website operation

Server request records including IP address, user agent, referring page and timestamps, used to deliver the site, rate-limit and defend against abuse. Lawful basis: legitimate interests, GDPR Article 6(1)(f).

Consent state

Your cookie decision, the categories selected, the method and the timestamp, stored locally in your browser as evidence of consent. Lawful basis: legal obligation and legitimate interests, Articles 6(1)(c) and 6(1)(f).

Enquiries and intake

Name, organisation, contact details and anything you choose to include when you contact us or request an engagement. Lawful basis: steps prior to a contract and legitimate interests, Articles 6(1)(b) and 6(1)(f).

Optional measurement

Aggregate page and referral counts, only where you have opted in. Lawful basis: consent, Article 6(1)(a), withdrawable at any time.

Engagement research

Information lawfully and manifestly made public by the subject, or drawn from government records and widely distributed media, processed for corporate risk and due diligence. Lawful basis: legitimate interests, Article 6(1)(f), with special category material handled only under Article 9(2)(e).

§ 03What we do not do

No sale or sharing

We do not sell personal information and do not share it for cross-context behavioural advertising as those terms are defined by the CCPA/CPRA. We honour Global Privacy Control signals as a valid opt-out.

No consumer reports

We are not a Consumer Reporting Agency under the FCRA. Our work product may not be used as a factor in eligibility decisions for employment, credit, insurance or housing.

No automated decisions

We do not carry out automated decision-making producing legal or similarly significant effects within the meaning of GDPR Article 22. Every finding is reached and signed by a named analyst.

No model training

Client material and subject data are not used to train third-party models.

§ 04Your rights

GDPR / UK GDPR

Access, rectification, erasure, restriction, portability, objection to legitimate-interests processing, and the right to withdraw consent where consent is the basis. You may also lodge a complaint with your supervisory authority.

CCPA / CPRA

Right to know, delete and correct, to opt out of sale or sharing (which we do not conduct), to limit use of sensitive personal information, and to be free from retaliation for exercising a right. An authorised agent may act on your behalf with proof of authority.

Publicly available exemption

Information lawfully available from government records, widely distributed media, or made public by the individual is excluded from 'personal information' under Cal. Civ. Code § 1798.140. Where a request concerns exempt material we will say so in writing rather than silently decline.

Client-controlled matters

Where we process as a processor for a client, we route your request to that controller and support their response.

§ 05How to exercise a right

01 · Receipt

Requests are submitted to support@cerebellum.online and logged with a reference on the day of receipt.

02 · Verification

Identity is verified proportionately to the sensitivity of the material, without collecting more data than the verification requires.

03 · Determination

Scope, applicable framework and any exemption are assessed and recorded in a written determination.

04 · Response

Substantive response within thirty calendar days for GDPR requests and forty-five for CCPA requests, extendable once where permitted and notified to you.

§ 06Retention, security and transfers

Retention

Website and intake correspondence is retained for twelve months. Commercial assessment work product is retained for three years from delivery unless a mandate specifies otherwise. Engagement and conflicts records are retained for six years for defence of legal claims. Legal-hold material is segregated until the hold lifts.

Security

Encryption in transit and at rest, minimum-necessary case teams, role-based access, and subprocessors screened before engagement and bound by written processing terms.

International transfers

Transfers out of the EEA or UK rely on Standard Contractual Clauses with a documented transfer impact assessment. Jurisdiction-controlled residency is available by contract.

Incidents

Confirmed personal-data breaches are notified without undue delay and within seventy-two hours of confirmation, to the controller and to regulators or individuals where required.

§ 07Children and changes

Children

This site is not directed to children and we do not knowingly process the personal information of anyone under sixteen. We do not sell or share the personal information of individuals under sixteen.

Changes

Material changes are reflected here with a revised date. Where a change affects a consent-based purpose, consent is requested again before that purpose resumes.

See also the Cookie Policy and the Compliance architecture.