What we process, the lawful basis for each purpose, how long it is kept and how to exercise your rights. Last updated 8 September 2026.
§ 01Who is responsible
Cerebellum Intel Group, a Delaware limited liability company, is the controller for data processed through this website and for research conducted on its own account. Where we conduct an engagement on a client's instructions, the client is the controller and we act as processor under written terms.
Privacy correspondence, including rights requests, should be sent to support@cerebellum.online with 'Privacy request' in the subject line.
§ 02What we process and why
Server request records including IP address, user agent, referring page and timestamps, used to deliver the site, rate-limit and defend against abuse. Lawful basis: legitimate interests, GDPR Article 6(1)(f).
Your cookie decision, the categories selected, the method and the timestamp, stored locally in your browser as evidence of consent. Lawful basis: legal obligation and legitimate interests, Articles 6(1)(c) and 6(1)(f).
Name, organisation, contact details and anything you choose to include when you contact us or request an engagement. Lawful basis: steps prior to a contract and legitimate interests, Articles 6(1)(b) and 6(1)(f).
Aggregate page and referral counts, only where you have opted in. Lawful basis: consent, Article 6(1)(a), withdrawable at any time.
Information lawfully and manifestly made public by the subject, or drawn from government records and widely distributed media, processed for corporate risk and due diligence. Lawful basis: legitimate interests, Article 6(1)(f), with special category material handled only under Article 9(2)(e).
§ 03What we do not do
We do not sell personal information and do not share it for cross-context behavioural advertising as those terms are defined by the CCPA/CPRA. We honour Global Privacy Control signals as a valid opt-out.
We are not a Consumer Reporting Agency under the FCRA. Our work product may not be used as a factor in eligibility decisions for employment, credit, insurance or housing.
We do not carry out automated decision-making producing legal or similarly significant effects within the meaning of GDPR Article 22. Every finding is reached and signed by a named analyst.
Client material and subject data are not used to train third-party models.
§ 04Your rights
Access, rectification, erasure, restriction, portability, objection to legitimate-interests processing, and the right to withdraw consent where consent is the basis. You may also lodge a complaint with your supervisory authority.
Right to know, delete and correct, to opt out of sale or sharing (which we do not conduct), to limit use of sensitive personal information, and to be free from retaliation for exercising a right. An authorised agent may act on your behalf with proof of authority.
Information lawfully available from government records, widely distributed media, or made public by the individual is excluded from 'personal information' under Cal. Civ. Code § 1798.140. Where a request concerns exempt material we will say so in writing rather than silently decline.
Where we process as a processor for a client, we route your request to that controller and support their response.
§ 05How to exercise a right
Requests are submitted to support@cerebellum.online and logged with a reference on the day of receipt.
Identity is verified proportionately to the sensitivity of the material, without collecting more data than the verification requires.
Scope, applicable framework and any exemption are assessed and recorded in a written determination.
Substantive response within thirty calendar days for GDPR requests and forty-five for CCPA requests, extendable once where permitted and notified to you.
§ 06Retention, security and transfers
Website and intake correspondence is retained for twelve months. Commercial assessment work product is retained for three years from delivery unless a mandate specifies otherwise. Engagement and conflicts records are retained for six years for defence of legal claims. Legal-hold material is segregated until the hold lifts.
Encryption in transit and at rest, minimum-necessary case teams, role-based access, and subprocessors screened before engagement and bound by written processing terms.
Transfers out of the EEA or UK rely on Standard Contractual Clauses with a documented transfer impact assessment. Jurisdiction-controlled residency is available by contract.
Confirmed personal-data breaches are notified without undue delay and within seventy-two hours of confirmation, to the controller and to regulators or individuals where required.
§ 07Children and changes
This site is not directed to children and we do not knowingly process the personal information of anyone under sixteen. We do not sell or share the personal information of individuals under sixteen.
Material changes are reflected here with a revised date. Where a change affects a consent-based purpose, consent is requested again before that purpose resumes.
See also the Cookie Policy and the Compliance architecture.