OakridgeKernel

Regulatory
Alignment
& Compliance

Last updated: July 2026

Privacy Protocol

GDPR Art. 13–14

1. Data Controller Identity

The data controller responsible for processing your personal data within the scope of this website is OakridgeKernel, registered at 211 15, Stortorget 3, Malmo, Sweden, Sweden. You may contact our data protection officer at [email protected].

2. Categories of Personal Data Processed

We collect and process the following categories of personal data: (a) identification data (name, email address, telephone number); (b) communication data (messages, inquiries, project briefs submitted via contact forms); (c) technical data (IP address, browser type and version, operating system, referring URLs, pages visited, time and date of visit, duration of session); (d) payment and transaction data (processed exclusively through our PCI DSS-compliant payment processor, Stripe). We do not collect special categories of personal data as defined under GDPR Article 9.

3. Legal Basis for Processing

We process personal data under the following legal bases as stipulated in GDPR Article 6(1): (a) Consent — Article 6(1)(a) — where you have given explicit consent for specific processing purposes (e.g., marketing communications); (b) Contractual necessity — Article 6(1)(b) — where processing is necessary for the performance of a contract to which you are party, or for pre-contractual measures taken at your request; (c) Legitimate interest — Article 6(1)(f) — where processing is necessary for the purposes of our legitimate interests (e.g., fraud prevention, service improvement), provided such interests are not overridden by your fundamental rights.

4. Purpose of Data Processing

Personal data is processed for the following specific purposes: (a) to respond to your inquiries and provide requested services; (b) to perform contractual obligations including project delivery, billing, and payment processing; (c) to send administrative communications (invoices, project updates, legal notices); (d) to analyze website usage patterns and optimize user experience through anonymized analytics; (e) to comply with legal obligations including tax retention requirements and regulatory audits.

5. Data Retention Periods

Personal data is retained for the minimum period necessary to fulfill the purposes for which it was collected: (a) Contact form submissions: 24 months from last interaction; (b) Contract-related data: duration of the contract plus 10 years (Swedish Bookkeeping Act requirements); (c) Analytics data: 26 months in anonymized/aggregated form; (d) Cookie data: as specified in our Cookie Governance section below. Upon expiration of the retention period, data is securely deleted or irreversibly anonymized.

6. Data Recipients and Transfers

Your personal data may be shared with the following categories of recipients: (a) our hosting infrastructure provider (located within the European Economic Area); (b) Stripe Inc. for payment processing (data transfer mechanisms: Standard Contractual Clauses per GDPR Article 46(2)(c)); (c) analytics service providers operating under Data Processing Agreements compliant with GDPR Article 28; (d) public authorities where legally mandated. We do not sell, rent, or commercially distribute personal data to third parties.

7. Your Rights Under GDPR

Under the General Data Protection Regulation, you have the following rights: (a) Right of access (Art. 15) — request confirmation of whether your data is being processed and obtain a copy; (b) Right to rectification (Art. 16) — request correction of inaccurate personal data; (c) Right to erasure (Art. 17) — request deletion of your personal data ("right to be forgotten"); (d) Right to restriction of processing (Art. 18) — request limitation of processing in specific circumstances; (e) Right to data portability (Art. 20) — receive your data in a structured, machine-readable format; (f) Right to object (Art. 21) — object to processing based on legitimate interests or direct marketing; (g) Right not to be subject to automated decision-making (Art. 22). To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

8. Right to Lodge a Complaint

If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with a supervisory authority. In Sweden, the supervisory authority is: Datainspektionen (Swedish Authority for Privacy Protection), Box 8114, 104 20 Stockholm, Sweden. Website: www.datainspektionen.se.

Cookie Governance

ePrivacy Dir. 2002/58/EC

1. What Are Cookies

Cookies are small text files placed on your device when you visit a website. They enable the website to recognize your device, store your preferences, and analyze how you interact with the site. Cookies may be "session cookies" (deleted when you close your browser) or "persistent cookies" (retained for a specified period).

2. Cookies We Deploy

Strictly Necessary Cookies: These are essential for the website to function and cannot be disabled. They include session management cookies, security tokens (CSRF protection), and load-balancing identifiers. These cookies do not require consent under the ePrivacy Directive.

Functional Cookies: These remember your preferences (e.g., cookie consent choice, language settings) to provide a personalized experience. They are set only with your explicit consent.

Analytics Cookies: These collect anonymized data about how visitors use the website (pages visited, time spent, bounce rate). All analytics data is aggregated and does not identify individual users. These cookies are set only with your explicit consent.

3. Managing Cookie Preferences

When you first visit our website, a cookie consent banner is presented allowing you to accept or decline non-essential cookies. Your choice is stored locally in your browser (localStorage) and respected across sessions. You may modify your preferences at any time by clearing your browser's local storage for this site or by revisiting this page. Additionally, you can configure your browser to block or delete cookies. Please note that disabling strictly necessary cookies may impair website functionality.

4. Third-Party Cookies

Our website may set cookies through embedded content (e.g., Google Maps on the contact page). Google Maps may set cookies to track usage and improve its services. These third-party cookies are governed by the respective third party's privacy policy. We do not control the data collected by these third parties. For information on Google's privacy practices, consult Google's Privacy & Terms page.

Refund Framework

EU Consumer Rights

1. Scope of This Policy

This refund framework applies to all services provided by OakridgeKernel. As our services involve custom digital engineering, web development, and consulting, standard consumer withdrawal rights under the EU Consumer Rights Directive (2011/83/EU) Article 16(e) (contracts for digital content not supplied on a tangible medium, where performance has commenced with the consumer's prior consent and acknowledgement of loss of withdrawal rights) are modified as described below.

2. Pre-Commencement Cancellation

If you cancel a project before any work has commenced, you are entitled to a full refund of any advance payment within 14 business days. Cancellation must be submitted in writing to [email protected]. "Commencement" is defined as the first billable hour of engineering work or the delivery of the first milestone artifact, whichever occurs first.

3. Milestone-Based Refund Structure

For projects structured with defined milestones, refunds are calculated based on completed and incomplete milestones: (a) Completed milestones that have been delivered and accepted are non-refundable; (b) Incomplete milestones for which payment has been received in advance are eligible for a pro-rata refund based on percentage of work completed; (c) Partially completed milestones are assessed individually — you will receive a refund proportional to the percentage of work not yet executed. Assessment is conducted within 10 business days of cancellation request.

4. Service Quality Remedies

If delivered work materially deviates from the agreed scope, specifications, or quality standards defined in the project brief or statement of work, you may request: (a) Remediation — correction of deviations at no additional cost within a reasonable timeframe; (b) Partial refund — proportional price reduction reflecting the diminished value of the deliverable; (c) Termination — cancellation of the remaining project scope with refund for unperformed work. Quality disputes are subject to a 30-day resolution window from the date of delivery.

5. Refund Processing

All approved refunds are processed to the original payment method within 14 business days. Refund amounts are denominated in the original transaction currency (EUR). Banking fees or currency conversion costs incurred during refund processing are borne by OakridgeKernel. You will receive written confirmation of the refund amount and expected processing timeline.

Terms of Engagement

Contractual Protocol

1. Contract Formation

A binding contract between you ("the Client") and OakridgeKernel ("the Provider") is formed upon: (a) your written acceptance of a project proposal or statement of work (SOW); (b) receipt of initial payment as specified in the SOW; or (c) commencement of work by the Provider following your verbal or written authorization. Each project is governed by its individual SOW, which shall take precedence over these general terms in the event of conflict.

2. Scope and Change Management

The Provider will deliver services strictly within the scope defined in the applicable SOW. Any request for scope changes ("Change Requests") must be submitted in writing. The Provider will assess the impact on timeline, cost, and resources and provide a written Change Order for Client approval before implementation. Neither party may unilaterally modify the agreed scope without written consent.

3. Payment Terms

Invoices are issued according to the milestone payment schedule defined in the SOW. Payment is due within 14 calendar days of invoice date unless otherwise specified. Late payments accrue interest at the rate of 8% per annum plus the applicable statutory reference rate per the Swedish Interest Act (Räntelagen 1975:635). The Provider reserves the right to suspend work if payment is more than 14 days overdue, with 7 days written notice.

4. Intellectual Property

Upon full payment of all outstanding invoices, the Provider assigns to the Client all intellectual property rights in the delivered work product, including but not limited to source code, designs, documentation, and configurations. This assignment is conditional upon complete payment. The Provider retains the right to use anonymized, non-identifiable elements of the work for portfolio and case study purposes, unless explicitly restricted in the SOW. Pre-existing intellectual property and third-party components remain subject to their original licenses.

5. Confidentiality

Both parties agree to maintain strict confidentiality of all proprietary information exchanged during the course of the engagement. This obligation survives termination of the agreement for a period of 3 years. Confidential information includes, but is not limited to: business strategies, technical specifications, source code, user data, financial information, and trade secrets. Exceptions apply for information that: (a) is publicly available through no fault of the receiving party; (b) was known to the receiving party prior to disclosure; (c) is independently developed without reference to the confidential information.

6. Limitation of Liability

The Provider's total aggregate liability under any agreement shall not exceed the total fees paid by the Client for the specific project giving rise to the claim. Neither party shall be liable for indirect, consequential, incidental, or punitive damages, including but not limited to loss of profits, data, or business opportunities, regardless of whether such damages were foreseeable. These limitations do not apply to liability arising from gross negligence, willful misconduct, or breaches of confidentiality obligations.

7. Force Majeure

Neither party shall be liable for failure or delay in performance resulting from events beyond its reasonable control, including but not limited to natural disasters, pandemics, government actions, war, terrorism, infrastructure failures, or internet service disruptions. The affected party must notify the other party within 48 hours of becoming aware of such event. If the force majeure event continues for more than 60 days, either party may terminate the affected SOW without liability.

8. Governing Law and Dispute Resolution

This agreement is governed by the laws of Sweden, excluding its conflict of laws provisions. Any disputes arising from or relating to this agreement shall first be submitted to mediation administered by the Swedish Arbitration Institute. If mediation is unsuccessful within 60 days, disputes shall be finally resolved by arbitration in accordance with the Rules for Expedited Arbitration of the Stockholm Chamber of Commerce. The seat of arbitration is Malmö, Sweden. The language of proceedings is English.

9. Termination

Either party may terminate an agreement with 30 days written notice for convenience. The Provider may terminate immediately upon written notice if the Client: (a) fails to make payment within 30 days of the due date; (b) materially breaches any term and fails to remedy within 14 days of written notice; (c) becomes insolvent or enters bankruptcy proceedings. Upon termination for convenience by the Client, the Provider is entitled to payment for all work completed to date plus any non-cancellable third-party commitments.