Privacy policy
Last updated: September 2026
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is KernelHost GmbH, Krottenbachstraße 277, 1190 Vienna, Austria, represented by the managing director Ing. Hani Hussein, B.Sc. Email: info@kernelhost.com, phone: +43 650 8209883.
Hosting and server log files
This website is operated on servers owned by KernelHost GmbH in the Frankfurt am Main data centre (Germany). When you visit, technically necessary data is processed: IP address, date and time, page accessed, amount of data transferred, browser and operating system as well as the previously visited page. This data is stored in server log files and deleted after 14 days at the latest unless a security-related evaluation is required.
The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in the secure and stable operation of the website and in defending against attacks.
Cookies and local storage
This website does not use tracking or advertising cookies and no analytics services. Only the following are technically necessary: a cookie "hanitlg_land" storing your country selection (Germany or Austria, valid for 12 months) and an entry "hh_theme" in the local storage of your browser for the selected light or dark mode. This data is not transmitted to us and serves display purposes only. The legal basis is § 165 (3) Austrian TKG 2021 and § 25 (2) German TDDDG in conjunction with Art. 6 (1) (f) GDPR.
Contact form and ticket system
When you use the request form, the data entered (name, email address, optionally company and phone number, topic, message) as well as your IP address and the time are transmitted to the KernelHost GmbH ticket system (client portal kernelhost.com, operated on own servers in Frankfurt) and stored there as a support ticket. You receive an automatic confirmation by email. The IP address serves to protect against abuse and is additionally stored for a maximum of two hours in a rate limit on the web server.
The legal basis is Art. 6 (1) (b) GDPR (initiation and performance of a contract) and Art. 6 (1) (f) GDPR (protection against abuse). Tickets are stored after completion of the request for the duration of statutory retention obligations, but no longer than seven years; if no contract is concluded they are deleted after three years at the latest.
Email, phone and client portal
When you contact us by email at info@kernelhost.com or by phone, we process the data you provide to handle your request (Art. 6 (1) (b) and (f) GDPR). Emails to this address are processed in the KernelHost GmbH ticket system. For the email operations of KernelHost GmbH, services of Google Ireland Limited (Google Workspace) are used; a data processing agreement with EU standard contractual clauses is in place with Google. If you create a client account at kernelhost.com, the privacy policy of kernelhost.com additionally applies.
Live chat (KernelHost chatbot)
On request you can start a live chat. The chat is only loaded when you click the "Live chat" button. A script from kernelhost.com (KernelHost GmbH) is then loaded and a random session identifier is stored in your browser (cookie and local storage, no link to your person). Your messages are stored on KernelHost GmbH servers and transmitted to Anthropic PBC (USA), which provides the language model, in order to generate answers. Anthropic is certified under the EU-US Data Privacy Framework; standard contractual clauses apply additionally. Please do not enter passwords or particularly sensitive data in the chat.
The legal basis is Art. 6 (1) (a) GDPR (consent by actively starting the chat) and Art. 6 (1) (b) GDPR. Chat histories are deleted after 90 days unless they become part of a support request.
If you contact us via WhatsApp, WhatsApp Ireland Limited (Meta) processes your phone number, metadata and message content according to its own privacy policy, also outside the EU. We use WhatsApp Business exclusively for communication with you and do not upload contact data from our address book. Use is voluntary and on your initiative (Art. 6 (1) (a) and (b) GDPR). Alternatively, email, form and phone are available.
External links
This website contains links to kernelhost.com and to third-party websites. The respective provider is responsible for their data processing. No third-party content is embedded automatically; fonts and all resources are loaded from our own server.
Data security
Transmission takes place exclusively encrypted via TLS (HTTPS). The web server is configured with current security policies (Content Security Policy, HSTS), access is limited to the necessary minimum and backups are stored encrypted.
Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You may withdraw consent at any time with effect for the future. Please contact info@kernelhost.com.
You also have the right to lodge a complaint with a supervisory authority. In Austria this is the Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, www.dsb.gv.at. Data subjects in Germany may also contact the state data protection authority responsible for their place of residence.
Changes
We adapt this privacy policy when the legal situation or our processing changes. The version published on this page applies.