Privacy Policy
How Korner LLC collects, uses, retains and discloses information in the course of operating network and compute infrastructure.
Scope and controller
This policy applies to the korner.team website and to the infrastructure services operated by Korner LLC, a limited liability company registered in the State of Wyoming, United States ("Korner", "we", "us").
Korner acts as a data controller in respect of its own customer and website data, and as a data processor in respect of end-user data that passes through or is stored on infrastructure operated on a customer’s behalf.
Information we collect
Account and commercial data
- Identity and contact details supplied at registration or during onboarding.
- Billing entity, tax identifiers and payment status. Card data is handled by our payment processors and is not stored by Korner.
- Correspondence with sales, support and network operations.
Operational and network data
- Connection metadata: source and destination addresses, ports, protocol, packet and byte counts, timestamps.
- Flow records and sampled packet headers used for mitigation, capacity planning and abuse investigation.
- Attack telemetry: signatures, classification results and mitigation actions taken.
- Authentication, provisioning and control-panel audit logs.
Website data
Server logs containing IP address, user agent, referrer and requested resource. The public website does not use advertising or cross-site tracking technology.
How we use information
- To deliver, provision, operate and support contracted services.
- To detect, classify and mitigate denial-of-service and other network abuse.
- To bill, collect payment and maintain financial records.
- To investigate abuse reports and enforce the Acceptable Use Policy.
- To comply with legal obligations and respond to lawful requests.
Legal bases
| Purpose | Basis (GDPR Art. 6) |
|---|---|
| Service delivery and support | Performance of a contract |
| Network security and abuse mitigation | Legitimate interests |
| Billing and financial records | Legal obligation |
| Marketing communications | Consent, withdrawable at any time |
Retention
| Category | Retention |
|---|---|
| Flow records and mitigation telemetry | Up to 30 days |
| Control-panel and authentication logs | Up to 12 months |
| Support correspondence | Duration of contract + 24 months |
| Financial records | As required by applicable law |
Your rights
Depending on your jurisdiction you may have rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with a supervisory authority. Requests should be sent to legal@korner.team and will be answered within statutory timeframes.
Security
Access to production systems is restricted, logged and subject to multi-factor authentication. Physical infrastructure is housed in access-controlled, carrier-neutral facilities. No system is absolutely secure; we commit to notifying affected customers without undue delay in the event of a breach affecting their data.
International transfers
Korner operates infrastructure in North America, Europe, Asia-Pacific, Latin America, the Middle East and Africa. Operating that network necessarily involves transferring data across borders, including to the United States.
Where personal data originating in the European Economic Area or the United Kingdom is transferred outside those areas, Korner relies on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable. Copies of the relevant transfer mechanism are available on request.
Customers may request that a workload be pinned to a specific region. Where technically possible this is honoured, but denial-of-service mitigation is inherently global: hostile traffic is absorbed at whichever edge it arrives at.
Automated processing
Mitigation decisions are automated by design: traffic is classified and dropped in milliseconds, faster than any human review could occur. This processing acts on connection metadata and behaviour, not on the identity of individuals, and does not produce legal effects concerning a data subject within the meaning of GDPR Article 22.
Where automated classification results in a customer service being suspended, a human engineer reviews the decision and the customer may contest it by contacting noc@korner.team.
Law enforcement and legal requests
- Korner discloses customer data only where compelled by valid legal process issued under the laws of a jurisdiction in which it operates.
- Requests are reviewed for validity, scope and proportionality, and are narrowed wherever lawfully possible.
- Unless prohibited by law or court order, Korner notifies the affected customer before disclosing their data and allows a reasonable opportunity to object.
- Requests should be served on legal@korner.team. Informal requests without legal process are refused.
United States privacy rights
Residents of California and other US states with comprehensive privacy statutes may request access to, correction of, or deletion of their personal information, and may request details of any disclosure to third parties.
Korner will not discriminate against anyone for exercising a privacy right. Requests may be submitted to legal@korner.team and are verified against account records before being actioned.
Children
Korner sells infrastructure to businesses and does not knowingly collect personal information from anyone under 16. If such information is discovered it is deleted without delay.
Changes and contact
Material changes to this policy will be notified to account contacts at least 30 days before they take effect. The revision number and effective date in the control block above always identify the version in force.
Questions, requests and complaints may be directed to legal@korner.team, or by post to Korner LLC at the registered address shown in the site footer. Where a supervisory authority has jurisdiction, you also have the right to complain to it directly.