Data should be processed with purpose, control and accountability.
Data should be processed with purpose, control and accountability.
Data processing is an essential part of modern software.
HexaKernel is designed to make domain logic explicit, but responsible data handling must remain equally explicit.
This policy describes the principles that guide the processing of personal and other protected information in connection with HexaKernel.
Data should be collected and processed for defined and legitimate purposes.
Information should not be used for unrelated purposes without an appropriate legal basis or authorization.
Only data reasonably necessary for a defined purpose should be collected or processed.
The existence of technical capability does not by itself justify collecting additional information.
Reasonable measures should be taken to keep personal data accurate and up to date where accuracy is relevant to the processing.
Data should not be retained indefinitely without a legitimate reason.
Retention periods should reflect:
The purpose of processing
Legal requirements
Contractual requirements
Operational needs
Security considerations
Access to data should be limited according to legitimate responsibilities and authorization.
Where appropriate, systems should apply role-based permissions, authentication and other controls.
Where third-party providers process data on behalf of Atavistico OÜ or its customers, appropriate contractual and technical safeguards should be applied.
The specific providers and processing activities depend on the services actually used.
Where HexaKernel processes customer data as part of providing a service, the applicable contractual arrangements determine the respective responsibilities of the parties.
Where personal data is processed on behalf of a customer, a Data Processing Agreement may be required.
Where data is transferred or accessed across jurisdictions, applicable requirements concerning international data transfers will be considered and appropriate safeguards applied where required.
Where applicable, individuals may exercise rights relating to their personal data, including access, rectification, deletion, restriction, objection and portability.
Requests should be directed to:
[privacy@hexakernel.com]
The specific rights available depend on applicable law and the circumstances of the processing.
Data protection should be considered when systems are designed, not only after they are deployed.
This principle aligns with the broader HexaKernel approach:
make important things explicit from the beginning.
Data should be processed with purpose, control and accountability.
Build software from the logic of your business.
HexaKernel is an execution architecture for domain-driven, AI-native software.
Formalize your domain. Let AI transform it. Let HexaKernel execute it.
HexaKernel is a technology product and brand operated by Atavistico OÜ.
© 2026 Atavistico OÜ. All rights reserved.
HexaKernel | ATAVISTICO SPECFORGE