1. Who we are
Kercel (the "Service") is a competitive-displacement lead-intelligence service provided byUnity Space SLU, a company incorporated in Spain, with registered address at Calle Lirica 9, Spain ("we", "us", "our"). Kercel is a brand of Unity Space SLU.
This Privacy Policy explains how we collect, use, disclose and protect personal information when you visit our website (kercel.io), use the Kercel application, or interact with us in other ways. It is written for the European Economic Area (EEA), the United Kingdom and Switzerland in mind, and complies with the GDPR, the UK GDPR and the Swiss Federal Act on Data Protection where applicable.
We are the controller of the personal information described in this policy. If you have any questions, contact us at privacy@kercel.io or by writing to the address above.
2. Who this policy applies to
Depending on how you interact with us, you fall into one or more of these categories:
- Visitors — people who browse the Kercel website or read our content without an account.
- Customers and Users — people who create an account or are invited to a workspace and use the Service.
- Business profiles — individuals whose professional information appears in public sources and is surfaced by the Service as a potential lead. If this applies to you, you are not our customer, but this policy explains what we hold about you, why, and how to ask us to remove it.
3. Information we collect
3.1 Information you give us
- Visitors: when you submit a contact form or get in touch, we collect your name, email address and the contents of your message.
- Customers and Users: when you create an account we collect your name, work email address, and the workspace you belong to. You may also provide business configuration data such as your ideal customer profile (ICP), the search terms and competitors you want to track. We collect payment and billing information when you subscribe to a paid plan; card details are processed by our payment provider (Stripe) and are not stored by us.
3.2 Information we collect automatically
- Cookies and similar technologies: our website uses cookies for necessary functionality, analytics and, where you consent, marketing. See our Cookie Policy for details and controls.
- Log and usage data: when you visit the website or use the Service, we may collect technical information such as IP address, browser type, device information, pages visited, and how you interact with the Service. Server and application logs are retained for a maximum of 30 days.
3.3 Information we collect from public sources (business profiles)
The Service's purpose is to help our customers find businesses that are showing signs of being ready to switch from a competitor. To do this, we scan publicly available sources only — including search engine results, public posts and public profiles on social platforms, public review sites, public advertising libraries, and websites of the businesses themselves. We do not collect information from gated, private or non-public sources, and we do not obtain or resell private databases of contact information.
From those public sources we may collect information such as:
- Business and professional contact details that are publicly published (e.g. company name, role, public profile handles);
- The content of public posts, comments and reviews that relate to a business or competitor;
- The technologies a business publicly exposes on its own website (for "tech-stack fingerprinting");
- The URLs of publicly accessible pages.
3.4 Derived information
We analyse and combine the public information above to derive new information, such as switch-readiness signals, signal scores, and source attributions. Some of this analysis uses machine learning and third-party large language model providers (see Section 7). Derived information is used only to score and present potential leads to our customers.
4. How we use your information
- To provide, operate, maintain and improve the Service (accounts, scanning, scoring, dashboards, digests, support).
- To communicate with you about the Service, including transactional emails, digests you have enabled, and responses to your requests.
- To process payments, manage subscriptions and enforce plan limits and quotas.
- To keep the Service secure, prevent fraud and abuse, and comply with legal obligations.
- To understand how the website and Service are used, and to improve them.
- To build and maintain our index of business profiles from public sources, and to derive signals and scores for our customers.
5. Legal bases for processing (GDPR)
We process personal information only where we have a lawful basis to do so:
| Purpose | Legal basis |
|---|---|
| Providing the Service, managing accounts, processing payments, and responding to support requests | Performance of a contract with you (Art. 6(1)(b) GDPR) |
| Collecting and analysing public information to identify potential leads and derive signals | Legitimate interests (Art. 6(1)(f) GDPR) — see Section 6 |
| Analytics and marketing cookies, and any marketing communications where consent is required | Consent (Art. 6(1)(a) GDPR) |
| Security, fraud prevention, and complying with legal, tax and accounting obligations | Legal obligation and legitimate interests (Art. 6(1)(c) and 6(1)(f) GDPR) |
6. Legitimate interest statement
We rely on legitimate interests to collect, analyse and present publicly available business information. Our legitimate interest is to operate a business-to-business lead-intelligence service: helping our customers identify organisations that may be open to switching providers. The information we process is limited to information that is already public, we minimise what we collect to what is relevant for this purpose, we never sell personal information, and we provide an easy way for individuals to object and request removal (see Section 12). We have balanced our interests against the rights and interests of the individuals concerned and concluded that our processing is proportionate. You may object to this processing at any time by contacting privacy@kercel.io.
7. Artificial intelligence
We use machine learning and third-party large language model (LLM) providers (currently routed through OpenRouter) to score signals, infer ICP suggestions, and power certain analysis. The following applies:
- Only the content needed for the specific analysis is sent to an LLM provider (for example, a public snippet and the customer's ICP description).
- We require our LLM providers, by contract, not to use your information or our customers' information to train their models, and to retain inputs and outputs only for a limited period required for abuse monitoring.
- Signal scores are decision-support: they are presented to the customer as suggestions that a human reviews. We do not use automated processing to make decisions that produce legal or similarly significant effects on any individual (Article 22 GDPR), and we do not target or profile individuals for consumer marketing.
8. Cookies and similar technologies
Our website uses cookies for three categories: necessary, analytics andmarketing. Analytics and marketing cookies are loaded only after you consent via our cookie banner. See our Cookie Policy for a full description and how to manage your preferences.
We also use session storage (not cookies) to capture ad click identifiers and UTM parameters when you arrive from an advertising campaign, so that if you sign up we can attribute your visit to the correct campaign. This data is stored only for the current browser session and is passed along to the sign-up page to help us measure advertising performance. It does not require the analytics or marketing cookie consent because it is session-only and non-persistent, but you can clear it by closing your browser. We do not use this data for cross-site tracking of individuals beyond advertising attribution for our own campaigns.
We also collect aggregate CTA engagement (which call-to-action buttons you click) via our analytics provider, loaded only after you accept the analytics category.
9. How we share your information
- Service providers (processors): we share information with companies that help us run the Service, including hosting, database, analytics, payments, AI, error-monitoring and observability providers. They process information only on our documented instructions and are bound by data processing agreements. A current list is available on our Subprocessors page.
- Customers: business-profile information surfaced by the Service is shown to our customers within their own workspaces. Customers who export or use that information act as independent controllers of their own use of it.
- Legal and safety: we may disclose information where required by law, legal process or government request, to enforce our terms, or to protect our rights, property or the safety of others.
- Business transactions: in the event of a merger, acquisition or sale of assets, your information may be transferred as part of that transaction.
We do not sell personal information. Business-profile information is never sold or licensed to third parties to build competing databases.
10. International transfers
Some of our service providers are located outside the EEA, the UK and Switzerland (in particular in the United States). Where we transfer personal information across borders, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Agreement where applicable) and, where available, the EU-US / UK / Swiss Data Privacy Frameworks. You can obtain a copy of the relevant safeguards by contactingprivacy@kercel.io.
11. Data retention
We retain personal information only as long as necessary for the purposes set out in this policy:
| Data | Retention |
|---|---|
| Account and configuration data | While your account is active, and for as long as we are required to keep it by law or to defend legal claims. |
| Business-profile (lead) data and derived signals | While the account that collected it is active. Removed when the account is deleted or on a valid removal request, except where we are required to retain it by law. |
| Page snapshots cached for tech-stack analysis | Up to 90 days. |
| Server and application logs | Up to 30 days. |
| Backups | For a limited period needed for recovery (typically up to 30 days beyond the deletion of the underlying data). |
| Suppression records | Kept to honour a removal or opt-out request and prevent re-collection, unless you ask us to delete them too. |
12. Your rights
Depending on where you live, you may have the following rights under the GDPR, UK GDPR and similar laws:
- Access — obtain a copy of the personal information we hold about you.
- Rectification — ask us to correct inaccurate or incomplete information.
- Erasure — ask us to delete your personal information, subject to legal exceptions.
- Restriction — ask us to restrict processing in certain circumstances.
- Portability — receive your information in a structured, machine-readable format.
- Objection — object to processing based on our legitimate interests, including profiling, and object to direct marketing at any time.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
- Not be subject to automated decisions — not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
- Lodge a complaint — with your local data protection authority (in Spain, the Agencia Española de Protección de Datos — AEPD).
If you are a business profile surfaced by the Service and you want your information removed or corrected, or you want to object to our processing, use ourdata removal page or email privacy@kercel.io. We will respond within the timeframes required by law (usually 30 days), and we keep a suppression record to avoid re-collecting your information.
We may ask you to verify your identity before acting on a request.
13. Security
We apply appropriate technical and organisational measures to protect personal information, including encryption in transit and at rest, access controls, and monitoring of our services (including error monitoring and observability tooling). No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a personal data breach, we will notify affected individuals and the relevant supervisory authority as required by law.
14. Children
The Service is a business-to-business product and is not directed at children. We do not knowingly collect personal information from children under the age of 16. If you believe we have collected information from a child, contact us at privacy@kercel.io and we will delete it.
15. Changes to this policy
We may update this Privacy Policy from time to time. We will post any changes on this page and update the "Last updated" date above. If we make material changes, we will take reasonable steps to notify you (for example, by email or a notice in the Service).
16. Contact
For any questions, requests or complaints about this policy or our privacy practices, contact us atprivacy@kercel.io or write to Unity Space SLU, Calle Lirica 9, Spain. You also have the right to lodge a complaint with your local data protection supervisory authority, in particular in the country where you are established or where an alleged infringement took place.
