Legal
Privacy Policy
How Cernor collects, uses, discloses and protects personal data across our websites, applications, candidate-facing experiences and APIs.
This Privacy Policy explains how Cernor, a company organized under the laws of the State of Delaware, United States (“Cernor,” “we,” “us,” or “our”), collects, uses, discloses, stores, and otherwise processes personal data in connection with our websites, applications, candidate-facing experiences, APIs, communications, and related services (collectively, the “Services”).
Cernor provides AI-assisted decision infrastructure for hiring and related high-stakes selection workflows. The Services help organizations define and lock evaluation standards, evaluate candidate materials, identify uncertainty, conduct structured follow-up, preserve evidence and decision history, and create decision-support work product.
This Privacy Policy is intended to apply globally. Local law may provide additional or different rights, obligations, or limitations. Where applicable law provides greater protection than this Privacy Policy, we will apply the requirements of that law.
For privacy questions or requests, contact [email protected]. For security questions, contact [email protected].
1. Scope
This Privacy Policy applies when you:
- visit or interact with a Cernor website;
- create or use a Cernor account or workspace;
- use the Services on behalf of an organization;
- upload, submit, or otherwise provide role, candidate, project, or evaluation information;
- receive and use a candidate follow-up link;
- submit information through a candidate-facing Cernor experience;
- request a demo, support, security information, or other communication from us;
- interact with an integration or API operated as part of the Services; or
- otherwise interact with Cernor where this Privacy Policy is presented or referenced.
This Privacy Policy does not govern a third party’s independent processing of personal data. For example, an employer or recruiting organization using Cernor may process candidate information for its own hiring purposes under its own privacy notice.
2. Our Role: Controller, Processor, and Service Provider
Cernor may process personal data in different legal roles depending on the context.
2.1 When Cernor acts on behalf of a customer
When an organization uses Cernor to process role information, candidate materials, candidate responses, hiring criteria, evaluation records, or related information for that organization’s hiring or selection process, Cernor generally processes that information on behalf of the customer.
In those circumstances:
- the customer generally determines the purpose of the hiring or selection process;
- the customer is responsible for establishing an appropriate legal basis and providing notices required by applicable law;
- Cernor acts as a processor, service provider, contractor, or comparable service-provider role to the extent those concepts apply; and
- our processing is governed by the customer’s agreement with Cernor, any applicable data processing addendum, and the customer’s documented instructions.
If you are a candidate or other individual whose data was submitted to Cernor by a customer, the customer may be the organization primarily responsible for responding to requests concerning the hiring decision or the customer’s processing of your data.
2.2 When Cernor acts for its own purposes
Cernor may act as an independent controller or business for limited purposes such as:
- administering accounts and business relationships;
- operating and securing the Services;
- preventing fraud, abuse, and unauthorized access;
- maintaining service, security, and audit records;
- responding to support, legal, privacy, or security requests;
- managing billing and contracts;
- improving the reliability, usability, and security of the Services using data we are permitted to use for those purposes; and
- communicating about Cernor where permitted by law.
We do not treat a customer’s hiring purpose as our own independent purpose merely because we provide the technology used in the workflow.
3. Personal Data We Process
The categories below describe the personal data we may process. The specific data involved depends on how the Services are used.
3.1 Account and organization information
We may process:
- name;
- business email address;
- business telephone number;
- job title;
- employer or organization name;
- workspace and project memberships;
- account identifiers;
- authentication and access information;
- user roles and permissions; and
- administrative settings.
3.2 Role, project, and hiring-standard information
Customers may provide information such as:
- job descriptions;
- role requirements;
- role location and work arrangement;
- seniority, function, sector, and company context;
- compensation or role constraints where supplied by the customer;
- work-authorization, scheduling, or location requirements;
- evaluation criteria and must-have requirements;
- operator calibration answers;
- notes and project instructions; and
- versions of a locked hiring or decision standard.
This information may contain personal data if it identifies or relates to a particular person.
3.3 Candidate and applicant information
Customers or candidates may provide:
- name and contact information;
- résumé or CV information;
- employment history;
- education;
- professional qualifications and licenses;
- skills and experience;
- portfolio or work-product information;
- work authorization or employment eligibility;
- location, time-zone, work-arrangement, or scheduling information;
- compensation expectations where supplied;
- links to professional profiles or materials;
- application materials;
- candidate communications;
- interview or recruiter notes;
- explanations or clarifications provided by the candidate; and
- other information included in documents or text submitted to the Services.
3.4 Candidate follow-up information
Where a customer uses Cernor’s structured follow-up functionality, we may process:
- candidate-link identifiers and status;
- link creation, opening, expiry, and revocation information;
- candidate selections and structured responses;
- answer-path and progress information;
- submission timestamps;
- optional candidate-provided explanations or notes; and
- information necessary to evaluate the response against the customer’s locked standard.
3.5 Evaluation, inference, and decision-support information
The Services may create or store information derived from customer-provided data, including:
- criteria-level assessments;
- fit or support scores;
- evidence references;
- proof or support posture;
- uncertainty and unresolved items;
- trust or consistency cautions;
- follow-up targets;
- bounded score movements;
- workflow status and next-action labels;
- candidate decision packets;
- cohort or project slates;
- comparison and change-history information;
- version and provenance information; and
- other AI-generated or software-generated decision-support outputs.
These are decision-support records. They may constitute personal data where they relate to an identifiable individual.
3.6 Technical, security, and usage data
We may collect or generate:
- IP address;
- browser and device information;
- operating system;
- timestamps;
- session and authentication events;
- API and request metadata;
- token or credential metadata;
- service logs;
- security events;
- error and diagnostic information;
- feature usage;
- model and runtime metadata;
- packet and source hashes;
- version identifiers;
- audit receipts; and
- information about administrative or consequential actions taken in the Services.
We seek to avoid placing unnecessary candidate content into general analytics or telemetry.
3.7 Communications and support data
We may process information you provide when you:
- request a demo;
- submit a website form;
- contact sales, support, privacy, or security;
- respond to a survey;
- participate in a security review;
- report a problem; or
- otherwise communicate with Cernor.
This may include your name, work email, company, role, message content, and related correspondence.
3.8 Billing and transaction data
If paid Services are offered, we may process:
- billing contact information;
- subscription and order information;
- invoices;
- transaction identifiers;
- payment status; and
- tax or accounting information.
Payment-card details may be processed by a payment provider rather than stored directly by Cernor.
3.9 Cookies and similar technologies
We may use cookies or similar technologies for:
- authentication;
- session continuity;
- fraud and security prevention;
- user preferences;
- service operation;
- measurement of website or product performance; and
- analytics where permitted.
Where local law requires consent for non-essential cookies or similar technologies, we will request consent before using them.
Cernor does not use Candidate Data or Customer Content for cross-context behavioral advertising.
4. Sensitive and Special-Category Data
Hiring materials can contain information that is considered sensitive, special-category, protected, or otherwise subject to heightened legal requirements in some jurisdictions.
Examples may include:
- government identification numbers;
- citizenship or immigration information;
- work authorization;
- race or ethnicity;
- religious or philosophical beliefs;
- political opinions;
- trade-union membership;
- genetic or biometric information;
- health or disability information;
- sexual orientation or sex-life information;
- criminal-history information;
- financial information;
- precise geolocation; or
- other information designated as sensitive by applicable law.
Cernor is not designed to require customers to provide protected characteristics as hiring criteria. Customers must not use the Services to discriminate unlawfully or to instruct Cernor to make employment decisions based on characteristics that applicable law prohibits from being used for that purpose.
Customers should avoid submitting sensitive data that is unnecessary for the supported workflow. Data subject to special contractual or regulatory regimes should not be submitted unless the customer has a lawful basis, the use is permitted, and any required written agreement with Cernor is in place.
5. How We Obtain Personal Data
We may obtain personal data:
- directly from customer administrators and authorized users;
- directly from candidates through candidate-facing experiences;
- from documents and materials uploaded by customers;
- from integrations enabled by a customer;
- from communications with you;
- automatically from use of the Services;
- from service providers that support our business; and
- from publicly available or customer-directed sources where permitted by law.
A customer may submit personal data about individuals who do not have a Cernor account. The customer is responsible for ensuring it has the authority and legal basis to provide that data to Cernor.
6. Why We Process Personal Data
We process personal data for purposes including the following.
6.1 Provide and operate the Services
This includes:
- creating and maintaining accounts;
- setting up workspaces and projects;
- ingesting role and candidate materials;
- authoring and versioning standards;
- running candidate evaluations;
- generating structured follow-up;
- receiving candidate responses;
- generating decision-support outputs;
- preserving project history and receipts;
- supporting comparison, export, and recalibration; and
- maintaining persistent project state.
6.2 Process data on customer instructions
Where we act as a processor or service provider, we process personal data to perform the services the customer has requested and in accordance with the applicable agreement.
6.3 Secure, monitor, and maintain the Services
We may process data to:
- authenticate users;
- enforce authorization and tenancy boundaries;
- detect and prevent abuse;
- secure accounts and credentials;
- investigate incidents;
- diagnose failures;
- maintain service integrity;
- record consequential actions; and
- protect Cernor, customers, candidates, and others.
6.4 Support users and customers
We use data to:
- respond to questions;
- investigate support requests;
- provide implementation assistance;
- conduct security or privacy reviews;
- manage customer relationships; and
- communicate about service incidents or changes.
6.5 Comply with law and protect legal rights
We may process data to:
- comply with lawful requests;
- enforce agreements;
- establish, exercise, or defend legal claims;
- meet accounting, tax, and recordkeeping requirements; and
- comply with applicable privacy, employment, AI, security, sanctions, or other laws.
6.6 Improve service quality and reliability
We may use operational and usage information to understand performance, reliability, security, and usability.
We do not use Customer Content or Candidate Data to train or fine-tune generalized foundation models for Cernor.
Any use of personal data for product improvement will be limited to purposes and data that Cernor is legally and contractually permitted to use.
6.7 Marketing and business development
Where permitted by law, we may use business contact information to:
- respond to requests for information;
- provide requested product or company updates;
- invite prospective customers to demos; or
- communicate about related Cernor offerings.
You may opt out of marketing communications at any time.
7. Legal Bases Where Required
Where a law such as the GDPR or UK GDPR requires a legal basis, the basis depends on the context.
Cernor may rely on:
- contractual necessity to provide Services requested by an account holder or contracting customer;
- legitimate interests in operating, securing, supporting, and improving the Services and conducting B2B communications, where those interests are not overridden by applicable privacy rights;
- legal obligation where processing is necessary to comply with law;
- consent where the law requires consent and we ask for it; and
- other lawful bases available under applicable law.
When Cernor processes Candidate Data solely on behalf of a customer, the customer is generally responsible for identifying the legal basis for the customer’s hiring or selection activity.
8. AI and Model Processing
AI processing is a core part of the Services.
8.1 What may be sent for AI processing
Depending on the workflow, Cernor may transmit to an approved AI inference or model provider only the information reasonably necessary for the relevant task, such as:
- the applicable role or project context;
- the locked standard or relevant portions of it;
- candidate evidence or other source material required for the judgment;
- candidate follow-up information;
- prior governed packet state needed for the current task; and
- instructions required to produce the requested structured output.
8.2 Upstream AI infrastructure
Cernor may use:
- AI inference gateways;
- model-hosting providers;
- cloud AI services;
- model developers;
- specialized inference providers; and
- related infrastructure providers.
Specific model providers and hosting paths may change as models, security requirements, availability, cost, and product quality evolve.
Our public Privacy Policy is intentionally provider-neutral. Current production subprocessors and relevant processing locations may be documented separately or provided as part of a security review.
8.3 Model training and data use
Cernor does not use Customer Content or Candidate Data to train or fine-tune generalized foundation models.
We do not intentionally opt Customer Content or Candidate Data into third-party generalized model training.
We select and configure production AI processing based on documented data-handling restrictions, including restrictions concerning model training and retention. Where appropriate and technically available, Cernor may use provider controls that restrict data collection, training, logging, retention, fallback routing, or processing location.
Some providers may retain limited information when required for security, abuse prevention, legal compliance, service operation, or other contractually permitted purposes. Applicable retention depends on the provider, endpoint, contract, and customer configuration.
8.4 No model-provider authority over the hiring decision
Model providers do not set the customer’s hiring standard and do not receive authority to make the customer’s final hiring decision merely because they process an inference request.
Cernor separates model judgment from source records, access control, locked-standard authority, deterministic policy, stored system state, and final human decision authority.
9. Automated Processing and Hiring Decision Support
Cernor uses AI and software to analyze candidate information and generate decision-support outputs.
These outputs may include:
- evaluations;
- scores;
- classifications;
- evidence and uncertainty summaries;
- trust or consistency cautions;
- follow-up questions;
- bounded score movement;
- rankings or relative position;
- next-action recommendations;
- decision packets; and
- cohort summaries.
Cernor is designed as decision-support infrastructure, not as a substitute for the customer’s legal responsibility for hiring decisions.
The hiring organization remains responsible for:
- deciding whether and how to use a Cernor output;
- providing legally required human review;
- ensuring that a person with appropriate authority can review, question, or override the output where required;
- providing notices to candidates where required;
- conducting legally required bias audits, impact assessments, or similar reviews;
- handling requests for accommodation or alternative processes;
- complying with anti-discrimination and employment laws; and
- making the final employment decision.
If applicable law gives you rights concerning automated decision-making, profiling, explanation, review, appeal, or opt-out, those rights may be exercised against the organization responsible for the relevant decision. Where Cernor processes the relevant data on that organization’s behalf, we will provide reasonable assistance as required by law and contract.
10. How We Disclose Personal Data
We may disclose personal data to the following categories of recipients when reasonably necessary for the purposes described in this Privacy Policy.
10.1 Customers and authorized users
Candidate, role, evaluation, project, and decision-support information may be made available to the customer and its authorized users according to workspace, project, or account permissions.
10.2 Service providers and subprocessors
We may use service providers or subprocessors for:
- cloud hosting;
- databases and storage;
- AI inference and model processing;
- networking and content delivery;
- security and monitoring;
- communications;
- customer support;
- analytics;
- billing and payments;
- document processing;
- logging;
- backups and recovery; and
- other infrastructure necessary to operate the Services.
These providers are permitted to process personal data only for authorized purposes and subject to applicable contractual and legal requirements.
10.3 Customer-enabled integrations
If a customer enables an integration, data may be exchanged with that third-party service as directed by the customer.
The third party’s independent use of data may be governed by its own terms and privacy notice.
10.4 Professional advisers
We may disclose information to lawyers, auditors, insurers, accountants, consultants, and similar advisers where reasonably necessary and subject to appropriate confidentiality obligations.
10.5 Corporate transactions
If Cernor is involved in a financing, merger, acquisition, restructuring, sale of assets, insolvency process, or similar transaction, personal data may be disclosed as part of due diligence or transferred as part of the transaction, subject to applicable law and appropriate protections.
10.6 Legal and safety disclosures
We may disclose personal data if we reasonably believe disclosure is necessary to:
- comply with applicable law or legal process;
- respond to a lawful request from a competent authority;
- protect the rights, property, or safety of Cernor, our customers, candidates, or others;
- investigate fraud, abuse, or security incidents; or
- establish, exercise, or defend legal claims.
Where legally permitted and appropriate, we seek to limit disclosures to what is necessary.
11. Subprocessors
Cernor may engage subprocessors to support the Services, including model and inference providers.
Because model and infrastructure providers may change, we do not hard-code a single provider into this Privacy Policy.
A current subprocessor list, including relevant processing functions and locations where appropriate, may be provided through Cernor’s security materials or by contacting [email protected].
Enterprise agreements or data processing addenda may provide additional subprocessor notice or objection rights.
12. International Data Transfers
Cernor is a Delaware company in the United States, and the Services may involve processing in the United States and other countries.
Personal data may therefore be transferred to or processed in a country different from the country where it was collected.
Where applicable law requires transfer safeguards, Cernor will use legally recognized mechanisms or protections as appropriate to the circumstances. These may include:
- contractual protections;
- Standard Contractual Clauses;
- United Kingdom transfer mechanisms;
- adequacy decisions;
- customer-approved regional processing arrangements; or
- another lawful transfer mechanism available under applicable law.
Specific data-residency commitments, where offered, will be stated in the applicable Order Form, data processing addendum, or security documentation rather than implied by this Privacy Policy.
13. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, customer instructions, contractual obligations, security requirements, dispute resolution, and applicable law.
Retention may differ by data category.
13.1 Customer Content and Candidate Data
Customer Content and Candidate Data are generally retained according to:
- the customer’s account or workspace configuration;
- the status and lifecycle of the project;
- the customer’s documented retention instructions;
- the applicable contract or data processing addendum;
- deletion requests;
- backup and recovery cycles; and
- legal requirements.
Where available, customers may apply retention rules or request scoped deletion for candidate or project records.
13.2 Project history and decision records
Because Cernor is designed to preserve version history, provenance, and decision receipts, a customer may choose to retain certain project records for audit, governance, or business purposes.
Deletion of source or candidate data may affect the ability to replay, inspect, or explain prior decisions.
13.3 Security, audit, billing, and legal records
Security events, administrative audit records, billing records, records of deletion, and legally required records may be retained separately from active Customer Content for a period reasonably necessary for security, fraud prevention, accounting, legal compliance, dispute resolution, or proof of compliance.
13.4 Backups
Deleted data may remain in encrypted or access-restricted backups until the relevant backup cycle expires. We do not restore deleted data into active use except where necessary for disaster recovery or legal obligations, and any restored data remains subject to applicable deletion requirements.
14. Data Deletion and Return
Subject to applicable law, contract, and technical limitations:
- customers may request export or return of Customer Content;
- customers may request deletion of candidate, project, or account data;
- candidates may exercise applicable rights through the responsible customer or directly with Cernor where Cernor is the relevant controller; and
- Cernor may retain limited records where required for security, fraud prevention, billing, legal compliance, or establishment or defense of legal claims.
A deletion request may not require Cernor to erase information that we are legally permitted or required to retain.
15. Security
Cernor uses technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access.
Our security program is designed around measures such as:
- protection of data in transit and production storage;
- authenticated workspace and project boundaries;
- access controls and least-privilege principles;
- server-side protection of production credentials and secrets;
- separation of customer-facing and internal authority;
- operational and security event recording;
- backup and recovery practices;
- dependency and release controls;
- environment separation;
- source and packet integrity controls;
- versioning and attributable consequential actions; and
- incident investigation and response procedures.
No system can guarantee absolute security. Customers and users are also responsible for protecting their credentials, devices, and accounts.
Security information, architecture summaries, data-flow information, and current controls may be available through Cernor’s security review process.
16. Individual Privacy Rights
Depending on where you live and which law applies, you may have some or all of the following rights:
- to know or be informed about processing;
- to access personal data;
- to obtain a copy or portable version of personal data;
- to correct inaccurate personal data;
- to delete personal data;
- to restrict processing;
- to object to processing;
- to withdraw consent where processing is based on consent;
- to opt out of certain sales, sharing, targeted advertising, or profiling;
- to limit certain uses of sensitive personal data;
- to obtain information about certain automated processing;
- to request human review or challenge a qualifying automated decision;
- to appeal certain privacy-request decisions;
- not to be discriminated against for exercising privacy rights; and
- to complain to a data protection or privacy regulator.
These rights are subject to conditions and exceptions under applicable law.
16.1 How to exercise rights
You may submit a privacy request to [email protected].
We may need to verify your identity before completing a request. We may also ask for information reasonably necessary to identify the relevant customer, workspace, project, or account.
16.2 Requests relating to Customer-controlled Candidate Data
If Cernor processes your data only on behalf of an employer or other customer, we may:
- direct you to that customer;
- notify the customer of your request; or
- assist the customer in responding.
The customer remains responsible for requests relating to the customer’s underlying hiring decision unless applicable law provides otherwise.
16.3 Authorized agents
Where applicable law allows an authorized agent to submit a request on your behalf, we may require evidence of the agent’s authority and may verify your identity directly.
16.4 Appeals
Where applicable law gives you a right to appeal our decision on a privacy request, you may appeal by replying to our response or contacting [email protected] with the subject line “Privacy Appeal.”
17. EEA, United Kingdom, and Switzerland
If the GDPR, UK GDPR, Swiss data-protection law, or a similar regime applies, you may have rights including access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and the right to lodge a complaint with a supervisory authority.
You may also have rights relating to decisions based solely on automated processing that produce legal or similarly significant effects.
Where Cernor processes Candidate Data on behalf of an employer or other customer, the customer generally determines the purpose of the processing and is responsible for the employment decision. Cernor will provide processor assistance where required by applicable law and contract.
18. California and Other U.S. State Privacy Rights
If a U.S. state privacy law applies, you may have rights to:
- know or access personal information;
- correct personal information;
- delete personal information;
- obtain a portable copy;
- opt out of sale;
- opt out of certain sharing or targeted advertising;
- opt out of certain profiling or automated decision-making;
- limit certain uses of sensitive personal information; and
- appeal a denied request.
Cernor does not sell Candidate Data or Customer Content.
Cernor does not use Candidate Data or Customer Content for cross-context behavioral advertising.
Where Cernor acts solely as a service provider, contractor, or processor for a customer, the customer is generally responsible for consumer or candidate rights associated with the customer’s hiring purpose, and Cernor will provide assistance as required by law and contract.
19. Global Privacy Rights
Privacy laws in jurisdictions including Canada, Brazil, Australia, New Zealand, Singapore, Japan, South Korea, and other countries may provide rights that overlap with those described above.
Rather than limiting this Privacy Policy to a closed list of jurisdictions, Cernor will honor applicable mandatory rights when the relevant law applies to our processing.
Where local law requires a different or additional notice, consent, representative, transfer mechanism, retention rule, or rights process, that requirement will control.
20. Sale, Sharing, Advertising, and Data Brokerage
Cernor’s business model is to provide decision infrastructure to customers.
We do not operate as a data broker for Candidate Data or Customer Content.
We do not sell Candidate Data or Customer Content.
We do not use Candidate Data or Customer Content to build advertising profiles or for cross-context behavioral advertising.
If our practices change in a way that creates a legal right to opt out, we will update this Privacy Policy and provide the legally required mechanism before applying the changed practice to affected personal data.
21. Children and Minors
The Services are directed primarily to organizations, professionals, and individuals participating in employment or other supported selection workflows.
Cernor does not knowingly solicit personal data from children for consumer purposes.
If a customer uses the Services in connection with a person who is a minor under applicable law, the customer is responsible for determining whether that use is lawful and for obtaining any parental, guardian, or other authorization required by law.
If you believe a child has provided personal data to Cernor unlawfully, contact [email protected].
22. Candidate Links and Portal Security
Candidate follow-up links may be subject to controls such as:
- expiry;
- revocation;
- one-time or state-aware use;
- server-side validation;
- limited token display;
- access-state tracking; and
- restrictions after submission.
Candidates should not share private follow-up links with unauthorized persons.
If you believe a candidate link has been compromised, contact the hiring organization or Cernor promptly.
23. Third-Party Sites, Integrations, and Services
The Services may link to, integrate with, or interoperate with third-party services.
A customer’s decision to enable an integration may cause data to be disclosed to or received from the selected third party.
Cernor is not responsible for a third party’s independent privacy practices. You should review the applicable third-party terms and privacy notices.
24. Government and Law-Enforcement Requests
Cernor may receive requests for information from governmental, regulatory, or law-enforcement authorities.
We assess requests under applicable law and, where legally permitted and appropriate:
- seek appropriate legal process;
- limit disclosure to information responsive to the lawful request; and
- notify the affected customer where permitted.
We do not voluntarily provide Customer Content to public authorities for unrelated purposes.
25. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
If we make material changes, we may provide additional notice through the Services, by email, or by another legally appropriate method.
The date at the top of this Privacy Policy identifies the most recent revision.
If a change requires consent under applicable law, we will request that consent before applying the change where required.
26. Contact
For privacy questions, requests, or complaints:
Cernor
Delaware, United States
Email: [email protected]
For general inquiries:
Email: [email protected]
If applicable law requires a local privacy representative, supervisory contact, or other jurisdiction-specific contact, the relevant details may be provided in an applicable regional notice, data processing addendum, or contractual document.
27. Relationship to Customer Agreements
This Privacy Policy is a public transparency notice.
A customer agreement, Order Form, data processing addendum, security addendum, or other written agreement may contain additional privacy and security terms.
If a binding written agreement gives a customer greater contractual protection regarding Customer Content, the written agreement governs the parties’ contractual obligations to the extent of any conflict.
Nothing in this Privacy Policy limits rights that cannot lawfully be limited.