Privacy Policy

Last updated: April 16, 2026

1. Data We Collect

We collect: (a) Account data — email, name, company; (b) Usage data — request counts per API key, SDK type, operation type; (c) Payment data — processed via Stripe (we do not store card data); (d) Technical data — IP address, user agent, for security and abuse prevention.

1-A. Quantum Exposure Calculator

If you use the calculator and request the report, we store only: the email you provide, your answers (years of secrecy, size of your systems estate, sector), the calculated result, and the date of your consent. We do NOT store IP address, user agent, or any browsing trail for this feature. The legal basis is your consent, given in the form. We use this data to send you the report and to contact you about it — nothing else. We keep it for 24 months or until you request deletion, whichever comes first; you may withdraw consent at any time at privacy@posquantum.com, with no need to give a reason.

2. What We Do NOT Collect

PQSL SDKs operate 100% locally on your device. The data you encrypt, sign, or process NEVER passes through PosQuantum servers. We only count the number of operations performed for licensing purposes. The content of your data remains exclusively in your environment.

3. PUCE Services (Cloud Processing)

For PUCE services (compression, streaming, archive), files are sent for processing on secure GPU servers. Files are: (a) encrypted in transit with ML-KEM + AES-256-GCM; (b) processed in memory; (c) automatically deleted after job completion; (d) never permanently stored on our servers.

4. Legal Basis (GDPR)

We process data based on: (a) Contractual performance — to provide the contracted Services; (b) Legitimate interest — for security, fraud prevention, and Service improvement; (c) Legal compliance — when required by law.

5. Data Security

We use post-quantum cryptography (FIPS 203/204/205) to protect all data in transit and at rest. API keys are generated with 256 bits of entropy. Audit logs are maintained for security and compliance.

6. Your Rights

Under GDPR, you have the right to: (a) Access your data; (b) Rectify incorrect data; (c) Request deletion of your data; (d) Data portability; (e) Object to processing; (f) Withdraw consent. Contact privacy@posquantum.com to exercise these rights.

7. Data Retention

We retain account data while your subscription is active. Usage data is aggregated and anonymized after 90 days. Audit logs are retained for 12 months. After cancellation, data is deleted within 30 days.

8. Contact

For privacy questions: privacy@posquantum.com. Data Protection Officer: dpo@posquantum.com.