Privacy Policy

Last updated: December 15, 2024

GDPR Compliant

1. Information We Collect

We collect information you provide directly to us and information we obtain automatically when you use our Service:

Information You Provide

  • Account information (name, email address, company)
  • Optimization problems and datasets (CSV, Parquet files)
  • Communication preferences and support requests
  • Payment and billing information (processed by third-party providers)

Information We Collect Automatically

  • Usage data (job execution times, backend selections, cost metrics)
  • Performance metrics and optimization results
  • Log data and error reports
  • Device and browser information

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Provide, maintain, and improve our quantum computing optimization services
  • Process transactions and manage your account
  • Generate audit-ready manifests and traceability reports
  • Communicate with you about service updates, security alerts, and support
  • Analyze usage patterns to improve our algorithms and service performance
  • Comply with legal obligations and enforce our terms of service

3. Data Processing and BYOC Model

Under our Bring Your Own Compute (BYOC) model:

  • We do not store or have persistent access to your quantum computing provider credentials
  • Your optimization problems are processed temporarily and deleted after job completion
  • We maintain audit trails and manifests for traceability and reproducibility
  • All data processing follows data minimization principles with PII gating

4. Information Sharing and Disclosure

We do not sell, trade, or otherwise transfer your personal information to third parties, except in the following circumstances:

  • With your explicit consent
  • To quantum computing providers (AWS Braket, IBM Quantum, Rigetti) for job execution
  • To service providers who assist us in operating our Service (under strict confidentiality agreements)
  • When required by law or to protect our rights and safety
  • In connection with a business transfer or acquisition

5. Data Security and Encryption

We implement comprehensive security measures to protect your information:

  • KMS encryption with automatic key rotation
  • Data minimization and PII gating controls
  • Export and OFAC compliance controls
  • Regular security audits and penetration testing
  • Access controls and authentication requirements
  • Secure data transmission using TLS encryption

6. Data Retention and Deletion

We retain your information only as long as necessary to provide our services and comply with legal obligations. Optimization problems and datasets are automatically deleted after job completion. Audit trails and manifests are retained for the duration specified in your service agreement, typically 7 years for compliance purposes.

7. Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information (subject to legal requirements)
  • Portability: Request transfer of your data to another service provider
  • Objection: Object to processing of your personal information
  • Restriction: Request restriction of processing in certain circumstances

8. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisions, to protect your personal information in accordance with applicable data protection laws.

9. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience, analyze usage patterns, and improve our services. You can control cookie settings through your browser preferences. Some features of our Service may not function properly if cookies are disabled.

10. Children's Privacy

Our Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete such information.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.

Contact Information

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:

QuantFenix Privacy Officer

Email: privacy@quantfenix.com

Address: [Company Address]

For EU residents: You also have the right to lodge a complaint with your local data protection authority.