Legal · Privacy

Privacy Policy

We treat customer data with the same rigor we apply to quantum state preparation — minimal, reversible, and observed only when strictly necessary.

Last updated: 1 May 2026 · Effective for all Kepler Q-Max services.

1. Data we collect

We collect three classes of data: (a) account data — email, name, organization, hashed credentials; (b) usage data — API calls, model invocations, feature inputs you submit; (c) telemetry — anonymized latency, error rates, and platform health metrics.

We never collect biometric data, location, or browsing history outside our own domains.

2. How we use it

To deliver inference results, authenticate sessions, bill usage, prevent abuse, and improve model quality. Customer payloads submitted to /predict are never used to train models without an explicit opt-in agreement.

3. Data residency & sub-processors

Inference is served from us-east, eu-west, and ap-south regions. EU customer data stays within the EEA. Sub-processors: AWS (compute), IBM Quantum (training only, anonymized), Stripe (billing), Resend (transactional email).

4. Retention

API request payloads are retained 30 days for debugging, then purged. Aggregated metrics are kept indefinitely. Account data is deleted within 30 days of account closure.

5. Your rights (GDPR, CCPA)

You may request access, correction, export, or deletion of your personal data at any time by emailing privacy@sonicium.ltd. We respond within 30 days.

6. Security

All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Access to production is limited to on-call engineers via short-lived SSO sessions and audit-logged. See the Security page for details.

7. Contact

Data Protection Officer — Sonicium Quantum Lab Ltd · privacy@sonicium.ltd