Privacy Policy
Last updated: June 2026
This Privacy Policy explains how Q by Wentzel ("the Service"), operated by Wentzel Investments LLC ("Wentzel," "we," "us," or "our"), collects, uses, shares, and protects personal data in connection with our post-quantum cryptography assessment platform. It applies to visitors to our website and to organizations and authorized users who access the Service. Where we process personal data on behalf of a customer organization as part of providing the Service, we do so as a processor under that organization's instructions and our Data Processing Addendum.
1. Information We Collect
We collect the following categories of information:
- Account data. When you register, we collect your name, email address, organization name, and an irreversibly hashed password (we never store passwords in plain text). Authentication is handled by Better Auth, which we operate ourselves.
- Assessment and scan data.To provide the Service, we process the scan targets, configurations, Cryptographic Bills of Materials (CBOMs), Harvest-Now-Decrypt-Later (HNDL) scores, and assessment results you generate. This content can reveal your organization's cryptographic posture, and we treat it as confidential. You retain ownership of all data you submit.
- Billing data. Paid plans are processed by Stripe. We receive limited billing details (such as plan, billing contact, and the last four digits and brand of a card) but we do not store full payment card numbers — Stripe processes and stores payment instruments directly.
- Usage, log, and device data. We collect technical information such as IP address, browser and device type, pages viewed, feature usage, and timestamps, primarily to operate, secure, and improve the Service.
2. How We Use Information
We use personal data to:
- Provide, maintain, and secure the Service and your account;
- Generate and deliver assessment results, CBOMs, and reports;
- Process payments and manage subscriptions;
- Communicate with you about your account, security, and service updates (including transactional email);
- Monitor for, prevent, and respond to fraud, abuse, and security incidents;
- Improve the Service and develop new features, using aggregated or de-identified data where practicable; and
- Comply with legal obligations and enforce our Terms.
We do not sell personal data, and we do not use your assessment or scan data to train models offered to other customers.
3. Legal Bases for Processing
Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases: performance of a contract (to provide the Service you request); legitimate interests (to secure, operate, and improve the Service, and to prevent abuse), balanced against your rights; consent (where required, for example for certain communications); and compliance with a legal obligation.
4. How We Share Information & Subprocessors
We do not sell your personal data and do not share it except as described here. We share data with service providers ("subprocessors") who process it on our behalf, under written contracts requiring appropriate confidentiality and security. Our subprocessors are:
- Cloudflare, Inc. (United States) — application hosting, edge delivery, and database/object storage.
- Amazon Web Services, Inc. (United States) — transactional email (Amazon SES) and object storage.
- Stripe, Inc. (United States) — payment processing for paid plans.
We may also disclose personal data where required by law, to protect our rights, safety, and property or those of others, or in connection with a merger, acquisition, or sale of assets (subject to this Policy).
5. International Data Transfers
Our subprocessors are located in the United States, so providing the Service may involve transferring personal data internationally. Where such transfers are subject to the EU or UK GDPR, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), supplemented as necessary.
6. Data Retention
We retain personal data for as long as your account is active and for a reasonable period thereafter for archival, legal, and operational purposes, consistent with our Terms of Service. Following termination, we make your scan data available for export for thirty (30) days, after which we may delete it. We may retain limited records longer where required to comply with legal obligations, resolve disputes, or enforce our agreements.
7. Security
We implement industry-standard technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls and least-privilege practices, and monitoring of our infrastructure. No method of transmission or storage is completely secure; we work to protect your data but cannot guarantee absolute security.
8. Your Rights
Depending on your location, you may have the right to access, correct, delete, or receive a portable copy of your personal data; to object to or restrict certain processing; and to withdraw consent where processing is based on consent. If you are a California resident, you have the right to know what personal information we collect, to request deletion, and to opt out of the "sale" or "sharing" of personal information — and we confirm that we do not sell or share personal information as those terms are defined under California law. Where we process personal data on behalf of a customer organization, we will refer requests to that organization. To exercise any right, contact us at the address below; we will respond consistent with applicable law and will not discriminate against you for exercising your rights.
9. Cookies & Similar Technologies
We use only strictly necessary cookies and similar browser storage to operate the Service — for example, to keep you signed in and to remember your light/dark theme preference. We do notload third-party advertising, marketing, or cross-site tracking technologies, and we do not run third-party web analytics that set cookies in your browser. Our service-level usage and security metrics (see "Usage, log, and device data" above) are generated on our own infrastructure and are not collected through cookies or scripts placed on your device.
Because we currently set only strictly necessary cookies, there are no optional cookies to accept or reject. If we introduce any non-essential cookies or similar technologies in the future, we will gate them through a region-aware consent banner: visitors in the EU, EEA, United Kingdom, and Switzerland will be asked to opt in before any such technology loads, while visitors elsewhere will see a notice with the ability to opt out. In all regions we honor the Global Privacy Control (GPC) signal as a request to decline non-essential processing, and you can review or change your choice at any time using the "Cookie settings" link in our website footer. You can also control cookies through your browser settings; disabling strictly necessary cookies may affect how the Service functions.
10. Children's Privacy
The Service is a business-to-business product intended for use by organizations and is not directed to children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us personal data, please contact us and we will take appropriate steps to delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated Policy on the Service and revise the "Last updated" date above. For material changes, we will provide additional notice where required. Your continued use of the Service after an update constitutes acceptance of the revised Policy.
12. Contact Us
For questions about this Privacy Policy or to exercise your rights, contact us at support@wentzel.ai.