Privacy Policy

Effective: 1 January 2026 · Peter Matejka

1. Who we are

The Quantum Secure Gateway API service ("QSG" or the "Service") is operated by Peter Matejka ("I", "my", or "me") and offered through the domains api.quantumsecuregateway.com, quantumsecuregateway.com, and quamtx.com.

Contact: privacy@quamtx.com

2. What data we collect

The QSG API is designed to minimise personal data collection. The following data is processed in the course of providing the service:

  • API usage metadata — endpoint accessed, timestamp, source IP (hashed), tier, and response size. This is used for rate-limiting, metering, and operational monitoring.
  • Provenance and audit records — cryptographic hashes, job IDs, backend identifiers, and entropy-quality metrics associated with each entropy draw. These form the compliance audit trail.
  • Customer account data — email address and company name provided during access request, used solely for account provisioning and support.
  • Form submissions — email address, company, and use-case description submitted via the access request form.

We do not collect the entropy output values drawn by clients. Entropy is delivered directly to the client and is not retained after transmission.

3. How we use your data

  • Delivering the entropy API service and generating provenance records
  • Operational monitoring, rate-limiting, and billing metering
  • Compliance auditing (permanent audit trail retention, per the service tier)
  • Responding to support requests submitted via email
  • Security monitoring and incident response

We do not use your data for profiling, automated decision-making, or marketing purposes.

4. Data retention

  • Operational audit logs (KV) — 90-day rolling window, automatically purged.
  • Persistent audit records (R2 JSONL) — retained for 7 years from the date of each entropy draw, region-pinned per the Enterprise tier agreement.
  • API usage metadata — retained for 12 months for metering and security analysis.
  • Account data (email, company) — retained until account deletion; deleted within 30 days of a verified deletion request.

5. Data sharing

We do not sell, rent, or share your personal data with third parties except:

  • Cloudflare, Inc. — our infrastructure provider, acting as a data processor under appropriate contractual safeguards, for the purpose of DDoS mitigation, bot management, and edge caching.
  • IBM Quantum — our entropy source hardware provider, for the purpose of submitting and retrieving quantum hardware job results. IBM processes job metadata (backend name, job ID, shot count) as an independent controller.
  • Law enforcement or regulators — where required by applicable law or a valid legal process.

6. Security

Data in transit is encrypted with TLS 1.3. Data at rest (KV, R2) is encrypted using AES-256-GCM. The cryptographic primitives used are X25519 + ML-KEM-1024 for key establishment (FIPS 203 Category 5) and AES-256-GCM for authenticated encryption (FIPS 197).

You can review my full security posture, penetration-test summary (under NDA), and vulnerability disclosure policy at quantumsecuregateway.com/security/.

7. Your rights (GDPR / EU)

If you are located in the European Economic Area, you have the following rights with respect to your personal data:

  • Access — request a copy of data we hold about you
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion of your account data
  • Restriction — request limitation of processing in certain circumstances
  • Portability — request your data in a machine-readable format
  • Objection — object to processing based on legitimate interests

To exercise any right, contact privacy@quamtx.com. I will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.

8. Cookies

The QSG API does not use cookies. The web properties at quantumsecuregateway.com and quamtx.com use only strictly necessary cookies for security and session management (Cloudflare's bot-management cookie). No tracking or marketing cookies are used.

9. International transfers

Peter Matejka is based in Spain. Data may be processed by Cloudflare, Inc. (US) and IBM Quantum (US) as described above. Where data is transferred outside the EEA, we rely on Standard Contractual Clauses or equivalent legal mechanisms.

10. Changes to this policy

We will notify material changes to this policy by updating the "Effective" date above and, for significant changes, by posting a notice on the service homepage. Continued use of the service after any change constitutes acceptance of the updated policy.