Legal
Privacy Policy
This policy separates two very different kinds of data: information about you as a visitor to this website, and the estate data our customers submit to AutoPQC for scanning. Conflating those two is the most common failure of a page like this, so we keep them apart throughout.
Last updated 27 July 2026
01Who we are
This Privacy Policy is issued by Theos Quantum Technologies Private Limited (“Theos Quantum”, “we”, “us”), a company incorporated in India, in connection with the website at www.theosquantum.com and the AutoPQC product.
02What we collect
We collect two categories of data that should not be confused with each other.
| Category | What it is | Examples |
|---|---|---|
| Site-visitor data | Information about people who browse this marketing and documentation website, whether or not they ever become a customer. | Contact-form and demo-request submissions (name, work email, company, role, message); standard web-server and hosting-provider log data such as IP address, browser type and pages requested; the cookie-consent and theme choices described in the Cookie Policy. |
| Customer-estate data | Data a paying customer submits to, or authorises AutoPQC to observe within, its own estate for the purpose of cryptographic discovery and scoring. This is processed on the customer's behalf, under the terms of that customer's order form, not collected from the general public. | Discovery metadata about cryptographic assets (for example algorithm, key length, protocol, location within the estate); configuration and scope information the customer supplies; findings, scores and remediation records generated by the Service. |
03Purposes
We use site-visitor data to respond to enquiries, schedule demonstrations, operate the readiness-check tool, and understand aggregate use of the website (only where you have opted in to analytics — see the Cookie Policy).
We process customer-estate data solely to provide the Service to the customer that submitted it: running discovery, computing exposure scores under the Theos Method, generating reports, and supporting that customer's remediation work. We do not use one customer's estate data to build products for, or share it with, another customer.
04Legal bases
Where applicable data-protection law requires a stated legal basis for processing (for example under the GDPR, or a comparable requirement under other regimes), the specific basis for each processing activity above — consent, contract, legitimate interest, or another basis — is a determination we are making with counsel and have not finalised for publication here.
05Retention
Site-visitor data submitted through a form is kept for as long as reasonably necessary to respond to the enquiry and for a limited period afterwards for record-keeping, after which it is deleted or anonymised.
Customer-estate data is retained for the duration of the customer's engagement and for a period afterwards, as agreed in the order form, to support continuity of service and audit history. Specific retention periods, expressed in a fixed number of days or months, are not yet published on this page.
06Disclosure and subprocessors
We disclose personal information only to service providers that help us operate this website or the Service (for example hosting and communications infrastructure), under contractual confidentiality obligations, and where required by law.
We do not sell personal information, and we do not share customer-estate data across customers.
The current list of infrastructure and processing arrangements, once finalised, will be maintained on the Assurance Center rather than duplicated on this page, so that a single page stays authoritative.
07International transfers
Where personal information is transferred outside the country in which it was collected, we intend to rely on appropriate safeguards recognised under applicable law. The specific transfer mechanism (for example standard contractual clauses, an adequacy finding, or another lawful mechanism) depends on the destination and is being confirmed with counsel.
08Security
We apply access controls, encryption in transit, and least-privilege practices to the systems that handle site-visitor and customer-estate data, at the level described honestly in the Assurance Center and Security & Disclosure pages.
We do not claim a specific security certification, audit outcome or attestation on this page unless the corresponding page states it with a verifiable date. No system is unbreachable; our approach to disclosure if something goes wrong is described at /security.
09Your rights
Depending on where you are, applicable law gives you rights over your personal information. This section states what those laws provide, factually; it does not add rights beyond what the law grants, and it does not subtract from them.
- Under India's Digital Personal Data Protection Act, 2023, a Data Principal has rights that include obtaining a summary of personal data processed and the processing activities, seeking correction and erasure of personal data, and grievance redressal against a Data Fiduciary, subject to the Act's conditions and exceptions.
- Under the EU General Data Protection Regulation, a data subject has rights that include access, rectification, erasure, restriction of processing, data portability, and objection to processing, subject to the Regulation's conditions and exceptions.
The practical mechanism for exercising any of these rights against Theos Quantum — the contact address, verification steps and expected response time — is not yet published.
10Children
This website and the Service are directed at business professionals and are not intended for use by children. We do not knowingly collect personal information from children.
11Automated decision-making
AutoPQC's exposure scoring is automated: the Theos Method computes a 0–100 score for a cryptographic asset from weighted inputs, without a human re-deriving the arithmetic for each asset. Stated plainly, this automation is applied to cryptographic assets and systems, not to people.
A score, tier or attestation produced by AutoPQC is a decision aid for a customer's own security team; it is not an automated decision made about an individual person, and it does not determine anyone's access to a service, employment outcome, or legal status.
12Changes to this policy
We will post changes to this policy on this page and update the “last updated” date. For a material change affecting how customer-estate data is handled, we will make a reasonable effort to notify affected customers directly, in addition to updating this page.