Qstamp / Privacy Policy
Privacy

Privacy Policy

How Quantova Inc collects, uses, shares and protects personal data in connection with the Qstamp website, the network endpoints it operates and the Qstamp SDK.

1. Who we are

The Qstamp website at qstamp.org is published by Quantova Inc, a corporation incorporated in the State of Delaware, United States, whose address is 1000 N. West Street, Suite 1501, Wilmington, Delaware 19801, United States. Quantova Inc is the controller of the personal data described in this policy. This means that it decides why and how that data is processed.

Questions about this policy and requests about your personal data can be sent to [email protected]. General support questions can be sent to [email protected]. We have not designated a data protection officer. Individuals in the European Economic Area, the United Kingdom and every other jurisdiction may contact us directly at [email protected].

2. Scope of this policy

This policy applies to personal data that we process when you visit the Qstamp website, when software sends requests to a Quantova network endpoint that we operate, such as the test network endpoint used by the Qstamp SDK, and when you write to us by email.

The Qstamp SDK runs on systems chosen and controlled by the organisation that uses it. That organisation, and not Quantova Inc, is responsible for the records it processes with the SDK. The Data Protection Policy describes those responsibilities. This policy does not apply to external websites that we link to, such as GitHub and npm, which apply their own privacy policies.

3. Summary of our practices

  • The website has no forms, no accounts, no advertising, no third party analytics and no social media trackers, and it loads no fonts or scripts from third parties.
  • Our servers record each request in a server log. We use those logs, and daily records derived from them, to keep our services secure, to plan capacity and to produce aggregate traffic statistics.
  • Audience measurement runs only if you accept it in the cookie notice, and it uses no cookie and no identifier.
  • We do not sell personal data and we do not share it for advertising.

4. Personal data we collect

Server logs. Our web servers record every request made to the website and to the network endpoints we operate. For each request the log contains the IP address from which the request was made, the date and time, the host name and path requested, the response status, the number of bytes sent, the referring page and the browser identification string, known as the user agent.

Security and traffic monitoring records. We derive daily records from the server logs, including an approximate location and a device type for each IP address, as described under Security and traffic monitoring below.

Country of request. Cloudflare, Inc, which protects our servers, tells us the country from which each request originates.

Audience measurement data. If you accept audience measurement, each page you view sends us its path and the length of time it was open, as described under Audience measurement below.

Security cookies. Cloudflare may set a strictly necessary security cookie in your browser when it checks a request for automated abuse, as described in the Cookie Notice.

Your consent choice. Your choice in the cookie notice is stored in your own browser and is not sent to us.

Email. If you write to us, we receive your email address, any name or other details you include, and the content of your message and of any attachments.

Network endpoint requests. Requests sent to a network endpoint we operate, for example by the Qstamp SDK, carry the IP address of the calling system and are recorded in the server logs in the same way as website requests. Transactions submitted through an endpoint are published to the Quantova network, as described under The Qstamp SDK and the Quantova network below.

We do not collect names, postal addresses, payment details or account credentials through the website, because it has no forms and no accounts. We do not ask for special categories of personal data.

5. Sources of personal data

We obtain personal data from the following sources.

  • your browser, or the system that sends a request, which supplies the request data
  • Cloudflare, Inc, which supplies the country of each request
  • our own analysis, which derives an approximate location from each IP address using a geolocation database held on our own servers, and a device type from the user agent
  • you, when you write to us
  • the public Quantova network, which anyone can read

6. Purposes and legal bases

We process personal data for the purposes below. For the GDPR and the UK GDPR, each purpose is listed with the legal basis on which we rely.

  • Delivering the website and endpoints. We use request data to deliver pages and responses. We use the country of the request, or the language preference sent by your browser, to choose the language of the first page you see. That choice is not stored, and you can change the language at any time with the language selector. We rely on our legitimate interests in providing a working website and service, under Article 6(1)(f).
  • Security and abuse prevention. We use server logs, monitoring records and the security checks of Cloudflare to detect and block attacks, abuse and automated scraping, including by blocking IP addresses at our firewall or through Cloudflare. We rely on our legitimate interests in keeping our services, our network and their users secure, under Article 6(1)(f).
  • Capacity planning and traffic statistics. We use server logs and monitoring records to understand the load on our services, to plan capacity and to produce aggregate traffic statistics. We rely on our legitimate interests in operating our services efficiently, under Article 6(1)(f).
  • Audience measurement. We use the page path, the time a page was open and the country of the request to understand which pages are read. We rely on your consent, under Article 6(1)(a), which you may withdraw at any time.
  • Correspondence and requests. We use your messages to reply to you and to handle any request you make. We rely on our legitimate interests in answering enquiries, under Article 6(1)(f), and, where you exercise a legal right, on the need to comply with a legal obligation, under Article 6(1)(c).
  • Legal compliance and claims. We may use any of the data described in this policy to comply with the law, to respond to lawful requests from public authorities and to establish, exercise or defend legal claims. We rely on the need to comply with a legal obligation, under Article 6(1)(c), and on our legitimate interests in protecting our rights, under Article 6(1)(f).

Where we rely on legitimate interests, we have weighed those interests against your rights and limited the data to what each purpose requires. You have the right to object to this processing, as explained under Your rights below. Where other laws apply, we process personal data only on the grounds those laws permit, and we ask for consent where they require it.

We do not use personal data for advertising or marketing. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Our security measures, and those of Cloudflare, may challenge or block requests from an IP address that is associated with attack, abuse or scraping, either automatically or after review. If you believe that your access has been blocked in error, please write to [email protected].

7. Security and traffic monitoring

We operate an internal monitoring system on our own servers. It is run by Quantova itself and is not provided by a third party. The system reads the server logs and keeps, for each of our websites and for each day, the IP addresses from which requests were made, the number of requests and page views from each address, and a device type label, derived from the user agent, that indicates the family of operating system.

Each IP address is matched against a geolocation database held on our own servers to give an approximate country, region and city. IP addresses are not sent to any external service for this purpose.

We use these records to detect and block attacks, abuse and automated scraping, including by blocking IP addresses at our firewall or through Cloudflare, to plan capacity and to produce aggregate traffic statistics. The legal basis is our legitimate interests in the security and efficient operation of our services.

The daily records are kept for up to 400 days and are then deleted automatically. The system uses no cookies and stores nothing on your device. It works from the server logs and therefore operates whatever choice you make in the cookie notice. We do not use these records to identify individual visitors, except where that is necessary to investigate a security incident or abuse of our services, or where the law requires it.

8. Audience measurement

Each page includes a short first party script, served from our own servers, that measures how long the page is open. It sends nothing unless you have ticked the box in the cookie notice and selected Accept. If you have accepted, when you leave or hide a page, the script sends the path of the page and the length of time it was open to our server at the address /qtov-beacon. Visits of less than one second are not counted.

Our server works out the country from the IP address of the request and adds the duration to aggregate totals by country. The script sets no cookie and assigns no identifier, and the aggregate totals contain no IP address. The request that carries the measurement is itself recorded in the server logs, like any other request.

If you decline, or make no choice, nothing is sent. You may withdraw your consent at any time with Cookie settings at the foot of every page. Withdrawal does not affect measurements sent before it, which form part of aggregate totals that cannot be linked to you.

9. Cookies and similar technologies

We do not use cookies for advertising, analytics or tracking. Cloudflare may set a strictly necessary security cookie, and your choice in the cookie notice is stored in your browser under the key qs-consent. The Cookie Notice explains these items and how to change your choice.

10. The Ask Qstamp assistant

The Ask Qstamp assistant on this website selects its replies from a fixed set of answers contained in the page. What you type is processed only in your browser and is not sent to us or to anyone else.

11. The Qstamp SDK and the Quantova network

The Qstamp SDK runs on the systems of the organisation that uses it. Records and their fingerprints are never sent to Quantova Inc. For each batch of records, the SDK writes to the public Quantova network a salted 32 byte commitment, from which the content of the records cannot be derived, together with the kind of record. Each such transaction also carries ordinary transaction data, namely the address of the signing account, the contract called, the block, the time and the fee.

The Quantova network is public. Anyone can read the data written to it, and that data cannot be altered or erased by Quantova Inc or by anyone else. An account address is a pseudonymous identifier. It may be personal data where it can be linked to an individual, for example where an individual is known to control the account.

Requests that the SDK sends to a network endpoint we operate carry the IP address of the calling system and are recorded and kept in the same way as website requests.

12. QVMScan and declared profiles

QVMScan, the Quantova explorer, and its Superintelligence Fingerprints page display data that is public on the Quantova network, together with profile information that operators choose to declare. Operators are responsible for the information they declare and should not declare personal data about any individual unless they are entitled to publish it.

13. How we share personal data

We do not sell personal data, and we do not share it with advertisers or data brokers. We disclose personal data only as follows.

  • to Cloudflare, Inc, which provides network delivery and security protection for our servers and acts as our processor under a data processing agreement. Cloudflare receives the data carried by each request, may set a strictly necessary security cookie and supplies the country of each request
  • to the providers that operate our email service, when you write to us
  • to professional advisers, such as lawyers and accountants, who are bound by a duty of confidentiality, where we need their advice
  • to courts, regulators, law enforcement agencies and other public authorities, where the law requires it or where it is necessary to protect our rights, our users or the public
  • to a successor in connection with a merger, acquisition or transfer of all or part of our business, which will be bound by this policy

Our servers are operated by Quantova and are protected by Cloudflare. Information written to the Quantova network is public and can be read by anyone.

14. International transfers

Quantova Inc is established in the United States. Our website and network endpoints run on servers operated by Quantova and are protected by Cloudflare, whose global network includes the United States. Your personal data may therefore be processed in countries outside the country in which you live, including the United States, whose data protection laws may differ from those of your country.

Where Cloudflare processes personal data on our behalf, our agreement with Cloudflare incorporates the standard contractual clauses approved by the European Commission and, for transfers from the United Kingdom, the International Data Transfer Addendum issued by the Information Commissioner. Where the law of another jurisdiction, such as Singapore, Japan or Korea, requires specific measures for transfers abroad, we take the measures it requires so that personal data receives a comparable standard of protection. You may request further information about these safeguards, including a copy of the relevant clauses, at [email protected].

15. How long we keep personal data

  • Raw server logs are kept for no longer than is necessary for security and the operation of our services. They are reviewed and deleted periodically. We are introducing automatic deletion after a fixed period, which we intend to be fourteen days, and we will update this policy when it is in place.
  • Security and traffic monitoring records are kept for up to 400 days and are then deleted automatically.
  • Audience measurement totals contain no IP address and no identifier, and are kept for as long as they remain useful.
  • Cloudflare security cookies expire after a short period, as described in the Cookie Notice.
  • Your consent choice remains in your browser until you change it or clear the storage of your browser.
  • Email correspondence is kept for as long as needed to deal with your message and any follow up. Records of requests to exercise your rights are kept for as long as needed to show how we handled them.
  • Data written to the Quantova network is permanent and cannot be deleted.

Any record may be kept for longer where it is needed to investigate a specific security incident, to establish, exercise or defend a legal claim, or to comply with the law, and then only for as long as that need lasts.

16. Your rights

If the GDPR or the UK GDPR applies to our processing of your personal data, you have the following rights, subject to the conditions and exceptions in that law.

  • to obtain confirmation of whether we process your personal data, and a copy of it
  • to have inaccurate personal data corrected
  • to have personal data erased
  • to have processing restricted
  • to receive personal data you provided to us in a structured, commonly used and machine readable format, where processing is based on consent and carried out by automated means
  • to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests
  • to withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal
  • to lodge a complaint with a supervisory authority

Because the website has no accounts, we can usually find personal data about you only from your IP address and the dates and times of your visits, and we may ask you for those details. Where we cannot identify you from the data we hold, we will tell you, and some rights may then not apply, as Article 11 of the GDPR provides. Audience measurement totals cannot be linked to you. Data written to the Quantova network cannot be altered or erased by us.

17. Rights in other jurisdictions

California. If the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to us, California residents have the right to know what personal information we collect, use and disclose and to obtain a copy of it, to correct it, to delete it, and not to receive discriminatory treatment for exercising these rights. In the past twelve months we have collected identifiers such as IP addresses, internet or other electronic network activity information such as pages requested, referring pages and user agents, approximate geolocation derived from IP addresses and, where you wrote to us, your email address and message. We collected them for the purposes described in this policy and disclosed them for business purposes to our service provider Cloudflare, Inc. We do not sell personal information, we do not share it for cross context behavioural advertising, and we do not use or disclose sensitive personal information for purposes that would give rise to a right to limit its use. You may make a request through an authorised agent, and we may ask you or the agent to verify your identity.

Singapore. Under the Personal Data Protection Act 2012, you may ask for access to personal data about you in our possession or under our control and for information about the ways in which it has been used or disclosed within the past year, ask us to correct an error or omission, and withdraw any consent you have given.

Hong Kong. Under the Personal Data (Privacy) Ordinance, you may make a data access request and a data correction request. We will respond within the period of 40 days that the Ordinance requires.

Japan. Under the Act on the Protection of Personal Information, you may request disclosure of retained personal data about you and of records of its provision to third parties, its correction, addition or deletion, the suspension of its use or its erasure, and the cessation of its provision to third parties, where the conditions of the Act are met.

Korea. Under the Personal Information Protection Act, you may request access to your personal information, its correction or deletion and the suspension of its processing, withdraw your consent, and request an explanation of, or refuse, a fully automated decision that significantly affects you.

Other laws may give you further rights, and we will respect them where they apply.

18. How to exercise your rights

Send your request to [email protected], stating the right you wish to exercise and, where relevant, the IP address you used and the approximate dates and times of your visits. We may ask for further information to confirm your identity or to locate your data, and we will use that information only for that purpose. We will respond within the time limits required by the law that applies. Under the GDPR and the UK GDPR this is one month, which may be extended by two further months for complex or numerous requests. We do not charge a fee, except where the law permits one.

19. Complaints

We would welcome the chance to address any concern first, at [email protected]. You also have the right to complain to a supervisory authority.

In the European Economic Area this is the data protection authority of the member state in which you live or work or in which the alleged infringement took place. In the United Kingdom it is the Information Commissioner's Office. In Singapore it is the Personal Data Protection Commission, in Hong Kong the Office of the Privacy Commissioner for Personal Data, in Japan the Personal Information Protection Commission, in Korea the Personal Information Protection Commission, which is supported by the Personal Information Dispute Mediation Committee, and in California the California Privacy Protection Agency or the Attorney General.

20. Children

The website and the SDK are intended for organisations and professionals and are not directed at children. We do not knowingly collect personal data from children beyond the technical data that every request carries. If you believe that a child has sent us personal data, please contact us at [email protected] so that we can delete it.

21. Security

We protect personal data with technical and organisational measures appropriate to the risk. The website and the endpoints are served over encrypted connections, the website uses strict browser security headers, requests pass through the security protections of Cloudflare, and access to server logs and monitoring records is restricted to authorised Quantova personnel. No method of transmission or storage is completely secure. If a personal data breach occurs, we will notify the competent authorities and the individuals affected where the law requires it.

22. Changes to this policy

We may update this policy. We will publish the updated version on this page with a new effective date and, where a change is material, we will draw attention to it on the website. Where a change requires your consent, we will ask for it.

23. Contact

Quantova Inc, 1000 N. West Street, Suite 1501, Wilmington, Delaware 19801, United States. Privacy enquiries and requests can be sent to [email protected].