Privacy Policy
Last updated: 9 March 2026
1. Data controller
QuantumLayer Platform Ltd (“we”, “us”, “our”) is the data controller for personal data processed through the QuantumVerifi platform at quantumverifi.com.
- Company number: 16381947
- VAT registration: GB 507 1047 26
- Registered address: 86-90 Paul Street, London, EC2A 4NE
- Data protection contact: [email protected]
- ICO registration: Registered data controller under the Data Protection Act 2018
2. Personal data we collect
Account data
- Name and email address (from Clerk authentication or Google/Microsoft sign-in)
- Organisation name (if you create a team)
- Profile image (from OAuth provider)
Usage data
- Repository URLs, website URLs, and API specifications you submit for analysis
- Analysis results, generated tests, and security findings
- Automated analysis tasks may involve retrieving publicly accessible resources from systems you have authorised the platform to analyse
- Feature usage and interaction patterns (only with your consent — see Cookie Policy)
Billing data
- Subscription plan and usage counts
- Payment information is processed directly by Stripe — we never see or store your card details
Technical data
- IP address, browser type, and device information (from server logs)
- Error reports (via Sentry — see sub-processors below)
3. AI processing disclosure
QuantumVerifi uses artificial intelligence systems to analyse software repositories, websites, APIs, and code. This section explains how AI processes your data.
What AI processes
- Source code from repositories you submit (cloned temporarily, not stored permanently)
- Website pages you submit for E2E test generation (crawled during analysis only)
- API specifications (OpenAPI/Swagger) you submit for contract test generation
- URLs you submit for performance load testing
How AI processes it
- Large language models (LLMs) analyse your inputs to generate tests, security findings, and documentation
- All AI processing occurs in isolated, secure execution environments (sandboxed containers)
- AI-generated tests are validated through syntax checking, compilation, and sandbox execution before being returned to you
- Self-healing pipelines may re-process failing tests up to 3 times to improve quality
Per-tenant model training
On Scale and Enterprise plans, QuantumVerifi may fine-tune adapter models on patterns from your analyses to improve accuracy over time. These adapters are isolated per tenant — your data is never used to train models for other customers. You can deactivate trained adapters at any time via the Training dashboard.
What AI does not do
- We do not use your code or data to train general-purpose AI models
- We do not share your inputs with other customers
- We do not make automated decisions that produce legal effects concerning you
- We do not retain source code beyond the duration of your analysis (cached results use content hashes, not raw code)
4. AI transparency and limitations
AI-generated results — including tests, security findings, documentation, and performance reports — are probabilistic outputs and may contain errors, omissions, or false positives.
- All AI outputs should be reviewed by a qualified human before use in production environments
- Security findings are informational and do not constitute a professional security audit or penetration test
- Generated tests validate expected behaviour at the time of analysis — they may require updates as your codebase evolves
- Compliance evidence chains provide tamper-evident records but do not constitute legal or regulatory certification
QuantumLayer Platform Ltd does not guarantee the accuracy, completeness, or fitness for purpose of any AI-generated output. Use of AI-generated results is at your own discretion and risk.
5. Lawful basis for processing
Under UK GDPR Article 6, we process your personal data on the following bases:
| Purpose | Lawful basis |
|---|---|
| Provide the analysis service | Contract performance (Art. 6(1)(b)) |
| AI processing of submitted code, URLs, and APIs | Contract performance (Art. 6(1)(b)) |
| Per-tenant model fine-tuning (Scale/Enterprise) | Contract performance (Art. 6(1)(b)) |
| Process payments | Contract performance (Art. 6(1)(b)) |
| Send service notifications | Legitimate interest (Art. 6(1)(f)) |
| Analytics and product improvement | Consent (Art. 6(1)(a)) |
| Error tracking and debugging | Legitimate interest (Art. 6(1)(f)) |
| Fraud prevention and security | Legitimate interest (Art. 6(1)(f)) |
| Comply with legal obligations | Legal obligation (Art. 6(1)(c)) |
6. Sub-processors
We share personal data with the following third-party processors, each under a data processing agreement:
| Processor | Purpose | Location |
|---|---|---|
| Clerk | Authentication and user management | US (SCCs) |
| Stripe | Payment processing | US (SCCs) |
| Cloudflare | CDN, DDoS protection, DNS | Global (SCCs) |
| PostHog | Product analytics (consent-gated) | EU (Frankfurt) |
| Sentry | Error tracking and performance monitoring | US (SCCs) |
| Azure (Microsoft) | Container registry, LLM inference (Azure OpenAI) | UK South |
| Anthropic | LLM inference (failover) | US (SCCs) |
| Modal Labs | Sandbox test execution | US (SCCs) |
| GitHub | Repository access, PR creation | US (SCCs) |
SCCs = Standard Contractual Clauses approved by the UK ICO for international transfers.
7. International transfers
Your primary data (analyses, results, account information) is stored on servers in the United Kingdom. Some sub-processors operate in the United States. Where personal data is transferred outside the UK, we rely on Standard Contractual Clauses (SCCs) as the transfer mechanism, in accordance with UK GDPR Article 46(2)(c). We assess each sub-processor's data protection practices before engagement.
8. Data retention
| Data type | Retention period |
|---|---|
| Account data | Until account deletion + 30 days |
| Analysis results and generated tests | 90 days from creation |
| Compliance evidence chains | 7 years (regulatory requirement) |
| Billing records | 6 years (HMRC requirement) |
| Server logs | 30 days |
| Analytics data (PostHog) | 12 months |
| Error reports (Sentry) | 90 days |
9. Your rights
Under UK GDPR, you have the following rights. To exercise any of these, email [email protected] — we will respond within 30 days.
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion of your data (“right to be forgotten”)
- Restriction — request we limit processing of your data
- Portability — receive your data in a structured, machine-readable format
- Object — object to processing based on legitimate interest
- Withdraw consent — withdraw analytics consent at any time via cookie settings (this does not affect the lawfulness of prior processing)
10. Cookies
We use cookies and similar technologies. Analytics cookies are only set after you give consent via our cookie banner. For full details of each cookie, its purpose, and duration, see our Cookie Policy.
11. Children
QuantumVerifi is not directed at individuals under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us and we will delete it promptly.
12. Security
We implement appropriate technical and organisational measures to protect your data, including: TLS encryption in transit, encryption at rest for stored data, role-based access controls, multi-tenant isolation with row-level security, and regular security assessments. No system is 100% secure — if you discover a vulnerability, please report it to [email protected].
13. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email or an in-app notice. The “Last updated” date at the top indicates when the policy was last revised.
14. Complaints
If you are unhappy with how we handle your data, please contact us first at [email protected]. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
15. Contact
QuantumLayer Platform Ltd (Company No. 16381947)
86-90 Paul Street
London, EC2A 4NE
United Kingdom
Privacy: [email protected]
General: [email protected]