Privacy Policy

Last Updated: August 27, 2026

Effective: August 27, 2026

All policiesVersion history

Quantum Solutions (Private) Limited ("we", "us") provides the Quantum Solutions platform. This policy explains what personal data we handle, why, and what rights you have.

This policy has two parts, and which one applies depends on how your data reached us.

  • Part A covers data for which we decide why and how it is processed — your account, your organisation, your subscription. Here we are the controller.
  • Part B covers data a customer of ours put into the platform about their customers. There, our customer decides why and how, and we act on their instructions. We are the processor, and Part A's rights sections do not apply to us for that data.

If you received an invoice from a business that uses Quantum Solutions, Part B is the part that concerns you.


Part A — Where we are the controller

A1. Who we are and how to reach us

Quantum Solutions (Private) Limited NO 61/12, 6th Pope Paul Road, Negombo, 11500, Sri Lanka Company registration number: PV 00338570

We do not offer the Service to individuals in the European Economic Area or the United Kingdom, and we do not target or monitor people there. We have therefore not designated a representative under Article 27 of the EU or UK GDPR. If that changes, we will appoint one and name them here before we begin.

A2. What we collect

CategoryWhat it includesWhere it comes from
Account identityEmail address, first and last name, unique account identifierYou, at signup or by invitation
AuthenticationPassword (stored only as a hash by our identity provider), multi-factor enrolment including authenticator-app and email factors, session and token records, sign-in eventsYou, and generated by us
ProfileDisplay name, contact details, saved postal addresses, locale and currency preferencesYou
OrganisationOrganisation name, legal entity name, tax registration number, billing email, billing address, logo, countryYou
MembershipWhich people belong to which organisation, their roles, who invited them, invitation statusYou and your administrators
Subscription and billingPlan, subscription status, trial history, invoices we issue you, payment recordsGenerated by us
Payment methodsPayment token, card brand, last four digits, network transaction identifiers. Never the full card number, expiry date or security codeOur payment provider
SupportMessages you send us and our repliesYou
Technical and securityIP address, browser and device information, request logs, rate-limit counters, abuse and fraud signals, multi-factor reset eventsAutomatically, when you use the Service
Consent recordsWhich document version you accepted, when, from which IP and browser, and a digest of the exact text you were shownGenerated by us when you accept

We do not collect special categories of personal data (health, biometrics, religion, political opinions and similar), and ask that you do not submit them.

We do not use analytics, advertising or marketing cookies. See our Cookie Policy.

PurposeLegal basis
Creating and running your account; providing the ServicePerformance of a contract
Taking payment, invoicing you, collecting amounts duePerformance of a contract
Authenticating you and securing the ServiceLegitimate interests — keeping the Service and its users secure
Preventing fraud and abuse; rate limitingLegitimate interests — protecting the Service and other customers
Responding to your support requestsPerformance of a contract; legitimate interests
Service and security notificationsPerformance of a contract
Keeping accounting and tax recordsLegal obligation
Recording your acceptance of our legal documentsLegal obligation; legitimate interests — being able to show what was agreed
Establishing, exercising or defending legal claimsLegitimate interests
Optional marketing emailsConsent — withdrawable at any time

Where we rely on legitimate interests, we have considered your rights and concluded they do not override ours. You may object — see A7.

A4. How long we keep it

We keep personal data no longer than we need it. Where the law sets a minimum, that minimum applies even if you ask us to delete the data.

DataRetention periodWhy
Invoices, payment records, accounting ledgers10 years from the end of the relevant financial yearStatutory tax and accounting record-keeping. This survives a deletion request
Account and profile dataDeleted or anonymised 30 days after the account is closedGrace period for accidental closure and reactivation
Organisation and membership records30 days after the organisation is closed, except records forming part of a retained invoiceAs above
Saved payment methodsDeleted when you remove them or when the account closesNo reason to keep them
Authentication, session and security logs90 daysEnough to investigate an incident, no longer
Abuse, fraud and multi-factor reset records12 monthsDetecting repeat abuse
Support correspondence24 months from the last messageHandling follow-up and recurring issues
Consent recordsFor the life of the account, then 6 yearsThe limitation period for a contractual claim
BackupsPurged on the normal backup rotation cycle, currently within 35 daysBackups cannot be edited selectively — see below

About backups. When we delete data from our live systems it may persist in encrypted backups until they rotate. We do not restore deleted data from a backup except to recover from a system failure, and if that happens we re-apply outstanding deletions.

A5. Who we share it with

We do not sell personal data, and we do not share it for advertising.

We share it with:

  • Service providers who process it on our behalf under contract — hosting, database, email delivery, payment processing and bot protection. Each is listed with its purpose and location in our sub-processor list.
  • Our own staff, who can access customer data through an internal administration console strictly where needed to operate and support the Service. Access is role-restricted and logged.
  • Professional advisers — accountants, auditors and lawyers — under duties of confidentiality.
  • Authorities, where we are legally required to. Where we are permitted to tell you, we will.
  • A successor, if we are involved in a merger, acquisition or sale of assets. We will tell you before your data becomes subject to a different privacy policy.

A6. International transfers

Our infrastructure runs in the United States. We are established in Sri Lanka. Your personal data is therefore processed outside the country you are in.

We protect data in transit and at rest with encryption, restrict access, and apply the measures in A9 wherever it is processed. You can ask us at hello@quantumsolutions.dev what safeguards apply to you.

A7. Your rights

Subject to your local law, you may have the right to:

  • access the personal data we hold about you, and receive a copy;
  • rectify data that is inaccurate or incomplete;
  • erase your data, where we have no overriding obligation or legitimate ground to keep it;
  • restrict processing while a dispute about accuracy or legitimate interests is resolved;
  • port the data you gave us, in a structured, commonly used, machine-readable format;
  • object to processing based on legitimate interests, and to direct marketing at any time;
  • withdraw consent where consent is the basis, without affecting processing before withdrawal.

To exercise any of these, email hello@quantumsolutions.dev. We will respond within 30 days. If your request is complex we may extend that by a further two months and will tell you why. We may ask you to verify your identity first.

We do not charge for this unless a request is manifestly unfounded or excessive.

A8. Automated decision-making

We use automated processing for rate limiting, abuse detection and fraud prevention, which can result in a request being refused or an account being temporarily restricted.

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR. If an automated control has restricted your access and you believe it is wrong, contact hello@quantumsolutions.dev and a person will review it.

A9. How we protect it

  • Encryption in transit (TLS) and at rest
  • Multi-factor authentication available on every account, and required for our own staff
  • Role-based access control, enforced centrally on every request
  • Least-privilege access for staff, with access logged
  • Rate limiting and automated abuse detection
  • Append-only records for consent and security-sensitive events
  • Payment card fields hosted by the payment provider, so full card numbers never reach our systems
  • Regular dependency and vulnerability scanning

No system is perfectly secure, and we cannot guarantee absolute security.

A10. Personal data breaches

If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and within 72 hours of becoming aware of it where required, and we will tell you directly without undue delay where the risk to you is high.

A11. Children

The Service is a business tool, not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, contact hello@quantumsolutions.dev and we will delete it.

A12. Complaints

Please raise concerns with us first at hello@quantumsolutions.dev — we would rather fix a problem than have you take it elsewhere.

You also have the right to complain to the data protection authority with jurisdiction over you — in Sri Lanka, the authority established under applicable data protection law.

A13. Changes to this policy

We may update this policy. For a material change we will give at least 30 days' notice by email and by publishing the revised policy with the date it takes effect. Every version is listed with its effective date in our legal changelog.


Part B — Where we are the processor

B1. When this part applies

Our customers are businesses. They use Quantum Solutions to manage their own customers and to issue invoices. In doing so, they put personal data about their customers into our platform: names, email addresses, phone numbers, billing and shipping addresses, and the invoices and payment records that relate to them.

For that data:

  • our customer is the controller. They decide why it is collected and what happens to it;
  • we are the processor. We only act on their documented instructions.

B2. What we do with it

We host it, keep it secure and available, and make it usable through the features our customer has chosen. We do not use it for our own purposes. Specifically, we do not sell it, do not use it for advertising, and do not use it to train machine-learning models.

The terms governing this are in our Data Processing Addendum, which every customer processing personal data through the platform enters into with us. It sets out our security obligations, our use of sub-processors, breach notification, and deletion on termination.

B3. If you are one of our customer's customers

If a business sent you an invoice through Quantum Solutions, or gave you an account to pay one, your relationship for that data is with that business, not with us.

To access, correct or delete that data, or to object to its processing, contact the business directly. They are the controller and only they can decide. If you contact us instead, we will pass your request on to them and tell you we have done so — we cannot act on it ourselves.

Where that business gave you your own login, the account credentials themselves — your email, password and multi-factor settings — are covered by Part A, because we determine how authentication works. The rest of what that business holds about you is Part B.

B4. Retention

We keep this data for as long as our customer instructs. On termination we delete or return it within 30 days, except where we must retain records by law — invoices in particular, which are subject to the statutory period in A4.


Quantum Solutions (Private) Limited · NO 61/12, 6th Pope Paul Road, Negombo, 11500, Sri Lanka · +94 77 643 4458