Privacy Policy
Effective date: 2026-09-17
This Privacy Policy explains how SoftQuantus innovative OÜ ("SoftQuantus", "we", "us") collects, uses, shares, and protects personal data when you use SynapseX — the chat at chat.synapsex.ai, the API platform at platform.synapsex.ai, the desktop and command-line applications, the quantum lab, and this website (together, the "Services"). It also explains the choices and rights you have.
It applies to consumers and to individual users of business accounts. Where a business customer has a separate data-processing agreement with us, that agreement governs the data we process on its behalf.
1. Who is responsible for your data
The data controller is SoftQuantus innovative OÜ, a private limited company registered in Estonia (registry code 17048927, VAT EE102767458), Veskiposti tn 2-1002, Kesklinna linnaosa, Tallinn 10138, Harju maakond, Estonia. For data-protection matters, including to reach our Data Protection Officer, write to info@softquantus.com.
2. What we collect
Information you give us
- Account data — your email address, name if you provide one, password (stored only as a salted hash), and the settings and preferences you choose. If you sign in with Google, we receive the profile fields Google shares (email, name, avatar).
- Inputs and Outputs — the prompts, messages, code, circuits, files, and other content you submit, and the responses, results, and artefacts the Services produce for you.
- Payment data — when you buy a plan or credits, our payment processor collects your payment-card details directly. We never see or store full card numbers; we receive the payment method type, last four digits, billing name and country, and transaction records.
- Connected services — if you choose to connect a third-party account (for example an email or storage provider), we store the access token and the data you ask the Services to fetch from it, for as long as the connection is active.
- Communications — the content of support requests, feedback, and other messages you send us.
Information collected automatically
- Usage and metering records — for every billable run: what ran, when, on which backend, how many tokens, shots, or seconds it consumed, and what it cost. This is what makes estimates, reserves, settlement, and your own spend audit work.
- Technical data — IP address, browser and device type, operating system, language, time zone, referring pages, request timestamps, and error logs.
- Cookies and similar technologies — see Section 8.
3. Why we use it, and on what legal basis
- To provide the Services (contract): to run your jobs, store your history, meter and bill usage, authenticate you, and show your results back to you.
- To keep the Services safe and reliable (legitimate interests, legal obligation): to detect abuse, fraud, and security incidents, enforce our Terms and Responsible Use Policy, and debug failures.
- To improve the Services (legitimate interests): aggregate, de-identified usage statistics tell us which features are used and where they fail.
- To train or fine-tune models (consent): only if you explicitly opt in. See Section 4.
- To communicate with you (contract, legitimate interests, consent for marketing): service notices, security alerts, billing receipts, and replies to your requests. Marketing email is sent only with your consent and always has an unsubscribe link.
- To comply with the law (legal obligation): tax, accounting, sanctions, and responses to lawful requests from authorities.
4. Model training — opt-in only
We do not use your Inputs or Outputs to train or fine-tune models unless you explicitly opt in. When an opt-in is offered, the product tells you what would be used and for what; you can withdraw at any time through the same control or by writing to us, and withdrawal stops future use. Content you submit to help us investigate a Trust & Safety report, or that we are required to retain by law, may be used to enforce our policies regardless of your training choice.
5. Who we share it with
We do not sell your personal data. We share it only with:
- Infrastructure and model providers — the cloud providers that host the Services and execute your workloads, and the third-party model and quantum-hardware providers that a run is routed to. They process your Content on our instructions, under contracts that restrict them to providing the service to us, and gain no independent rights over it.
- Payment processor — to process payments, prevent fraud, and issue invoices.
- Email delivery provider — to send sign-in links, receipts, and service notices.
- Services you connect — when you link a third-party account, data flows to and from that provider under its own privacy policy.
- Professional advisers and authorities — where required to comply with the law, enforce our Terms, or protect the rights, property, or safety of SoftQuantus, our users, or the public.
- A successor — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
6. International transfers
We are established in the European Union. Some of our processors operate outside the European Economic Area. Where personal data leaves the EEA, we rely on an adequacy decision of the European Commission or on the Standard Contractual Clauses, with supplementary measures where needed. You can ask us for a copy of the relevant safeguards.
7. How long we keep it
- Account data — for as long as your account is active.
- Inputs, Outputs, and run history — for as long as your account is active, so you can audit your spend and reproduce past runs. You can delete individual conversations and runs from the product at any time.
- Usage, metering, and billing records — for the period required by tax and accounting law after the transaction, regardless of account status.
- Technical logs — for a limited period sufficient to detect abuse and diagnose failures, then deleted or aggregated.
When your account is deleted (on your request to info@softquantus.com), we delete or anonymise your personal data within a reasonable period, except records we must keep for billing, accounting, legal, or security obligations, and residual copies in backups that are overwritten on their normal rotation.
8. Cookies
The Services use only essential cookies and local storage: the session cookie that keeps you signed in, a CSRF token, and your interface preferences (such as theme). We set no advertising cookies and no cross-site tracking cookies, and we do not load third-party analytics scripts. You can block cookies in your browser, but the signed-in Services will not work without the session cookie.
9. Security
We protect personal data with technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls with least privilege, salted password hashing, audit logging, and separation of production data from development. No system is perfectly secure; if we become aware of a personal-data breach that is likely to result in a risk to you, we will notify you and the competent supervisory authority as the law requires.
10. Your rights
Under the General Data Protection Regulation and, where it applies, the law of the country where you live, you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected and incomplete data completed;
- have your data erased, subject to the retention obligations above;
- restrict or object to processing based on our legitimate interests;
- receive the data you gave us in a portable, machine-readable format;
- withdraw consent at any time, without affecting processing that happened before;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you;
- lodge a complaint with a supervisory authority — in our case the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) — or with the authority of the country where you live.
To exercise a right, use your account settings where the option exists, or write to info@softquantus.com. We will verify your identity and respond within one month, extendable where the law allows for complex requests. Exercising your rights is free unless a request is manifestly unfounded or excessive.
11. Children
The Services are not directed at, and may not be used by, anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the Services or the law change. If a change is material, we will give notice by email or in the product before it takes effect. The effective date at the top always reflects the current version, and earlier versions are available on request.
13. Contact
SoftQuantus innovative OÜ, Veskiposti tn 2-1002, Kesklinna linnaosa, Tallinn 10138, Estonia. Privacy questions and requests: info@softquantus.com.