Legal

Privacy & Terms

How Kvantis collects and processes personal data under the EU General Data Protection Regulation (GDPR), and the terms that apply when you use our websites and enquiry forms.

Last updated: 11 July 2026
Plain-language summary. We only collect the details you send us through our enquiry form or by contacting us directly, and technical logs needed to run the site securely. We do not use advertising or analytics cookies, we do not sell your data, and you can ask us to access or delete your information at any time via info@kvantis.no.

Part A

Privacy Policy

01 Who we are (data controller)

Kvantis provides independent post-quantum cryptography (PQC) readiness audits for regulated European organisations. For the personal data described in this notice, the data controller is:

Registered nameKvantis AS
Organisation number[org. no.]
Registered address[street, postcode, city], Norway

We are not required to appoint a Data Protection Officer. You can raise any privacy matter, or exercise any of your rights, by emailing info@kvantis.no.

↑ Back to top

02 Personal data we collect

Information you give us

When you complete our enquiry form or contact us, we process the details you choose to provide:

  • Organisation name
  • Your name and role
  • Work email address
  • Sector
  • Any information you include in the free-text “what needs to stay protected” field or in follow-up correspondence

Information processed automatically

We do not run analytics or tracking on our websites. As with any website, our hosting and security provider automatically processes limited technical data — such as your IP address and standard server logs — as a necessary part of delivering pages and protecting the site against abuse. We do not use this to build profiles of visitors, and we do not combine it with the enquiry details you send us.

Please do not include special categories of personal data (for example health, biometric, or similar sensitive information) in the free-text field. Describe the type of data or system you want to protect, not its contents.

↑ Back to top

03 How and why we use it — legal bases

We only process your personal data where the GDPR gives us a lawful basis to do so:

Purpose
What this involves
Legal basis (Art. 6 GDPR)
Purpose
Respond to your enquiry
What this involves
Reviewing your message, assessing whether we are a fit, and replying to you
Legal basis
Steps at your request prior to a contract (Art. 6(1)(b)); our legitimate interest in answering business enquiries (Art. 6(1)(f))
Purpose
Provide audit services
What this involves
Delivering and administering an agreed PQC readiness audit
Legal basis
Performance of a contract (Art. 6(1)(b))
Purpose
Site security & operation
What this involves
Serving the website, preventing spam and abuse (including a form honeypot), and maintaining logs
Legal basis
Our legitimate interest in a secure, functioning website (Art. 6(1)(f))
Purpose
Legal & accounting
What this involves
Keeping records required by law, and establishing or defending legal claims
Legal basis
Compliance with a legal obligation (Art. 6(1)(c)); legitimate interest (Art. 6(1)(f))
↑ Back to top

04 Cookies and tracking

Our websites do not use advertising cookies or third-party analytics, and we do not track you across other sites. We do not display a cookie consent banner because we do not set non-essential cookies.

Strictly necessary technical measures may be applied by our hosting and security provider to keep the site available and protect it against attacks. We serve our own fonts and do not load fonts, scripts, or other resources from third-party content-delivery networks, so browsing our pages does not expose your IP address to advertising or font networks.

↑ Back to top

05 Who we share data with

We do not sell your personal data. We share it only with service providers (“processors”) that help us run our website and respond to you, each acting under a data-processing agreement and only on our instructions:

  • Cloudflare, Inc. — website hosting, content delivery, security, and the messaging function that delivers your enquiry to us.
  • FormSubmit — a fallback that forwards your enquiry to us by email only if our primary delivery fails.

We may also disclose personal data where required by law, or to establish, exercise, or defend legal claims.

↑ Back to top

06 International data transfers

Some of our providers are based, or process data, outside the European Economic Area (EEA) — for example in the United States. Where personal data is transferred outside the EEA/Norway, we rely on an appropriate safeguard recognised by the GDPR, such as the European Commission’s Standard Contractual Clauses and/or the provider’s certification under the EU–US Data Privacy Framework, together with supplementary measures where needed.

You can request more information about the safeguards that apply to a specific transfer by contacting us.

↑ Back to top

07 How long we keep data

We keep personal data only for as long as we need it:

  • Enquiries that do not lead to an engagement — kept while we handle your request and for a reasonable follow-up period, then deleted or anonymised.
  • Client engagement data — handled in line with the written agreement for that engagement, then deleted or returned as agreed.
  • Records required by law (for example accounting documents) — kept for the statutory retention period.
  • Technical logs — kept for a short period for security and troubleshooting.
↑ Back to top

08 Your rights under the GDPR

Subject to the conditions in the GDPR, you have the right to:

  • Access the personal data we hold about you;
  • Have inaccurate data corrected (rectification);
  • Have your data erased (“right to be forgotten”);
  • Restrict how we process your data;
  • Receive your data in a portable format (data portability);
  • Object to processing based on our legitimate interests;
  • Withdraw any consent you have given, without affecting earlier processing.

To exercise any of these rights, email info@kvantis.no. We will respond within the time limits set by the GDPR (normally one month).

If you believe we have not handled your data properly, you may lodge a complaint with a supervisory authority. In Norway this is Datatilsynet; you may also contact the data protection authority in your own EEA country.

↑ Back to top

09 Security

We apply appropriate technical and organisational measures to protect your data, including encryption of traffic in transit (HTTPS/TLS), access controls, and selecting reputable providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your information and to notify you and the relevant authority where the law requires it.

↑ Back to top

10 Changes to this notice

We may update this notice from time to time to reflect changes in our practices or the law. The “last updated” date at the top of this page shows when it was last revised. Where changes are significant, we will take reasonable steps to make them prominent.

↑ Back to top

Part B

Terms of Use

01 Acceptance

By accessing or using kvantis.no, explainer.kvantis.no, or our enquiry forms (the “websites”), you agree to these Terms of Use. If you do not agree, please do not use the websites.

02 Our services, and what they are not

Kvantis provides independent, fixed-scope PQC readiness audits. Content on the websites is provided for general information only.

Our audits and website content are not a certification of regulatory compliance and are not legal advice. References to frameworks such as DORA, NIS2, ENISA guidance, or NIST standards are provided to give context; your organisation remains responsible for determining what applies to it and for obtaining its own legal and regulatory advice.

03 No warranty

The websites and their content are provided “as is” and “as available”, without warranties of any kind, whether express or implied, to the fullest extent permitted by law. We do not warrant that the websites will be uninterrupted, error-free, or free of harmful components, or that the information is complete or current.

04 Limitation of liability

To the fullest extent permitted by applicable law, Kvantis will not be liable for any indirect, incidental, special, or consequential loss, or for any loss of profits, revenue, data, or goodwill, arising out of or in connection with your use of the websites. Nothing in these terms excludes or limits liability that cannot be excluded or limited under applicable law.

05 Intellectual property

The websites and all their content — including text, graphics, layout, the Kvantis name and marks — are owned by Kvantis or its licensors and are protected by intellectual property laws. You may view and print pages for your own reference, but you may not reproduce, republish, or exploit them commercially without our prior written permission.

06 Acceptable use

You agree not to misuse the websites, including by attempting to gain unauthorised access, introducing malicious code, scraping at a scale that disrupts the service, or using the websites for any unlawful purpose.

07 Third-party links

The websites may link to third-party sites. We do not control and are not responsible for their content, availability, or privacy practices. Following external links is at your own risk.

08 Engagements

Any audit engagement is governed by a separate written agreement covering scope, data handling, deliverables, fees, and liability. Where that agreement conflicts with these website terms, the engagement agreement prevails for that engagement.

09 Governing law and jurisdiction

These terms, and any non-contractual obligations arising from them, are governed by the laws of Norway. The courts of Norway have jurisdiction, without prejudice to any mandatory consumer-protection rights you may have in your country of residence within the EEA.

10 Contact

Questions about this notice, our data practices, or these terms:

↑ Back to top