Privacy Policy
Last updated: 31 August 2026
1. Who is responsible for your personal data
Post-Quantum Institute, a Delaware corporation doing business as Stratsec, is the controller of the personal data described in this policy. In this policy, “we”, “us” and “our” mean Post-Quantum Institute, and “you” means the individual whose personal data is processed.
Defined terms that appear here and are not defined below have the meanings given in section 1 of the Terms of Use.
Privacy enquiries and requests to exercise your rights should be sent to [email protected].
2. What we collect, why, and on what legal basis
| Data | Purpose | Legal basis |
|---|---|---|
| Website visitors: IP address, browser and device information, pages viewed, referring site | Operating and securing the website, and understanding how it is used | Our legitimate interest in operating and securing the site. Consent for any non-essential analytics cookie |
| Newsletter subscribers: email address, and any name you provide | Sending the free Newsletter | Consent, withdrawable at any time |
| Subscriber account: name, business email address, organisation, job title, Portal credentials | Providing and administering a Subscription | Performance of the contract with your organisation, and our legitimate interest in administering it |
| Member Lens configuration: jurisdictions, themes and named instruments selected by your organisation | Prioritising and filtering coverage to your organisation’s exposure | Performance of the contract |
| Triage records: which Briefing Items a named user has added to actions, marked as done, or dismissed, with the date and time of each action | Producing the auditable record of what was flagged and what was done about it, which is a core function of the Radar | Performance of the contract, and the legitimate interest of the subscribing organisation in holding that record |
| Portal usage: sign-in times, IP address, items viewed | Security, prevention of credential sharing and abuse, and support | Our legitimate interest in protecting the service |
| Billing records: billing contact, billing address, VAT or tax registration number, invoices and transaction records | Taking payment, accounting and tax compliance | Performance of the contract, and legal obligation |
| Enquiries: name, email address and the content of your message | Responding to you | Our legitimate interest in answering enquiries |
| Calls with analysts and reviewers: attendance, and any notes taken | Delivering the advisory element of a Subscription | Performance of the contract. A call is recorded only with the consent of everyone present |
| Stratsec Circle and Roundtables: name, email address, organisation and role | Maintaining the members’ directory and administering invitations and events | Consent |
Card details are handled entirely by Stripe and are never held by us.
3. Triage records, and who can see them
The Portal records which Briefing Items each named user has actioned, completed or dismissed. That is the product’s audit trail. It is also a record of what an identified individual acted on and what they set aside.
A triage record is visible to the user who created it and to administrators designated by the subscribing organisation. It is not disclosed outside the subscribing organisation, and it is not used to evaluate any individual.
Where your organisation holds the Subscription, decisions about who within it is given administrator access are made by your organisation and not by us.
4. Cookies and analytics
Cookies that are strictly necessary to operate the website and the Portal, including the cookie that keeps you signed in, are set without consent because the service cannot be delivered without them.
Analytics cookies are set only where you consent through the consent notice, and consent may be withdrawn at any time through the same notice. Where you do not consent, no analytics cookie is set and no analytics data is collected about your visit.
This website sets no advertising cookies and displays no advertising. No personal data is shared with any advertising network.
5. Who we share personal data with
Personal data is not sold, rented or shared for the marketing purposes of any third party.
The following providers process personal data on our behalf, under contract and on our instructions:
- Hosting: the provider that hosts stratsec.com and the Portal.
- Email: the provider that delivers service, billing and correspondence email.
- Payments: Stripe, which processes card payments and holds card details.
- Consent management: the provider that operates the consent notice.
- Analytics: the analytics provider, where you have consented.
The free Newsletter is distributed through Substack, which holds the email addresses of Newsletter subscribers on its own platform. Substack applies its own privacy policy to your relationship with that platform.
Personal data may also be disclosed where we are required to do so by law, or where disclosure is necessary to establish, exercise or defend a legal claim.
6. AI model providers receive no personal data about you
Briefing Items are produced with the assistance of AI models supplied by Anthropic, OpenAI and Google. The material sent to those providers is published source content, such as the text of an instrument, a consultation document or a standards publication. Where a published source names an individual, that name forms part of the source and is processed as published material.
No subscriber personal data is sent to any model provider. Account details, Member Lens configuration, triage records, Portal usage and the content of any call are held within the service and are never used as model input.
Because these providers do not process personal data on our behalf, they are technology suppliers and not processors of your personal data. The AI Use and Editorial Standards statement describes the method in full.
7. Where your personal data is processed
We are established in the United States, and personal data described in this policy is processed there and by providers that may process it in the United States and elsewhere.
Where personal data originating in the European Economic Area or the United Kingdom is transferred, appropriate safeguards are applied to that transfer, and details of the safeguards applied are available on request from [email protected].
8. How long we keep personal data
- Subscriber account data, Member Lens configuration and triage records: for the Subscription Term and for twelve months after it ends, after which they are deleted.
- Portal usage logs: twelve months.
- Billing, invoice and tax records: seven years, as required for accounting and tax purposes.
- Newsletter subscription: until you unsubscribe. Your email address is then held on a suppression list so that you are not added again in error.
- Enquiries and correspondence: twenty-four months from the last message in the exchange.
- Circle and Roundtable records: for the duration of membership or attendance, and for twelve months after.
- Analytics data, where you have consented: fourteen months.
Personal data may be held beyond these periods where it is needed to establish, exercise or defend a legal claim, and only for as long as that need lasts.
9. Your rights
You have the right to:
- ask for a copy of the personal data held about you;
- have inaccurate data corrected;
- have data erased;
- ask us to restrict processing;
- object to processing that relies on a legitimate interest;
- receive certain data in a portable form.
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing carried out before it.
Requests should be sent to [email protected] and will be answered within one month. No fee is charged.
If you are not satisfied with our response, you may complain to a data protection supervisory authority. In the United Kingdom that is the Information Commissioner’s Office. In the European Economic Area it is the supervisory authority of the country where you live or work.
10. Automated decision-making
AI is used to monitor sources and draft Briefing Items, as described in section 6. No decision producing legal effects concerning you, or similarly significantly affecting you, is made by automated means.
11. Security
Access to subscriber data is restricted to personnel who need it to deliver or support the service. Portal access requires an account, and credentials must not be shared outside the subscribing organisation.
12. Changes to this policy
This policy may be updated. Where an update materially affects how personal data is used, notice will be given to affected subscribers by email, and the date at the top of this page states the version in force.
13. Contact
Post-Quantum Institute, doing business as Stratsec
155 N Wacker Dr, Suite 4250
Chicago, IL 60606
United States
[email protected]