Legal · Privacy notice
Privacy.
We're a small consulting firm. We don't run trackers, we don't sell data, and we don't keep what we don't need. This page is the long version of that.
Draft: counsel review pending
This notice is a plain-language placeholder. Have it reviewed by counsel before relying on it for GDPR, CCPA, or any contractual purpose.
The short version
What's actually going on.
Quantum Data Wave Ltd. ("QDW", "we") operates quantumdatawave.com. This site has one purpose: let you read about what we do and reach us about a possible engagement. The personal data we touch comes almost entirely from the contact form, and we use it only to reply to you.
This site still sets no cookies. We use Cloudflare Web Analytics, run by our own hosting provider, to see aggregate traffic. It doesn't use cookies, doesn't fingerprint you, and doesn't store your IP address or any other personal data.
What we collect
What we collect.
From the contact form and direct emails, we collect:
- Your name and work email
- Your company and (optionally) your role
- Whatever you write in the "sketch the problem" field
- Your topic and timing selections
From normal web operations, our hosting provider keeps short-lived access logs (IP address, user agent, requested URL, timestamp) for security and abuse-prevention purposes. These are not joined to your form submission.
Why we collect it
Why we collect it.
We use contact-form data only to reply to your enquiry, hold the First Hour calls, and follow up if you ask us to. We may keep a record of past correspondence for the duration of the relationship, plus the retention period below.
Under EU GDPR terminology, the legal basis is the steps you ask us to take before entering a contract (Art. 6(1)(b)) and, where applicable, our legitimate interest in responding to business enquiries (Art. 6(1)(f)).
How long we keep it
How long we keep it.
- Contact-form submissions: 24 months from your last interaction with us, then deleted.
- Engagement-related correspondence: retained for the duration of the engagement and up to 7 years afterwards, where required by applicable accounting or limitation-period laws.
- Access logs: 30 days, then deleted by our hosting provider.
Your rights
Your rights.
Wherever you live, you can ask us to do the following with the data we hold about you:
- Access: tell you what we have
- Correct: fix anything that's wrong
- Erase: delete it (subject to the retention period above and any legal hold)
- Restrict or object: stop us using it for a given purpose
- Port: give you a machine-readable copy
Email [email protected] with the request. We aim to reply within 30 days.
Security
Security.
Data in transit is encrypted with TLS 1.2 or higher. Data at rest sits in encrypted storage offered by the providers above. Access to client-related data within QDW is restricted to the people working on that engagement, on a named basis.
We're in audit for ISO 27001; certification is expected January 2027. No security posture eliminates risk; if a breach involves your data we'll notify you as required by law and explain what happened in plain language.
Cookies & analytics
Cookies & analytics.
We use Cloudflare Web Analytics for aggregate traffic and performance numbers: page views, load times, that kind of thing. It's cookie-free, it doesn't track you across sites, and it doesn't store your IP address or any other personal data. That's why we still don't have a cookie banner — the EU cookie-consent rule is triggered by things like cookies or fingerprinting, and this tool does neither. If that ever changes (for example, if we add a feature that genuinely needs a cookie), we'll add a banner before the cookie ships, not after.
Contact & complaints
Contact, and complaints.
Privacy questions, requests, or complaints go to [email protected]. If you're in the EU/EEA and you're not satisfied with our response, you can lodge a complaint with the Bulgarian Commission for Personal Data Protection (the CPDP), or your local supervisory authority.