Privacy Policy
Last updated: January 2026 | LGPD compliant (Lei nº 13.709/2018)
1. Data Controller
The data controller responsible for processing your personal data is OCI-S Technologies. For privacy inquiries, contact: rubens@oci-s.com
2. Data We Collect
- Account data: email address, company name, hashed password.
- Usage data: API request timestamps, benchmark job parameters, job results, and error logs.
- Technical data: IP address (used for rate limiting and fraud prevention only, not stored long-term), User-Agent header.
- Provider tokens: IBM Quantum tokens you supply are encrypted at rest using AES-256 and are only decrypted during job execution.
3. Legal Basis (LGPD Art. 7)
- Contract performance — to provide the Service you requested (Art. 7, II).
- Legitimate interest — to detect fraud, enforce rate limits, and maintain service security (Art. 7, IX).
- Consent — for optional communications such as product updates (Art. 7, I). You may withdraw consent at any time.
4. How We Use Your Data
- To authenticate requests and associate benchmark jobs with your account.
- To generate and deliver benchmark reports.
- To enforce usage limits per your subscription plan.
- To improve the Service (aggregated, anonymized analytics only).
5. Data Sharing
We do not sell or rent your personal data. We may share data with:
- IBM Quantum: your provider token is transmitted to IBM's API only when executing a benchmark job on real hardware.
- Infrastructure providers: cloud hosting (Supabase/PostgreSQL) under data processing agreements.
- Legal authorities: if required by applicable law or court order.
6. Data Retention
Account data is retained for the duration of your account plus 90 days after deletion. Benchmark job data (including reports) is retained for 12 months. Logs are retained for 90 days.
7. Your Rights (LGPD Art. 18)
- Access — request a copy of your personal data.
- Correction — request correction of inaccurate data.
- Deletion — request deletion of your account and associated data.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest.
To exercise any of these rights, email rubens@oci-s.com with subject "LGPD Data Request".
8. Security
We implement industry-standard security measures including: TLS in transit, AES-256 encryption for sensitive tokens at rest, bcrypt password hashing, and rate limiting. No system is perfectly secure; please use a unique password for your OCI-S account.
9. Cookies
The dashboard uses localStorage (not cookies) to persist your session API key on your device. No third-party tracking cookies are used.
10. Changes to This Policy
We will notify registered users by email of material changes to this Privacy Policy at least 15 days before they take effect, as required by LGPD Art. 8, §6.