Privacy Policy
Last updated: 28 June 2026
This policy explains how SeQr Labs ("SeQr", "we") handles data for the SeQr post-quantum cryptography (PQC) assessment service. SeQr is operated by P S Lochan (pre-incorporation) and is currently in beta.
What we collect
- Account data — name, email, and organisation name/sector you provide at sign-up.
- Scan inputs — the domains, hosts, or endpoints you submit for assessment.
- Scan outputs — technical cryptographic metadata of those endpoints (TLS versions, certificate algorithms, key-exchange groups, CDN, and derived risk findings). This is technical configuration data, not personal data.
- Operational logs — IP address and timestamps, used for security and rate limiting.
What we do not collect
SeQr observes only what a public TLS handshake exposes. We do not exploit systems, capture application payloads, or collect the personal data of your end-users. Scans are passive, rate-limited connections equivalent to an ordinary client.
How we use data
To deliver the service (generate your Cryptographic Bill of Materials, risk scores, and reports), to secure and rate-limit the platform, and to improve the product. We do not sell your data or use it for advertising.
Sub-processors
We use third-party infrastructure providers to run the service: application hosting, managed PostgreSQL database, managed Redis, and frontend hosting. Each processes data only to provide hosting to us.
Where data is processed
During beta, data may be processed on cloud infrastructure located outside India. We intend to host production data in an India region (ap-south-1) before onboarding regulated customers, in line with data-localisation expectations. If India-only processing is a requirement for you, contact us before signing up.
Retention
We keep account data while your account is active and for up to 90 days after closure. You can delete your assets and scan data at any time from the dashboard; deletion is permanent.
Security
Passwords are hashed (bcrypt), API keys are stored only as hashes, data is encrypted in transit (TLS), and every tenant's data is isolated by organisation. No system is perfectly secure; we work to protect your data using reasonable safeguards.
Your rights
You may request access to, correction of, or erasure of your personal data, and may withdraw consent, by emailing contact@seqrlabs.com. Under India's Digital Personal Data Protection Act 2023, you also have the right to grievance redressal.
Grievance Officer
P S Lochan — contact@seqrlabs.com. We respond to data-protection grievances within the timelines required by applicable law.
Children
SeQr is not intended for individuals under 18.
Changes
We may update this policy; material changes will be posted on this page with a new date.