Privacy Policy
Version Quatnex Secure Privacy Policy 2 ·
Effective June 15, 2026
This Privacy Policy describes how Quantex Secure LLC ("Quantex Secure," "we," "us") collects, uses, and protects information when you use the Notentra portal at https://myaccount.notentra.com, the Notentra licensing service at https://license.notentra.com, and related software (collectively, the "Service").
If you are entering into the Notentra Terms of Service on behalf of an organization, that organization is the "Customer" and the controller of Personal Data submitted through the Service; we act as a processor on its behalf for that data.
1. Information We Collect
1.1 Account information you provide
- Registration data — company name, your full name, work email address, password (stored only as a BCrypt hash), and answers to three security questions (stored only as BCrypt hashes of a normalized form).
- Profile and team data — display name, role within your organization (Admin, Contract Manager, Technical Contact, License Manager, Named Caller), and the assignment / approval status of other members you invite.
- Support content — the contents of support tickets, comments, attachments, and any logs you choose to upload to our Log Scanner. We retain log uploads only as long as needed for the support session or, when linked to a ticket, until 15 days after the ticket is closed.
- Knowledge-base interactions — articles viewed, ratings, and feedback you submit.
- Billing and commercial data — quotes, invoices, payment method (processed by Stripe), and license entitlements. We do not store full payment-card numbers on our systems.
- Legal acceptance evidence — the version of each Terms of Service / Privacy Policy you have accepted, the timestamp, your IP address, and your user-agent at the time of acceptance.
1.2 Information we collect automatically
- Usage and security telemetry — IP address, browser user-agent, timestamps and outcomes of login / registration / password-reset / email-verification attempts, and rate-limit decisions. Used to operate the Service, detect abuse, and investigate security incidents.
- Session cookies — an authentication cookie set after you sign in, and an anti-forgery cookie. Both are essential for the Service to function; we do not use advertising or cross-site tracking cookies.
- Application logs — structured logs of portal activity, retained for 12 months for operational and security purposes.
1.3 License-usage telemetry from your Notentra deployment
When you install the Notentra identity-provider software in your own environment, that software periodically reports the following to our License Server:
- Server identifier (a unique value we issued in your .nlic license file).
- Active Authorized-User counts within your licensed pool.
- Software version, hostname, and a stable machine identifier of the host(s) running the Notentra software.
- Activation and check-in timestamps.
We use this telemetry to enforce license terms, deliver entitlements, and support your deployment. We do not collect the contents of your end-users' authentication sessions, passwords, or directory data through this channel.
2. How We Use Information
We use the information described above to:
- provide, operate, and maintain the Service;
- create and manage your account, verify your email address, and authenticate you;
- issue, enforce, and renew your licenses and Entitlements;
- process payments and send invoices;
- respond to your support requests and notify you about service changes;
- send transactional emails (verification, password reset, support, billing);
- detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Service;
- comply with legal obligations and enforce our agreements; and
- generate aggregated, de-identified statistics about Service usage.
3. Legal Bases for Processing (EEA / UK)
If you are in the European Economic Area, United Kingdom, or another jurisdiction with similar requirements, our legal bases include:
- Performance of a contract — to provide the Service to you or your organization (registration, license issuance, billing, support).
- Legitimate interests — to operate, secure, and improve the Service (telemetry, anti-abuse, fraud prevention, sales-rep assignment).
- Compliance with a legal obligation — tax records, anti-money-laundering checks, and lawful disclosure requests.
- Consent — where we explicitly ask for it (e.g., optional marketing emails). You may withdraw consent at any time.
4. How We Share Information
We do not sell Personal Data. We share Personal Data only with the following categories of recipients, and only as needed:
- Service providers (sub-processors) — for hosting, payment processing (Stripe), email delivery (our SMTP relay provider), and similar infrastructure. A current list of sub-processors is available at https://myaccount.notentra.com/legal/subprocessors or on request.
- Your organization — administrators on your account can see your membership, role, and basic profile within the Service.
- Legal and regulatory bodies — when required by law, court order, or to protect the rights, property, or safety of Quantex Secure, our users, or others.
- Successors — in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets. We will give notice and ensure any successor honors this Privacy Policy.
5. International Data Transfers
Personal Data may be transferred to, stored at, and processed in countries outside of your country of residence, including the United States. Where required, we rely on appropriate transfer mechanisms such as the European Commission's Standard Contractual Clauses and supplementary measures.
6. Retention
We retain Personal Data only for as long as is necessary for the purposes described in this policy. In general:
- Account, billing, and license-usage records: for the life of your account and up to seven (7) years afterward where required for tax, accounting, and legal-compliance purposes.
- Application and security logs: 12 months (longer if required for an ongoing investigation).
- Support tickets and attachments: for the life of your account, then a reasonable archival period.
- Legal-acceptance evidence: retained for the life of your account and a reasonable period thereafter for dispute resolution.
When data is no longer needed, we delete or de-identify it within a reasonable timeframe.
7. Security
We use industry-standard technical and organizational measures to protect Personal Data, including:
- TLS in transit for all portal and license-server traffic.
- BCrypt password hashing (work factor 12) and one-way SHA-256 hashing of password-reset and email-verification tokens at rest.
- Role-based access control on internal administrative interfaces.
- ECDSA P-256 digital signatures on issued license files.
- Audit logging of administrative actions affecting customer accounts.
- Rate limiting and anti-abuse controls on authentication endpoints.
No method of transmission or storage is perfectly secure. If you believe your account has been compromised, contact us immediately at privacy@notentra.com.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- access the Personal Data we hold about you;
- correct inaccurate or incomplete information;
- request deletion of your Personal Data;
- restrict or object to certain processing;
- request portability of your data in a machine-readable format;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a supervisory authority in your jurisdiction.
To exercise any of these rights, contact us at privacy@notentra.com. We may need to verify your identity before fulfilling the request. If you are a member of a Customer organization, please direct routine requests to that organization first.
9. Children
The Service is intended for use by businesses and is not directed to individuals under 16 years of age. We do not knowingly collect Personal Data from children. If you believe we have inadvertently collected data from a child, contact us at privacy@notentra.com and we will delete it.
10. Cookies and Tracking
The Service uses only the cookies strictly necessary to operate (authentication and anti-forgery). We do not use advertising, marketing, or third-party analytics cookies. We do not respond to browser "Do Not Track" signals because we do not perform the types of tracking those signals are designed to address.
11. Changes to this Policy
We may update this Privacy Policy from time to time. If we make a material change we will notify you through the Portal, by email to the address on your account, or by other reasonable means before the change takes effect. The "Effective Date" at the top of this policy reflects the date of the most recent version.
12. Contact
For questions about this Privacy Policy or our data practices:
Quantex Secure LLC
Attn: Privacy
204 W. Bogart Rd Sandusky OH 44870
Email: privacy@quantexsecure.com
Data Protection Officer (if applicable): Not applicable