Home / Legal
Privacy Policy
This document is a working draft pending attorney review. It is published for transparency; the executed agreement governs any engagement.
Nexus Prism Intelligence Platform Quinn Defense Systems
Version: 1.0-draft (Pending Attorney Review) Effective Date: upon Terms of Service sign-off
1. About this Policy
This Privacy Policy explains what personal data Quinn Defense Systems ("we", "us") collects when you use the Nexus Prism Intelligence Platform (the "Platform"), how we use it, who we share it with, and how you can exercise your rights.
It covers two distinct populations:
- Users -- natural persons who authenticate into the Platform on behalf of a Customer organisation (the "Tenant").
- Subjects -- natural persons whose data appears within the OSINT Content that Users query or that we aggregate from third-party feeds.
We play different roles for these two populations:
| Population | Our role | Lawful basis |
|---|---|---|
| Users | Controller (and Processor for the Tenant) | Contract (ToS), legitimate interest (security) |
| Subjects | Processor on behalf of the querying Tenant; Controller only to the extent we curate our own feeds | Customer's lawful basis; for our own feeds, public interest and legitimate interest after a documented balancing test |
If you are a Subject and you want to know how a specific Tenant uses your data, contact that Tenant first. If you cannot identify the Tenant, contact privacy@quinndefensesystems.com and we will route your request.
2. Data We Collect About Users
2.1 Account data -- name, email address, Keycloak sub, Tenant
assignment, role, and (if enabled) multi-factor-authentication device
identifier. Collected from Keycloak at first sign-in and from Tenant
admins when they invite you.
2.2 Usage data -- every authenticated request is recorded in
beta_activity_log (path, HTTP method, response code, response time,
User-Agent, IP address, session fingerprint, Tenant ID, role). We use
this to provide the service, protect against abuse, meter usage, and
produce audit reports for your Tenant admin.
2.3 Billing data -- Stripe customer ID, plan, card last-four and expiry (held by Stripe, not us), invoice history, and metered-usage quantities reported by our billing pipeline.
2.4 Support data -- email and chat correspondence, screenshots you share when filing tickets, diagnostic logs you opt-in to attach.
3. Data in OSINT Content (Subjects)
3.1 OSINT Content queried through the Platform may include personal data of Subjects, specifically: IP addresses, email addresses, phone numbers, user-name handles, photo URLs (never inline photos), domain registration information, IoC (indicator-of-compromise) enrichments, vehicle and aircraft identifiers, public-record court case numbers, and aggregated threat-correlation scores. It does not include biometric identifiers, health records, genetic data, or financial account numbers.
3.2 Content is organised per Tenant and isolated via PostgreSQL
row-level security keyed on the nexus.current_tenant session GUC.
3.3 Our in-house feeds (e.g., aviation track correlation, construction anomaly detection) are generated from publicly available observational data under a documented Legitimate Interests Assessment (LIA); Subjects who object may write privacy@quinndefensesystems.com and we will remove their data from our curated feeds within thirty (30) days unless overriding legitimate interests apply (open criminal investigations etc.).
4. How We Use Data
4.1 Users -- to authenticate you, operate the Platform, meter usage, bill you, protect against abuse, train Tenant admins on their own users' behaviour, comply with audit and export-control obligations, and improve the Platform. We do not sell User data.
4.2 Subjects (on behalf of Tenants) -- we process Subject data only to execute the Tenant's query, persist correlated enrichments for the Tenant, and retain audit trail for the investigation. We do not repurpose one Tenant's Subject data for another Tenant.
4.3 Analytics -- aggregate, de-identified telemetry (adoption curves, feature usage distributions) used to prioritise engineering.
5. Sharing
5.1 Stripe, Inc. -- payment processing. Receives Stripe customer ID, plan, usage quantities, and the card data you enter during Checkout. US-based; SOC 1, SOC 2, PCI-DSS Level 1.
5.2 Keycloak -- self-hosted by us on the Platform's infrastructure. No external sub-processor for identity.
5.3 Third-party OSINT providers -- Shodan, VirusTotal, AbuseIPDB, IntelX, OTX, URLScan. When you make an enrichment query we send the query parameter (IP, hash, URL) to the relevant provider. We do not send User identity or Tenant ID to the provider unless the upstream licence requires it.
5.4 Cloudflare -- DDoS protection and tunnelling for the public endpoints. Sees request metadata (IP, headers, TLS fingerprint); does not see decrypted Tenant Content.
5.5 Sub-processor list -- the current list is published at https://quinndefensesystems.com/legal/subprocessors and updated at least ten (10) calendar days before we add or remove a sub-processor.
5.6 Law enforcement / court order -- as required by law. Where lawful we notify affected Customers before disclosure so they may seek a protective order.
6. Retention
- User account data: duration of the Subscription + ninety (90) days grace.
- Usage / audit data: seven (7) years (Gold, Platinum) or two (2) years (Bronze, Silver) per ToS Section 6.2.
- Billing data: seven (7) years for US tax compliance.
- OSINT Content stored per Tenant: controlled by the Tenant; our default is 180 days rolling plus whatever a case file explicitly retains.
- Backups: we rotate backups on a sixty (60) day cycle.
7. Security
7.1 TLS 1.3 in transit, AES-256 at rest (PostgreSQL TDE where enabled,
filesystem LUKS elsewhere), tenant isolation enforced at the DB row
level, signed audit trails, Keycloak-authenticated access with
(optional) MFA for admin and tenant_admin roles.
7.2 Incident response: twenty-four-hour triage SLA, seventy-two-hour regulator / Customer notification SLA consistent with GDPR Art. 33(2).
8. Your Rights
Depending on where you live, you may have the right to:
- access your personal data (Subject Access Request);
- correct inaccurate data;
- erase your data ("right to be forgotten", subject to our retention obligations in Section 6);
- restrict or object to processing;
- port your data in a machine-readable format;
- withdraw consent (where processing relies on consent);
- lodge a complaint with a supervisory authority.
To exercise a right, write to privacy@quinndefensesystems.com. We will respond within thirty (30) days (GDPR), forty-five (45) days extendible to ninety (90) days (CCPA / CPRA), or the shortest applicable local deadline.
US state privacy laws. If you are a resident of California (CCPA / CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), or Utah (UCPA), you have the rights listed above and the right not to be discriminated against for exercising them. We do not sell personal data in the CCPA's defined sense and do not engage in "cross-context behavioural advertising".
9. International Transfers
9.1 We are headquartered in the United States. If you access the Platform from the European Economic Area, the United Kingdom, or Switzerland, personal data will be transferred to the US. The legal basis is the EU Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum (IDTA).
9.2 Federal customers of the US government are governed by the applicable FAR / DFARS clauses in their Services Agreement rather than the SCCs.
10. Children
The Platform is not directed at children under sixteen (16). We do not knowingly collect personal data from anyone under sixteen. If you believe we have such data, write privacy@quinndefensesystems.com and we will delete it.
11. Changes
We may update this Policy by posting a new version at https://quinndefensesystems.com/legal/privacy and giving fourteen (14) days' notice by email or in-portal banner before the effective date. Material reductions in your rights require affirmative acceptance at next sign-in.
12. Contact
Privacy officer: privacy@quinndefensesystems.com Security incidents: security@quinndefensesystems.com Legal notices: legal@quinndefensesystems.com
Postal: Quinn Defense Systems, LLC, North Texas, USA (street address on request -- we do not publish it because of operator safety).
Quinn Defense Systems -- Nexus Prism Intelligence Platform