Last Updated: August 23, 2026

Cyberquantm Technologies LLC, a Massachusetts limited liability company ("Cyberquantm," "Company," "we," "our," or "us"), respects your privacy and is committed to protecting it through our compliance with this policy. This Privacy Policy describes the types of information we may collect from you or that you may provide when you access or use our sovereign cloud security, post-quantum cryptography, and AI-driven risk assessment platform, including our first operating product, Odysseus Careers, together with all related websites, applications, APIs, dashboards, and software (collectively, the "Services"), and our practices for collecting, using, maintaining, protecting, and disclosing that information.

This Privacy Policy is incorporated by reference into, and should be read together with, our Terms of Service. By accessing or using the Services, you agree to the collection, use, and disclosure of information as described in this Privacy Policy.

1. What Information We Collect and How

a. Your Content

In the course of providing the Services, Cyberquantm may process data, files, configurations, risk models, telemetry, and encrypted materials that you or your authorized users upload, submit, or generate through the Services ("Your Content"). Because significant portions of the platform are architected around post-quantum encryption and owner-controlled access, Cyberquantm's ability to view Your Content in plaintext is intentionally limited, and in many configurations, Cyberquantm cannot access the substantive contents of Your Content at all.

b. Customer Information

We collect information that identifies, relates to, or could reasonably be linked with you or your organization ("Personal Information"), including:

● Account and registration information, such as name, work email address, company name, job title, and password;

● Billing information, such as billing address and payment details (processed by our third-party payment processors, as described in Section 3);

● Communications you send to us, including support requests, feedback, and correspondence; and

● Information provided when you register for events, webinars, or request an executive briefing or systems assessment.

c. Information We Collect Automatically

When you access or use the Services, we and our service providers may automatically collect certain information, including:

Device and Usage Data: IP address, browser type, operating system, device identifiers, referring URLs, pages viewed, features used, and timestamps of activity;

Log and Diagnostic Data: system logs, error reports, performance metrics, and API call data generated in connection with your use of the Services;

Cookies and Similar Technologies: we and our service providers use cookies, pixels, and similar technologies to operate and secure the Services, remember your preferences, and understand usage patterns, as further described in Section 1.d.

Collectively, the data described in this Section 1.c is referred to as "Usage Data." Usage Data does not include the substantive content of Your Content.

d. Cookies and Tracking Technologies

We use strictly necessary cookies to operate the Services (such as maintaining your session and enforcing security controls), as well as optional analytics and functionality cookies, where permitted, to understand how the Services are used and to improve them. Where required by applicable law, we will obtain your consent before deploying non-essential cookies, and you may manage cookie preferences through your browser settings or any cookie consent tool made available on our website.

e. Information from Third Parties

We may receive information about you from third parties, including:

● Identity and authentication providers (e.g., single sign-on services) if your organization enables such integrations;

● Integration partners that you authorize to connect with the Services; and

● Publicly available sources, for purposes such as fraud prevention and due diligence.

2. How We Use Information

We use the information we collect for the following purposes:

a. To provide, operate, maintain, and secure the Services, including authenticating users, processing risk assessments, and delivering Risk Intelligence outputs;

b. To detect, investigate, and prevent fraudulent, unauthorized, or illegal activity, and to protect the security and integrity of the Services and our infrastructure;

c. To communicate with you, including responding to inquiries, providing customer support, and sending administrative or security-related notices;

d. To improve and develop the Services, including training and refining the models underlying our Risk Intelligence features, using aggregated or de-identified data wherever feasible;

e. To process payments and manage billing, subscriptions, and account administration;

f. To comply with applicable legal obligations, respond to lawful requests from public authorities, and enforce our Terms of Service; and

g. With your consent, or as otherwise permitted, to send marketing communications, which you may opt out of at any time.

Legal Bases for Processing (EEA/UK Users)

Where the General Data Protection Regulation ("GDPR") or the UK GDPR applies, we process Personal Information on the following legal bases: (i) performance of a contract with you or your organization; (ii) our legitimate interests in operating, securing, and improving the Services, provided such interests are not overridden by your rights; (iii) compliance with a legal obligation; and (iv) your consent, where required, such as for certain marketing communications or non-essential cookies.

3. How We Disclose Information

We do not sell your Personal Information. We may disclose information as follows:

a. Service Providers and Vendors

We share information with third-party vendors that perform services on our behalf, including cloud hosting and infrastructure providers, payment processors, customer support platforms, and analytics providers. These vendors are contractually bound to use information only as necessary to provide services to us and to maintain appropriate confidentiality and security safeguards.

b. Affiliates

We may share information with our corporate affiliates for purposes consistent with this Privacy Policy.

c. Business Transfers

If Cyberquantm is involved in a merger, acquisition, financing, reorganization, or sale of all or a portion of its assets, information may be disclosed or transferred as part of that transaction, subject to standard confidentiality protections.

d. Legal Requirements and Sovereign Infrastructure Protections

We may disclose information where we believe in good faith that disclosure is required by law, regulation, legal process, or governmental request. Consistent with our sovereign infrastructure commitments, Cyberquantm does not grant foreign government authorities routine or direct access to encrypted Customer Content. Where Cyberquantm is legally compelled to disclose information, we will, to the extent permitted by law, use commercially reasonable efforts to (i) narrow the scope of any disclosure, (ii) notify affected customers, and (iii) challenge requests we believe are overbroad or unlawful.

e. With Your Consent

We may disclose information for any other purpose with your consent.

4. International Data Transfers

Cyberquantm's Services are designed to support customers with data residency and sovereignty requirements. Where you have selected Sovereign Infrastructure features, Your Content will be processed and stored within the geographic region specified in your Order Form, subject to the technical limitations described in your service configuration.

Where Personal Information is transferred internationally, including from the European Economic Area, United Kingdom, or Switzerland to the United States or other jurisdictions, we rely on appropriate safeguards, which may include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or other lawful transfer mechanisms recognized under GDPR and applicable post-Schrems II guidance. We conduct transfer impact assessments where required and implement supplementary technical measures, including post-quantum encryption, to mitigate risk associated with cross-border processing.

5. Security

Cyberquantm implements administrative, technical, and physical safeguards designed to protect Personal Information and Your Content against unauthorized access, disclosure, alteration, and destruction, including:

a. Post-Quantum Encryption: implementation of NIST-approved post-quantum cryptographic algorithms (including lattice-based key encapsulation and digital signature schemes) for data at rest and in transit, designed to resist both classical and quantum cryptanalytic attacks;

b. Owner-Controlled Access and No Backdoors: architecture designed so that, in applicable configurations, decryption keys remain under your control, and Cyberquantm does not maintain intentional backdoors or master keys enabling bypass of encryption safeguards;

c. Access Controls: role-based access controls, multi-factor authentication, and the principle of least privilege applied to internal systems handling Personal Information and Your Content;

d. Monitoring and Incident Response: continuous security monitoring, vulnerability management, and a documented incident response process, including notification procedures consistent with applicable law; and

e. Vendor Security Review: due diligence and contractual security requirements applicable to third-party vendors with access to Personal Information.

No security measure is completely infallible. While we work to protect the confidentiality, integrity, and availability of information within the Services, we cannot guarantee absolute security, and you are responsible for maintaining appropriate configuration, access controls, and key management practices within your organization, as further described in our Terms of Service.

6. Data Retention

We retain Personal Information and Your Content for as long as necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Retention periods vary depending on the type of information and the purpose for which it is processed. Upon termination of your account, we will make Your Content available for export for a period consistent with our Terms of Service, after which it will be deleted or de-identified, except where retention is required by applicable law, encrypted backup schedules, or legitimate business purposes such as fraud prevention.

7. Your Privacy Rights

Depending on your jurisdiction, you may have the following rights with respect to your Personal Information:

a. Access: the right to request confirmation of whether we process your Personal Information and to obtain a copy of it;

b. Correction: the right to request correction of inaccurate or incomplete Personal Information;

c. Deletion: the right to request deletion of your Personal Information, subject to certain exceptions;

d. Portability: the right to receive a copy of your Personal Information in a structured, commonly used, machine-readable format;

e. Objection and Restriction: the right to object to, or request restriction of, certain processing activities, including processing based on legitimate interests or for direct marketing; and

f. Withdrawal of Consent: where processing is based on consent, the right to withdraw that consent at any time.

California Privacy Rights

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CPRA"), grants you additional rights, including the right to know the categories and specific pieces of Personal Information we collect, the right to delete Personal Information, the right to correct inaccurate Personal Information, the right to opt out of the "sale" or "sharing" of Personal Information (we do not sell or share Personal Information as those terms are defined under the CPRA), and the right to non-discrimination for exercising your privacy rights.

To exercise any of these rights, please contact us at privacy@cyberquantm.com. We will verify your request and respond within the timeframes required by applicable law. You may designate an authorized agent to submit a request on your behalf, subject to our ability to verify that authorization.

8. Children's Privacy

The Services are not directed to, and are not intended for use by, individuals under the age of 18. We do not knowingly collect Personal Information from children. If we become aware that we have collected Personal Information from a child without verification of parental consent, we will take steps to delete that information. If you believe we may have collected information from a child, please contact us at privacy@cyberquantm.com.

9. Third-Party Links and Integrations

The Services may contain links to third-party websites or allow integrations with third-party platforms that you choose to connect. This Privacy Policy does not apply to those third-party websites or platforms, and we encourage you to review their respective privacy policies.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. If we make material changes, we will provide notice through the Services or by email prior to the changes taking effect. The "Last Updated" date at the top of this Privacy Policy indicates when it was last revised. We encourage you to review this Privacy Policy periodically.

11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Cyberquantm Technologies LLC

Attn: Privacy Team

82 Wendell Ave., Suite 100

Pittsfield, MA 01201, USA

Email: privacy@cyberquantm.com

Privacy Policy