<!-- Generated from the privacy page by the site build (site/integrations/md-twins.mjs); never edit by hand. -->

# Privacy Policy

Effective July 5, 2026 · Controller: Pauli, Inc., a Delaware corporation · [hello@pauli.xyz](mailto:hello@pauli.xyz)

## 1. What we collect

- **Account data:** legal name (individual and, if applicable, entity), email address, declared country, workspace name.

- **Compliance data:** restricted-party screening inputs and results, IP addresses and derived geolocation at signup and job submission, routing and denial decisions, and an append-only audit log of each screening decision.

- **Service data:** quantum circuits you submit, execution results, job metadata (device, shots, timing, cost).

- **Payment data:** handled by Stripe; we receive transaction status and last-4/card brand, never full card numbers. Stripe’s privacy policy governs its processing.

- **Technical data:** standard server logs (IP, user agent, timestamps).

We do not use advertising cookies or sell personal information.

## 2. How we use it

To provide and bill the Service; to comply with U.S. export-control and sanctions law (screening, geolocation blocking, recordkeeping, and government reporting where required); to secure and debug the Service; and to communicate service notices. Legal bases (where GDPR applies): contract performance, legal obligation, and legitimate interests in security and abuse prevention.

## 3. Sharing

- **Hardware providers:** your circuits and job metadata are transmitted to the third-party provider operating the selected device and are processed outside our infrastructure, solely to execute your job.

- **Processors:** Stripe (payments), cloud hosting and storage, screening-list data sources.

- **Legal:** government authorities where required by law (including export and sanctions authorities), and to protect rights, safety, or the Service.

- **Corporate events:** a merger, acquisition, or asset sale, with notice.

## 4. Retention

- **Compliance records** (screening decisions, denials, geolocation determinations, transaction records): retained at least 10 years after the transaction, as required by U.S. sanctions regulations (31 C.F.R. § 501.601), and by default indefinitely in our append-only audit log. **These records are exempt from deletion requests to the extent retention is legally required.**

- **Circuits and results:** retained while your account is active and for 90 days after closure, then deleted, except data embedded in compliance or billing records.

- **Account and billing data:** life of the account plus the compliance retention period.

## 5. Your rights

Depending on your jurisdiction (for example, California CCPA/CPRA, EU/UK GDPR) you may request access, correction, deletion, portability, or restriction, and you may not be discriminated against for exercising rights. Submit requests to [hello@pauli.xyz](mailto:hello@pauli.xyz); we verify identity before acting. Deletion requests are honored except where retention is required by law (Section 4). California residents: we do not sell or share personal information as defined by the CPRA. EU/UK users: transfers to the United States rely on Standard Contractual Clauses; you may complain to your supervisory authority.

## 6. Security

Encryption in transit and at rest, access controls, and least-privilege administration. No method is 100% secure; we will notify you of breaches as required by law. The specific controls are described on the [security page](https://pauli.xyz/security).

## 7. Children

The Service is not directed to anyone under 18; we do not knowingly collect their data.

## 8. Changes and contact

We will post updates here and notify material changes by email. Contact: [hello@pauli.xyz](mailto:hello@pauli.xyz).
