Privacy Policy

Version 1.0 — Effective Date: March 14, 2026

1. Introduction

Northbeam Solutions LLC ("Company," "we," "us," or "our"), located at 8 The Green Ste B, Dover, DE 19901, operates the QAE Safety Kernel API and QAE-FinRisk API (collectively, the "Services") and the developer portal at https://api.qaesubstrate.com (the "Portal").

This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our Services and Portal. By using our Services, you agree to the practices described in this policy.

2. Information We Collect

2.1 Information You Provide

2.2 Information We Collect Automatically

2.3 Information We Do NOT Collect

Our APIs are stateless certification engines. We do not collect or store portfolio contents, market data inputs, action parameters, state deltas, or certificates issued by the API. All input data is processed in memory and discarded when the response is returned.

3. How We Use Your Information

PurposeLegal Basis (GDPR)
Provide and operate the ServicesPerformance of contract
Authenticate your identity and manage your accountPerformance of contract
Process payments (via Stripe)Performance of contract
Send transactional emails (account confirmation, usage alerts)Performance of contract
Send onboarding and product update emailsLegitimate interest
Monitor and enforce rate limits and usage quotasLegitimate interest
Analyze aggregate usage patterns to improve the ServicesLegitimate interest
Comply with legal obligationsLegal obligation

We do not sell your data, use it for advertising, train machine learning models with it, or use it for profiling or automated decision-making that produces legal effects.

4. Data Retention

Data TypeRetention Period
Account data (email, hashed API keys)Until you request deletion
API usage logs (aggregate metrics)90 days, then automatically purged
Payment recordsAs required by tax law (typically 7 years), managed by Stripe
Transactional email records90 days
Support correspondence1 year after resolution

5. Data Sharing

We do not sell, rent, or trade your personal information. We share data only with the following third-party processors:

5.1 Stripe (Payment Processing)

Stripe processes all payment transactions on our behalf. See the Stripe Privacy Policy.

5.2 Resend (Email Delivery)

Resend delivers transactional and product emails on our behalf. See the Resend Privacy Policy.

5.3 Legal Requirements

We may disclose your information if required by law, court order, or governmental request, or to protect our rights, your safety, or the safety of others.

6. Cookie Policy

The Portal uses no tracking cookies, advertising cookies, or third-party analytics cookies.

The only client-side storage used is browser local storage for JWT session tokens and API keys for Portal authentication. You can clear this data at any time by logging out or clearing your browser's local storage.

7. Security Measures

8. Your Rights Under GDPR (EEA Residents)

If you are located in the European Economic Area, you have the following rights:

8.1 Right of Access

You may request a copy of the personal data we hold about you. We will respond within 30 days.

8.2 Right to Rectification

You may request correction of inaccurate personal data through the Portal or by contacting us.

8.3 Right to Erasure

You may request deletion of your personal data. We will delete your account, revoke API keys, remove your email from all mailing lists, and purge usage logs within 30 days.

8.4 Right to Data Portability

You may receive your personal data in a structured, machine-readable format (JSON), including account information and aggregate usage statistics.

8.5 Right to Restrict Processing

You may request that we limit how we process your data while addressing a concern you have raised.

8.6 Right to Object

You may object to processing based on legitimate interests. To opt out of product update emails, use the unsubscribe link in any email or contact us.

8.7 How to Exercise Your Rights

Contact us at bill@northbeam.solutions. We will respond within 30 days and may request identity verification.

8.8 Supervisory Authority

If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.

9. Your Rights Under CCPA (California Residents)

9.1 Right to Know

You may request disclosure of the categories and specific pieces of personal information we collect, the purposes for collection, and the third parties with whom we share it.

9.2 Right to Delete

You may request deletion of the personal information we have collected, subject to exceptions permitted by law.

9.3 Right to Opt-Out of Sale

We do not sell your personal information. We have not sold personal information in the preceding 12 months and have no plans to do so.

9.4 Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA rights.

9.5 How to Exercise Your Rights

Contact us at bill@northbeam.solutions. We will verify your identity and respond within 45 days.

10. Data Deletion Requests

To request deletion of your personal data, email bill@northbeam.solutions with the subject line "Data Deletion Request" and include the email address associated with your account.

We will acknowledge your request within 5 business days and complete deletion within 30 days. Deletion is irreversible; all associated API keys will be revoked.

11. Children's Privacy

The Services are not directed at individuals under 18. We do not knowingly collect personal information from children.

12. International Data Transfers

If you access the Services from outside the United States, your data may be transferred to and processed in the United States. By using the Services, you consent to this transfer. We rely on Standard Contractual Clauses (SCCs) as approved by the European Commission for transfers of personal data from the EEA to the United States.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting a notice on the Portal. Your continued use of the Services after changes take effect constitutes acceptance of the updated policy. We encourage you to review this policy periodically.

14. Contact Us