Skip to content
PacketSense

Legal

Privacy Policy

How PacketSense handles website enquiries, email-verified pilot registration, licensing and support information while keeping packet evidence local by default.

Effective
6 August 2026
Version
privacy-2026-08

Who we are and what this policy covers

PacketSense is operated by QuantamQ Solutions Pty Limited (ABN 26 698 317 574) (“QuantamQ”, “PacketSense”, “we”, “us” or “our”). We are responsible for the personal information handled through the public PacketSense website, pilot registration and licensing services, and direct support interactions described here.

This policy explains what we collect, why we use it, when providers handle it for us, how long we keep it, and how you can ask questions or exercise privacy rights. If an employer or another organisation provides your PacketSense access, that organisation may separately control information it handles about you.

Ordinary website visits

When you request a public page, Cloudflare and our hosting infrastructure can process your IP address and network information, browser, device and operating-system information made available in request headers, pages requested, any referrer supplied by your browser, timestamps, and security and routing metadata. We use these data to deliver, secure and diagnose the website, route traffic and investigate abuse or service faults.

Cloudflare and Cloudflare Turnstile may use essential cookies or similar storage where needed for security, session integrity, traffic management and abuse prevention. Your browser controls can remove or block this storage, although doing so may affect protected features such as the contact form.

Website and pilot-access enquiries

When you submit the website contact form, we process your name, company, role, work email, selected use case, capture volume or team-size description, interests and the page path from which you submitted the request. We also process request time, country code, Cloudflare request identifier, network and security metadata, and a Cloudflare Turnstile token used to detect automated abuse.

The form runs through Cloudflare Pages and Cloudflare Turnstile. Its contents are sent to our team and a confirmation is sent to you through Resend. The website function does not create a separate lead database, but the resulting messages and delivery records remain in our and our providers' email systems according to their normal retention and our business needs.

Registered-trial and email-verification data

To begin a trial, we use the email address you submit to deliver a six-digit verification code. The trial service processes a pseudonymous email subject, pseudonymous device binding, device-binding version, platform and app version, accepted terms and privacy versions, service-email acknowledgement, marketing preference, challenge and handoff identifiers, idempotency and request-security values, timestamps, verification state and failed-attempt count.

After successful verification, we retain a trial registration, pseudonymous email and device uniqueness records, signed entitlement claims, issue and expiry times, feature level, key identifier, status and limited audit events. These records let the app prove its 14-day entitlement and help us enforce trial eligibility, recover an interrupted issuance safely, investigate abuse and support users.

Packet data remains local by default

The desktop app processes PCAP, PCAPNG, supported text captures and user-selected live traffic locally. Raw packet captures, converted captures, local analysis databases, packet details, streams, anomalies, reports, diagnostics and on-device assistant output remain on your device by default. Trial registration and licence checks do not require this content.

Packet data can contain personal information and highly sensitive content. You control the captures you import, the interfaces you monitor, local storage and exports. You are responsible for having authority to analyse that traffic and for protecting and deleting local material in accordance with your obligations.

Support and optional cloud AI

If you contact support, we process the contact details, messages, screenshots, logs, diagnostics and files you choose to provide. Please do not send captures, credentials, private keys or regulated information unless we ask you to use an agreed secure channel.

Optional cloud AI is off by default. If a user or authorised administrator enables and configures it, selected analysis context may be sent to the chosen provider for the requested operation. The exact context depends on the feature and may include capture-derived metadata or selected payload excerpts. The provider's terms and privacy practices also apply. PacketSense does not silently send raw captures to a cloud AI provider.

Why we process information

  • to respond to pilot enquiries and provide support;
  • to verify control of an email address and deliver required service messages;
  • to issue, verify, recover and enforce a trial entitlement;
  • to activate, renew, deactivate and administer paid licences and seats;
  • to enforce one-trial eligibility and detect fraud, abuse and security incidents;
  • to operate, secure, troubleshoot and improve PacketSense and its documentation;
  • to record the legal versions and choices accepted during registration; and
  • to comply with legal obligations and establish, exercise or defend legal claims.

Service providers and disclosures

We use a limited set of providers to operate these services:

  • Cloudflare hosts and protects the website and provides Cloudflare Turnstile for abuse detection.
  • Resend delivers website contact notifications and confirmations.
  • Amazon Web Services hosts the registered-trial and paid licensing services in AWS Asia Pacific (Sydney), and Amazon SES delivers required trial-verification email.
  • A cloud AI provider selected by you or your organisation processes only context sent through an explicitly enabled cloud-AI feature.

We may also disclose limited information to professional advisers, regulators, courts, law-enforcement bodies or another party where required by law, needed to protect rights and safety, or connected with a genuine corporate transaction subject to appropriate safeguards. We do not sell packet-capture content or personal information.

Overseas handling

The registered-trial application and its DynamoDB records are configured for Sydney, Australia. Cloudflare and Resend operate global infrastructure and may process website, security and email-delivery information in the United States and other countries where they or their subprocessors operate. A cloud AI provider you select may process data in locations chosen in that provider's configuration or terms.

Privacy and data-protection rules in another country may differ from Australian law. We limit information shared with providers, use their security and contractual controls where appropriate, and assess provider access according to the service involved.

Service email and marketing choices

A verification code is a required operational message requested when you start the trial. We do not treat required email verification as marketing consent. The registration flow records service-email acknowledgement separately from the optional marketing preference.

We send promotional email only with your consent or where otherwise permitted by law. Marketing messages identify the sender and provide contact details, include a functional unsubscribe, and we honour a valid unsubscribe request within five working days. Withdrawing marketing consent does not prevent security, verification, entitlement or support messages that are necessary to provide a service you requested.

Security

We use controls appropriate to the information and service, including local-first product architecture, transport encryption, AWS-managed encryption for trial tables, pseudonymous HMAC-based email and device identifiers, short-lived verification challenges, rate limits, restricted service permissions and digitally signed trial entitlements. The verification code itself is stored as a keyed authentication value, rather than readable code text.

No system is completely secure. You should protect endpoint access and treat captures, exported reports and support material as sensitive. Please report a suspected privacy or security issue promptly to the contact below.

Retention and deletion

A verification challenge expires after ten minutes and is then scheduled for automated deletion by the service's time-to-live process; physical removal may occur after its expiry time. A verification attempt may lock earlier after repeated incorrect codes.

Trial registrations, pseudonymous uniqueness records and audit records are kept only while reasonably needed for pilot administration, entitlement proof, security, abuse prevention, support, disputes and legal obligations. We then delete or de-identify them where practicable.

Paid entitlements, activations and derived machine hashes are retained only while reasonably needed for licence delivery, renewal, deactivation, seat administration, security, support, disputes and legal obligations. They are then deleted or de-identified where practicable. Contact emails and support records are kept for the period reasonably needed to respond, maintain business records and resolve disputes. Provider logs may be retained for their documented operational periods.

Local captures, databases, reports, assistant output and logs remain on your device until you, your organisation or the operating system deletes them.

Access, correction and privacy complaints

You may ask what personal information we hold about you, request access or correction, ask us to delete information where applicable, withdraw optional marketing consent, or raise a privacy concern. We may need to verify your identity and may retain limited data where law, security, fraud prevention or legal claims require it.

Email admin@quantamq.com with enough detail for us to understand the request. We aim to acknowledge and respond within 30 days. If your access is managed by an organisation, you may also need to contact its administrator. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner or another regulator available to you.

Children

PacketSense is a professional network-analysis product for adults and organisations. It is not directed to children, and a trial applicant must be at least 18 years old. Contact us if you believe a child has provided personal information through our services.

Changes to this policy

We may update this policy when the product, providers or legal requirements change. We will publish the current effective date and version here and provide additional notice or seek a new acknowledgement where a material change requires it. A trial entitlement records the privacy version acknowledged when it was issued.

Contact

Send privacy requests or questions to admin@quantamq.com. Please do not include packet captures, credentials or other sensitive evidence in an ordinary email.

Questions about this document?

Contact QuantamQ Solutions Pty Limited at admin@quantamq.com.