Privacy Policy

Last updated: 15 January 2026

This Privacy Policy explains how QuantumAdvisor d.o.o. ("we", "our", or "us") collects, uses, and protects your personal information when you use our website and services. We are committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

Data Controller Information

QuantumAdvisor d.o.o. is the data controller responsible for your personal data. Our contact details are:

Data We Collect

The data we collect includes information you provide directly to us and information collected automatically when you use our website. Our data collection practices are designed to provide you with the best possible service whilst respecting your privacy rights.

Information You Provide to Us

  • Contact Information: Name, email address, phone number, company name, and postal address when you contact us or request our services
  • Professional Information: Business details, industry sector, and specific risk management requirements when you enquire about our services
  • Communication Records: Content of emails, messages, and other communications you send to us
  • Service Information: Details about the hedging strategies and risk management services you are interested in or have engaged us to provide

Information Collected Automatically

  • Website Usage Data: Pages visited, time spent on our website, referring websites, and general geographic location
  • Technical Information: IP address, browser type and version, device information, and operating system
  • Cookies and Tracking Technologies: Information collected through cookies and similar technologies as detailed in our Cookie Policy

How We Use Your Information

We use your personal data for legitimate business purposes and only where we have a lawful basis to do so. Our use of your data helps us provide professional hedging strategies and risk management services tailored to your specific needs.

Service Provision

  • Responding to your enquiries and providing information about our services
  • Conducting risk assessments and developing customised hedging strategies
  • Delivering professional advisory services and ongoing risk management support
  • Maintaining client relationships and providing customer support

Legal and Regulatory Compliance

  • Complying with EU financial services regulations and reporting requirements
  • Maintaining records as required by applicable laws and professional standards
  • Preventing fraud and ensuring the security of our services

Business Operations

  • Improving our website functionality and user experience
  • Analysing website usage to enhance our services
  • Sending relevant information about our services and industry developments

Cookies and Tracking Technologies

We may use cookies and tracking technologies for analytics, advertising, and remarketing purposes, including Google Ads. These technologies help us measure campaign effectiveness, deliver relevant advertisements, and improve our services. You can manage your cookie preferences at any time through our cookie consent banner.

For detailed information about the cookies we use and how to control them, please see our Cookie Policy.

Legal Basis for Processing

Under GDPR, we process your personal data based on the following lawful bases:

  • Contract: Processing necessary for the performance of a contract with you or to take steps at your request before entering into a contract
  • Legitimate Interests: Processing necessary for our legitimate business interests, such as improving our services and preventing fraud
  • Legal Obligation: Processing necessary to comply with our legal obligations under EU financial services regulations
  • Consent: Where you have given explicit consent for specific processing activities, such as marketing communications

Data Sharing and Disclosure

We do not sell, trade, or otherwise transfer your personal data to third parties without your consent, except as described in this policy. We may share your information in the following circumstances:

  • Service Providers: With trusted third-party service providers who assist us in operating our website and providing our services
  • Legal Requirements: When required by law, regulation, or legal process
  • Business Transfers: In connection with any merger, sale of company assets, or acquisition of all or a portion of our business
  • Professional Advisors: With lawyers, accountants, and other professional advisors when necessary for business purposes

Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, comply with our legal obligations, and protect our legitimate business interests. Our data retention periods are determined based on:

  • The nature and sensitivity of the personal data
  • Legal and regulatory requirements applicable to financial services
  • The purposes for which we process your personal data
  • Whether we can achieve those purposes through other means

Generally, we retain client information for a minimum of seven years after the end of our business relationship, in accordance with financial services regulations. Marketing data is retained until you withdraw your consent or for a maximum of three years from your last interaction with us.

Your Rights

Under GDPR and applicable data protection laws, you have the following rights regarding your personal data:

  • Right of Access: You can request a copy of the personal data we hold about you
  • Right to Rectification: You can ask us to correct inaccurate or incomplete personal data
  • Right to Erasure: You can request deletion of your personal data in certain circumstances
  • Right to Restrict Processing: You can ask us to limit how we use your personal data
  • Right to Data Portability: You can request a copy of your personal data in a structured, machine-readable format
  • Right to Object: You can object to processing based on legitimate interests or for direct marketing purposes
  • Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time

Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. Our security measures include:

  • Encryption of data in transit and at rest
  • Regular security assessments and updates
  • Access controls and staff training on data protection
  • Secure hosting and backup procedures

International Data Transfers

As we operate primarily within the European Union, your personal data is generally processed within the EU/EEA. If we need to transfer your data outside the EU/EEA, we ensure appropriate safeguards are in place, such as adequacy decisions or standard contractual clauses approved by the European Commission.

Contact Us

If you have any questions about this Privacy Policy, wish to exercise your rights, or have concerns about how we handle your personal data, please contact us:

Supervisory Authority

You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with data protection laws. In Slovenia, the supervisory authority is the Information Commissioner (Informacijski pooblaščenec).

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by posting the updated policy on our website and updating the "Last updated" date. We encourage you to review this policy periodically to stay informed about how we protect your information.

Note: This Privacy Policy applies to personal data collected through our website and in the course of providing our professional services. For specific questions about data processing in relation to our hedging strategies and risk management services, please contact us directly.