Data processing (DPA)
What qrhub processes on your behalf, why, for how long, and how the related requests are handled.
1. What this page is
This page explains what qrhub processes as a processor acting on your behalf as controller, why it is processed, how long it is kept, and which third-party services are involved.
It is not a signed contract in itself. If you need a signable version (with both parties, signature blocks and governing law), ask through the contact page and we will issue a countersignable text under your organisation’s name.
2. Scope and purpose
Data categories: account identifiers (email, name, language preference); the QR code records you create (name, type, content fields, appearance settings, folders and design templates); assets you upload; dynamic-code scan events (time, resolved country/region/city, device and operating system, and the pseudonymous identifier described in section 3); and what you submit through the contact and abuse forms.
Purposes: providing and maintaining QR code generation, resolution, landing page rendering and scan analytics; keeping the Service secure (rate limiting, anomalous traffic detection, investigating reported short links); replying to your enquiries and tickets.
Not used for: advertising profiles, cross-site tracking, or selling or sharing personal information with third parties. The Service sets no tracking cookies on the scanner’s side.
3. Security measures
Raw scanner IP addresses are not stored: a request is immediately converted to a keyed HMAC-SHA256 hash before it is written, the key is derived from a server secret and never stored alongside the data, and the hash is used only to tell whether two scans on the same day came from the same source.
Sign-in state is kept as a token in browser local storage; passwords are stored only as an irreversible derived value, never in plain text.
Operations-side actions (permission changes, content review, enforcement decisions) are recorded in an audit trail; form submissions are protected by human verification and rate limits.
Access on the operations side follows least privilege, and the admin API is authenticated separately from user data endpoints.
4. Retention and deletion
Scan detail records are kept for 90 days by default and then cleaned up by a background task according to the retention policy; that period is configurable by operations.
Daily aggregates are kept long term, but contain no IP hash and nothing that can be traced back to a single scan.
You can export your account data yourself in account settings (codes, landing pages, aggregated statistics and billing records), and delete QR codes and media you created. Closing your account starts a 7-day grace period, after which the account and its data are deleted; audit trails required by law are retained.
5. Subprocessors and transfers
The Service relies on a small number of third-party services (such as human verification and content delivery). Their purpose, processing location and notification procedure are listed on the Subprocessors page.
That page is updated before a subprocessor is added or replaced, and you can request the current list through the contact page.
6. Data subject requests
Scanners are not registered users of the Service; their requests (access, erasure) come to us through you or directly. We help once the request is verified as reasonable.
For data under your account, use the export and closure capabilities in account settings. For anything else, write through the contact page with the account email and what you need.
7. Changes
When the scope, security measures or retention periods change materially, this page is updated and the change is announced before it takes effect, in the app or by email.
Ask through the contact page if you need a historical version that records when each change took effect.
Return to the website