Data Processing Agreement

Last updated: June 10, 2026  ·  Effective: June 10, 2026

This Data Processing Agreement (“DPA”) forms part of the QR Node Terms of Service and applies where QR Node processes personal data on behalf of a Customer in the course of providing the Service. This DPA satisfies the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) and equivalent legislation.

Need a signed DPA? Enterprise and Business plan customers can request a countersigned copy by emailing privacy@qrnode.net with the subject line “DPA Request”.

1. Definitions

  • "Controller": The Customer — the natural or legal person who determines the purposes and means of processing personal data using the Service.
  • "Processor": QR Node — processes personal data on behalf of the Controller.
  • "Data Subjects": The individuals whose personal data is processed, e.g. end-users who scan QR codes or visit bio pages created by the Customer.
  • "Personal Data": Any information relating to an identified or identifiable natural person, as defined by GDPR Article 4(1).
  • "Processing": Any operation performed on personal data, including collection, storage, retrieval, use, disclosure, or deletion.
  • "Sub-processor": Any third party engaged by QR Node to process personal data in connection with the Service.
  • "Security Incident": Any confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

2. Nature and Purpose of Processing

QR Node processes personal data solely to provide the Service as described in the Terms of Service and as instructed by the Customer. The nature, purpose, categories of data, and categories of data subjects are set out below.

Subject matterOperation of QR codes, short links, bio pages, vCards, landing pages, analytics
DurationFor the term of the Customer's subscription plus 90 days retention period post-termination
NatureCollection, storage, analysis, and deletion of scan/interaction data
PurposeTo provide QR Node features including analytics, redirects, and link management
Categories of dataIP addresses (anonymised), device type, browser, OS, approximate location (city/country), timestamp, referrer URL
Categories of data subjectsEnd-users who interact with Customer-created QR codes, short links, or pages

3. Processor Obligations

QR Node shall:

  1. Process personal data only on documented instructions from the Controller (the Terms of Service constitute such instructions), unless required to do so by applicable law.
  2. Ensure that personnel authorised to process personal data are bound by confidentiality obligations.
  3. Implement appropriate technical and organisational security measures as described in Section 5.
  4. Not engage sub-processors without prior written authorisation from the Controller. General written authorisation is granted for the sub-processors listed in Section 6 and at qrnode.net/privacy.
  5. Assist the Controller in responding to Data Subject requests for access, rectification, erasure, portability, restriction of processing, and objection.
  6. Assist the Controller in ensuring compliance with GDPR Articles 32–36 (security, breach notification, DPIAs, prior consultation).
  7. At the Controller’s choice, delete or return all personal data at the end of the Service, and delete existing copies unless applicable law requires storage.
  8. Make available to the Controller all information necessary to demonstrate compliance and allow for audits.

4. Controller Obligations

The Customer agrees to:

  1. Have a lawful basis (e.g. legitimate interest, consent) for directing QR Node to collect and process personal data through the Service.
  2. Provide any privacy notices required to data subjects about the collection of analytics data by QR Node.
  3. Notify QR Node promptly of any instructions that may conflict with applicable data protection law.

5. Security Measures

QR Node implements the following technical and organisational measures to protect personal data:

  • Encryption in transit via TLS 1.2+ for all data transfers
  • Encryption at rest using AES-256 for stored data
  • Role-based access controls; production data accessible only to authorised personnel
  • Regular automated backups with point-in-time recovery
  • Intrusion detection and DDoS protection via Cloudflare
  • Vulnerability assessment and penetration testing on a regular basis
  • Secure development practices aligned with OWASP guidelines

Full details are available at qrnode.net/security.

6. Sub-processors

The Controller grants general authorisation for QR Node to engage the following sub-processors. QR Node will notify the Controller at least 30 days before adding or replacing a sub-processor by updating the list at qrnode.net/privacy. The Controller may object within 30 days; if no agreement is reached, either party may terminate the affected Service.

Sub-processorProcessing activityLocationTransfer mechanism
Hetzner Online GmbHCloud hosting and file storageeu-central network zone, Nuremberg, GermanyEU processing + Hetzner DPA
PaddlePayment processing (Controller billing data only)UK / EUUK GDPR adequacy + SCCs
Google AnalyticsAggregated website analyticsUSAGoogle DPA + SCCs
CloudflareDDoS mitigation, CDN, bot protectionGlobal (EU nodes)Cloudflare DPA + SCCs

7. International Data Transfers

Where personal data is transferred from the EEA or UK to a third country, QR Node relies on the Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914/EU) or the UK International Data Transfer Agreement (IDTA), as applicable. Copies are available on request at privacy@qrnode.net.

8. Security Incidents

QR Node will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Security Incident affecting Controller personal data. Notification will be sent to the Controller’s account email address and will include, to the extent known: the nature of the incident, categories and approximate number of data subjects concerned, categories and approximate number of records concerned, likely consequences, and measures taken or proposed to address the incident.

9. Data Deletion and Return

Upon termination or expiry of the Service, QR Node will retain personal data for up to 90 days to allow the Controller to export data, then permanently delete it from all systems including backups. The Controller may request earlier deletion by contacting privacy@qrnode.net. Data export is available via Settings → Export Data or via the API.

10. Governing Law

This DPA is governed by the laws of the Republic of Turkey. Notwithstanding the foregoing, where the Controller is established in the EEA, the provisions of the GDPR and applicable national implementing legislation of the Controller’s member state shall prevail over any conflicting provision of this DPA to the extent required by law.

11. Contact

For DPA-related enquiries or to request a countersigned copy, contact us at privacy@qrnode.net.