Last updated: June 10, 2026 · Effective: June 10, 2026
This Data Processing Agreement (“DPA”) forms part of the QR Node Terms of Service and applies where QR Node processes personal data on behalf of a Customer in the course of providing the Service. This DPA satisfies the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) and equivalent legislation.
Need a signed DPA? Enterprise and Business plan customers can request a countersigned copy by emailing privacy@qrnode.net with the subject line “DPA Request”.
QR Node processes personal data solely to provide the Service as described in the Terms of Service and as instructed by the Customer. The nature, purpose, categories of data, and categories of data subjects are set out below.
| Subject matter | Operation of QR codes, short links, bio pages, vCards, landing pages, analytics |
| Duration | For the term of the Customer's subscription plus 90 days retention period post-termination |
| Nature | Collection, storage, analysis, and deletion of scan/interaction data |
| Purpose | To provide QR Node features including analytics, redirects, and link management |
| Categories of data | IP addresses (anonymised), device type, browser, OS, approximate location (city/country), timestamp, referrer URL |
| Categories of data subjects | End-users who interact with Customer-created QR codes, short links, or pages |
QR Node shall:
The Customer agrees to:
QR Node implements the following technical and organisational measures to protect personal data:
Full details are available at qrnode.net/security.
The Controller grants general authorisation for QR Node to engage the following sub-processors. QR Node will notify the Controller at least 30 days before adding or replacing a sub-processor by updating the list at qrnode.net/privacy. The Controller may object within 30 days; if no agreement is reached, either party may terminate the affected Service.
| Sub-processor | Processing activity | Location | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Cloud hosting and file storage | eu-central network zone, Nuremberg, Germany | EU processing + Hetzner DPA |
| Paddle | Payment processing (Controller billing data only) | UK / EU | UK GDPR adequacy + SCCs |
| Google Analytics | Aggregated website analytics | USA | Google DPA + SCCs |
| Cloudflare | DDoS mitigation, CDN, bot protection | Global (EU nodes) | Cloudflare DPA + SCCs |
Where personal data is transferred from the EEA or UK to a third country, QR Node relies on the Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914/EU) or the UK International Data Transfer Agreement (IDTA), as applicable. Copies are available on request at privacy@qrnode.net.
QR Node will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Security Incident affecting Controller personal data. Notification will be sent to the Controller’s account email address and will include, to the extent known: the nature of the incident, categories and approximate number of data subjects concerned, categories and approximate number of records concerned, likely consequences, and measures taken or proposed to address the incident.
Upon termination or expiry of the Service, QR Node will retain personal data for up to 90 days to allow the Controller to export data, then permanently delete it from all systems including backups. The Controller may request earlier deletion by contacting privacy@qrnode.net. Data export is available via Settings → Export Data or via the API.
This DPA is governed by the laws of the Republic of Turkey. Notwithstanding the foregoing, where the Controller is established in the EEA, the provisions of the GDPR and applicable national implementing legislation of the Controller’s member state shall prevail over any conflicting provision of this DPA to the extent required by law.
For DPA-related enquiries or to request a countersigned copy, contact us at privacy@qrnode.net.