logo

Data Processing Agreement

Last updated: 2026-07-19

This Data Processing Agreement ("DPA") is entered into between CodeQR ("Processor") and the customer using the CodeQR service ("Controller"). It forms an integral part of the CodeQR Terms of Service and is incorporated into them by reference. This DPA applies whenever the Controller uses the service to process personal data of its own visitors and leads. A formally executed (signed) copy of this DPA is available upon request via contact@codeqr.io.

1. Definitions

"Personal data", "processing", "controller", "processor", "data subject", and "supervisory authority" have the meanings given to them in the EU General Data Protection Regulation (GDPR), the UK GDPR, or the Brazilian Lei Geral de Proteção de Dados (LGPD), whichever applies to the processing at hand.

2. Subject Matter and Duration

The Processor processes click and scan events, form and lead data, and page data on behalf of the Controller. Processing lasts for the duration of the Controller's account with the service.

3. Nature and Purpose of Processing

Processing consists of hosting, link and QR code analytics, conversion attribution, and the delivery of integrations that the Controller has enabled.

4. Categories of Personal Data and Data Subjects

The following categories of personal data may be processed:

  • Online identifiers: transient IP address (not stored for EU visitors), user agent, a derived pseudonymous identifier, and click identifiers.
  • Device and geolocation data (country and city).
  • Referrer information.
  • Data the Controller chooses to collect through forms, such as name, email address, and phone number.

Data subjects are the Controller's visitors and leads.

5. Obligations of the Processor

The Processor shall:

  • process personal data only on the Controller's documented instructions; the Controller's configuration of the service constitutes those instructions;
  • ensure that personnel authorized to process personal data are bound by confidentiality obligations;
  • implement the technical and organizational measures described in Annex II;
  • assist the Controller, taking into account the nature of the processing, in responding to data subject requests and in carrying out data protection impact assessments;
  • notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data;
  • delete or return personal data at the end of the provision of services: deleting the account removes the Controller's data, while aggregated, anonymized event data may be retained.

6. Subprocessors

The Controller grants the Processor general authorization to engage subprocessors. The current list is maintained at codeqr.io/legal/subprocessors. The Processor gives advance notice of changes to that list by updating the page and announcing the change in the changelog. The Processor imposes on each subprocessor the same data protection obligations as set out in this DPA.

7. International Transfers

Where processing involves a transfer of personal data subject to the GDPR outside the European Economic Area, the parties rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), which are incorporated into this DPA by reference. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum issued by the ICO applies. For transfers subject to the LGPD, the parties rely on contractual clauses in accordance with the LGPD.

8. Audit

Upon the Controller's reasonable request, the Processor makes available reports and documentation demonstrating compliance with this DPA.

Annex I — Description of Processing

Subject matter: processing of click and scan events, form and lead data, and page data on behalf of the Controller.

Duration: the lifetime of the Controller's account.

Nature and purpose: hosting, link and QR code analytics, conversion attribution, and delivery of integrations enabled by the Controller.

Categories of personal data: online identifiers (transient IP address — not stored for EU visitors, user agent, derived pseudonymous identifier, click identifiers), device and geolocation data (country and city), referrer information, and form data the Controller chooses to collect (name, email address, phone number).

Data subjects: the Controller's visitors and leads.

Annex II — Technical and Organizational Measures

  • Encryption in transit (TLS/HTTPS).
  • Role-based access control and least privilege within the workspace.
  • Pseudonymization of visitor identifiers through a derived hash.
  • IP addresses of EU visitors are not stored in event data.
  • Event identifiers are retained for no longer than 90 days.
  • Audit log of key workspace actions.
  • Infrastructure managed by established providers, including isolation, backups, and continuity.
  • URL security scanning and anti-abuse controls.
  • Consent management platform (CMP) on the website.

Contact

Questions about this DPA can be sent to contact@codeqr.io.