Data Processing Agreement
Last updated: July 22, 2026
This Data Processing Agreement (“DPA”) forms part of and is incorporated by reference into the QR Maker Terms of Service. It applies whenever you (the “Customer”) use QR Maker to process personal data on behalf of your end users or clients — most commonly when you subscribe to a paid API plan, enterprise plan, or use QR Maker’s photo-gallery features to collect content from guests.
This page contains our standard DPA. It is legally binding on both parties as an addendum to the Terms of Service. A signed copy on our letterhead is available on request at privacy@qr-maker.io — include your organisation’s legal name, jurisdiction, and address.
1. Definitions
- Data Controller / Data Processor have the meanings given in the EU GDPR (Regulation 2016/679).
- Personal Data means any information relating to an identified or identifiable natural person that Customer submits to or processes through QR Maker.
- Subprocessor means any third-party processor engaged by QR Maker to process Personal Data on Customer’s behalf.
- Data Subject means the individual to whom the Personal Data relates (e.g. a guest scanning a QR code, a wedding guest whose face appears in a gallery photo).
2. Roles & Responsibilities
For Personal Data submitted through QR Maker in the course of providing the Service:
- The Customer is the Data Controller and determines the purposes and means of processing.
- QR Maker acts as Data Processor and processes Personal Data only on documented instructions from the Customer — namely the Customer’s use of the Service in accordance with the Terms of Service.
- The Customer represents and warrants that it has a valid legal basis (under GDPR Article 6 and, where applicable, Article 9) to process the Personal Data and to instruct QR Maker to process it.
For the AI curation pipeline described in the Privacy Policy §4b, QR Maker acts as a joint controller together with the Customer for the specific decisions we make about which AI models, prompts, and subprocessors to use. The Customer remains the sole controller for the choice to invoke the pipeline and for the outputs it consumes.
3. Scope of Processing
Subject matter: processing Personal Data in connection with QR code generation, dynamic short links, event photo galleries, AI curation, physical album fulfillment, and analytics.
Duration: for the term of the Terms of Service, plus retention windows described in the Privacy Policy §5.
Nature of processing: storage, retrieval, use, disclosure to subprocessors, deletion, and — for photo galleries with AI curation enabled — automated analysis via computer vision and image embedding models.
Categories of Personal Data: email address, name, IP address (transient, not stored), photos and short videos uploaded by hosts or guests, shipping address (for physical goods), payment metadata (via Stripe — QR Maker never handles card numbers).
Categories of Data Subjects: Customers and their employees; end-users of Customer’s applications; wedding hosts, wedding guests, and any individuals visible in guest-uploaded photographs.
4. QR Maker’s Obligations
- Process Personal Data only on Customer’s documented instructions, including with regard to transfers of Personal Data to a third country.
- Ensure that persons authorised to process Personal Data are bound by confidentiality obligations.
- Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (see Section 7).
- Assist the Customer in responding to Data Subject requests to exercise their rights, including rights of access, rectification, erasure, restriction, portability, and objection.
- Assist the Customer in ensuring compliance with obligations pursuant to GDPR Articles 32–36 (security, breach notification, DPIAs, prior consultation).
- At Customer’s choice, delete or return all Personal Data at the end of the Service, subject to legal retention obligations.
- Make available to Customer all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by Customer or a mutually agreed auditor.
5. Subprocessors
Customer authorises QR Maker to engage the subprocessors listed in the Privacy Policy §4 to provide the Service. That list is authoritative and is updated whenever we add or remove a subprocessor. QR Maker will notify Customer of any intended additions or replacements of subprocessors at least 30 days in advance, giving Customer the opportunity to object. If Customer reasonably objects, the parties will work in good faith to resolve the concern; if unresolved, Customer may terminate the affected Service with a pro-rated refund of unused subscription fees.
QR Maker imposes on each subprocessor, by written contract, the same data protection obligations as set out in this DPA.
6. International Transfers
Personal Data processed under this DPA may be transferred to or accessed from countries outside the European Economic Area, including the United States. For all such transfers, the parties rely on the following mechanisms, in this order of preference:
- An adequacy decision by the European Commission (including transfers to organisations certified under the EU-U.S. Data Privacy Framework).
- Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914) — Module Two (Controller-to-Processor) with QR Maker as the data importer, incorporated into this DPA by reference and available in unmodified form at commission.europa.eu. Docking clauses accepted.
- Supplementary measures (encryption, pseudonymisation, minimisation) where a transfer impact assessment identifies residual risk.
The UK International Data Transfer Addendum applies analogously for UK-originating transfers.
7. Security Measures
QR Maker implements the following technical and organisational measures (the “TOMs”):
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256 where the underlying storage provider supports it — currently Supabase, DigitalOcean managed databases).
- Role-based access control internally; least-privilege by default.
- Secrets managed via Kubernetes secrets; passwords hashed using industry-standard adaptive functions.
- Regular dependency and infrastructure security reviews; vulnerability patching on a defined SLA.
- Structured logging with a 30-day retention; logs redacted for known-sensitive fields (authorisation headers, session cookies).
- Backups with defined RPO/RTO for paid tiers; documented restore procedures.
- Personnel are contractually bound by confidentiality obligations and trained on data protection.
8. Personal Data Breach
QR Maker will notify Customer without undue delay — and in any event within 48 hours — after becoming aware of a Personal Data Breach affecting Customer’s Personal Data, providing at minimum: nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed to address the breach and mitigate its effects. This does not create an obligation to notify where the breach is unlikely to result in a risk to Data Subjects’ rights and freedoms.
9. Deletion & Return of Data
Upon termination of the Service, QR Maker will, at Customer’s choice made within 30 days of termination, delete or return all Personal Data to Customer, except where retention is required by applicable law (e.g. billing records for tax purposes — see Privacy Policy §5).
10. Miscellaneous
In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to data protection matters. In the event of a conflict between this DPA and the SCCs incorporated by reference, the SCCs prevail. The remaining provisions of the Terms of Service continue to apply.
This DPA is governed by the same law as the Terms of Service (Spanish law for EU/EEA customers, Delaware law for others), subject to any mandatory requirements of the customer’s local data protection law.
11. Contact & Signed Copies
For a signed copy of this DPA on our letterhead, or to negotiate customer-specific terms (typically enterprise engagements), contact privacy@qr-maker.io.
XANTICO CONSULTING SL
CIF: B26564195
C/ Hermosilla 48, 1º Dcha., 28001 Madrid, Spain