This document must be reviewed by a lawyer before publication. Items in brackets must be completed.
1. Parties and purpose
This agreement (the "DPA") is entered into between the business customer of the QRTada service (the "Customer", controller) and [TO COMPLETE: first and last name], EI, a French sole trader trading as QRTada, [TO COMPLETE: address], France, SIRET [TO COMPLETE: SIRET] ("QRTada", processor).
It governs, in accordance with article 28 of Regulation (EU) 2016/679 ("GDPR"), the processing of personal data carried out by QRTada on behalf of the Customer as part of the QRTada service. It supplements the terms of sale and terms of use.
The DPA applies to every Business plan customer and, on request, to any business customer. It is accepted online from the customer account; a signed copy can be provided on request at [TO COMPLETE: privacy email].
2. Description of the processing
| Item | Description | |---|---| | Subject matter | Hosting and publishing the Customer's content, redirecting dynamic QR codes, producing scan analytics, managing workspace members | | Duration | Term of the subscription, then as long as needed for the lifetime guarantee of codes and the return of data under section 9 | | Nature of operations | Collection, recording, storage, organization, consultation, publication, aggregation, export, erasure | | Purpose | Providing the Service to the Customer according to its instructions | | Data subjects | People who scan the Customer's QR codes; people whose data appears in the Customer's content (employees on a business card, event organizers, etc.); members invited to the Customer's workspace; third parties receiving reports sent by the Customer | | Categories of data | For scans: date and time, device type, operating system, browser, language, referrer, country if provided by network infrastructure, technical fingerprint hashed with a daily key (no IP address in clear). For content: names, job titles, business contact details, photos, texts and files uploaded by the Customer. For members: email, name, role | | Sensitive data | None expected. The Customer shall not upload special categories of data (GDPR article 9) or data relating to criminal convictions |
QRTada acts as an independent controller for the Customer's account and billing, security, bot detection, abuse prevention and aggregated anonymous statistics, as described in its privacy policy.
3. Customer instructions
QRTada processes data only on the Customer's documented instructions, consisting of this DPA, the Service terms and the settings the Customer makes in the application (including through the API). QRTada immediately informs the Customer if, in its opinion, an instruction infringes the GDPR or other EU or Member State data protection law. If QRTada is required by law to process data otherwise, it informs the Customer before processing, unless the law prohibits it.
4. Confidentiality
People authorized to process the data are bound by confidentiality or a statutory duty of confidentiality. Access is limited to what is needed for the Service, support and security.
5. Security
QRTada implements the technical and organizational measures described in Annex 1, appropriate to the risk (GDPR article 32). QRTada may update them provided the overall level of protection is not reduced.
6. Sub-processors
The Customer gives general authorization for the sub-processors listed in Annex 2. QRTada notifies the Customer by email at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period; failing agreement, the Customer may terminate the Service free of charge, effective at the end of the current period. QRTada imposes on each sub-processor obligations equivalent to this DPA and remains liable to the Customer for their performance.
7. International transfers
Customer data is hosted in Germany. Any transfer outside the European Economic Area by a sub-processor relies on an adequacy decision (including the EU-US Data Privacy Framework for certified recipients) or the European Commission's standard contractual clauses.
8. Assistance
QRTada assists the Customer, through appropriate measures and insofar as possible:
- with data subject requests: the application's edit, export and deletion features allow this directly; any request received by QRTada is forwarded to the Customer without delay;
- with the security of processing;
- with data protection impact assessments and prior consultation of the supervisory authority, by providing the information QRTada holds.
Personal data breach: QRTada notifies the Customer of any personal data breach affecting it without undue delay and at the latest within 48 hours of becoming aware of it, with the information available (nature, categories and approximate number of data subjects and records, likely consequences, measures taken or proposed), supplemented as it becomes available.
9. End of processing
At the end of the Service, the Customer can export its data from the application. Data is then deleted according to the retention periods in the privacy policy, unless the law requires retention. By exception, and in line with the lifetime guarantee chosen by the Customer when subscribing, the data strictly needed for frozen codes to keep working (short address and latest destination, read-only hosted pages) is kept as long as those codes exist, unless the Customer instructs otherwise, for example by deleting its account.
10. Audits
QRTada makes available to the Customer the information needed to demonstrate compliance with this DPA. The Customer may carry out an audit, itself or through an independent auditor bound by confidentiality, at most once a year except after a confirmed breach, with 30 days' notice and without disrupting the Service. Audit costs are borne by the Customer. A written questionnaire is preferred.
11. Liability and term
Liability under this DPA is governed by the terms of sale, without prejudice to GDPR articles 82 and 83. The DPA takes effect upon acceptance and remains in force as long as QRTada processes data on the Customer's behalf. It is governed by French law.
Annex 1: security measures
- Hosting in a data center in Germany (Contabo GmbH).
- HTTPS encryption in transit; secrets (webhook keys, affiliate payout details) encrypted at rest.
- Passwords hashed with argon2; two-factor authentication available to every user.
- Workspace isolation and role checks enforced server-side on every request.
- Visitor IP addresses never stored in clear: fingerprint hashed with a daily key.
- Uploaded files checked (real file type, SVG sanitizing, rejection of active or encrypted PDFs) and image metadata removed.
- Logging of sensitive actions (permissions, billing, admin actions, impersonation).
- Encrypted daily backups stored off the main server, 30-day retention, monthly restore test.
- Automatic security updates, firewall, key-only administrative access.
- No personal data or secrets in application logs.
Annex 2: sub-processors
| Sub-processor | Service | Location | |---|---|---| | Contabo GmbH, Aschauer Straße 32a, 81549 Munich, Germany | infrastructure hosting | Germany (EU) | | [TO COMPLETE: Brevo (Sendinblue SAS) or SMTP provider name] | sending emails (invitations, reports) | [TO COMPLETE: location, EU expected] | | [TO COMPLETE: encrypted off-site backup provider] | backups | [TO COMPLETE: location, EU expected] |