Skip to content

Data processing agreements (DPA): analysis

QR Branding API — GDPR Art. 28

FieldValue
ControllerQR Branding (Quartzon)
Date2026-10-07
Version3.0

1. AI generation: two models

1.1 QR Branding's own provider accounts

The AI designer on qr-branding.com and the managed marketplace endpoint (POST /api/qr/ai/generate-managed) use QR Branding's own API keys with Groq, Google (Gemini) and OpenAI, through an internal fallback chain. For these requests:

  • QR Branding is the controller and these providers act as its processors, listed on the subprocessors page.
  • Only the design prompt and the generation parameters are sent to the provider; no email, billing data, IP address or customer identifier.

1.2 BYOK (Bring Your Own Key) model

The marketplace endpoint POST /api/qr/ai/generate uses a BYOK model. This means that:

  • QR Branding does not use its own accounts or API keys for these requests.
  • The customer supplies their own API key (llmApiKey) with every request and chooses the provider: OpenAI, Anthropic, Google, Mistral, Cohere, Groq, xAI, DeepSeek or Qwen, or their own OpenAI-compatible endpoint (local).
  • QR Branding acts as a technical intermediary that forwards the design prompt to the provider using the customer's key.
  • The customer's API key is neither stored nor logged, and is discarded once the HTTP request ends.

GDPR implications

Under the BYOK model, the contractual relationship with the LLM provider is a direct one between the customer and the provider. Therefore:

  • For BYOK requests, QR Branding is not the controller vis-à-vis the LLM provider.
  • It is the customer who must have their own DPA with the LLM provider if they process personal data.
  • QR Branding does not need DPAs with the providers for BYOK requests.

2. DPAs required by QR Branding

QR Branding needs DPAs with its direct providers (the full list is on the subprocessors page). Those relevant to the API and to AI generation are:

ProviderRoleDPAStatus
Microsoft AzureHosting (Azure Functions), telemetry (Application Insights)Online Services Terms (OST) with DPA included✅ In force (automatic with the Azure subscription)
RapidAPIMarketplace, authentication, billingPlatform terms✅ In force (automatic on publishing the API)
GroqAI generation with QR Branding's accountsProvider's data processing terms⚠️ Pending confirmation
Google (Gemini)AI generation with QR Branding's accountsProvider's data processing terms⚠️ Pending confirmation
OpenAIAI generation with QR Branding's accountsProvider's data processing terms⚠️ Pending confirmation

3. Customer responsibility (BYOK endpoint)

The API documentation and the Privacy Policy inform the customer that:

  1. When using the BYOK AI endpoint, their prompt is sent to the LLM provider they select, using their own API key.
  2. The relationship with the LLM provider is governed by the customer's own terms with that provider.
  3. If the customer processes personal data through the BYOK AI endpoint, it is their responsibility to have the appropriate agreements (DPA) in place with the LLM provider.
  4. QR Branding recommends that customers review the privacy policies of the LLM provider they choose.

Supported providers (reference for the customer)

ProviderSelf-service DPAContact
OpenAIplatform.openai.com → Settings → Legalprivacy@openai.com
AnthropicConsole → Legalsales@anthropic.com
Google (Gemini)Google Cloud Console → Security → DPAcloud.google.com
Mistral AIconsole.mistral.ai → Settingsprivacy@mistral.ai
CohereContact salesprivacy@cohere.com
GroqContact legallegal@groq.com

The BYOK endpoint also supports xAI, DeepSeek and Qwen, and the customer's own OpenAI-compatible endpoint. The customer should check the data processing terms of those providers directly.


4. Technical measures protecting customer API keys

Although we do not store customer API keys, we apply the following protective measures:

MeasureDescription
No storageThe API key is used solely for the duration of the HTTP request
No loggingSanitizeForLog() automatically redacts API key patterns (sk-, key-, Bearer, gsk_, AIza)
No persistenceNo database, no cache, no writes to disk
TLS in transitAll communication runs over TLS 1.2+
[JsonIgnore]Sensitive model fields are excluded from serialization in responses

Document updated on 2026-10-07. Version 2.0 only described the BYOK model; this version adds AI generation with QR Branding's own provider accounts (the site and the managed endpoint).