Data processing agreements (DPA): analysis
QR Branding API — GDPR Art. 28
| Field | Value |
|---|---|
| Controller | QR Branding (Quartzon) |
| Date | 2026-10-07 |
| Version | 3.0 |
1. AI generation: two models
1.1 QR Branding's own provider accounts
The AI designer on qr-branding.com and the managed marketplace endpoint (POST /api/qr/ai/generate-managed) use QR Branding's own API keys with Groq, Google (Gemini) and OpenAI, through an internal fallback chain. For these requests:
- QR Branding is the controller and these providers act as its processors, listed on the subprocessors page.
- Only the design prompt and the generation parameters are sent to the provider; no email, billing data, IP address or customer identifier.
1.2 BYOK (Bring Your Own Key) model
The marketplace endpoint POST /api/qr/ai/generate uses a BYOK model. This means that:
- QR Branding does not use its own accounts or API keys for these requests.
- The customer supplies their own API key (
llmApiKey) with every request and chooses the provider: OpenAI, Anthropic, Google, Mistral, Cohere, Groq, xAI, DeepSeek or Qwen, or their own OpenAI-compatible endpoint (local). - QR Branding acts as a technical intermediary that forwards the design prompt to the provider using the customer's key.
- The customer's API key is neither stored nor logged, and is discarded once the HTTP request ends.
GDPR implications
Under the BYOK model, the contractual relationship with the LLM provider is a direct one between the customer and the provider. Therefore:
- For BYOK requests, QR Branding is not the controller vis-à-vis the LLM provider.
- It is the customer who must have their own DPA with the LLM provider if they process personal data.
- QR Branding does not need DPAs with the providers for BYOK requests.
2. DPAs required by QR Branding
QR Branding needs DPAs with its direct providers (the full list is on the subprocessors page). Those relevant to the API and to AI generation are:
| Provider | Role | DPA | Status |
|---|---|---|---|
| Microsoft Azure | Hosting (Azure Functions), telemetry (Application Insights) | Online Services Terms (OST) with DPA included | ✅ In force (automatic with the Azure subscription) |
| RapidAPI | Marketplace, authentication, billing | Platform terms | ✅ In force (automatic on publishing the API) |
| Groq | AI generation with QR Branding's accounts | Provider's data processing terms | ⚠️ Pending confirmation |
| Google (Gemini) | AI generation with QR Branding's accounts | Provider's data processing terms | ⚠️ Pending confirmation |
| OpenAI | AI generation with QR Branding's accounts | Provider's data processing terms | ⚠️ Pending confirmation |
3. Customer responsibility (BYOK endpoint)
The API documentation and the Privacy Policy inform the customer that:
- When using the BYOK AI endpoint, their prompt is sent to the LLM provider they select, using their own API key.
- The relationship with the LLM provider is governed by the customer's own terms with that provider.
- If the customer processes personal data through the BYOK AI endpoint, it is their responsibility to have the appropriate agreements (DPA) in place with the LLM provider.
- QR Branding recommends that customers review the privacy policies of the LLM provider they choose.
Supported providers (reference for the customer)
| Provider | Self-service DPA | Contact |
|---|---|---|
| OpenAI | platform.openai.com → Settings → Legal | privacy@openai.com |
| Anthropic | Console → Legal | sales@anthropic.com |
| Google (Gemini) | Google Cloud Console → Security → DPA | cloud.google.com |
| Mistral AI | console.mistral.ai → Settings | privacy@mistral.ai |
| Cohere | Contact sales | privacy@cohere.com |
| Groq | Contact legal | legal@groq.com |
The BYOK endpoint also supports xAI, DeepSeek and Qwen, and the customer's own OpenAI-compatible endpoint. The customer should check the data processing terms of those providers directly.
4. Technical measures protecting customer API keys
Although we do not store customer API keys, we apply the following protective measures:
| Measure | Description |
|---|---|
| No storage | The API key is used solely for the duration of the HTTP request |
| No logging | SanitizeForLog() automatically redacts API key patterns (sk-, key-, Bearer, gsk_, AIza) |
| No persistence | No database, no cache, no writes to disk |
| TLS in transit | All communication runs over TLS 1.2+ |
| [JsonIgnore] | Sensitive model fields are excluded from serialization in responses |
Document updated on 2026-10-07. Version 2.0 only described the BYOK model; this version adds AI generation with QR Branding's own provider accounts (the site and the managed endpoint).