Record of processing activities (ROPA)
QR Branding API — GDPR Art. 30
| Field | Value |
|---|---|
| Controller | QR Branding (Quartzon) |
| Date | 2026-03-08 |
| Version | 1.0 |
Activity 1: QR code generation
| Field | Description |
|---|---|
| Name | Generation of customized QR codes |
| Controller | QR Branding |
| Purpose | Generating QR images (PNG/SVG/PDF/Base64) from content and configuration supplied by the user |
| Legal basis | Performance of a contract — Art. 6(1)(b) |
| Categories of data subjects | API users (developers, businesses) and contacts included in vCards |
| Categories of data | URLs, free text, WiFi credentials (SSID/password), vCard contact details (name, email, phone, address, organization), geolocation, email addresses, phone numbers |
| Recipients | None: processing is exclusively internal; the result is returned to the user |
| International transfers | No: processing on Azure (host region) |
| Erasure periods | Immediate: data is processed in memory and discarded after the HTTP response |
| Security measures | TLS 1.2+, input validation (OWASP), SSRF protection, EXIF stripping, rate limiting, RapidAPI authentication, IP anonymization in logs |
Activity 2A: AI-generated QR codes with QR Branding's provider accounts
| Field | Description |
|---|---|
| Name | QR design generation using artificial intelligence, with QR Branding's own LLM provider accounts |
| Scope | The AI designer on qr-branding.com and the managed marketplace endpoint (POST /api/qr/ai/generate-managed) |
| Controller | QR Branding |
| Purpose | Generating a QR design configuration from a natural-language prompt |
| Legal basis | Performance of a contract — Art. 6(1)(b) |
| API key model | QR Branding's own API keys. Each request goes through an internal fallback chain of providers (Groq, Google Gemini, OpenAI): if one provider fails, the next one is tried |
| Categories of data subjects | Users of the qr-branding.com site and API users |
| Categories of data | Design prompt (free text) and generation parameters (style preset, creativity, strict scannability). QR content is not sent to the LLM |
| Recipients | The LLM provider that serves the request in the fallback chain |
| Processors | Groq, Inc., Google LLC (Gemini) and OpenAI, OpCo, LLC, as listed on the subprocessors page |
| International transfers | Yes: the three providers are located in the USA. The transfer relies on each provider's data processing terms, as stated on the subprocessors page |
| Erasure periods | The prompt text is processed in memory and is not stored by QR Branding. The generated design configuration may be kept in the prompt cache for up to 30 days, under a key derived from a SHA-256 hash of the prompt and the parameters. Retention by the provider is governed by its own terms |
| Security measures | Prompt delimiters, anti-leak instructions, nullification of URL/base64 fields, HTML sanitization, output token cap on every LLM call, response size limits (1MB), API key redaction in logs (SanitizeForLog). No email, billing data, IP address or customer identifier is sent to the provider |
Activity 2B: AI-generated QR codes with the customer's own key (BYOK)
| Field | Description |
|---|---|
| Name | QR design generation using artificial intelligence, with the customer's own LLM API key |
| Scope | The marketplace endpoint POST /api/qr/ai/generate |
| Controller | QR Branding (prompt processing and rendering) |
| Purpose | Generating a QR design configuration from a natural-language prompt |
| Legal basis | Performance of a contract — Art. 6(1)(b) |
| API key model | BYOK (Bring Your Own Key): the customer supplies their own LLM provider API key (llmApiKey) with each request and chooses the provider: OpenAI, Anthropic, Google, Mistral, Cohere, Groq, xAI, DeepSeek or Qwen, or their own OpenAI-compatible endpoint (local) |
| Categories of data subjects | API users |
| Categories of data | Design prompt (free text), customer API key (transient, not stored), QR content (not sent to the LLM) |
| Recipients | The LLM provider (or the customer's own endpoint) selected by the user, using the user's own API key |
| Processors | None for this activity: QR Branding acts as a technical intermediary. The contractual relationship with the LLM provider is a direct one between the customer and the provider |
| International transfers | The transfer of data to the LLM provider is the responsibility of the customer, who maintains their own contractual relationship with the provider. QR Branding only forwards the prompt at a technical level |
| Erasure periods | The prompt text is processed in memory and is not stored. The generated design configuration may be kept in the prompt cache for up to 30 days, under a key derived from a SHA-256 hash of the prompt and the parameters. The customer's API key is neither stored nor logged |
| Security measures | Prompt delimiters, anti-leak instructions, nullification of URL/base64 fields, HTML sanitization, output token cap on every LLM call, response size limits (1MB), API key redaction in logs (SanitizeForLog) |
Activity 3: Rate limiting and abuse prevention
| Field | Description |
|---|---|
| Name | Request rate control |
| Controller | QR Branding |
| Purpose | Preventing abuse and protecting service availability and operating costs |
| Legal basis | Legitimate interest — Art. 6(1)(f) |
| Legitimate interest | Protecting the infrastructure and the availability of the service for all users |
| Categories of data subjects | All API users |
| Categories of data | RapidAPI identifier (pseudonymous), subscription identifier, IP address (anonymized) |
| Recipients | None: internal processing |
| International transfers | No |
| Erasure periods | 2 minutes (in-memory sliding window with automatic eviction) |
| Security measures | Data held in volatile memory (not persisted), IP anonymization (last octet), cap of 50,000 tracked IPs, periodic cleanup every 2 minutes |
Activity 4: Telemetry and diagnostics
| Field | Description |
|---|---|
| Name | Performance monitoring and error diagnostics |
| Controller | QR Branding |
| Purpose | Keeping the service reliable, diagnosing errors and monitoring performance |
| Legal basis | Legitimate interest — Art. 6(1)(f) |
| Legitimate interest | Ensuring operational stability and a fast response to incidents |
| Categories of data subjects | All API users |
| Categories of data | Request paths (no QR content), HTTP status codes, response times, errors (no PII), performance metrics |
| Recipients | Microsoft (Azure Application Insights) as processor |
| International transfers | Possible, depending on the configured Application Insights region |
| Erasure periods | 90 days (Application Insights default setting) |
| Security measures | PII-free error messages, API key redaction (SanitizeForLog), IP anonymization, no logging of QR content or AI prompts |
Activity 5: API authentication
| Field | Description |
|---|---|
| Name | RapidAPI authentication check |
| Controller | QR Branding (middleware), RapidAPI (platform) |
| Purpose | Validating that requests come from the authorized RapidAPI proxy |
| Legal basis | Legitimate interest — Art. 6(1)(f) |
| Categories of data subjects | All API users |
| Categories of data | X-RapidAPI-Proxy-Secret header (a server secret, not personal data) |
| Recipients | None |
| International transfers | No |
| Erasure periods | Not applicable: the secret is verified in memory and is not stored |
| Security measures | Comparison in middleware, secret stored in Azure App Settings (encrypted), never exposed in logs or responses |
Summary of processors
| Processor | Activity | DPA | Location |
|---|---|---|---|
| Microsoft Azure | Hosting, Application Insights | ✅ Standard OST/DPA | EU/US (configurable) |
| RapidAPI | Marketplace, billing, auth | ✅ Platform terms | USA |
| Groq | AI generation with QR Branding's accounts (Activity 2A) | ⚠️ Provider's data processing terms, pending confirmation | USA |
| Google (Gemini) | AI generation with QR Branding's accounts (Activity 2A) | ⚠️ Provider's data processing terms, pending confirmation | USA |
| OpenAI | AI generation with QR Branding's accounts (Activity 2A) | ⚠️ Provider's data processing terms, pending confirmation | USA |
Note on LLM providers: Groq, Google (Gemini) and OpenAI are QR Branding processors only for AI generation with QR Branding's own accounts (Activity 2A). On the BYOK endpoint (Activity 2B) no LLM provider is a QR Branding processor: the customer supplies their own API key, and the contractual relationship and the DPA with the provider they choose are the customer's direct responsibility.
Document generated on 2026-03-08. Update whenever any processing activity changes.