Skip to content

Record of processing activities (ROPA)

QR Branding API — GDPR Art. 30

FieldValue
ControllerQR Branding (Quartzon)
Date2026-03-08
Version1.0

Activity 1: QR code generation

FieldDescription
NameGeneration of customized QR codes
ControllerQR Branding
PurposeGenerating QR images (PNG/SVG/PDF/Base64) from content and configuration supplied by the user
Legal basisPerformance of a contract — Art. 6(1)(b)
Categories of data subjectsAPI users (developers, businesses) and contacts included in vCards
Categories of dataURLs, free text, WiFi credentials (SSID/password), vCard contact details (name, email, phone, address, organization), geolocation, email addresses, phone numbers
RecipientsNone: processing is exclusively internal; the result is returned to the user
International transfersNo: processing on Azure (host region)
Erasure periodsImmediate: data is processed in memory and discarded after the HTTP response
Security measuresTLS 1.2+, input validation (OWASP), SSRF protection, EXIF stripping, rate limiting, RapidAPI authentication, IP anonymization in logs

Activity 2A: AI-generated QR codes with QR Branding's provider accounts

FieldDescription
NameQR design generation using artificial intelligence, with QR Branding's own LLM provider accounts
ScopeThe AI designer on qr-branding.com and the managed marketplace endpoint (POST /api/qr/ai/generate-managed)
ControllerQR Branding
PurposeGenerating a QR design configuration from a natural-language prompt
Legal basisPerformance of a contract — Art. 6(1)(b)
API key modelQR Branding's own API keys. Each request goes through an internal fallback chain of providers (Groq, Google Gemini, OpenAI): if one provider fails, the next one is tried
Categories of data subjectsUsers of the qr-branding.com site and API users
Categories of dataDesign prompt (free text) and generation parameters (style preset, creativity, strict scannability). QR content is not sent to the LLM
RecipientsThe LLM provider that serves the request in the fallback chain
ProcessorsGroq, Inc., Google LLC (Gemini) and OpenAI, OpCo, LLC, as listed on the subprocessors page
International transfersYes: the three providers are located in the USA. The transfer relies on each provider's data processing terms, as stated on the subprocessors page
Erasure periodsThe prompt text is processed in memory and is not stored by QR Branding. The generated design configuration may be kept in the prompt cache for up to 30 days, under a key derived from a SHA-256 hash of the prompt and the parameters. Retention by the provider is governed by its own terms
Security measuresPrompt delimiters, anti-leak instructions, nullification of URL/base64 fields, HTML sanitization, output token cap on every LLM call, response size limits (1MB), API key redaction in logs (SanitizeForLog). No email, billing data, IP address or customer identifier is sent to the provider

Activity 2B: AI-generated QR codes with the customer's own key (BYOK)

FieldDescription
NameQR design generation using artificial intelligence, with the customer's own LLM API key
ScopeThe marketplace endpoint POST /api/qr/ai/generate
ControllerQR Branding (prompt processing and rendering)
PurposeGenerating a QR design configuration from a natural-language prompt
Legal basisPerformance of a contract — Art. 6(1)(b)
API key modelBYOK (Bring Your Own Key): the customer supplies their own LLM provider API key (llmApiKey) with each request and chooses the provider: OpenAI, Anthropic, Google, Mistral, Cohere, Groq, xAI, DeepSeek or Qwen, or their own OpenAI-compatible endpoint (local)
Categories of data subjectsAPI users
Categories of dataDesign prompt (free text), customer API key (transient, not stored), QR content (not sent to the LLM)
RecipientsThe LLM provider (or the customer's own endpoint) selected by the user, using the user's own API key
ProcessorsNone for this activity: QR Branding acts as a technical intermediary. The contractual relationship with the LLM provider is a direct one between the customer and the provider
International transfersThe transfer of data to the LLM provider is the responsibility of the customer, who maintains their own contractual relationship with the provider. QR Branding only forwards the prompt at a technical level
Erasure periodsThe prompt text is processed in memory and is not stored. The generated design configuration may be kept in the prompt cache for up to 30 days, under a key derived from a SHA-256 hash of the prompt and the parameters. The customer's API key is neither stored nor logged
Security measuresPrompt delimiters, anti-leak instructions, nullification of URL/base64 fields, HTML sanitization, output token cap on every LLM call, response size limits (1MB), API key redaction in logs (SanitizeForLog)

Activity 3: Rate limiting and abuse prevention

FieldDescription
NameRequest rate control
ControllerQR Branding
PurposePreventing abuse and protecting service availability and operating costs
Legal basisLegitimate interest — Art. 6(1)(f)
Legitimate interestProtecting the infrastructure and the availability of the service for all users
Categories of data subjectsAll API users
Categories of dataRapidAPI identifier (pseudonymous), subscription identifier, IP address (anonymized)
RecipientsNone: internal processing
International transfersNo
Erasure periods2 minutes (in-memory sliding window with automatic eviction)
Security measuresData held in volatile memory (not persisted), IP anonymization (last octet), cap of 50,000 tracked IPs, periodic cleanup every 2 minutes

Activity 4: Telemetry and diagnostics

FieldDescription
NamePerformance monitoring and error diagnostics
ControllerQR Branding
PurposeKeeping the service reliable, diagnosing errors and monitoring performance
Legal basisLegitimate interest — Art. 6(1)(f)
Legitimate interestEnsuring operational stability and a fast response to incidents
Categories of data subjectsAll API users
Categories of dataRequest paths (no QR content), HTTP status codes, response times, errors (no PII), performance metrics
RecipientsMicrosoft (Azure Application Insights) as processor
International transfersPossible, depending on the configured Application Insights region
Erasure periods90 days (Application Insights default setting)
Security measuresPII-free error messages, API key redaction (SanitizeForLog), IP anonymization, no logging of QR content or AI prompts

Activity 5: API authentication

FieldDescription
NameRapidAPI authentication check
ControllerQR Branding (middleware), RapidAPI (platform)
PurposeValidating that requests come from the authorized RapidAPI proxy
Legal basisLegitimate interest — Art. 6(1)(f)
Categories of data subjectsAll API users
Categories of dataX-RapidAPI-Proxy-Secret header (a server secret, not personal data)
RecipientsNone
International transfersNo
Erasure periodsNot applicable: the secret is verified in memory and is not stored
Security measuresComparison in middleware, secret stored in Azure App Settings (encrypted), never exposed in logs or responses

Summary of processors

ProcessorActivityDPALocation
Microsoft AzureHosting, Application Insights✅ Standard OST/DPAEU/US (configurable)
RapidAPIMarketplace, billing, auth✅ Platform termsUSA
GroqAI generation with QR Branding's accounts (Activity 2A)⚠️ Provider's data processing terms, pending confirmationUSA
Google (Gemini)AI generation with QR Branding's accounts (Activity 2A)⚠️ Provider's data processing terms, pending confirmationUSA
OpenAIAI generation with QR Branding's accounts (Activity 2A)⚠️ Provider's data processing terms, pending confirmationUSA

Note on LLM providers: Groq, Google (Gemini) and OpenAI are QR Branding processors only for AI generation with QR Branding's own accounts (Activity 2A). On the BYOK endpoint (Activity 2B) no LLM provider is a QR Branding processor: the customer supplies their own API key, and the contractual relationship and the DPA with the provider they choose are the customer's direct responsibility.


Document generated on 2026-03-08. Update whenever any processing activity changes.