Skip to content

Legal

Data Processing Agreement

Updated 2026-05-24

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Juan José Camacho ("Processor") and applies whenever the Processor processes personal data on your behalf in the course of delivering the QR Branding service.

1. Parties

Controller: the natural or legal person who agreed to the Terms of Service. Processor: Juan José Camacho, registered at 04005, Almería, Spain, contact support@qr-branding.com.

2. Subject matter and duration

The Processor processes personal data solely to operate the QR Branding service: account management, QR generation, API access, billing reconciliation and customer support. Processing lasts for the duration of the Controller's account, plus the retention windows described in Section 11.

3. Nature and purpose of processing

Storage, retrieval, transmission and deletion of personal data necessary to render QR codes, deliver paid downloads, authenticate API calls, send transactional email and pay affiliate commissions.

4. Categories of data subjects and data

  • Data subjects: end users of the Controller, the Controller's employees, the Controller themselves.
  • Categories: email address, IP address, browser locale, country (derived from IP), purchase metadata, affiliate identifiers.

5. Controller instructions

The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to third countries. These Terms, the Privacy Policy and any written instructions sent to support@qr-branding.com constitute the documented instructions.

6. Confidentiality

Personnel authorised to process personal data are bound by confidentiality obligations equivalent to those in Article 28(3)(b) GDPR.

7. Security measures

The Processor implements appropriate technical and organisational measures pursuant to Article 32 GDPR, including encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access controls, audit logging, secret rotation, and regular review of supplier certifications (SOC 2 / ISO 27001 where available).

8. Sub-processors

The Controller authorises the following categories of sub-processors. The complete, named list (with legal entity and region) is published at /subprocessors and updated whenever a sub-processor changes:

  • Our Merchant of Record (EU-registered payments provider) — billing, refunds, tax remittance.
  • Our transactional email provider — delivery of receipts and account emails.
  • Our CDN + edge runtime provider — frontend hosting, asset CDN, object storage.
  • Our managed Postgres database provider (USA region) — orders and credits ledger.
  • Our managed cache + rate-limit counter provider — caching, rate limits, webhook idempotency.
  • Our serverless function host (Microsoft Azure West Europe) — engine compute and application telemetry.
  • Third-party LLM providers (invoked only when the end user explicitly opts in to AI generation) — the specific provider used per request is logged for cost reconciliation.

Each sub-processor is bound by a written agreement imposing data protection obligations equivalent to this DPA. The Processor will notify the Controller of any intended change of sub-processor with at least 30 days' notice via the /subprocessors page and allow the Controller to object on reasonable grounds.

9. International transfers

Where personal data is transferred outside the EEA, the Processor relies on the European Commission's Standard Contractual Clauses (Decision 2021/914) and applicable supplementary measures.

10. Data subject requests

The Processor assists the Controller in responding to data subject requests (access, rectification, erasure, portability, objection) without undue delay, by providing the tools and information necessary to fulfil the request.

11. Breach notification

The Processor notifies the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach, providing the information required by Article 33(3) GDPR.

12. Audit, term and termination

The Controller may, at most once per calendar year and at its own expense, audit compliance with this DPA by reviewing supplier certifications or by a mutually agreed third-party auditor under confidentiality. This DPA terminates automatically when the underlying Terms of Service end; upon termination, the Processor deletes or returns all personal data within 90 days unless retention is required by law.