This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer", "you") and to be confirmed ("Qrcado", "we", "us"), a NextFly product, and governs our processing of personal data on your behalf when you use Qrcado. It supplements our Terms of Service andPrivacy Policy. Where there is a conflict on data protection matters, this DPA prevails.
Roles and definitions
For personal data processed through your use of Qrcado, you act as the controller(or processor on behalf of your own customers) and Qrcado acts as the processor(or sub-processor). Terms such as "personal data", "processing", "controller", "processor", and "data subject" have the meanings given in applicable data protection law, including the GDPR.
Scope and subject matter
- Subject matter: our provision of the Qrcado platform to you.
- Duration: the term of your agreement with us, plus any wind-down period.
- Nature and purpose: hosting QR destinations and pages, resolving scans, and recording aggregate scan analytics.
- Types of data: account and contact data, content you attach to codes, and scan event data (timestamp, approximate IP-based location, coarse device/browser).
- Data subjects: your personnel, your customers, and people who scan your codes.
Processing instructions
We will process personal data only on your documented instructions — including this DPA, your configuration of the service, and your support requests — unless required to do otherwise by law, in which case we will inform you where legally permitted. We will notify you if, in our opinion, an instruction infringes applicable data protection law.
Confidentiality
We ensure that personnel authorised to process personal data are bound by appropriate obligations of confidentiality and are granted access only on a need-to-know basis.
Security measures
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These include encryption in transit, access controls, environment isolation, malware scanning of uploads, logging, and regular backups. A current description of our security measures is available at to be confirmed. We do not assert any specific certification in this draft; add any that apply once verified.
Sub-processors
You authorise us to engage sub-processors to help provide the service — for example, cloud hosting, payment processing, and email delivery. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. Our current list is available at to be confirmed. We will give you advance notice of any intended addition or replacement of a sub-processor and a reasonable opportunity to object.
Data-subject requests
Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights. Where a data subject contacts us directly about data we process on your behalf, we will refer them to you unless legally required to respond.
Personal data breach notification
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process for you, and we will provide information reasonably available to us to help you meet your own notification obligations.
Return and deletion of data
On termination or expiry of your agreement, we will, at your choice, delete or return the personal data we process on your behalf and delete existing copies, except where retention is required by law. Standard account data is handled as described in thePrivacy Policy.
Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality, scheduling, and scope limitations set out in to be confirmed.
International transfers
Where we transfer personal data to a country without an adequacy decision, we will rely on an appropriate transfer mechanism such as the Standard Contractual Clauses, which are incorporated by reference where applicable. Details of the mechanism we rely on are set out into be confirmed.
Governing law and contact
This DPA is governed by the laws of to be confirmed. For data protection matters under this DPA, contact us athello@qrcado.com. Our details:to be confirmed, to be confirmed.
Questions? Contact hello@qrcado.com.
Last updated: to be confirmed