Skip to content
QRCADO
  • Features

    • Dynamic QRChange where a printed code points, anytime
    • AnalyticsScans by time, place and device
    • Bulk & APIGenerate thousands from CSV or API
    • Design & framesColors, logo and frames to match your brand
    • Landing pagesHosted pages, no website needed
    • Custom domainServe short links on your own domain

    Popular code types

    • Website URL
    • PDF
    • vCard
    • Menu
    • Video
    • WiFi
    • App download
    • Reviews
    All 25 types
  • By industry

    • Restaurants
    • Retail
    • Events
    • Agencies
    • Education
    • Hotels

    By goal

    • Get more reviews
    • Collect leads
    • Contactless menus
    • App downloads
    • Grow social
    • Capture feedback
    • BlogGuides and notes
    • Help centerFAQs and docs
    • GuidesStep-by-step how-tos
    • GlossaryWhat is a QR code, static vs dynamic
    • Free toolsGenerator & scanner
  • Pricing
Log inStart free
Product
  • Dynamic QR
  • Analytics
  • Bulk & API
  • Design & frames
  • Landing pages
  • Custom domain
  • Website URL
  • PDF
  • vCard
  • Menu
  • Video
  • WiFi
  • App download
  • Reviews
Solutions
  • Restaurants
  • Retail
  • Events
  • Agencies
  • Education
  • Hotels
  • Get more reviews
  • Collect leads
  • Contactless menus
  • App downloads
  • Grow social
  • Capture feedback
Resources
  • Blog
  • Help center
  • Guides
  • Glossary
  • Free tools
Pricing
Log inStart free
  1. Home/
  2. Data Processing Addendum

This document is a draft and is not yet in force. It is a working template, not final or legally binding text, and it is not legal advice. Values shown as to be confirmedare awaiting review with qualified legal counsel before publication.

Data Processing Addendum

DraftEffective date pending·12 sections

On this page

  1. 1.Roles and definitions
  2. 2.Scope and subject matter
  3. 3.Processing instructions
  4. 4.Confidentiality
  5. 5.Security measures
  6. 6.Sub-processors
  7. 7.Data-subject requests
  8. 8.Personal data breach notification
  9. 9.Return and deletion of data
  10. 10.Audits
  11. 11.International transfers
  12. 12.Governing law and contact
On this page12 sections
  1. 1.Roles and definitions
  2. 2.Scope and subject matter
  3. 3.Processing instructions
  4. 4.Confidentiality
  5. 5.Security measures
  6. 6.Sub-processors
  7. 7.Data-subject requests
  8. 8.Personal data breach notification
  9. 9.Return and deletion of data
  10. 10.Audits
  11. 11.International transfers
  12. 12.Governing law and contact

This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer", "you") and to be confirmed ("Qrcado", "we", "us"), a NextFly product, and governs our processing of personal data on your behalf when you use Qrcado. It supplements our Terms of Service andPrivacy Policy. Where there is a conflict on data protection matters, this DPA prevails.

1.Roles and definitions

For personal data processed through your use of Qrcado, you act as the controller(or processor on behalf of your own customers) and Qrcado acts as the processor(or sub-processor). Terms such as "personal data", "processing", "controller", "processor", and "data subject" have the meanings given in applicable data protection law, including the GDPR.

2.Scope and subject matter

  • Subject matter: our provision of the Qrcado platform to you.
  • Duration: the term of your agreement with us, plus any wind-down period.
  • Nature and purpose: hosting QR destinations and pages, resolving scans, and recording aggregate scan analytics.
  • Types of data: account and contact data, content you attach to codes, and scan event data (timestamp, approximate IP-based location, coarse device/browser).
  • Data subjects: your personnel, your customers, and people who scan your codes.

3.Processing instructions

We will process personal data only on your documented instructions — including this DPA, your configuration of the service, and your support requests — unless required to do otherwise by law, in which case we will inform you where legally permitted. We will notify you if, in our opinion, an instruction infringes applicable data protection law.

4.Confidentiality

We ensure that personnel authorised to process personal data are bound by appropriate obligations of confidentiality and are granted access only on a need-to-know basis.

5.Security measures

We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These include encryption in transit, access controls, environment isolation, malware scanning of uploads, logging, and regular backups. A current description of our security measures is available at to be confirmed. We do not assert any specific certification in this draft; add any that apply once verified.

6.Sub-processors

You authorise us to engage sub-processors to help provide the service — for example, cloud hosting, payment processing, and email delivery. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. Our current list is available at to be confirmed. We will give you advance notice of any intended addition or replacement of a sub-processor and a reasonable opportunity to object.

7.Data-subject requests

Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights. Where a data subject contacts us directly about data we process on your behalf, we will refer them to you unless legally required to respond.

8.Personal data breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process for you, and we will provide information reasonably available to us to help you meet your own notification obligations.

9.Return and deletion of data

On termination or expiry of your agreement, we will, at your choice, delete or return the personal data we process on your behalf and delete existing copies, except where retention is required by law. Standard account data is handled as described in thePrivacy Policy.

10.Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality, scheduling, and scope limitations set out in to be confirmed.

11.International transfers

Where we transfer personal data to a country without an adequacy decision, we will rely on an appropriate transfer mechanism such as the Standard Contractual Clauses, which are incorporated by reference where applicable. Details of the mechanism we rely on are set out into be confirmed.

12.Governing law and contact

This DPA is governed by the laws of to be confirmed. For data protection matters under this DPA, contact us athello@qrcado.com. Our details:to be confirmed, to be confirmed.


Questions? Contact hello@qrcado.com.

Last updated: to be confirmed

Qrcado legal
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Data Processing Addendum
QRCADO

Dynamic QR codes you can edit, brand and track — with a hosted page worth scanning.

Create your QR — free

QR types

  • Website URL
  • PDF
  • vCard
  • Restaurant menu
  • WiFi
  • Coupon
  • Event
  • All 25 types

Product

  • All features
  • Dynamic QR
  • Analytics
  • For teams
  • Enterprise
  • API
  • Pricing

Solutions

  • Restaurants
  • Retail
  • Agencies
  • Get more reviews
  • Where to use
  • Occasions

Resources

  • Blog
  • Guides
  • Free tools
  • Print checklist
  • Glossary
  • Help center
  • Compare

Company

  • About
  • Contact
  • Terms
  • Privacy
  • DPA
  • Cookies

© 2026 Qrcado — a NextFly product.QR Code® is a registered trademark of DENSO WAVE Incorporated.