Data Processing Addendum
Last updated on August 20, 2026.
This Data Processing Addendum ("DPA") forms part of the GeoQR Terms of Service or another agreement between Dueoptics ("GeoQR") and the customer identified in that agreement ("Customer"). It applies where GeoQR processes Customer Personal Data on Customer's behalf in connection with the Service.
Capitalized terms not defined here have the meanings given in the Terms of Service. This DPA supplements, and does not replace, GeoQR's Privacy Policy, which describes processing for which GeoQR acts as controller.
"Applicable Data Protection Law" means the GDPR and any other privacy or data-protection law that applies to processing under this DPA. "Customer Personal Data" means personal data contained in Customer Content or otherwise processed by GeoQR on Customer's behalf under the agreement, excluding information for which GeoQR acts as controller. "Controller," "processor," "data subject," "personal data," and "processing" have the meanings given by Applicable Data Protection Law.
1. Roles and Scope
For Customer Personal Data, Customer is the controller and GeoQR is the processor, except where applicable law assigns different roles. Customer determines the purposes and essential means of processing and is responsible for the lawfulness of its instructions, Customer Content, public resolver publication, linked resources, and use of analytics.
GeoQR acts as an independent controller for account administration, billing, fraud and security operations, service telemetry, support administration, legal compliance, and abuse-report and enforcement records where GeoQR determines the purposes and means of processing.
2. Customer Instructions
GeoQR will process Customer Personal Data only on Customer's documented instructions, including the agreement, Customer's use and configuration of the Service, and other written instructions agreed by the parties, unless Union or Member State law requires otherwise. Where legally permitted, GeoQR will inform Customer before processing required by law.
GeoQR will promptly inform Customer if, in GeoQR's opinion, an instruction infringes applicable data-protection law. GeoQR may suspend the affected processing while the parties address the instruction.
3. Processing Details
- Subject matter: hosting and operating Customer's QR campaigns, redirects, domains, media, GS1 Digital Link resolver configurations, public resolver responses, exports, analytics, and related support.
- Duration: the agreement term, the applicable 30-day ordinary-cancellation export and handoff window, and the limited period needed for deletion, return, backup rotation, security, or legal obligations.
- Nature and purpose: collection, organization, storage, retrieval, transmission, public resolver publication at Customer's instruction, routing, aggregation, analysis, export, restriction, deletion, and technical support necessary to provide and secure the Service.
- Data subjects: Customer personnel and workspace members; people who scan or otherwise interact with Customer's QR codes and resolvers; and individuals identified in Customer Content or linked resource metadata.
- Personal-data categories: account and workspace references; Customer Content and destination data; custom-domain data; public GS1 identifiers, resource metadata, linksets, and destinations where they relate to a person; support information; and resolver or scan analytics consisting of time, QR and workspace references, country-level location, request and response category, and coarse client category.
The current resolver and scan-analytics pipeline does not store raw IP addresses or raw User-Agent strings in scan events, assign persistent device identifiers, perform cross-request visitor deduplication, or produce unique-visitor claims. Customer must not submit special-category personal data, criminal-conviction data, government identifiers, or other highly sensitive personal data unless GeoQR has expressly agreed in writing that the Service is suitable for that processing.
4. Confidentiality and Personnel
GeoQR ensures that people authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only as needed for their responsibilities. GeoQR remains responsible for its personnel's compliance with this DPA.
5. Security
Taking account of the state of the art, implementation costs, processing nature and risk, GeoQR maintains technical and organizational measures designed to provide security appropriate to the risk. These measures include, as applicable:
- encryption in transit and provider-managed encryption at rest;
- role-based access controls, authentication, workspace authorization, and least-privilege administration;
- logical tenant separation, input validation, redirect safety controls, and secrets management;
- availability, backup, recovery, monitoring, incident response, and change-management practices appropriate to the Service; and
- privacy-minimized resolver analytics and operational logs that exclude public identifiers, domains, destinations, IP addresses, User-Agent strings, report evidence, and free-text reasons where those values are not needed for the event's purpose.
6. Subprocessors
Customer gives GeoQR general written authorization to appoint subprocessors for the Service. The current subprocessors, their processing purposes, data categories, and location information are listed on the GeoQR Subprocessors page.
GeoQR will impose data-protection obligations on each subprocessor that are no less protective in substance than the obligations applicable to GeoQR under this DPA. GeoQR remains responsible for each subprocessor's performance of those obligations.
GeoQR will provide at least 30 days' prior notice to the Customer account contact before an addition or replacement of a subprocessor that processes Customer Personal Data. If urgent security or legal circumstances make advance notice impossible, GeoQR will provide notice as soon as legally and practically possible. Customer may object on reasonable data-protection grounds. The parties will work in good faith on a reasonable solution; if none is available, Customer may terminate the affected Service without penalty for the unused prepaid period.
7. International Transfers
GeoQR will not transfer Customer Personal Data outside the European Economic Area except on Customer's instructions or through a lawful transfer mechanism. Where a recipient is not covered by an applicable adequacy decision, GeoQR will enter into the applicable European Commission Standard Contractual Clauses with that recipient or use another valid safeguard, and will apply supplementary measures appropriate to the transfer risk.
8. Assistance and Data-Subject Requests
Taking account of the nature of processing and information available, GeoQR will reasonably assist Customer with data-subject requests, security obligations, breach notifications, data-protection impact assessments, and prior consultation duties. If GeoQR receives a request relating to Customer Personal Data, GeoQR will direct the requester to Customer unless legally prohibited and will not respond on Customer's behalf without authorization.
9. Personal-Data Breaches
GeoQR will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. The notice will include information reasonably available to GeoQR about the nature and extent of the breach, likely consequences, mitigation, and a contact for follow-up. GeoQR's notice is not an admission of fault or liability.
10. Return, Export, and Deletion
During active service and the applicable transition window, Customer may export supported Customer Content and GS1 resolver configurations using the Service's documented machine-readable export. Customer-owned domains remain under Customer's control and may be moved by changing DNS. GeoQR-owned resolver URLs are not URL-portable.
Upon termination, GeoQR will delete or return Customer Personal Data at Customer's choice after the applicable 30-day ordinary-cancellation export and handoff window, unless applicable law requires storage. Data may remain in isolated backups until overwritten through the ordinary backup cycle, during which it remains protected and is not used for other purposes. GeoQR may retain data it processes as controller in accordance with the Privacy Policy and applicable law.
11. Information and Audits
GeoQR will make information reasonably necessary to demonstrate compliance with this DPA available to Customer and allow audits and inspections required by Applicable Data Protection Law. Ordinarily, one remote audit per calendar year is sufficient. Additional or on-site review may be requested where remote evidence is insufficient, a personal-data breach or material compliance concern justifies it, or a supervisory authority or applicable law requires it. Audits must protect other customers' information, security, confidential information, and service continuity. Customer bears its audit costs unless the audit identifies a material breach of this DPA by GeoQR.
12. Liability, Precedence, and Changes
The agreement's liability limitations apply to this DPA to the extent permitted by law. If this DPA conflicts with the agreement on processing of Customer Personal Data, this DPA controls. If the Standard Contractual Clauses apply and conflict with this DPA, those clauses control.
GeoQR may update this DPA where reasonably necessary to reflect changes in law, processing, or the Service. GeoQR will provide notice of a material reduction in protection. An update will not materially reduce the protection of Customer Personal Data during a current subscription without a lawful basis or Customer's agreement.
13. Contact
Questions, instructions, objections, and audit requests under this DPA may be sent to info@geoqr.io or to Dueoptics, Vindingvej 34, 7100 Vejle, Denmark.