Back to Legal Documents

Data Processing Agreement

Last updated: February 1, 2026

1. Purpose

This Data Processing Agreement (“DPA”) forms part of the Terms of Service and applies where QR Breeze processes personal data on behalf of a customer in connection with the Service.

2. Roles

  • Customer is the Data Controller
  • QR Breeze is the Data Processor

QR Breeze processes personal data only on documented instructions from the Customer.

3. Scope of Processing

3.1 Types of Personal Data

May include:

  • Names, emails, and contact details
  • Menu or content data uploaded by the Customer
  • Analytics data related to QR scans (country, city, device type, timestamps)

3.2 Purpose

Processing is limited to:

  • Providing and operating the Service
  • Analytics and reporting
  • Security and abuse prevention
  • Customer support

4. Security Measures

QR Breeze implements reasonable technical and organisational measures including:

  • Encryption in transit
  • Access controls
  • Role-based permissions
  • Monitoring and logging

5. Subprocessors

QR Breeze may use subprocessors such as:

  • Cloud hosting providers
  • Payment processors
  • Email and notification services
  • Error monitoring tools

QR Breeze remains responsible for subprocessors’ compliance.

6. International Transfers

Where data is transferred outside the UK, QR Breeze ensures appropriate safeguards are in place.

7. Data Breach Notification

QR Breeze will notify the Customer without undue delay upon becoming aware of a personal data breach affecting Customer data.

8. Data Subject Rights

QR Breeze will assist the Customer, where reasonably possible, in responding to data subject requests.

9. Data Deletion

Upon termination of the Service, QR Breeze will delete or anonymise personal data within a reasonable timeframe, subject to backups and legal obligations.

10. Governing Law

This DPA is governed by the laws of England and Wales.

Have questions about this document?

Contact our team