1. Data controller
Dynamic QR Pro is operated by Blue Networks Oร (registry code 11490042), Vase 5, 10155 Tallinn, Estonia. We are the data controller for the personal data described here.
Privacy contact: Reio Rajaveer - [email protected]. We have not appointed a separate Data Protection Officer (DPO); for any data processing questions, reach us at the address above.
2. What personal data we process
- โAccount data: name, email, password (hashed), and billing details (handled by Stripe - we don't store card numbers).
- โWorkspace data: workspace name, team members you invite, the QR codes you create, and the destinations you set.
- โScan metadata (about people who scan your QR codes): timestamp, device and browser type, and a rough location derived from a truncated IP address.
- โProduct usage: pages visited and actions taken in the app, to improve it.
- โCookies: see the Cookies policy.
3. What we don't collect
- โThe identity or personal details of the people who scan your QR codes.
- โThe contents of the destinations you link to.
- โYour phone number.
4. Why we process it
- โAccount & service: we use account data to create and manage your account, provide the service, and issue invoices.
- โFunctionality: we use workspace data to deliver the service - creating and managing QR codes and routing destinations.
- โAnalytics & security: we use scan metadata and product usage data for aggregate analytics, service security, and fraud prevention.
- โCommunication: we use email to send transactional messages (invoices, notifications) and, with consent, marketing messages.
5. Legal basis (GDPR)
- โPerformance of a contract - to provide the service you pay for.
- โLegitimate interest - product analytics, security, and fraud prevention.
- โConsent - marketing emails and optional cookies (analytics, ads, and website chat).
- โLegal obligation - tax, accounting, and lawful requests.
Where we rely on legitimate interest, we have carried out a legitimate-interest assessment. To review it, email [email protected].
6. Required data
Account, workspace, and billing data are needed to create your account, provide the service, and issue invoices. If you do not provide the required account or billing data, we may not be able to provide the service.
Optional cookies, website chat, and marketing messages are not required to use the service. You can refuse or withdraw consent without affecting your account.
7. Recipients and subprocessors
| Provider | Purpose | Region |
|---|
| Stripe | Payments & invoicing | EU/global |
| Amazon Web Services (AWS) | App hosting, database & object storage (S3) | EU |
| Resend | Transactional email (invoices, notifications) | US/global (SCCs) |
| Cloudflare | Marketing site, CDN, security | EU edge |
| Google Analytics | Website analytics (consent-gated) | Global |
| Meta (Pixel) | Ads measurement, when campaigns run (consent-gated) | Global |
| Crisp | Website chat (consent-gated) | EU (France) |
| CookieYes | Cookie consent management | EU |
Each operates under its own Data Processing Agreement (DPA), in line with Article 28 of the GDPR. A current DPA list is available on request.
8. Security and access to data
We apply appropriate physical, organizational, and technical safeguards: TLS encryption in transit, hashed passwords, encrypted daily backups, and production access limited to named people.
Access to personal data is restricted to named staff who need it to provide the service and customer support. See our security overview on the Trust page for more.
9. International transfers
Your data is stored in the European Union. Where a subprocessor processes data outside the EU, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
10. Retention
- โAccount data: while your account is active, plus 30 days after account closure unless a longer legal retention period applies.
- โQR codes, destinations, and workspace data: kept while your account exists, including after cancellation, so you can resubscribe and restore them. You can request account deletion.
- โScan metadata: kept while your account exists, including after cancellation, unless you request deletion or we must keep limited data for legal reasons.
- โAggregate, non-identifying analytics: retained indefinitely.
- โAccounting source documents: personal data contained in them is kept for seven years (Estonian Accounting Act).
- โPayment and legal disputes: related data is kept until the claim is satisfied or the limitation period ends.
11. Your rights
- โAccess and correction: you can access and correct your data in account settings or by emailing [email protected].
- โPortability: the right to receive your data in a machine-readable format; we respond within one month.
- โErasure: the right to request deletion; we respond within one month and specify which data we won't delete and on what legal basis (e.g. accounting obligations).
- โRestriction: the right to request restriction of processing where data is inaccurate, incomplete, or processed unlawfully.
- โObjection: the right to object to processing, including direct marketing.
- โWithdraw consent: where processing is based on consent, you can withdraw it at any time in account settings or by notifying support.
To exercise any of these rights, email [email protected].
12. Direct marketing
We use your email address to send direct marketing messages only with your consent. You can opt out via the link in the footer of any message or by emailing [email protected]. We do not carry out profiling for automated decision-making.
13. Automated decisions and profiling
We do not use your personal data for automated decisions that produce legal or similarly significant effects. We do not profile users for automated decision-making.
14. Children
Accounts are not intended for people under 18, and we don't knowingly collect account data from minors.
15. Changes
If we make material changes, we'll email account holders and post a notice here, keeping prior versions on record.
16. Dispute resolution and supervisory authority
For any questions or disputes about the processing of personal data, contact [email protected]. You also have the right to lodge a complaint with the supervisory authority: the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon - [email protected], www.aki.ee).