1. Data controller
Dynamic QR Pro is operated by Blue Networks Oร (registry code 11490042), Vase 5, 10155 Tallinn, Estonia. We are the data controller for the personal data described here.
Privacy contact: Reio Rajaveer โ [email protected]. We have not appointed a separate Data Protection Officer (DPO); for any data processing questions, reach us at the address above.
2. What personal data we process
- โAccount data: name, email, password (hashed), and billing details (handled by Stripe โ we don't store card numbers).
- โWorkspace data: workspace name, team members you invite, the codes you create, and the destinations you set.
- โScan metadata (about people who scan your codes): timestamp, device and browser type, and a rough location derived from a truncated IP address.
- โProduct usage: pages visited and actions taken in the app, to improve it.
- โCookies: see the Cookies policy.
3. What we don't collect
- โThe identity or personal details of the people who scan your codes.
- โThe contents of the destinations you link to.
- โYour phone number.
4. Why we process it
- โAccount & service: we use account data to create and manage your account, provide the service, and issue invoices.
- โFunctionality: we use workspace data to deliver the service โ creating and managing codes and routing destinations.
- โAnalytics & security: we use scan metadata and product usage data for aggregate analytics, service security, and fraud prevention.
- โCommunication: we use email to send transactional messages (invoices, notifications) and, with consent, marketing messages.
5. Legal basis (GDPR)
- โPerformance of a contract โ to provide the service you pay for.
- โLegitimate interest โ product analytics, security, and fraud prevention.
- โConsent โ marketing emails and optional cookies (analytics, ads, chat).
- โLegal obligation โ tax, accounting, and lawful requests.
Where we rely on legitimate interest, we have carried out a legitimate-interest assessment. To review it, email [email protected].
6. Recipients and subprocessors
| Provider | Purpose | Region |
|---|
| Stripe | Payments & invoicing | EU/global |
| Amazon Web Services (AWS) | App hosting, database & object storage (S3) | EU |
| Resend | Transactional email (invoices, notifications) | US/global (SCCs) |
| Cloudflare | Marketing site, CDN, security | EU edge |
| Google Analytics | Website analytics (consent-gated) | Global |
| Meta (Pixel) | Ads measurement, when campaigns run (consent-gated) | Global |
| Crisp | Website live chat (consent-gated) | EU (France) |
| CookieYes | Cookie consent management | EU |
Each operates under its own Data Processing Agreement (DPA), in line with Article 28 of the GDPR. A current DPA list is available on request.
7. Security and access to data
We apply appropriate physical, organizational, and technical safeguards: TLS encryption in transit, hashed passwords, encrypted daily backups, and production access limited to named people.
Access to personal data is restricted to named staff who need it to provide the service and customer support. See our security overview on the Trust page for more.
8. International transfers
Your data is stored in the European Union. Where a subprocessor processes data outside the EU, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
9. Retention
- โAccount data: while your account is active, plus 30 days after closure.
- โScan metadata: retained while your subscription is active.
- โAggregate, non-identifying analytics: retained indefinitely.
- โAccounting source documents: personal data contained in them is kept for seven years (Estonian Accounting Act).
- โPayment and legal disputes: related data is kept until the claim is satisfied or the limitation period ends.
10. Your rights
- โAccess and correction: you can access and correct your data in account settings or by emailing [email protected].
- โPortability: the right to receive your data in a machine-readable format; we respond within one month.
- โErasure: the right to request deletion; we respond within one month and specify which data we won't delete and on what legal basis (e.g. accounting obligations).
- โRestriction: the right to request restriction of processing where data is inaccurate, incomplete, or processed unlawfully.
- โObjection: the right to object to processing, including direct marketing.
- โWithdraw consent: where processing is based on consent, you can withdraw it at any time in account settings or by notifying support.
To exercise any of these rights, email [email protected].
11. Direct marketing
We use your email address to send direct marketing messages only with your consent. You can opt out via the link in the footer of any message or by emailing [email protected]. We do not carry out profiling for automated decision-making.
12. Children
The service isn't intended for children under 16, and we don't knowingly collect their data.
13. Changes
If we make material changes, we'll email account holders and post a notice here, keeping prior versions on record.
14. Dispute resolution and supervisory authority
For any questions or disputes about the processing of personal data, contact [email protected]. You also have the right to lodge a complaint with the supervisory authority: the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon โ [email protected], www.aki.ee).