eqr.link
Back to eqr.link

Data Processing Agreement (DPA)

Last Updated: June 13, 2026

Note (June 13, 2026): §3.7 (On-Chain Payload Exception) was corrected — decryption keys are derived from a master secret we control, not stored in the database; erasure removes data from our operational systems but does not render on-chain ciphertext cryptographically irrecoverable.

This Data Processing Agreement ("DPA") is entered into by and between Piaxonika Software Services SINGLE MEMBER S.A., company number 179072201000, registered office: 3is Septemvriou 144, 112 51 Athens, Greece ("Processor" or "Company") and the customer entity subscribing to the Service ("Controller" or "Customer"). This DPA is incorporated into and forms part of the Terms of Service.


1. Scope, Purpose, and Definitions

  • GDPR Application: This DPA applies where and to the extent that Processor processes Personal Data on behalf of Controller in the course of providing the Service, and such processing is subject to the General Data Protection Regulation (GDPR) or other applicable data protection laws.
  • Definitions: The terms "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Supervisory Authority" have the meanings given in Article 4 of the GDPR.

2. Roles and Scope of Processing

  • Roles: The Customer is the Data Controller, and the Company is the Data Processor.
  • Subject Matter: Provision of the eqr.link QR code platform, redirect routing services, file hosting, and lead capture forms.
  • Duration of Processing: The duration of the Terms of Service plus the period until all Customer data is deleted from the Processor's systems.
  • Nature and Purpose: To route QR scans, generate analytics, host files, display lead capture forms, and collect lead submissions in accordance with the Customer's configurations.
  • Data Categories:
    • Account Data: Customer email address and Google user ID.
    • Redirect Analytics: Truncated IP hashes, country codes, User-Agent strings, and referer hostnames.
    • Hosted Files: Any personal data contained within files uploaded by the Customer.
    • Lead Submission Data: Contact details (names, emails, phone numbers, or custom fields) submitted by scanners on the Customer's lead capture forms.
  • Categories of Data Subjects: The Customer's users/employees and individuals (scanners) who scan the Customer's QR codes or access their redirect links.

3. Obligations of the Processor

The Processor agrees to:

3.1. Documented Instructions

Process Personal Data only on documented instructions from the Controller (including instructions to perform redirects, host files, and capture leads), unless required to do so by Union or Member State law.

3.2. Confidentiality

Ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

3.3. Security Measures

Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as detailed in our Security Notice. These measures include AES-256-GCM encryption of destination URLs, PASETO authentication, and SSRF network guards.

3.4. Subprocessors

  • General Authorization: Controller grants Processor a general written authorization to engage subprocessors. The current list of subprocessors is maintained at List of Subprocessors.
  • Notice of Changes: Processor will notify Controller of any intended changes concerning the addition or replacement of subprocessors at least 30 days in advance (via updates to the Subprocessors page or email notification).
  • Objection: Controller may object to a new subprocessor on data protection grounds within 14 days of notification. If the parties cannot resolve the objection, either party may terminate the Service.
  • Liability: Processor remains fully liable to Controller for the performance of the subprocessor's obligations.

3.5. Data Subject Rights

Assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Controller's obligation to respond to requests for exercising the Data Subject's rights (e.g., access, rectification, erasure).

3.6. Security Incident Notification

Notify Controller without undue delay (and in any event within 48 hours) after becoming aware of a personal data breach affecting Customer's data.

3.7. Deletion or Return of Data

At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of services, and delete existing copies unless Union or Member State law requires storage of the Personal Data.

  • On-Chain Payload Exception: Data cryptographically anchored to the Base L2 blockchain is immutable and cannot be deleted or returned. Upon erasure, Processor deletes the relevant database rows. Destination URLs are encrypted with a key Processor derives from a master secret it controls (not a key stored in the database); the encrypted payload remains publicly readable on-chain, and Processor retains the technical ability to decrypt it. Erasure therefore removes the Personal Data from Processor's operational systems but does not render the on-chain ciphertext cryptographically irrecoverable. Controllers and users should avoid embedding personal data in destination URLs.

3.8. Audits

Make available to the Controller all information necessary to demonstrate compliance with GDPR Article 28 obligations and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.


4. International Transfers

If the processing of Personal Data involves transfers outside the EEA to countries without an adequacy decision, the parties agree that the EU Standard Contractual Clauses (SCCs) (Module 2: Controller-to-Processor) are hereby incorporated by reference and form an integral part of this DPA.


5. Contact Information

For DPA-related matters, contact: support@eqr.link

eqr.link

Eternal QR codes — backend-controlled routing, per-user encryption, blockchain-backed survivability.

All systems normalv1.0.0+prod.c8be364
Product
DashboardPricingCompare plansExpired trialsUse casesChangelog
Use cases
Permanent needsRetailEventsRestaurantsAll use cases →
Resources
ArchitectureSecurity noticeAcceptable useDPARecovery key
Legal
Terms of ServicePrivacy PolicyCookie PolicyRefunds & cancellationSubprocessorsContact
© 2026 Piaxonika Software Services SINGLE MEMBER S.A. · 3is Septemvriou 144, 112 51 Athens, Greece · hello@eqr.linkprod · v1.0.0+prod.c8be364