Data Processing Agreement (DPA)
Last Updated: August 17, 2026
Note (August 17, 2026): This DPA declared itself part of the Terms of Service, and the Terms said nothing about it. A document cannot incorporate itself into another one, so a Controller reading both had no way to tell whether this Agreement bound anybody, and no way to enter into it if it did. Section 2 of the Terms of Service now incorporates this DPA, and the new §5 says how a Controller accepts it — by using the Service under those Terms, which is the electronic written form Article 28(9) allows — and where to write for a signed copy, since there is no signing flow in the app to send anyone to. §3.4 also now names where processing physically happens, because "the current list of subprocessors" was the only answer this document gave to a question a Controller has to answer in its own records.
Note (August 13, 2026): §2 now lists the on-chain anchored record as a category of Personal Data in its own right and names Backblaze as the location of hosted files. §3.7 was extended to state exactly which two values are written on-chain, that re-anchoring leaves the earlier ciphertext in the chain's history, and that encryption is not anonymisation. Processor's data protection impact assessment for that processing is referenced there.
Note (June 13, 2026): §3.7 (On-Chain Payload Exception) was corrected — decryption keys are derived from a master secret we control, not stored in the database; erasure removes data from our operational systems but does not render on-chain ciphertext cryptographically irrecoverable.
This Data Processing Agreement ("DPA") is entered into by and between Piaxonika Software Services SINGLE MEMBER S.A., company number 179072201000, registered office: 3is Septemvriou 144, 112 51 Athens, Greece ("Processor" or "Company") and the customer entity subscribing to the Service ("Controller" or "Customer"). This DPA is incorporated into and forms part of the Terms of Service.
1. Scope, Purpose, and Definitions
- GDPR Application: This DPA applies where and to the extent that Processor processes Personal Data on behalf of Controller in the course of providing the Service, and such processing is subject to the General Data Protection Regulation (GDPR) or other applicable data protection laws.
- Definitions: The terms "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Supervisory Authority" have the meanings given in Article 4 of the GDPR.
2. Roles and Scope of Processing
- Roles: The Customer is the Data Controller, and the Company is the Data Processor.
- Subject Matter: Provision of the
eqr.linkQR code platform, redirect routing services, file hosting, and lead capture forms. - Duration of Processing: The duration of the Terms of Service plus the period until all Customer data is deleted from the Processor's systems.
- Nature and Purpose: To route QR scans, generate analytics, host files, display lead capture forms, and collect lead submissions in accordance with the Customer's configurations.
- Data Categories:
- Account Data: Customer email address and Google user ID.
- Redirect Analytics: Truncated IP hashes, country codes, User-Agent strings, and referer hostnames.
- Hosted Files: Any personal data contained within files uploaded by the Customer. Held in a private object-storage bucket at Backblaze (United States) and served from an unguessable address that anyone holding the link can open without signing in.
- Lead Submission Data: Contact details (names, emails, phone numbers, or custom fields) submitted by scanners on the Customer's lead capture forms.
- On-Chain Anchored Records (paid Eternal codes only): The random identifier of a QR code and the encrypted form of its destination URL, written permanently to a public blockchain. See §3.7.
- Categories of Data Subjects: The Customer's users/employees and individuals (scanners) who scan the Customer's QR codes or access their redirect links.
3. Obligations of the Processor
The Processor agrees to:
3.1. Documented Instructions
Process Personal Data only on documented instructions from the Controller (including instructions to perform redirects, host files, and capture leads), unless required to do so by Union or Member State law.
3.2. Confidentiality
Ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3. Security Measures
Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as detailed in our Security Notice. These measures include AES-256-GCM encryption of destination URLs, PASETO authentication, and SSRF network guards.
3.4. Subprocessors
- General Authorization: Controller grants Processor a general written authorization to engage subprocessors. The current list of subprocessors is maintained at List of Subprocessors.
- Where processing happens: Processor owns no infrastructure. The application runs on a virtual server rented from Hetzner Online GmbH in Finland, the database is hosted by Turso in the European Union, redirects execute on Cloudflare's global edge network, and hosted files are held at Backblaze in the United States. Section 1.1 of the Subprocessors list states what the edge logs and for how long.
- Notice of Changes: Processor will notify Controller of any intended changes concerning the addition or replacement of subprocessors at least 30 days in advance (via updates to the Subprocessors page or email notification).
- Objection: Controller may object to a new subprocessor on data protection grounds within 14 days of notification. If the parties cannot resolve the objection, either party may terminate the Service.
- Liability: Processor remains fully liable to Controller for the performance of the subprocessor's obligations.
3.5. Data Subject Rights
Assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Controller's obligation to respond to requests for exercising the Data Subject's rights (e.g., access, rectification, erasure).
3.6. Security Incident Notification
Notify Controller without undue delay (and in any event within 48 hours) after becoming aware of a personal data breach affecting Customer's data.
3.7. Deletion or Return of Data
At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of services, and delete existing copies unless Union or Member State law requires storage of the Personal Data.
- On-Chain Payload Exception: For paid Eternal codes, Processor writes exactly two values to the Base L2 blockchain: the random identifier of the QR code and the AES-256-GCM ciphertext of its destination URL. The transaction is signed by Processor's own relayer wallet, whose address is public. No email address, account identifier, IP address, scan data or plaintext destination is written on-chain. Data so anchored is immutable and cannot be deleted or returned, and re-anchoring leaves the earlier ciphertext in the chain's transaction history permanently. Upon erasure, Processor deletes the relevant database rows. Destination URLs are encrypted with a key Processor derives from a master secret it controls (not a key stored in the database); the encrypted payload remains publicly readable on-chain, and Processor retains the technical ability to decrypt it. Encryption is not anonymisation: the on-chain ciphertext remains Personal Data. Erasure therefore removes the Personal Data from Processor's operational systems but does not render the on-chain ciphertext cryptographically irrecoverable. Controllers and users must not embed personal data in destination URLs. Processor's assessment of this processing is recorded in a data protection impact assessment, available to Controller on request.
3.8. Audits
Make available to the Controller all information necessary to demonstrate compliance with GDPR Article 28 obligations and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
4. International Transfers
If the processing of Personal Data involves transfers outside the EEA to countries without an adequacy decision, the parties agree that the EU Standard Contractual Clauses (SCCs) (Module 2: Controller-to-Processor) are hereby incorporated by reference and form an integral part of this DPA.
5. How This DPA Is Entered Into
- Acceptance. There is no separate signature ceremony and no click-through DPA screen in the application. Section 2 of the Terms of Service incorporates this Agreement by reference, so a Controller who uses the Service under those Terms has entered into it, and the version that applies to a given act of processing is the one published at
eqr.link/dpaon the day it happens. Article 28(9) GDPR requires the contract between controller and processor to be in writing, including in electronic form — this document, incorporated into the Terms the Controller accepts, is that written form. - A signed copy. If your own compliance file needs one, write to support@eqr.link and we will return this Agreement countersigned, or counter-sign a copy you have signed. We would rather give you an address that a person reads than describe a signing button that does not exist in the product.
- Order of precedence. Where this Agreement and the Terms of Service disagree about the processing of Personal Data, this Agreement prevails, and only for that subject matter.
6. Contact Information
For DPA-related matters, contact: support@eqr.link