Personal Data Processing Agreement (DPA)
Preamble
This Data Processing Agreement (hereinafter the "DPA") is entered into between:
MA REPUTATION EN LIGNE PRODUCCIONES SL (hereinafter "iziqrcode" or "the Processor"), a company under Spanish law, registered with CIF B88432935, with registered office in Madrid, Spain, operating the SaaS service "iziqrcode" available at https://iziqrcode.com.
AND
The B2B Customer (hereinafter "the Controller"), as identified by their registration and acceptance of iziqrcode's Terms of Service (Terms).
Together referred to as "the Parties".
1Article 1 — Purpose
This DPA governs the processing of personal data (hereinafter "Personal Data") carried out by iziqrcode on behalf of the Controller, in the context of the iziqrcode service as defined by the Terms.
Its purpose is to set out the conditions under which the Processor undertakes to process Personal Data in compliance with Regulation (EU) 2016/679 ("GDPR") and the applicable Spanish legislation (LOPDGDD).
2Article 2 — Definitions
The terms used in this DPA have the meaning given to them by Article 4 GDPR, notably: Personal Data, Processing, Controller, Processor, Sub-processor, Personal Data breach, Data subject.
3Article 3 — Duration
This DPA takes effect on the date of the Controller's registration to the iziqrcode service and applies for the entire duration of the contractual relationship as defined by the Terms. It ends upon termination, expiry or non-renewal of the main contract, without prejudice to surviving obligations (Articles 13 and 14).
4Article 4 — Description of processing
4.1 Nature and purpose of processing
iziqrcode processes Personal Data on behalf of the Controller exclusively to:
- Generate and host static and dynamic QR codes according to the Controller's configurations ;
- Redirect end-visitors of the QR codes to the defined target URLs ;
- Collect anonymised usage statistics (scan counts, country-level geolocation only, device type) ;
- Store QR code content (target URLs, vCard content, WiFi configurations, etc.) as defined by the Controller ;
- Allow the Controller to access, modify and export its data via the service interface.
4.2 Categories of Personal Data processed
- Controller's Personal Data (iziqrcode customer account): professional email, name, billing data, login IP ;
- End-visitors' Personal Data (Controller's end-users): pseudonymised IP address (hashed), pseudonymised User-Agent, country of origin, scan timestamp, scanned target URL ;
- Personal Data embedded by the Controller in QR code content: varies by use case (e.g. vCard contact information, WiFi credentials, etc.) — falls under the Controller's sole responsibility.
4.3 Categories of data subjects
- The Controller and its representatives (iziqrcode account users) ;
- End-visitors of QR codes generated by the Controller ;
- Persons whose Personal Data is embedded by the Controller into its QR codes.
4.4 Retention duration
- Customer account Personal Data: duration of the contractual relationship + 3 years (accounting + statute of limitations) ;
- End-visitor QR-scan Personal Data (scan logs): 12 months rolling, automatic purge ;
- Personal Data embedded by the Controller in its QR codes: kept as long as the QR code is active, deleted upon account termination.
5Article 5 — Processor's obligations
iziqrcode undertakes to:
1. Process Personal Data only on documented instructions from the Controller, as resulting from the Terms, account configurations, and any subsequent written instruction ;
2. Ensure confidentiality by making sure any person authorised to process the Personal Data is bound by confidentiality or subject to an appropriate statutory obligation ;
3. Implement appropriate technical and organisational measures in accordance with Article 32 GDPR (see Annex II) ;
4. Notify the Controller of any Personal Data breach within a maximum of 72 hours of becoming aware (see Article 10) ;
5. Assist the Controller in responding to data subjects' rights requests (access, rectification, erasure, portability, objection, restriction) — see Article 11 ;
6. Assist the Controller in complying with its obligations relating to security, impact assessments (DPIA) and prior consultation with the supervisory authority ;
7. Delete or return the Personal Data at the end of the contract per Article 13 ;
8. Make available to the Controller any information necessary to demonstrate compliance with this DPA and allow audits (see Article 12) ;
9. Maintain a register of processing activities carried out on behalf of the Controller in accordance with Article 30.2 GDPR.
6Article 6 — Controller's obligations
The Controller undertakes to:
1. Document in writing any instruction relating to the processing of Personal Data by iziqrcode (configurations made through the service interface have the value of an instruction) ;
2. Ensure compliance with the minimisation principle when creating QR codes containing Personal Data ;
3. Inform its own end-users (QR code visitors) of the use of iziqrcode as Processor, through its own privacy policy ;
4. Collect consent or justify any other GDPR legal basis for Personal Data embedded in its QR codes ;
5. Supervise iziqrcode's compliance with this DPA, exercising as needed its right to audit.
7Article 7 — Sub-processors
7.1 General authorisation
The Controller authorises iziqrcode to use the sub-processors listed in Article 7.2 for the provision of the service.
7.2 List of authorised sub-processors
| Sub-processor | Country | Purpose | Safeguards |
|---|---|---|---|
| Stripe Payments Europe Ltd | Ireland (EU) | Payment processing, subscription management, EU OSS VAT compliance | Stripe DPA + EU residency |
| Resend (Bird.com Inc.) | United States | Transactional email delivery (magic-link auth, notifications) | Resend DPA + Standard Contractual Clauses (Module 2) |
| Cloudflare Inc. | United States | CDN, DDoS protection, R2 storage (logos), Workers (QR redirection), Turnstile (anti-bot) | Cloudflare DPA + EU residency for R2 and Workers (Falkenstein) |
| Hetzner Online GmbH | Germany (EU) | Infrastructure hosting (servers, PostgreSQL database, Redis cache, backups) | Hetzner DPA (AVV) + intra-EU |
| Anthropic PBC | United States | AI menu translation and import (dish names + descriptions) | Anthropic DPA + Standard Contractual Clauses (Module 2) + no model training on submitted data |
| Google Ireland Ltd | Ireland (EU) — transfers to the United States possible | Marketing-site audience measurement (Google Analytics 4), only after consent; never on public menu pages (`/p/*`) | Google DPA + Standard Contractual Clauses (Module 2) + IP anonymisation + prior consent (Consent Mode v2) |
7.3 Information on sub-processor changes
iziqrcode undertakes to inform the Controller of any planned addition or replacement of a sub-processor at least 30 days before implementation, by email notification to the customer account address and publication on the page https://iziqrcode.com/dpa.
The Controller has 30 days to object to the new sub-processor. In the event of a reasoned objection and impossibility to find a compromise, the Controller may terminate without penalty.
7.4 Cascade commitment
iziqrcode contractually imposes on each sub-processor the same data-protection obligations as those set in this DPA. In the event of a sub-processor's failure, iziqrcode remains fully liable to the Controller.
8Article 8 — Transfers outside the European Union
Sub-processors located in the United States (Resend, Cloudflare) apply the Standard Contractual Clauses ("SCCs") adopted by the European Commission (Decision 2021/914 of 4 June 2021), Module 2 (controller-to-processor) and where applicable Module 3 (processor-to-processor).
No Personal Data transfer is made to other third countries without appropriate safeguards within the meaning of Article 46 GDPR.
9Article 9 — Security measures
iziqrcode implements the technical and organisational measures described in Annex II of this DPA, in accordance with Article 32 GDPR.
These measures include: encryption of data in transit (TLS 1.3) and at rest, role-based access control, logging of administrator access, daily encrypted backups, network isolation, anti-DDoS protection, anti-bot protection (Cloudflare Turnstile), rate-limiting of sensitive requests, regular internal security audits.
10Article 10 — Personal Data breach notification
In the event of a Personal Data breach, iziqrcode notifies the Controller without undue delay and within 72 hours of becoming aware.
The notification includes, as far as possible:
- The nature of the breach (categories of Personal Data and data subjects, approximate number) ;
- The probable consequences ;
- The measures taken or proposed to remedy the breach ;
- The contact details of iziqrcode's contact point for further information.
The Controller remains responsible for any notification to the supervisory authority (CNIL, AEPD) and to data subjects if required by Articles 33 and 34 GDPR.
11Article 11 — Assistance for data subject rights
iziqrcode assists the Controller, insofar as possible and through appropriate technical and organisational measures, in responding to data subjects' rights requests (access, rectification, erasure, portability, objection, restriction).
For Personal Data managed by the Controller through its iziqrcode account, the service interface allows direct export, modification and deletion.
For other cases, the Controller may address its request to [email protected] (response time: 10 business days).
12Article 12 — Audits
The Controller may, at its expense, carry out an audit of iziqrcode's compliance with this DPA:
- Minimum notice: 60 days ;
- Maximum frequency: 1 audit per year (except in case of a proven security incident) ;
- Modalities: by documents (SOC 2 reports, ISO 27001 certifications of sub-processors where available, iziqrcode internal audits), or in person at relevant sites during business hours ;
- Auditor: independent and bound by a confidentiality undertaking.
iziqrcode may refuse an auditor who is a direct competitor.
13Article 13 — Fate of data at end of contract
Upon termination of the main contract, the Controller may choose:
- Return: full export of its Personal Data in CSV / JSON format via the service interface (Article 20 GDPR functionality enabled by default) ;
- Deletion: complete erasure of its Personal Data within 30 days of termination, confirmed by email.
Absent explicit request within 30 days of termination, iziqrcode proceeds to automatic deletion of the Personal Data, subject to statutory retention obligations (accounting logs, tax obligations).
14Article 14 — Liability
Each Party is responsible for damages arising from a breach of its respective GDPR obligations.
In accordance with Article 82.5 GDPR, where iziqrcode and the Controller are involved in the same processing and are liable for damage, each Party bears responsibility to the extent of its contribution to the damage.
iziqrcode's liability under this DPA is capped under the conditions provided for in the Terms (Article 7bis).
15Article 15 — Governing law and jurisdiction
This DPA is governed by Spanish law, supplemented by the GDPR and applicable European Union law.
Any dispute relating to the interpretation or execution of this DPA shall be submitted to the exclusive jurisdiction of the courts of Madrid, Spain, subject to the mandatory consumer-protection rules if the Controller qualifies as such.
Annex I — Description of processing
Annex I fully reproduces the elements described in Article 4 above (nature and purpose, categories of Personal Data, categories of data subjects, retention durations).
Annex II — Technical and organisational security measures
Physical and logical security
- Hosting in ISO 27001-certified data centers (Hetzner Falkenstein, Germany) ;
- Restricted and logged physical access ;
- Electrical and network redundancy.
Access control
- Authentication via secure magic link (single-use link, 15-minute expiry) or Google OAuth ;
- No password-based authentication (eliminates credential-leak risk) ;
- Session rotation, immediate revocation possible ;
- Application-level roles (RBAC) per Free / Pro / Business plans.
Encryption
- Communications: TLS 1.3 for all connections (HTTP, database, cache) ;
- Storage: backup encryption ;
- Secrets: isolated environment variables, never logged.
Pseudonymisation and minimisation
- End-visitor IP addresses: SHA-256-hashed with a date-derived salt, renewed daily — no fingerprint links two days ;
- User-Agents: never retained — device type, operating system and browser are derived from them, the header itself is not stored ;
- Geolocation: country and approximate city derived from the IP address by the content delivery network, never precise coordinates nor device geolocation ;
- No individual tracking of end-visitors ;
- IP fingerprints destroyed after 7 days.
Monitoring and logging
- Centralised administrator-access logs kept 90 days ;
- Automatic detection of suspicious activity (rate-limiting, Cloudflare Turnstile anti-bot) ;
- Regular internal security audits.
Backups and continuity
- Daily encrypted database backups ;
- Monthly restoration test ;
- Backup retention: 30 days rolling.
Breach management
- Documented incident-response procedure ;
- Notification to Controller within 72 h ;
- Incident register.
Done in Madrid, Spain. Effective date: date of the Controller's registration to the iziqrcode service. MA REPUTATION EN LIGNE PRODUCCIONES SL — CIF: B88432935 — Madrid, Spain — [email protected]