Security & GDPR
iziqrcode is operated by a Spanish company and hosts **100% of primary data in Germany**. This page summarises the items that matter for your data's security and GDPR compliance. The **Privacy Policy** and the **Data Processing Agreement (DPA)** remain the legally binding documents; this page is an educational summary. *The French version of this page prevails in case of divergence.*
User data in Europe · Sub-processors framed by EU SCC · 0 advertising cookie
iziqrcode hosts the primary user data (account, QR codes, aggregated stats, uploaded logos) in Europe: Hetzner Germany (Falkenstein) + Cloudflare R2 EU. For secondary functions (payments, transactional emails, CDN), we use technical sub-processors based in the United States, strictly framed by the EU Standard Contractual Clauses 2021/914: Stripe (Ireland, US infrastructure), Cloudflare (US), Resend (US). See the full breakdown of the 4 sub-processors below.
11. Where is your data?
iziqrcode's primary data (user accounts, QR codes, aggregated stats, EU-uploaded logos) is hosted within the European Union:
- Next.js application + PostgreSQL database: Hetzner Online GmbH, Falkenstein datacenter (Germany) — EU jurisdiction.
- Uploaded logos: Cloudflare R2, EU instance.
Processing carried out by our technical sub-processors (Stripe payments, Resend emails, Cloudflare Workers for scan redirects) may transit outside the EU, framed by the Standard Contractual Clauses EU 2021/914. See Privacy Policy §6.
22. Hetzner — our primary hosting provider
Hetzner Online GmbH is one of Europe's leading hosting providers, based in Bavaria (Germany). The Falkenstein datacenter used by iziqrcode holds the following certifications:
- ISO/IEC 27001:2022 — information security management system ;
- ISO 14001 — environmental management ;
- ISO 50001 — energy management ;
- TCDP (Trusted Cloud Data Protection Profile) — independent audit of German GDPR compliance.
The entire infrastructure runs on 99% renewable energy (wind + hydro mix).
33. Sub-processors used
To deliver the service, iziqrcode uses 4 sub-processors explicitly listed in the Privacy Policy:
- Hetzner Online GmbH (Germany) — Next.js + PostgreSQL hosting
- Stripe Payments Europe Ltd (Ireland) — payments, billing, EU VAT calculation
- Cloudflare Inc. (USA) — CDN, R2 EU, Workers qr-redirect (3 distinct processings)
- Resend (Bird.com Inc., USA) — transactional emails
Each sub-processor is bound by a contract compliant with GDPR Article 28. The up-to-date list is maintained per Article 30. For the full list with addresses + third-party privacy-policy URLs, see the Privacy Policy §5.
44. Sub-processors — detail
Below is the complete list of the 5 technical sub-processors used by iziqrcode, with purpose, country and date of last review. This list is maintained per GDPR Article 30.
- Purpose
- Next.js + PostgreSQL hosting (Falkenstein)
- Transfer
- EU only
- Last reviewed
- 2026-05
- Purpose
- Payments, invoicing, EU OSS VAT calculation
- Transfer
- USA via EU SCC 2021/914
- Last reviewed
- 2026-05
- Purpose
- CDN + R2 (EU logos) + qr-redirect Workers
- Transfer
- USA via EU SCC 2021/914
- Last reviewed
- 2026-05
- Purpose
- Transactional emails (magic link, invoices)
- Transfer
- USA via EU SCC 2021/914
- Last reviewed
- 2026-05
- Purpose
- AI menu translation & import (dish names + descriptions)
- Transfer
- USA via EU SCC 2021/914
- Last reviewed
- 2026-07
Why US sub-processors?
Stripe is the global standard for SaaS payments (EU OSS VAT calculation, PCI DSS compliance, 135+ currencies). Resend is our transactional-email provider (high deliverability, simple API). Cloudflare provides our CDN and scan-redirect Workers (< 50 ms latency worldwide). All three are contractually bound by the EU Standard Contractual Clauses 2021/914, which guarantee a level of protection equivalent to the GDPR for cross-border data transfers.
Custom EU-only architecture
If you are an organisation subject to strict sovereignty requirements (healthcare, defence, public sector, HDS-compliant hosting, etc.), please reach out at [email protected] so we can design a 100% EU-only architecture for your needs (Mollie/EU payments, EU email provider, OVH/Scaleway CDN). A dedicated contract can be put in place depending on volume.
55. "Zero advertising cookie" commitment
iziqrcode does no ad targeting and resells no data. The only advertising cookie set — with your consent, refusable in one click — measures our own Google Ads campaigns: knowing which ads bring sign-ups. No Facebook Pixel, no Hotjar, no PostHog, no Mixpanel.
For the sole audience measurement of our marketing site, we use Google Analytics 4 — only after your explicit consent (refusable in one click), with anonymized IP (Consent Mode v2) and never on the public pages of your menus (`/p/*`). Technical cookies (session, CSRF, language) remain strictly necessary (functional exemption under Article 5.3 of the ePrivacy Directive 2002/58/EC). See the Cookie Policy.
66. Downloadable DPA
A Data Processing Agreement compliant with GDPR Article 28 is publicly available at /dpa. You can print it or save it as a PDF directly from your browser (Ctrl+P → "Save as PDF"), then have it signed by your compliance team.
iziqrcode acts as processor under the GDPR. You remain the controller of your data and that of your visitors.
77. Your GDPR rights
You may at any time exercise the rights provided by GDPR Articles 15-22: access, rectification, erasure, restriction, portability, objection. To exercise them, email [email protected] from the email address associated with your account. Reply within 30 days maximum.
You may also lodge a complaint with the Agencia Española de Protección de Datos (AEPD, www.aepd.es) or the supervisory authority of your country of residence.
Your GDPR rights — in 1 click
The actions below let you exercise your rights directly, without filling a form. Account changes (rectification, deletion) happen from your settings; access requests go through email for traceability.
88. Register of processing (GDPR Article 30)
Per GDPR Article 30, iziqrcode maintains a register of processing activities (purposes, data categories, recipients, retention periods, security measures).
The full register is available on request at [email protected] within 7 business days. A downloadable PDF / CSV export from your account is planned for a future iteration.
99. Going further
The following items are planned for a future iteration of iziqrcode:
- PDF / CSV export of the Article 30 register directly from your account ;
- Public incident notification procedure in case of a data breach ;
- Detailed business continuity plan (RTO / RPO) ;
- Annual external audit (public report) ;
- Bug bounty and responsible disclosure programme.
In the meantime, for any specific question, email [email protected].
Every substantive change to this page is logged in the internal amendment registry (see `docs/legal-compliance.md`) and the «Last updated» date at the top of the page is updated accordingly.
Current version: v1.0 (Mission 7-light, 16/05/2026)