Data Processing Addendum

Last updated July 2026

This Data Processing Addendum (DPA) forms part of the agreement between you and us and applies where we process personal data on your behalf.

This DPA is entered into between the customer (the "Controller") and Globe Astral LLC, a Wyoming limited liability company operating Global QR Codes (the "Processor"). It reflects the parties' agreement on the processing of personal data in accordance with the EU General Data Protection Regulation (GDPR), the UK GDPR and other applicable data protection laws. Where it conflicts with the Terms of Service, this DPA prevails for data protection matters.

1. Scope and roles

This DPA applies to the processing of personal data by us as Processor on behalf of you as Controller in connection with your use of the Service. You determine the purposes and means of processing Your Content; we process it only on your documented instructions, as set out in this DPA and the Terms of Service.

2. Definitions

Terms such as "personal data", "processing", "controller", "processor", "data subject" and "supervisory authority" have the meanings given to them in the GDPR. "Subprocessor" means any third party engaged by us to process personal data on your behalf.

3. Details of processing

  • Subject matter — provision of the Global QR Codes service, including QR code generation, dynamic redirects and scan analytics.
  • Duration — for the term of your use of the Service and until data is deleted or returned in accordance with this DPA.
  • Nature and purpose — hosting, storing, transmitting and analysing personal data to provide and support the Service.
  • Categories of data subjects — your end users, including people who scan your QR codes and your account users.
  • Categories of personal data — account identifiers, QR content you provide, and technical scan metadata such as device type, browser and approximate location. Where the customer enables optional retargeting pixels on a dynamic QR code, processing also facilitates the transmission of scan-event data (such as IP address, device and browser information, and platform cookies/identifiers) to the advertising platform(s) the customer configures.
  • Special categories — the Service is not intended for special-category data, and you agree not to submit it.

4. Processor obligations

  • Process personal data only on your documented instructions, including regarding international transfers, unless required by law.
  • Inform you if, in our opinion, an instruction infringes applicable data protection law.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Assist you, taking into account the nature of processing, in responding to data subject requests and in meeting your security, breach-notification and impact-assessment obligations.

5. Confidentiality

We ensure that our personnel and any subprocessors who have access to personal data are subject to appropriate confidentiality obligations and process the data only as necessary to provide the Service.

6. Security measures

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption in transit, access controls, hashed credentials, use of reputable infrastructure providers, and regular review of our security practices, taking into account the state of the art and the nature of the data.

7. Subprocessors

You provide general authorisation for us to engage the subprocessors listed below to process personal data. Each subprocessor is bound by data protection obligations no less protective than those in this DPA. We remain responsible for their performance.

SubprocessorPurposeLocation
Stripe, Inc.Subscription billing and payment processingUnited States
Vercel Inc.Application hosting, content delivery and aggregate analyticsUnited States
Supabase, Inc.Database hosting and user authenticationUnited States / EU

Advertising platforms that a Customer chooses to enable via the retargeting-pixels feature are not subprocessors under this DPA; see Section 7a.

We will inform you of any intended addition or replacement of a subprocessor, giving you the opportunity to object on reasonable data protection grounds.

7a. Customer-configured third-party pixels

If the Customer enables third-party advertising or analytics pixels (for example Meta, Google, TikTok or LinkedIn) on its dynamic QR codes, those providers are not our subprocessors. They are third parties engaged by the Customer, who acts as controller and determines the purposes and means of the resulting processing. The Customer is responsible for its own legal basis and for obtaining any required consent from data subjects, and its relationship with those platforms is governed by the platforms' own terms.

Our role is limited to providing the technical means to load the Customer's pixels and to collect scanner consent on the Customer's behalf, including presenting a consent screen to visitors in the EEA, UK and Switzerland, honouring Global Privacy Control signals, excluding automated traffic, and passing consent signals to Google via Google Consent Mode. We do not use these pixels or the resulting data for our own purposes.

8. Data subject rights

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under applicable data protection law. If we receive such a request directly, we will, where legally permitted, direct the data subject to you.

9. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process on your behalf, and will provide information reasonably available to us to help you meet your notification obligations to supervisory authorities and affected data subjects.

10. International transfers

Where processing involves the transfer of personal data outside the EEA or the UK to a country without an adequacy decision, such transfers are made subject to appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated into this DPA by reference.

11. Deletion or return of data

Upon termination of the Service, or at your request, we will delete or return the personal data we process on your behalf and delete existing copies, unless applicable law requires continued storage. Deletion is carried out within a reasonable period, subject to routine backup cycles.

12. Audits

We will make available to you information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality and frequency limits, and in a manner that does not compromise the security or privacy of other customers.

13. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.

14. Term and contact

This DPA takes effect when you accept the Terms of Service or begin using the Service and remains in force for as long as we process personal data on your behalf. To request a signed copy or to raise a data protection matter, contact Globe Astral LLC at privacy@globalqrcodes.com.