Data Processing Agreement (DPA)
Agreement pursuant to Art. 28 GDPR between you as controller and Simplify Data GmbH as processor for QRFlow.
As of June 2026
1. Parties and scope
This Data Processing Agreement (DPA) pursuant to Art. 28 GDPR is entered into between the customer ("Controller") and Simplify Data GmbH, Königsweg 48, 24114 Kiel, Germany ("Processor" or "QRFlow").
The DPA supplements the QRFlow SaaS agreement and covers all personal data processing performed by the Processor on behalf of the Controller – including dynamic QR codes, scan tracking, analytics, exports, webhooks and email notifications.
Processor contact: info@simplify-data.de
2. Subject and duration
Subject matter is provision of the QRFlow platform for creating, managing and analysing QR codes, including technical redirects and scan logging on behalf of the Controller.
Processing begins upon registration and ends when the contract terminates. Data is deleted or returned as described in section 11, unless statutory retention applies.
3. Nature and purpose
Processing is solely for fulfilling the contracted QRFlow services, including redirects, scan analytics, GeoIP, exports, API access, transactional emails, webhooks and smart redirect rules (schedule, geo, device, A/B) where enabled by the Controller.
4. Categories of data
Depending on use, the following categories may be processed: IP addresses, user-agent data, approximate GeoIP location, UTM parameters, screen resolution, account and billing data, and webhook/API logs.
5. Obligations of the Processor
QRFlow processes data only on documented instructions, ensures confidentiality, implements appropriate technical and organisational measures, assists with data subject requests and notifies the Controller of personal data breaches without undue delay.
6. Sub-processors
The Controller authorises use of sub-processors required for hosting, email delivery, payment (Stripe) and GeoIP. An up-to-date list is available on request at info@simplify-data.de.
7. International transfers
Where data is transferred outside the EEA, appropriate safeguards (e.g. Standard Contractual Clauses) are applied.
8. Audit rights
The Controller may audit compliance upon reasonable notice. QRFlow provides relevant documentation and audit log exports where applicable.
9. Deletion and return
Upon termination, Controller data is deleted or returned within 30 days unless legal retention obligations apply. Scan analytics may be anonymised or deleted according to the retention settings of the plan.
10. Liability
Liability follows the main service agreement and applicable law.
11. Final provisions
German law applies. Amendments require written form. Contact: info@simplify-data.de