Data Processing Agreement (DPA)

Agreement pursuant to Art. 28 GDPR between you as controller and Simplify Data GmbH as processor for QRFlow.

As of June 2026

1. Parties and scope

This Data Processing Agreement (DPA) pursuant to Art. 28 GDPR is entered into between the customer ("Controller") and Simplify Data GmbH, Königsweg 48, 24114 Kiel, Germany ("Processor" or "QRFlow").

The DPA supplements the QRFlow SaaS agreement and covers all personal data processing performed by the Processor on behalf of the Controller – including dynamic QR codes, scan tracking, analytics, exports, webhooks and email notifications.

Processor contact: info@simplify-data.de

2. Subject and duration

Subject matter is provision of the QRFlow platform for creating, managing and analysing QR codes, including technical redirects and scan logging on behalf of the Controller.

Processing begins upon registration and ends when the contract terminates. Data is deleted or returned as described in section 11, unless statutory retention applies.

3. Nature and purpose

Processing is solely for fulfilling the contracted QRFlow services, including redirects, scan analytics, GeoIP, exports, API access, transactional emails, webhooks and smart redirect rules (schedule, geo, device, A/B) where enabled by the Controller.

4. Categories of data

Depending on use, the following categories may be processed: IP addresses, user-agent data, approximate GeoIP location, UTM parameters, screen resolution, account and billing data, and webhook/API logs.

5. Obligations of the Processor

QRFlow processes data only on documented instructions, ensures confidentiality, implements appropriate technical and organisational measures, assists with data subject requests and notifies the Controller of personal data breaches without undue delay.

6. Sub-processors

The Controller authorises use of sub-processors required for hosting, email delivery, payment (Stripe) and GeoIP. An up-to-date list is available on request at info@simplify-data.de.

7. International transfers

Where data is transferred outside the EEA, appropriate safeguards (e.g. Standard Contractual Clauses) are applied.

8. Audit rights

The Controller may audit compliance upon reasonable notice. QRFlow provides relevant documentation and audit log exports where applicable.

9. Deletion and return

Upon termination, Controller data is deleted or returned within 30 days unless legal retention obligations apply. Scan analytics may be anonymised or deleted according to the retention settings of the plan.

10. Liability

Liability follows the main service agreement and applicable law.

11. Final provisions

German law applies. Amendments require written form. Contact: info@simplify-data.de