Skip to content
KeeperQR

Draft, not yet in force

This document has not been reviewed by a lawyer and does not bind anyone yet. It is published here so it can be read and corrected before launch. Do not rely on it.

Data Processing Addendum

Last updated 16 September 2026

This addendum applies where you use KeeperQR to process personal data about other people, which in practice means the scan records for your QR codes. For that data you are the controller and we are your processor. It forms part of the terms of service and takes effect automatically when you accept them. No signature is needed.

1.Roles and scope

You are the controller and decide why and how scan data is processed. We are the processor and act on your instructions. Your use of the service, and these terms, are those instructions. We will tell you if we believe an instruction breaches data protection law.

For your own account data, such as your name, email address, and billing records, we are a controller in our own right, and our privacy policy governs that rather than this addendum.

2.What is processed

Subject matter, duration, nature, purpose, data categories, and data subjects
ItemDetail
Subject matterResolving QR code scans and recording analytics about them
DurationFor as long as your account and the relevant QR codes exist
Nature and purposeCollection, storage, aggregation, display, and erasure, so you can measure how your codes are performing
Categories of dataTime of scan, country and city from network-level geolocation, device type, operating system, browser, referring page, a keyed one-way hash of the IP address, and a coarsely masked IP address. The raw IP address is never stored.
Data subjectsPeople who scan a QR code you created
Special category dataNone. Do not use KeeperQR in a way that makes a scan reveal special category data.

3.Our obligations

  • We process personal data only on your documented instructions, including for international transfers, unless the law requires otherwise.
  • Everyone we authorise to process the data is bound by confidentiality.
  • We keep appropriate technical and organisational security measures, described below.
  • We assist you, so far as is reasonable, with data subject requests, impact assessments, and consultations with regulators.
  • We notify you without undue delay, and in any case within 72 hours, of a personal data breach affecting your data.
  • On termination we delete the data, as described under Deletion below.
  • We make available the information needed to demonstrate compliance, and allow audits as set out below.

4.Subprocessors

You give general authorisation for us to use subprocessors. The current list, with what each one receives, is at keeperqr.com/legal/subprocessors.

We will give at least 30 days’ notice by email before adding or replacing a subprocessor. You may object on reasonable data protection grounds within that period. If we cannot resolve the objection, you may terminate and we will refund the unused portion of any prepaid term.

Each subprocessor is bound by obligations no less protective than these, and we remain liable to you for their performance.

5.Security

  • Data is encrypted in transit with TLS and encrypted at rest by our database and hosting providers.
  • Access to production data is limited to those who need it and is authenticated individually.
  • Passwords are hashed with bcrypt, and multi-factor authentication and passkeys are available on accounts.
  • The raw IP address of a scanner is never persisted. It is hashed with a keyed function and masked before storage, and the hash is erased after 13 months.
  • Customer data is logically separated and every query is scoped to a workspace.

6.International transfers

We are established in the United States and process data there. Where you transfer personal data from the UK, the EEA, or Switzerland, the transfer relies on the European Commission’s standard contractual clauses, with the UK International Data Transfer Addendum where applicable, which are incorporated into this addendum by reference. Module Two, controller to processor, applies.

7.Data subject requests

If a scanner contacts us directly, we will not respond substantively. We will pass the request on to you where we can identify the relevant customer, and tell the person to contact you.

The service gives you the tools to respond yourself: you can export scan data as CSV, and deleting a QR code deletes its scan records.

8.Audits

We will answer reasonable written questions about our processing, and provide whatever certifications or reports our infrastructure providers publish. An on-site audit is available no more than once a year, at your cost, on 30 days’ notice, subject to confidentiality, unless a regulator requires otherwise.

9.Deletion

Deleting a QR code deletes its scan records. Deleting your account deletes your codes, campaigns, and scan records. Backups are retained on a rolling basis by our database provider and expire on their normal schedule, typically within 30 days.

On termination of the agreement you may export your data. After a reasonable period we will delete it, except where the law requires us to keep it, such as billing records for tax purposes.

10.Contact

Data protection questions, and requests for a countersigned copy of this addendum: support@keeperqr.com.