Legal · Version 2026-08-05-v620
Data Processing Addendum (DPA)
Contract terms for business customers where Magic QR Studio processes personal data on their behalf.
These policies govern use of Magic QR Studio SaaS, including accounts, uploads, generated works, checkout, credits, plans, private downloads, support and content safety.
1. Scope, parties and incorporation
This Data Processing Addendum (DPA) forms part of the Terms of Service between the business or organisation using Magic QR Studio (Customer) and the operator identified on the Contact Support page (Provider). It applies only where Provider processes Customer Personal Data on behalf of Customer as a processor or sub-processor.
The DPA is incorporated when Customer accepts the Terms or uses the service to process Customer Personal Data. It is not a separate checkout requirement for an individual consumer and does not apply where Provider acts as an independent controller, including account administration, billing, fraud prevention, security, legal compliance, service operations and other activities described in the Privacy Policy.
2. Definitions and roles
Customer Personal Data means personal data contained in content, files, payloads, links, instructions or support material submitted by or for Customer and processed by Provider solely to deliver the service on Customer instructions. Controller, processor, processing, personal data, personal data breach and supervisory authority have the meanings given by applicable data-protection law.
Customer is the controller or a processor acting for another controller. Provider is the processor or sub-processor only for Customer Personal Data. Each party remains responsible for its own obligations and for correctly determining its role; labels in this DPA do not override the parties’ actual functions.
3. Customer instructions and responsibilities
Provider will process Customer Personal Data only on Customer’s documented instructions, including the Terms, product configuration, account actions and lawful support requests, unless applicable law requires other processing. Where legally permitted, Provider will inform Customer before processing required by law.
Customer is responsible for the lawfulness, fairness and transparency of its instructions; required notices, permissions and lawful bases; data accuracy and minimisation; responding to data subjects; and ensuring that Customer Personal Data and requested outputs comply with law and the Acceptable Use Policy. Customer must not submit highly sensitive or regulated data unless the service expressly supports it and the parties have agreed suitable safeguards.
4. Processing details
The subject matter, duration, nature, purpose, data categories and data-subject categories are described in Annex A. Processing lasts for the service term and the limited retention, deletion and backup periods stated in the Data Retention Policy, unless law requires longer retention.
Provider may collect, receive, transmit, host, organise, transform, render, validate, watermark, retrieve, support, restrict and delete Customer Personal Data only as reasonably necessary to provide and secure the requested QR-code, barcode, storage, download and support functions.
5. Confidentiality and personnel
Provider limits access to authorised personnel and contractors who need it for their duties and are bound by confidentiality obligations or an applicable statutory duty. Access is reviewed and may be revoked when no longer required.
Provider will take reasonable steps to ensure that persons authorised to process Customer Personal Data understand and follow the security and data-protection obligations relevant to their work.
6. Security measures
Taking account of the state of the art, implementation cost, processing context and risk, Provider will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. The current measures are summarised in Annex B and the Trust Center.
Customer is responsible for configuring its account, access permissions, payloads, destinations, retention choices and user devices securely. No system is completely secure, and the measures do not guarantee that every incident will be prevented.
7. Sub-processors
Customer gives general authorisation for Provider to use the sub-processors listed in Annex C and the Trust Center. Provider will impose data-protection obligations that are materially no less protective than the relevant obligations in this DPA for the services performed by each sub-processor and remains responsible for its own obligations under applicable law.
Provider will give reasonable advance notice of a material new or replacement sub-processor through the Trust Center, account notice or email where required and practicable. Customer may raise a reasonable data-protection objection within 14 days. The parties will work in good faith on a commercially reasonable alternative; if none is available, Customer may stop the affected processing or terminate the affected service.
8. Data-subject requests
Taking account of the nature of processing, Provider will provide reasonable assistance, through available product controls and support, so Customer can respond to requests to access, correct, delete, restrict, object to or export Customer Personal Data where applicable.
If Provider receives a request clearly relating to Customer Personal Data for which Customer is responsible, Provider will ordinarily direct the requester to Customer unless law requires Provider to respond. Customer remains responsible for verifying the requester and deciding the lawful response.
9. Personal data breaches
Provider will notify Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data. The notice will include information reasonably available about the nature of the breach, affected data and data subjects, likely consequences, mitigation and a contact route, and may be supplied in phases as the investigation progresses.
Provider will take reasonable steps to contain, investigate and mitigate the breach. Customer is responsible for determining whether and how to notify regulators, affected people or others, except where Provider has a direct legal duty.
10. Compliance assistance
Taking account of the nature of processing and information available, Provider will provide reasonable assistance with security assessments, personal data breach obligations, data-protection impact assessments and prior consultation with regulators where the requested assistance relates to the service and Customer Personal Data.
Provider may charge reasonable fees for unusually extensive, repetitive or customer-specific assistance not included in the service, after giving advance notice, unless applicable law requires the assistance without charge.
11. Information and audits
Provider will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant policies, security summaries, sub-processor information and available independent reports. Customer should first use those materials and written questions.
Where legally required and those materials are insufficient, Customer may conduct one audit in a 12-month period on reasonable advance notice, during normal business hours and subject to confidentiality, security and non-disruption requirements. An audit must not expose another customer’s data, source code, vulnerability details or privileged information. Customer bears its audit costs unless a material breach by Provider is established.
12. Return and deletion
During the service term, Customer may use available export and deletion controls. On termination or written request, Provider will delete or return Customer Personal Data within the normal product, retention and backup cycle, unless law requires or permits limited continued retention.
Deletion from active systems may precede expiry from encrypted backups and legal, security, billing or dispute records. Any retained data remains protected and is not used for unrelated purposes.
13. International transfers
Provider and its service providers may process data in countries outside Customer’s location. Before making a restricted transfer, the parties will use an applicable lawful mechanism where required, such as an adequacy decision, the European Commission Standard Contractual Clauses, the UK Addendum or IDTA, or another recognised mechanism together with supplementary safeguards.
Provider will not treat this DPA alone as completing a transfer mechanism where additional execution, assessment or provider documentation is legally required. Customer may request information reasonably available about the current transfer route. Each party remains responsible for transfer obligations that apply to its own disclosures.
14. Precedence, changes and contact
If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA controls. Mandatory data-protection law and any valid standard contractual clauses control over inconsistent wording. Other commercial liability limits in the Terms apply only to the extent permitted by mandatory law.
Provider may update this DPA to reflect legal, technical or service changes, but will not materially reduce the protection of Customer Personal Data during an active paid service term without appropriate notice. Data-protection questions and requests may be sent to [email protected].
Annex A — Processing details
- Subject matter and purpose: providing, securing and supporting the QR-code, barcode, image-processing, validation, storage and download services requested by Customer.
- Duration: the service term plus the limited retention and backup periods in the Data Retention Policy, subject to legal exceptions.
- Nature of processing: collection, receipt, transmission, hosting, organisation, transformation, rendering, validation, watermarking, retrieval, support, restriction, export and deletion.
- Data subjects: Customer personnel, administrators, contractors, customers, prospects, end users, contacts and persons depicted in or identifiable from submitted material.
- Personal-data categories: identifiers and contact details; account or organisational references; images and visual content; QR or barcode payloads and destination URLs; uploaded text and metadata; support communications; and technical metadata reasonably necessary for processing.
- Special-category or highly sensitive data: not intended for routine use. Customer must not submit it unless expressly supported, lawful and protected by additional agreed safeguards.
- Customer instructions: the Terms, this DPA, product settings, API or interface actions and documented lawful support instructions.
Annex B — Technical and organisational measures
- Access control and least privilege for production systems, private storage, databases and operational tools.
- Transport encryption, private object storage and short-lived signed download URLs; passwords are stored as salted one-way derivations rather than plaintext.
- HttpOnly session cookies, authentication controls, request validation, rate limiting and administrative audit records.
- Tenant and object ownership checks, scoped identifiers and controls intended to prevent one customer from accessing another customer’s private works.
- Automated output validation, integrity checks and technical traceability measures for formal generated works.
- Logging, monitoring, vulnerability and dependency review, incident triage and controlled deployment practices.
- Retention schedules, deletion jobs, restricted backups and procedures for account deletion and expired works.
- Business-continuity measures appropriate to the hosted service, including provider redundancy and recovery procedures where available.
Annex C — Current authorised sub-processors and other providers
- Cloudflare — core DNS, CDN, WAF, Turnstile and private R2 object storage; optional Workers AI safety screening. Data may include traffic identifiers, IP-derived location, files and reduced safety-classification inputs.
- Zeabur — core hosting for the web application, API, workers, PostgreSQL and Redis in the configured deployment region. Data may include Customer Personal Data and operational metadata needed to run the service.
- Zoho or Brevo — alternative transactional-email providers when configured. Data is normally limited to recipient address, language, message content and delivery metadata.
- Google Cloud — optional Vision image-safety classification and Safe Browsing URL checks when enabled. Google OAuth sign-in is a separate authentication context and may involve Google acting under its own terms.
- Sentry — optional minimised error and performance monitoring when enabled; the service is configured not to intentionally send passwords, full payment-card data or uploaded content.
- Creem acts as merchant of record and independent controller for checkout, tax, invoices, refunds and chargebacks and is not treated as a sub-processor under this DPA for those activities.
- Actual enabled providers, processing regions and available transfer information may change with configuration and are published in the Trust Center or provided on reasonable request.
Support: [email protected]
For privacy, copyright, data, billing or security requests, contact [email protected]. We may ask for job ID, code ID, order ID or account email to verify and investigate the request.