Legal
Last updated: 17 July 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Etcetera Digital LLC, 30 N Gould St., Suite 2413, Sheridan, WY 82801, USA (“QR Hero”, the “Processor”) and the customer accepting the QR Hero Terms of Service (the “Customer”, the “Controller”). It applies whenever QR Hero processes personal data on the Customer’s behalf in connection with the QR Hero service (the “Service”).
This page is the standard, generally applicable version of the DPA and is incorporated into the Terms of Service by reference. A countersigned copy for your records is available on request at privacy@qrhero.com.
“Personal data”, “processing”, “data subject”, “controller”, “processor”, and “supervisory authority” have the meanings given in the EU General Data Protection Regulation (GDPR) or, where applicable, the UK GDPR and other applicable data protection laws (“Data Protection Laws”).
The Customer is the controller of the personal data processed through its use of the Service; QR Hero is its processor. This covers, in particular:
QR Hero remains an independent controller for its own account, billing, and security data, as described in its Privacy Policy.
QR Hero processes personal data only on the Customer’s documented instructions, including instructions given through the QR Hero dashboard, API, and account configuration (for example GDPR feature toggles, analytics settings, retention windows, and pixel configuration), unless processing is required by law - in which case QR Hero will inform the Customer before processing, unless the law prohibits this. QR Hero will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
QR Hero ensures that persons authorized to process personal data are bound by confidentiality obligations, and limits access to personnel who need it to provide the Service.
QR Hero implements appropriate technical and organizational measures, taking into account the state of the art and the nature of the data, including:
The Customer gives general authorization for QR Hero to engage the sub-processors listed on the Sub-processor List. QR Hero will notify customers of intended additions or replacements (for example by updating that page and emailing account owners) at least 14 days in advance, and the Customer may object on reasonable data protection grounds; if the objection cannot be resolved, the Customer may terminate the affected service. QR Hero imposes data protection obligations on its sub-processors that are no less protective than this DPA and remains liable for their performance.
Taking into account the nature of the processing, QR Hero will assist the Customer with appropriate technical and organizational measures - including data export (CSV/JSON), deletion, and retention configuration - in fulfilling the Customer’s obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). If a data subject contacts QR Hero directly about the Customer’s processing, QR Hero will forward the request to the Customer without undue delay.
QR Hero will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s personal data, and will provide information reasonably required to help the Customer meet its own notification obligations, including the nature of the breach, the categories and approximate volumes affected, likely consequences, and measures taken or proposed.
QR Hero will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, where required and relating to the Service. QR Hero will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or its mandated auditor, subject to reasonable notice, confidentiality, and at most once per 12-month period unless a supervisory authority requires otherwise or a breach has occurred.
Upon termination of the Service, QR Hero will, at the Customer’s choice, delete or return the personal data processed on the Customer’s behalf, and delete existing copies within 90 days, unless applicable law requires longer storage. The Customer can export its data (including scan data) in CSV/JSON form before account closure.
Customer data is primarily hosted in the European Union, with a global edge network (Cloudflare) in front of redirect and web traffic. Where processing under this DPA involves a transfer of personal data protected by the GDPR or UK GDPR to a country without an adequacy decision - including access by QR Hero from the United States - the parties rely on the European Commission’s Standard Contractual Clauses (Module 2: controller to processor, and Module 3 where applicable), which are incorporated into this DPA by reference, together with the UK Addendum where UK data is concerned. The Annexes to the Clauses are completed by the details in sections 2, 3, 6, and the Sub-processor List.
The liability provisions of the Terms of Service apply to this DPA. In case of conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails. In case of conflict between this DPA and the Standard Contractual Clauses, the Clauses prevail.
This DPA takes effect when the Customer accepts the Terms of Service and remains in force for as long as QR Hero processes personal data on the Customer’s behalf.
Etcetera Digital LLC 30 N Gould St., Suite 2413 Sheridan, WY 82801, USA