Policy
Data processing agreement
When you use QRSalt to collect or host other people's personal data, you decide why and how, and we process it for you. These are the terms for that, as Article 28 of the GDPR requires.
Last updated 11 September 2026
1. Who this applies to
This agreement (the "DPA") is between you, the customer who holds a QRSalt account ("you", the controller), and Runless AS, a Norwegian company ("we", the processor). It forms part of our terms of service and applies automatically whenever we process personal data on your behalf. Nothing needs signing; if your organisation needs a countersigned copy, email [email protected].
Words such as "personal data", "processing", "controller", "processor" and "personal data breach" mean what they mean in the GDPR (Regulation (EU) 2016/679), as it applies in Norway and the rest of the EEA. Where UK or Swiss law applies to you, the equivalent terms of those laws apply in the same way.
This DPA does not cover data about you as our customer (your account, your billing). We are the controller of that, as the privacy policy explains.
2. What we process for you
| Subject matter | Providing the QRSalt service to you under the terms of service. |
|---|---|
| Duration | As long as you have an account, plus the deletion periods in section 9. |
| Nature and purpose | Hosting, redirecting, recording, aggregating and displaying data so you can run dynamic QR codes, hosted pages, contact cards, menus and forms, and see how they perform. |
| Data subjects | People who scan your codes or open your hosted pages; people who answer your forms; people whose details you put in your content (for example, on a contact card or a menu); your team members. |
| Categories of data |
|
| Special categories | The service is not designed for health, biometric or other special-category data, or for data about criminal convictions. Do not collect them through it unless you have a lawful basis and have told us first. |
3. Your instructions
We process this data only on your documented instructions, which are these terms, the settings you choose in the product, and anything else you ask of us in writing, unless the law requires otherwise; if it does, we will tell you first unless the law forbids that. If we think an instruction breaks data protection law, we will say so.
You are responsible for having a lawful basis for the data you collect with the service, for telling the people concerned (for example, in a notice on your form or on the printed piece beside your code), and for what your forms ask.
4. Confidentiality
Only people who need to run or support the service can access your data, and they are bound by confidentiality. We do not look at your data except to provide the service, to fix a problem, to deal with abuse, or when you ask us to.
5. Security
We maintain technical and organisational measures appropriate to the risk, as Article 32 requires. Today they include:
- Encryption in transit everywhere: HTTPS end to end, with HSTS.
- The origin server accepts web traffic only from our network provider, and only with its client certificate.
- Scan and form analytics never store a raw IP address; the daily visitor hash uses a key that is thrown away each day.
- Passwords are stored only as salted scrypt hashes; session tokens and API keys only as hashes.
- Every read of customer data checks that the signed-in person belongs to the workspace. Team roles limit who can change what.
- Rate limits and bot checks on sign-in, forms and other public endpoints.
- Hourly database and file backups, each verified when written, readable only by the system administrator, and restored in an automated test.
- Administrative access limited to named staff accounts.
We do not hold ISO 27001, SOC 2 or similar certifications. We will answer reasonable security questionnaires.
6. Sub-processors
You give us general authorisation to use the sub-processors on our sub-processor list. We bind each of them by contract to data protection obligations at least as protective as this DPA, and we remain responsible to you for them.
We will update the list at least 30 days before a new sub-processor starts processing your data, and notify you by email if you have asked to be told. You may object on reasonable data protection grounds within that time; if we cannot resolve the objection, you may end the affected service and we will refund any prepaid fees for the unused period.
7. International transfers
The service is hosted in the United States. Where your data leaves the EEA, the UK or Switzerland, the transfer is covered by the EU–US Data Privacy Framework where the recipient is certified, or by the European Commission's Standard Contractual Clauses (with the UK and Swiss addenda where they apply), as shown for each provider on the sub-processor list.
8. Helping you meet your obligations
- Requests from people. If someone asks us about data we hold for you, we will pass the request to you rather than answer it ourselves. The product lets you find, export and delete scan data, form responses and content yourself; where it does not, we will help.
- Assessments and consultations. We will give you the information you reasonably need for a data protection impact assessment or a consultation with a supervisory authority about the service.
- Personal data breaches. We will tell you without undue delay, and in any case within 48 hours, after becoming aware of a breach affecting your data. We will say what happened, what data and roughly how many people are affected, what we are doing about it, and who to contact, and add detail as we learn it.
9. Deletion and return
You can export and delete your data at any time from the dashboard. When you delete your account, it can be restored for 30 days, and after that everything we hold for you is permanently deleted from the live system. Backups containing it expire on their own schedule: local backups after 30 days, and off-site copies within 12 months. Until then they are kept encrypted in transit, access-controlled and unused, and if we ever had to restore one we would delete your data again before bringing it back into service. We keep a copy of anything only where the law requires us to.
10. Audits
We will make available the information needed to show that we meet Article 28, starting with this page, the sub-processor list and our answers to your questions. If that is not enough, you (or an independent auditor bound by confidentiality) may audit our compliance once a year, at your cost, on 30 days' written notice, in a way that does not disrupt the service or expose other customers' data. More frequent audits are allowed after a breach affecting you or when a supervisory authority requires one.
11. Liability and precedence
Liability under this DPA is subject to the limits in the terms of service, except where the law does not allow them. If this DPA and the terms of service conflict on data protection, this DPA wins. It is governed by Norwegian law, like the terms.
12. Contact
Data protection questions, requests for a signed copy and breach contacts: [email protected]. That is the same inbox as support, read by the people who run the service.