GDPR and QR codes

A QR code is just an image — it holds no personal data. GDPR enters the picture when a dynamic code records scans, because a scan can include an IP address and a location derived from it. The questions that matter are where that data is stored, on what basis, and for how long.

This page summarises those answers in plain English. The binding document is the privacy policy; where the two differ, the privacy policy applies.

Servers

Germany

Controller

London, United Kingdom

Third-party trackers

None

Common questions

Are QR codes GDPR-compliant?

The code itself is just an image and carries no personal data. GDPR becomes relevant the moment a dynamic code records scans, because a scan event can include an IP address and derived location. What matters is where that data is stored, on what legal basis, and for how long.

What data does QRiety record when someone scans a code?

For dynamic codes: timestamp, IP address, browser and operating system from the user agent, device type, referrer, and country, region and city derived from the IP. Static codes record nothing at all — there is no server request to record.

Where is that data stored?

On servers in Germany, operated by Hostinger International Ltd. as a processor under Art. 28 GDPR, with a data processing agreement in place. Scan data does not leave the EU.

Do you track visitors with Google Analytics?

No. There is no Google Analytics and no Meta Pixel on this site. Product analytics run through a single provider on its EU endpoint and only start after you accept analytics cookies. Decline, and no analytics events are sent.

How long is scan data kept?

Analytics retention follows your plan: no analytics history on the free plan, 90 days on Starter, 730 days on Professional. Beyond that, data is kept only as long as necessary for the purpose it was collected for, subject to statutory retention periods.

How do I exercise my rights?

Email support@zeuz-it.com. You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), plus the right to withdraw consent at any time and to lodge a complaint with a supervisory authority.

Who is the controller?

ZEUZ IT LTD, 4 Raven Road, Unit 1C3-838, E18 1HB London, United Kingdom. Registered with Companies House (UK) under number 16592489.