EU Data Security & Encryption

Security Architecture

TLS encryption everywhere, bcrypt password hashing, EU server hosting in Germany, and granular access controls for every dynamic QR code.

Traffic is encrypted end to end

Every request runs over TLS. HSTS is enabled site-wide, so browsers refuse to fall back to plain HTTP once they have seen the site.

Passwords are hashed with bcrypt

Account passwords are never stored in readable form. They are hashed with bcrypt at cost factor 12–14 before they reach the database.

Servers are in Germany

Hosting is provided by Hostinger International Ltd.; the servers are located in Germany. A data processing agreement under Art. 28 GDPR is in place.

No Google Analytics, no Meta Pixel

Product analytics run through a single provider on its EU endpoint, and only after you accept analytics cookies. Decline, and no analytics events are sent at all.

QR codes can be locked down

Dynamic codes support password protection, an expiry date and a maximum scan count. A code can also be deactivated at any time without reprinting.

Geolocation is resolved locally

Scan locations are derived from a local IP database on our own server. Scan data is not handed to a third-party geolocation service.

Reporting a Vulnerability

If you discover a security vulnerability, please email details directly to support@zeuz-it.com. We will review and remediate valid reports promptly.

Security Questions

Where is QR code scan data stored?

On servers in Germany, operated by Hostinger International Ltd. as a processor under Art. 28 GDPR. Scan data does not leave the EU.

Can I password-protect a QR code?

Yes. A dynamic QR code can require a password before the destination opens. You can also set an expiry date, cap the number of scans, or deactivate the code entirely — all without reprinting it.

Do you use Google Analytics?

No. There is no Google Analytics and no Meta Pixel on the site. Product analytics run through a single provider on its EU endpoint, and only after you accept analytics cookies.

How are account passwords stored?

They are hashed with bcrypt at cost factor 12–14 before reaching the database. Passwords are never stored in a readable form and cannot be recovered — only reset.

What happens if I delete a QR code?

The short link stops resolving immediately, so scans of the printed code no longer reach the destination.