Skip to main content Skip to primary navigation
Data protection

Privacy policy

Complete information about processed data, purposes, retention and your rights.

  • Last updated : 20 August 2026
  • GDPR, French law and supervision by the CNIL.

Controller and scope

This policy explains how SaS processes personal data in connection with Green QRCode, its websites, applications, customer areas, forms, dynamic QR code services and related features. Full publisher details are available in the legal notice.

For platform, account, billing, security, support, cookie preference and own analytics operations, SaS acts as controller.

When a customer uses Green QRCode to publish a showcase or collect information through a form, that customer generally determines the purposes and means of the processing. The customer then acts as controller and SaS may act as processor, depending on the feature and applicable contractual terms.

Categories of data processed

Depending on how the service is used, the following categories may be processed:

  • Account and identity: name, email address, optional phone number, language, account status, email verification and authentication information.
  • Organisation and collaboration: account name, members, invitations, roles, permissions and administrative action history.
  • Subscriptions and billing: plan, orders, invoices, transaction or subscription identifiers and information required for accounting follow-up. Full payment card details are not stored by Green QRCode.
  • QR codes and content: titles, links, text, images, documents, contact details, showcase settings, custom domains and files voluntarily published or stored by users.
  • Public forms and requests: invitation responses, adoption enquiries, incident reports, contact details, messages, attachments and consents where those features are enabled by a customer.
  • Support and contact: identity, email address, subject, correspondence and information required to handle the request.
  • Newsletter: email address, chosen language, subscription status, consent and confirmation dates, unsubscribe date and technical delivery history.
  • Technical and security data: access logs, date and time, browser, device, platform, language, requested domain, security events and pseudonymised fingerprints derived from an IP address.
  • Privacy preferences: cookie choices, policy version, language and consent or withdrawal dates.

Purposes and legal bases

Data is processed only for specified purposes and on an appropriate legal basis:

  • Performance of a contract or pre-contractual steps: account creation and management, QR codes and showcases, collaboration, support, orders, subscriptions, payments, domains and requested features.
  • Legal obligations: invoicing, accounting, tax compliance, responses to competent authorities and retention of evidence required to establish or defend legal claims.
  • Legitimate interests: platform security, prevention of fraud and abuse, logging, service improvement, limited audience measurement and technical continuity, subject to the rights and freedoms of individuals.
  • Consent: non-essential cookies or trackers, optional communications and forms where consent is the selected legal basis. Consent may be withdrawn at any time without affecting earlier processing.

Where information is required to create an account, complete an order or provide a feature, failure to provide it may prevent the relevant operation.

QR code scans and analytics

When a QR code is scanned, Green QRCode may record the date and time, a pseudonymised visitor identifier, a fingerprint of the IP address after anonymisation, country or region when supplied by the infrastructure, device type, platform, browser, language and referring domain.

The full IP address is not retained in scan analytics. For IPv4, the final octet is removed before hashing; for IPv6, only part of the network prefix is retained before hashing. Identified bots and prefetch requests are excluded where technically possible.

This data is used to provide aggregated trends, measure QR code use, detect anomalies and protect the service. It is not used by SaS to build individual advertising profiles.

Public showcases, forms and sensitive data

Content a customer chooses to publish becomes available to people who hold the link or scan the QR code. The customer must ensure that it has the required rights and legal bases, informs the relevant individuals and limits published data to what is necessary.

Some showcases may contain particularly sensitive information, including health data in an emergency medical QR code, information about personal circumstances or incident-report attachments. These features must only be used with an appropriate legal basis, controlled access and enhanced data minimisation. SaS does not use this content for its own commercial purposes.

Requests submitted through public forms are available to the account holder and authorised team members. The customer is responsible for defining an appropriate retention period and handling rights requests concerning data it collects.

Newsletter and electronic communications

\n

Subscription to the Green QRCode newsletter is optional and based on your consent. After submitting the form, a confirmation email is sent and the subscription becomes active only after you confirm the address (double opt-in).

\n

The email address and chosen language are used to send GreenQRCode news, product information and related editorial communications. Each campaign provides an unsubscribe mechanism. You may withdraw consent at any time without affecting processing carried out before withdrawal.

\n

Unconfirmed subscription requests are automatically deleted after 30 days by default. Delivery-history email snapshots are anonymised after 180 days by default while aggregate campaign statistics may be retained. A suppression record may be retained where necessary to ensure that a person who has unsubscribed or must no longer receive messages is not contacted again inadvertently.

Cookies and similar technologies

Strictly necessary cookies may be used for authentication, security, session management, language, cart and billing operations, and to remember privacy preferences. They are required for the service to function.

Non-essential cookies or measurement tools are activated only after consent where consent is required. Choices may be changed or withdrawn from the Cookie preferences page. Further information is available in the Cookie policy.

Recipients and service providers

Data is available only to people and organisations that need it for their duties:

  • authorised SaS staff and service providers subject to confidentiality obligations;
  • the account holder and team members with the required permissions;
  • hosting, backup, storage, email, technical monitoring and support providers;
  • payment providers, including Stripe and PayPal, for operations they process under their own responsibility or contractual role;
  • administrative, judicial or legally authorised bodies where disclosure is required by law.

SaS does not sell personal data and does not disclose user data to advertisers so that they may directly target those individuals.

Transfers outside the European Economic Area

Some technical or payment providers may process data from a country outside the European Economic Area. Where such a transfer occurs, it must rely on a mechanism recognised by the GDPR, such as an adequacy decision, European Commission standard contractual clauses or another appropriate safeguard.

Information about applicable safeguards may be requested at contact@greenqrcode.com.

Retention periods

Data is retained only for as long as necessary for the relevant purpose and is then deleted, anonymised or archived where required by law.

  • Accounts, content and settings: for the contractual relationship, followed by the period required for closure, export, settlement of pending operations and compliance with legal duties.
  • Invoices and accounting records: for the statutory period applicable to accounting, tax and evidential obligations.
  • Scan analytics: for the period provided by the account plan and options, followed by deletion or aggregation when no longer needed.
  • Audit logs: 365 days by default.
  • Cookie consent history: 730 days by default.
  • Accepted or expired account invitations: technical deletion after 30 days by default.
  • Failed queue jobs: technical deletion after 30 days by default.
  • Unconfirmed newsletter requests: deletion after 30 days by default.
  • \n
  • Newsletter delivery email snapshots: anonymisation after 180 days by default; aggregate campaign statistics may be retained.
  • Support requests and public forms: for the time required to handle them and then according to applicable obligations and, for customer forms, that customer’s instructions and responsibilities.

Retention may be extended where required by a legal obligation, dispute, investigation, security measure or the establishment, exercise or defence of legal claims.

Security and confidentiality

SaS implements technical and organisational measures proportionate to the risks, including access and role controls, logical account isolation, password hashing, CSRF protection, rate limiting, email verification, security logging, backups and encryption in transit where available in the production environment.

No system can provide absolute security. Where an incident is likely to create a risk for individuals, the notification measures required by applicable law are applied.

Your rights

Depending on your circumstances and the legal basis, you may exercise the following rights:

  • access to personal data and a copy;
  • correction of inaccurate or incomplete data;
  • erasure where provided by law;
  • temporary restriction of processing;
  • objection to processing based on legitimate interests;
  • portability of data you provided, where applicable;
  • withdrawal of consent at any time for consent-based processing;
  • instructions concerning personal data after death where French law applies.

Requests may be sent to contact@greenqrcode.com and should identify the relevant account and processing. Identity evidence may be requested only where necessary to avoid disclosure to another person. A response is normally provided within one month, subject to the extensions allowed by the GDPR.

Authenticated users may also use the export and deletion tools available in their personal area, subject to safeguards preventing deletion of an account required for service continuity or compliance with a legal obligation.

Complaint to the French data protection authority

If, after contacting us, you believe your rights have not been respected, you may lodge a complaint with the French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), through its official website: www.cnil.fr/fr/plaintes.

Children and automated decisions

The service is not specifically directed at children. Where a child uses a feature or appears in content, the account holder must verify the required authorisations and safeguards.

For its own purposes, SaS does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect an individual.

Changes to this policy

This policy may be updated to reflect legal, technical or functional developments. The date shown at the top of the page is the last update of the published version. Where a change is material, additional notice may be displayed in the platform or sent to account holders.

Contact

For questions about personal data or to exercise a right, use the Contact page or email contact@greenqrcode.com.

On iPhone or iPad, open the Share menu and choose “Add to Home Screen”.
Update available

A new Green QRCode version is ready. The update will be applied in a controlled way.