EnterQRBack to EnterQR

Legal

Data Processing Agreement

Last updated: 30 July 2026

This Data Processing Agreement ("DPA") forms part of the EnterQR Terms and Conditions. It is entered into between the customer identified in the EnterQR account or order documentation ("Customer") and Junex AB, Sweden ("EnterQR"). It applies automatically when EnterQR processes Customer Personal Data on the Customer's behalf.

1. Scope, definitions and priority

This DPA applies only to personal data processed by EnterQR as a processor on behalf of the Customer in connection with the EnterQR service ("Customer Personal Data"). It does not apply to personal data for which Junex AB acts as an independent controller, such as data used for account administration, billing, service security and its own legal obligations, as described in the Privacy Policy.

"Data Protection Laws" means the EU General Data Protection Regulation 2016/679 ("GDPR"), the Swedish Data Protection Act (2018:218), and any other data protection law that applies to the processing. Terms such as personal data, processing, controller, processor, data subject and personal data breach have the meanings given in applicable Data Protection Laws.

If this DPA conflicts with the Terms, this DPA prevails for the processing of Customer Personal Data. The Terms otherwise continue to apply.

2. Roles and documented instructions

The Customer is the controller and EnterQR is the processor for Customer Personal Data. Each party will comply with the obligations that apply to its role under Data Protection Laws.

EnterQR will process Customer Personal Data only on documented instructions from the Customer, including instructions expressed through the Terms, this DPA, the Customer's use and configuration of the service, and written support requests. EnterQR will not use Customer Personal Data for its own unrelated purposes.

If law requires EnterQR to process Customer Personal Data without a Customer instruction, EnterQR will inform the Customer before that processing unless the law prohibits notice. EnterQR will promptly inform the Customer if, in its opinion, an instruction infringes applicable Data Protection Laws.

3. Processing details

The subject matter, duration, nature, purpose, data types and data subject categories are described in Schedule 1. The Customer may provide further lawful instructions through the service, provided they are consistent with the agreement and do not require a material change to the service. Additional work may require a separate written agreement and reasonable fees.

4. Customer responsibilities

The Customer is responsible for:

  • ensuring that its instructions and processing have a valid legal basis and comply with Data Protection Laws;
  • providing required privacy information and handling data subject requests as controller;
  • limiting Customer Personal Data to what is necessary for the Customer's intended use of the service;
  • maintaining accurate manager permissions and protecting account credentials; and
  • ensuring it has the rights and authority required to upload, process and publish Customer content.

5. Public instruction content

The Customer acknowledges that publishing an item or instruction is a documented instruction to make that content available without end-user authentication. Anyone who obtains, receives or discovers the relevant item code or QR link may access, copy or share the published content. Published content must be treated as public even when it is intended mainly for a particular location or audience.

Customers should avoid including personal data in publicly accessible content unless it is necessary, lawful and appropriate for the intended purpose. The Customer is responsible for having a valid legal basis, providing required information to affected individuals and limiting personal data to what is necessary.

Special-category personal data, criminal-offence data, passwords, access credentials, security information, trade secrets, classified material and other confidential, sensitive or regulated information must not be included in published content. Because EnterQR is not designed as a repository for secrets, passwords, security information and confidential or similarly sensitive material must not be uploaded to drafts or other Customer fields either.

If the Customer publishes personal data, the Customer is responsible for the lawfulness and transparency of that public disclosure. EnterQR may restrict or remove content where reasonably necessary to protect individuals, security or the service.

6. Confidentiality

EnterQR will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations and access it only as necessary for their duties. These obligations continue after their access ends.

7. Security

Taking into account the state of the art, implementation costs, the nature, scope, context and purpose of processing, and the risks to individuals, EnterQR will maintain appropriate technical and organisational measures designed to protect Customer Personal Data. The measures currently used are summarised in Schedule 2.

Security measures protect restricted service areas and Customer Personal Data. They do not make content confidential after the Customer publishes it for code or QR access.

8. Subprocessors

The Customer gives EnterQR general written authorisation to use the subprocessors listed in Schedule 3 to provide the service. EnterQR will impose data protection obligations on each subprocessor that are no less protective than the relevant obligations in this DPA and remains responsible for the subprocessor's performance of those obligations.

EnterQR will give reasonable advance notice of a new or replacement subprocessor by updating Schedule 3 and, where the change may materially affect the processing, through the service or the Customer's registered contact. The Customer may object on reasonable data protection grounds within ten days of notice. The parties will work in good faith on a reasonable solution. If none is available, either party may terminate the affected service.

9. International transfers

EnterQR will not transfer Customer Personal Data outside the European Economic Area except on the Customer's documented instructions and in accordance with Data Protection Laws. Where required, EnterQR will use an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism, together with supplementary measures where appropriate.

10. Data subject requests

Taking into account the nature of the processing, EnterQR will provide reasonable assistance through appropriate technical and organisational measures so the Customer can respond to requests to exercise data subject rights. If EnterQR receives a request concerning Customer Personal Data directly, it will refer the requester to the Customer where legally permitted and will not respond substantively without the Customer's instructions.

11. Personal data breaches

EnterQR will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. As information becomes available, the notice will describe the nature of the breach, affected data and data subjects, likely consequences, and measures taken or proposed. EnterQR will provide reasonable assistance with the Customer's notification and documentation obligations.

12. Compliance assistance

Taking into account the nature of the processing and information available to EnterQR, EnterQR will provide reasonable assistance with the Customer's obligations concerning security, breach notifications, data protection impact assessments and prior consultation under Articles 32–36 GDPR. Assistance beyond standard service functionality may be subject to reasonable fees.

13. Return and deletion

During the subscription, the Customer may access, correct, unpublish and delete content through available service functions. Where export functionality is not available in the service, the Customer may contact EnterQR for reasonable assistance with obtaining Customer Personal Data in a commonly used format.

After the processing service ends, EnterQR will, at the Customer's choice, delete or return Customer Personal Data and delete remaining copies unless applicable law requires retention. The Customer should contact EnterQR if the relevant option is not available through service controls. Account and workspace deletion may be completed through the stated deletion process and recovery period.

Data retained in protected backups will remain isolated from normal use. Deleted or replaced media may remain in protected backup copies, and media placed in backup history is automatically deleted no later than 90 days after it is archived. Other backup copies are deleted through the applicable provider or service backup lifecycle. Data required for legal claims, security records or legal obligations may be retained only for the applicable period and protected under this DPA.

In the event of a serious service disruption, data-loss incident or recovery operation, the backup retention period may be temporarily extended where reasonably necessary to restore or verify Customer Personal Data. Any extension will be limited to the time required for recovery, and the data will remain protected and isolated from normal use.

14. Information and audits

EnterQR will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. The Customer may conduct, or appoint an independent auditor to conduct, an audit no more than once in any twelve-month period, unless a personal data breach, regulator request or credible evidence of material non-compliance justifies an additional audit.

Audits must be conducted on reasonable advance notice, during normal business hours, without accessing another customer's data or unreasonably disrupting the service. The Customer bears its audit costs unless the audit identifies a material breach by EnterQR. EnterQR may satisfy an audit request first through its current security documentation and, where available, relevant independent reports or certifications relating to its service providers.

15. Liability, governing law and duration

Liability under this DPA is subject to the liability provisions in the Terms to the extent permitted by law. This DPA is governed by Swedish law and the dispute provisions in the Terms.

This DPA remains in force while EnterQR processes Customer Personal Data. Provisions that by their nature must continue—including confidentiality, deletion, audit, liability and protection of retained data—survive termination.

Schedule 1 — Processing details

  • Subject matter: operation of the EnterQR QR-based instruction and information service for the Customer.
  • Duration: the subscription term and the limited period needed for return, deletion, backups and legally required retention.
  • Nature and purpose: collection, transmission, storage, organisation, retrieval, display, publication at the Customer's instruction, support, backup and deletion of items, instructions, steps, media and end-user suggestions.
  • Frequency: continuous or on demand, depending on the Customer's use of the service.
  • Data subjects: the Customer's managers, employees, contractors, visitors and other end users who access content or submit suggestions, and people incidentally identified in Customer content.
  • Personal data: names and contact details included in end-user suggestions; identifiers, images, voice or other information the Customer includes in restricted Customer content; and associated service metadata. Special-category and criminal-offence data are not intended or permitted.
  • Controller rights: the Customer may access, correct, export, publish, unpublish and delete content through available service controls and may issue lawful written instructions under this DPA.

Schedule 2 — Security measures

  • authenticated manager access and organisation-based separation of customer workspaces;
  • a minimum password length of twelve characters when manager passwords are created or reset;
  • role-based and least-privilege access for service administration;
  • encryption in transit and provider-managed protection of stored data;
  • logging, monitoring and procedures for investigating security events;
  • automated daily media backup to separate object storage, with protected backup history retained for no more than 90 days;
  • a documented media-restoration procedure that has been tested against a backup copy;
  • staging tests and documented procedures for incidents, system changes, dependency maintenance and vulnerability handling;
  • confidentiality obligations and security awareness for authorised personnel; and
  • periodic review of security measures, account access and subprocessor safeguards.

Schedule 3 — Authorised subprocessors

ProviderPurposeProcessing location
Supabase, Inc.Managed database, authentication and file storagePrimary project region in Ireland; ancillary processing as described in the provider's terms and safeguards
OpenAI service entity applicable to Junex AB's Sites accountApplication hosting, deployment and service operationEEA and other documented locations under an applicable transfer mechanism
Cloudflare, Inc.Media backup object storage, edge delivery and security infrastructureGlobal network, subject to applicable transfer safeguards

This list reflects the service architecture as of the date above. Junex AB will keep it current when subprocessors are added or replaced.

16. Contact

DPA notices and data protection questions may be directed to Junex AB at info@enterqr.com.

© 2026 EnterQR · Junex AB
Terms and ConditionsPrivacy PolicyContactHome