Legal
Privacy Policy
Last updated: 30 July 2026
1. Who we are
EnterQR is operated by Junex AB, company registration number 559587-1392, at Pålsbodagatan 23, Örebro, Sweden. Junex AB is the data controller for personal data used to operate EnterQR, administer accounts, manage subscriptions, provide support and keep the service secure.
For personal data placed in customer instructions or other customer content, the customer normally decides why and how that data is used. In that situation the customer is the data controller and Junex AB acts as a data processor on the customer's behalf under the Data Processing Agreement.
2. Personal data we process
- Account data, such as name, business email address, company name, role and account identifiers.
- Authentication and security data, such as session information, login events and access records.
- Customer content and metadata, including items, instructions, steps, uploaded media and publication status.
- Employee suggestion data, including the submitter's name, proposed changes, optional images and related metadata.
- Subscription and transaction identifiers. Payment card details are handled by the payment provider and are not stored by EnterQR.
- Technical data, such as IP address, device and browser information, timestamps, error logs and service usage data.
- Communications sent to support or otherwise relating to the customer relationship.
3. Why we use personal data
- To create accounts and provide the EnterQR service.
- To authenticate managers and protect customer workspaces.
- To process subscriptions, payments and account changes.
- To store, publish and deliver customer instructions.
- To receive and route employee suggestions for review.
- To provide support and communicate about the service.
- To detect abuse, investigate errors and improve reliability.
- To comply with accounting, tax and other legal obligations.
4. Legal bases
Depending on the processing, we rely on performance of a contract, compliance with legal obligations, our legitimate interests in operating and securing the service, or consent where consent is legally required. Legitimate interests are used only where those interests are not overridden by the rights and freedoms of the individual.
5. Sharing and service providers
We may share personal data with suppliers that support hosting, authentication, databases, file storage, payment processing, communications, security and technical operations. This currently includes infrastructure services used by EnterQR and may include Supabase and Stripe where their respective services are enabled.
We may also disclose information to professional advisers, authorities or other recipients where required by law, necessary to establish or defend legal claims, or needed to protect the service and its users. We do not sell personal data.
When customers place personal data in their workspace, they are responsible for ensuring that they have a lawful reason to use it. Junex AB processes that data only to provide EnterQR under the Data Processing Agreement.
6. International transfers
Some service providers may process data outside Sweden or the European Economic Area. Where required, we use an adequacy decision, approved contractual safeguards or another lawful transfer mechanism.
7. Retention
We retain personal data only for as long as needed for the purposes described in this Policy. Account and customer content is generally kept while the account is active and for a reasonable period afterwards to support recovery, resolve disputes and comply with legal obligations. Billing records may be retained for the period required by accounting and tax law.
Customers control much of the content in their workspace and may delete it through available service controls. Plan downgrades can make content unavailable without immediately deleting it.
8. Cookies and browser storage
EnterQR uses cookies, local storage and similar browser technologies that are strictly necessary to provide and secure the service. They may be used to:
- keep managers signed in and maintain authenticated sessions;
- protect accounts and prevent misuse of the service;
- remember essential service state and preferences; and
- support subscription payments and fraud prevention when Stripe checkout is used.
These necessary technologies cannot be disabled through a consent banner without affecting essential functionality. EnterQR does not currently use advertising cookies or non-essential analytics cookies. If non-essential analytics, advertising or similar technologies are introduced, we will provide information and request consent where required by law.
9. Public instruction content and security
Published item and instruction content is intentionally available without employee sign-in. Anyone who obtains, receives or discovers the relevant code or QR link may access and share it. Published content should therefore be treated as public, even if it is intended mainly for a particular workplace.
We use appropriate technical and organisational measures designed to protect personal data. No online service can guarantee absolute security. Customers must protect manager credentials and must not place personal data, special-category personal data, passwords, security information, trade secrets, confidential material or other sensitive or regulated information in published instructions. EnterQR is not intended to store secrets, so this information should not be uploaded to drafts or other customer fields either.
10. Your rights
Subject to applicable law, individuals may request access, correction, deletion, restriction or portability of their personal data, and may object to certain processing. Consent can be withdrawn at any time where processing relies on consent. These rights may be subject to legal exceptions.
Individuals also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority.
11. Customer-controlled data
Requests concerning personal data contained in a customer's instructions or workspace should normally be directed to that customer first. We assist customers with valid requests where we act as their data processor in accordance with the Data Processing Agreement.
12. Changes and contact
We may update this Policy and will change the date above when we do. Privacy questions or requests can be directed to Junex AB at info@enterqr.com.