Privacy Policy
Last updated: May 11, 2026
This is a courtesy translation. The German version is legally binding. Read the German version
This privacy policy (Datenschutzerklärung) informs you about which personal data QR Kontor (https://qrkontor.de) processes, for what purpose, on what legal basis, to whom it is disclosed, and which rights you have under the General Data Protection Regulation (GDPR (DSGVO)), the German Federal Data Protection Act (BDSG) and the German Digital Services Act (DDG).
1. Controller
The controller for data processing within the meaning of Art. 4 No. 7 GDPR is:
Thomas Rohmberger · Rohmberger Design
Waldstr. 81
04105 Leipzig, Deutschland
Email: info@qrkontor.de
A data protection officer is not legally required (§ 38 BDSG). If you have questions about data protection, please contact the email address above.
2. Definitions and general notes
We use the terms as defined in Art. 4 GDPR. "Processing" means any operation performed on personal data; "personal data" is any information relating to an identified or identifiable natural person.
Data transmission on the internet (e.g. email communication) is generally encrypted; however, complete protection against access by third parties cannot be technically guaranteed.
3. Which data we process
3.1 Visiting the website (server log files)
When you visit qrkontor.de, our hosting partner Vercel processes technical data that your browser transmits automatically. In the edge layer, country and city are derived from the Vercel headers x-vercel-ip-country and x-vercel-ip-city. The full IP address is not stored permanently.
- Date and time of access
- Requested URL and HTTP method
- HTTP status, amount of data transferred
- User agent (browser, operating system)
- Referrer (if transmitted)
- Derived country and city (via Vercel edge headers)
Purpose: stable operation, security, abuse prevention.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest).
Retention period: short-term as part of Vercel's standard processes; aggregate logs are deleted or anonymized after a maximum of 30 days.
3.2 Account registration and management
When you create or use an account, we process the following data:
- Email address (for authentication and communication)
- Name (optional, if you provide it)
- Stripe customer ID (to assign payments and subscriptions)
- Account metadata (creation date, booked plan, number of slots in use)
- Authentication sessions (via Supabase Auth, stored in a session cookie on your device)
Purpose: provision and management of the user account, authentication.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract or pre-contractual measures).
3.3 QR code content (vCard, target URLs)
You decide which content sits behind your QR codes. For dynamic redirects, we store the target URL you provide; for vCard QR codes, the contact details you provide. This data is processed solely for the purpose of delivering it to scanning devices.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract). Legal responsibility for the content lies with you; for vCards containing third-party data, you are the controller within the meaning of the GDPR.
3.4 Scan statistics
Each time one of your dynamic QR codes is scanned, we collect only aggregated, non-personal data:
- Country and city, derived from the Vercel edge headers
x-vercel-ip-country/x-vercel-ip-city– without storing the IP address - User agent (device type, browser, operating system)
- Referrer (if transmitted)
- Timestamp of the scan
We store no IP addresses and set no cookies on the scanning person's device, and there is no cross-site or cross-device tracking. The data does not allow conclusions to be drawn about individual persons.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest of the account holder in measuring the success of their codes). Since no personal data is processed and no information is stored on or read from the device, consent under § 25 TDDDG is not required.
3.5 Payment processing
All payments (one-time payments for slot packs and the Pro subscription) are processed via Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Irland. We receive from Stripe only the data necessary for contract performance and invoicing, in particular the Stripe customer ID, name, billing address, booked service and amount.
Card data, bank details and other payment method data are processed exclusively by Stripe. We ourselves do not store, see or process any card or bank data.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (c) GDPR (legal obligations under tax and commercial law).
3.6 Transactional emails
To send system emails (e.g. confirmation email on registration, invoices, cancellation confirmations), we use Resend (2261 Market Street #5039, San Francisco, CA 94114, USA). The data necessary for sending is processed (email address, message content, time of sending). We send marketing emails only with separate consent.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) or Art. 6 (1) (a) GDPR (consent), insofar as marketing content is concerned.
4. Cookies and similar technologies
QR Kontor uses only technically necessary cookies:
sb-*– authentication session cookie (Supabase Auth). Lifetime: until logout or expiry of the session.__stripe_*/cid– session cookies that Stripe sets only during a checkout process to prevent fraud and complete the payment. Lifetime: persistent only while Stripe Checkout is active; otherwise session.
These cookies do not require consent under § 25 (2) TDDDG, as they are strictly necessary to provide the telemedia service you have expressly requested (login, checkout).
We use no marketing, advertising or analytics cookies. In particular, we do not use Google Analytics, Meta Pixel, LinkedIn Insight Tag or comparable third-party trackers. A cookie banner requesting consent is therefore not required.
5. Recipients and processors
We use carefully selected service providers as processors within the meaning of Art. 28 GDPR. Data processing agreements (DPA, German: AVV) are in place with all processors.
| Provider | Purpose | Processing location | DPA |
|---|---|---|---|
| Vercel Inc. | App hosting, edge functions, server logs | Frankfurt (fra1) (EU) | DPA |
| Supabase Inc. | Database, authentication, file storage | eu-central-1 – Frankfurt (EU) | DPA |
| Resend Inc. | Sending transactional emails | USA (EU SCC) | DPA |
| Stripe Payments Europe Ltd. | Payment processing, subscription management | EU (Ireland) | DPA |
6. Transfer to third countries
Primary data processing takes place exclusively in EU data centers (Vercel: Frankfurt; Supabase: Frankfurt / eu-central-1; Stripe: Dublin, Ireland). A transfer of personal data to third countries is not required in normal operation.
Since Vercel Inc. and Resend Inc. are headquartered in the USA, a transfer to a third country cannot be ruled out in individual cases (e.g. support access or central account management). Both providers are certified under the EU-US Data Privacy Framework; in addition, EU standard contractual clauses (SCC) under Art. 46 (2) (c) GDPR have been concluded. Additional technical measures (transport encryption, encryption at rest) are implemented.
7. Retention period
- Account data: until the account is deleted by you or by us;
- QR codes and user-provided content: until you delete them or until the account is deleted;
- Scan statistics: aggregated without personal reference, otherwise available in the account without limit; deleted when the account is deleted;
- Accounting-relevant data (invoices, tax records): 10 years under § 147 AO and § 257 HGB (German tax and commercial codes);
- Server logs: short-term at provider level, usually deleted or anonymized within 30 days.
8. Your rights as a data subject
Under the GDPR, you have in particular the following rights:
- Access to the data stored about you (Art. 15 GDPR);
- Rectification of inaccurate data (Art. 16 GDPR);
- Erasure of your data, unless a statutory retention obligation applies (Art. 17 GDPR);
- Restriction of processing (Art. 18 GDPR);
- Data portability in a structured, commonly used and machine-readable format (Art. 20 GDPR);
- Objection to processing based on Art. 6 (1) (f) GDPR (Art. 21 GDPR);
- Withdrawal of consent with effect for the future (Art. 7 (3) GDPR).
To exercise your rights, an informal email to info@qrkontor.de is sufficient.
9. Right to lodge a complaint with a supervisory authority
Without prejudice to other remedies, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The supervisory authority responsible for the provider is:
Sächsische Datenschutz- und Transparenzbeauftragte (Saxon Data Protection and Transparency Commissioner)
Devrientstraße 1, 01067 Dresden
Web: www.saechsdsb.de
10. Automated decisions, profiling
No decision based solely on automated processing within the meaning of Art. 22 GDPR takes place. We do not carry out profiling.
11. Changes to this privacy policy
We reserve the right to adapt this privacy policy to reflect changes in the law, changes in processing or new features. The version published on qrkontor.de at the time of access applies. We inform active users of material changes by email.