Privacy Policy

Last updated: May 11, 2026

This is a courtesy translation. The German version is legally binding. Read the German version

This privacy policy (Datenschutzerklärung) informs you about which personal data QR Kontor (https://qrkontor.de) processes, for what purpose, on what legal basis, to whom it is disclosed, and which rights you have under the General Data Protection Regulation (GDPR (DSGVO)), the German Federal Data Protection Act (BDSG) and the German Digital Services Act (DDG).

1. Controller

The controller for data processing within the meaning of Art. 4 No. 7 GDPR is:
Thomas Rohmberger · Rohmberger Design
Waldstr. 81
04105 Leipzig, Deutschland
Email: info@qrkontor.de

A data protection officer is not legally required (§ 38 BDSG). If you have questions about data protection, please contact the email address above.

2. Definitions and general notes

We use the terms as defined in Art. 4 GDPR. "Processing" means any operation performed on personal data; "personal data" is any information relating to an identified or identifiable natural person.

Data transmission on the internet (e.g. email communication) is generally encrypted; however, complete protection against access by third parties cannot be technically guaranteed.

3. Which data we process

3.1 Visiting the website (server log files)

When you visit qrkontor.de, our hosting partner Vercel processes technical data that your browser transmits automatically. In the edge layer, country and city are derived from the Vercel headers x-vercel-ip-country and x-vercel-ip-city. The full IP address is not stored permanently.

Purpose: stable operation, security, abuse prevention.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest).
Retention period: short-term as part of Vercel's standard processes; aggregate logs are deleted or anonymized after a maximum of 30 days.

3.2 Account registration and management

When you create or use an account, we process the following data:

Purpose: provision and management of the user account, authentication.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract or pre-contractual measures).

3.3 QR code content (vCard, target URLs)

You decide which content sits behind your QR codes. For dynamic redirects, we store the target URL you provide; for vCard QR codes, the contact details you provide. This data is processed solely for the purpose of delivering it to scanning devices.

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract). Legal responsibility for the content lies with you; for vCards containing third-party data, you are the controller within the meaning of the GDPR.

3.4 Scan statistics

Each time one of your dynamic QR codes is scanned, we collect only aggregated, non-personal data:

We store no IP addresses and set no cookies on the scanning person's device, and there is no cross-site or cross-device tracking. The data does not allow conclusions to be drawn about individual persons.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest of the account holder in measuring the success of their codes). Since no personal data is processed and no information is stored on or read from the device, consent under § 25 TDDDG is not required.

3.5 Payment processing

All payments (one-time payments for slot packs and the Pro subscription) are processed via Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Irland. We receive from Stripe only the data necessary for contract performance and invoicing, in particular the Stripe customer ID, name, billing address, booked service and amount.

Card data, bank details and other payment method data are processed exclusively by Stripe. We ourselves do not store, see or process any card or bank data.

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (c) GDPR (legal obligations under tax and commercial law).

3.6 Transactional emails

To send system emails (e.g. confirmation email on registration, invoices, cancellation confirmations), we use Resend (2261 Market Street #5039, San Francisco, CA 94114, USA). The data necessary for sending is processed (email address, message content, time of sending). We send marketing emails only with separate consent.

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) or Art. 6 (1) (a) GDPR (consent), insofar as marketing content is concerned.

4. Cookies and similar technologies

QR Kontor uses only technically necessary cookies:

These cookies do not require consent under § 25 (2) TDDDG, as they are strictly necessary to provide the telemedia service you have expressly requested (login, checkout).

We use no marketing, advertising or analytics cookies. In particular, we do not use Google Analytics, Meta Pixel, LinkedIn Insight Tag or comparable third-party trackers. A cookie banner requesting consent is therefore not required.

5. Recipients and processors

We use carefully selected service providers as processors within the meaning of Art. 28 GDPR. Data processing agreements (DPA, German: AVV) are in place with all processors.

ProviderPurposeProcessing locationDPA
Vercel Inc.App hosting, edge functions, server logsFrankfurt (fra1) (EU)DPA
Supabase Inc.Database, authentication, file storageeu-central-1 – Frankfurt (EU)DPA
Resend Inc.Sending transactional emailsUSA (EU SCC)DPA
Stripe Payments Europe Ltd.Payment processing, subscription managementEU (Ireland)DPA

6. Transfer to third countries

Primary data processing takes place exclusively in EU data centers (Vercel: Frankfurt; Supabase: Frankfurt / eu-central-1; Stripe: Dublin, Ireland). A transfer of personal data to third countries is not required in normal operation.

Since Vercel Inc. and Resend Inc. are headquartered in the USA, a transfer to a third country cannot be ruled out in individual cases (e.g. support access or central account management). Both providers are certified under the EU-US Data Privacy Framework; in addition, EU standard contractual clauses (SCC) under Art. 46 (2) (c) GDPR have been concluded. Additional technical measures (transport encryption, encryption at rest) are implemented.

7. Retention period

8. Your rights as a data subject

Under the GDPR, you have in particular the following rights:

To exercise your rights, an informal email to info@qrkontor.de is sufficient.

9. Right to lodge a complaint with a supervisory authority

Without prejudice to other remedies, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The supervisory authority responsible for the provider is:

Sächsische Datenschutz- und Transparenzbeauftragte (Saxon Data Protection and Transparency Commissioner)
Devrientstraße 1, 01067 Dresden
Web: www.saechsdsb.de

10. Automated decisions, profiling

No decision based solely on automated processing within the meaning of Art. 22 GDPR takes place. We do not carry out profiling.

11. Changes to this privacy policy

We reserve the right to adapt this privacy policy to reflect changes in the law, changes in processing or new features. The version published on qrkontor.de at the time of access applies. We inform active users of material changes by email.