Terms of use

Terms of Service

DynamicQRS / dynamic-qrs.com
Effective and last updated: 9 August 2026

These Terms of Use (the Terms) govern access to and use of the DynamicQRS website, QR code application, redirect service, analytics tools, subscription features, and related services available through dynamic-qrs.com, www.dynamic-qrs.com, and related application pages (collectively, the Service).

The Service is operated by:

Presttige s. r. o.
Registered office: Veľké Bierovce, Slovakia
Company ID (IČO): 50 461 796
Commercial Register: Section Sro, Insert No. 33472/R
Email: info@dynamic-qrs.com

In these Terms, Presttige, DynamicQRS, we, us, and our refer to Presttige s. r. o. A User, you, or your means any visitor, registered user, subscriber, business, organization, or other person using the Service. A Consumer means an individual acting mainly outside their trade, business, craft, or profession.

By creating an account, selecting a subscription, clicking an acceptance checkbox, or otherwise using the Service, you agree to these Terms. If you do not agree, do not use the Service.

1. Scope and Order of Documents

These Terms apply globally, subject to mandatory laws that cannot be excluded by contract.

The following documents also form part of the agreement where applicable:

  • the Privacy Policy;
  • the Cookie Policy;
  • the pricing, plan, promotion, and checkout information presented before purchase; and
  • Annex A to these Terms, the Data Processing Addendum, where Presttige processes personal data on behalf of a business or organizational User.

If documents conflict, the checkout or order information controls commercial details for the specific purchase, Annex A controls processing performed by Presttige as a processor, and these Terms control all other matters. Mandatory consumer and data-protection law always prevails.

2. Eligibility and Authority

You may create an account only if you are legally capable of entering into a binding agreement. The Service is not directed to children. You must be at least 18 years old or have reached the age of legal majority in your country, whichever is higher, to purchase a subscription or operate an account for business purposes.

If you use the Service for a company, organization, client, or other legal entity, you confirm that you have authority to bind that entity. In that case, you includes that entity.

3. The Service

DynamicQRS provides tools that may allow Users to:

  • create static and dynamic QR codes;
  • configure destination URLs and device-specific redirects;
  • update dynamic QR destinations without replacing the printed QR code;
  • apply scan limits, fallback destinations, and access-control behavior;
  • view historical scan statistics and campaign analytics;
  • export available analytics data;
  • customize QR code colors and files; and
  • manage free or paid account features.

Available features depend on the current plan and may change in accordance with Section 20. The pricing page and checkout screen describe the features, billing period, price, currency, taxes where applicable, and promotional conditions for a purchase.

The Free plan may limit the number of active dynamic QR codes and may include a redirect delay. Paid plans may include instant redirects, additional customization, advanced analytics, scan-based access controls, exports, and device detection. References to unlimited scans or use remain subject to these Terms, technical limits, security controls, and the Fair Usage Policy.

4. Accounts and Security

You must provide accurate, current, and complete registration information and keep it updated. You are responsible for safeguarding your password, account sessions, and devices used to access the Service.

You must notify us promptly at info@dynamic-qrs.com if you suspect unauthorized account access, credential compromise, or misuse. You are responsible for activity performed through your account to the extent permitted by law, except where the activity results from our breach of duty.

We may require email verification, password resets, security checks, reCAPTCHA, or other reasonable measures to protect accounts and the Service. We may refuse or recover usernames that impersonate another person, infringe rights, or create security or operational risks.

5. Licence to Use the Service

Subject to these Terms, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable right to access and use the Service for lawful personal or internal business purposes during the term of your account.

You may not copy, sell, rent, lease, sublicense, reverse engineer, circumvent, scrape, or commercially exploit the Service except where expressly permitted by law or by written agreement with us. You may not access the Service to build or benchmark a competing service, interfere with its operation, or bypass plan, rate, scan, security, or access restrictions.

6. User Content and QR Destinations

User Content means information, text, URLs, files, contact details, event data, Wi-Fi details, payment links, labels, messages, redirect instructions, and other material that you submit, encode, configure, or make accessible through a QR code.

You retain ownership of your User Content. You grant Presttige a worldwide, non-exclusive, royalty-free licence to host, store, reproduce, format, transmit, redirect, and otherwise process User Content only as necessary to provide, secure, maintain, and support the Service and comply with law. After the relevant content is deleted or deactivated, this licence continues only to the extent necessary for restricted recovery storage, temporary backups, service security, fraud and abuse prevention, legal compliance, disputes, or legal claims, as described in the Privacy Policy.

You confirm that:

  • you own or have all rights and permissions needed for the User Content;
  • the User Content and destination do not violate law, these Terms, privacy rights, intellectual-property rights, or third-party agreements;
  • you have a lawful basis and provide required notices when entering another person’s personal data;
  • you will keep destination URLs, campaign information, and contact details accurate and safe; and
  • you will not place passwords, authentication secrets, payment credentials, sensitive health information, children’s data, or confidential third-party information in a QR code unless strictly necessary, secure, and lawful.

Dynamic QR codes redirect scanners to destinations selected by the QR owner. We do not control third-party destinations and do not endorse their content, availability, security, products, or privacy practices. QR owners are responsible for testing printed codes and destinations before distribution and after material changes.

7. Acceptable Use

You must not use the Service to create, distribute, redirect to, facilitate, or promote:

  • illegal goods, services, conduct, or instructions;
  • malware, viruses, harmful code, credential theft, phishing, spoofing, fraud, scams, or deceptive redirects;
  • spam, unsolicited bulk messaging, artificial scans, click manipulation, or abusive automation;
  • content that exploits or harms children;
  • terrorism, violent extremism, credible threats, or instructions intended to cause serious harm;
  • non-consensual intimate material, sexual exploitation, or unlawful sexually explicit content;
  • unlawful harassment, doxxing, impersonation, discrimination, or coordinated abuse;
  • infringement of copyright, trademark, privacy, publicity, database, or other rights;
  • medical, civic, or other misinformation where its distribution is unlawful or creates a material risk of serious harm; or
  • attempts to evade abuse detection, safety checks, plan limits, scan controls, or account restrictions.

You must not use analytics to unlawfully identify, profile, discriminate against, or target individual scanners. You must not combine scan information with other data in a manner that violates privacy, marketing, employment, credit, insurance, health, or anti-discrimination law.

We may investigate suspected violations and may disable a QR code, block a destination, limit activity, preserve relevant evidence, or suspend an account where reasonably necessary to protect users, third parties, or the Service. We may act without advance notice where the risk is urgent, unlawful, fraudulent, malicious, or could cause material harm. Where appropriate, we will provide a reason and a reasonable opportunity to contact us.

8. Fair Usage Policy

Free and paid plans are intended for ordinary personal, business, promotional, and campaign use. We may apply reasonable limits where usage:

  • materially degrades the Service for others;
  • is automated, artificial, fraudulent, or technically abusive;
  • creates unusual security, infrastructure, or third-party costs;
  • circumvents plan restrictions or is used for unauthorized resale; or
  • substantially exceeds normal usage patterns in a manner inconsistent with the selected plan.

Where practical, we will contact the account owner to clarify unusual use before imposing a non-urgent restriction. We may require a different plan, apply technical safeguards, temporarily limit traffic, or suspend the affected feature. Fair-use action will be proportionate to the operational or security risk.

9. Scan Analytics

When a dynamic QR code is scanned, the Service may process the QR identifier, scan date and time, browser session identifier, hashed IP address, approximate country or region, and broad device category. Raw IP addresses may be used temporarily to obtain approximate geolocation and are not displayed to QR owners through standard reports.

Scan analytics allow QR owners to measure campaign performance and understand general audience patterns, including how often, when, from which approximate locations, and from which device categories their QR codes are scanned. Analytics may be delayed, incomplete, duplicated, affected by privacy tools, or technically inaccurate. Location and device results are estimates and are not guaranteed to identify a scanner’s precise location, identity, or unique device.

Scan logs are retained while the related QR code and QR owner’s account remain active so the QR owner can access historical campaign analytics. We do not currently apply a fixed automatic expiration period to active scan logs.

When a user deletes a QR code, the QR code is deactivated and removed from ordinary account access. Deletion does not necessarily result in the immediate destruction of the QR image file, configuration, backups, or associated scan logs. These records may persist only as restricted server-side copies. The user can no longer access, modify, export, or erase those copies through ordinary account tools. Restricted recoverable server-side copies may be preserved in accordance with the Privacy Policy for accidental-deletion recovery, service integrity, or the proportionate preservation of records that may be relevant to suspected fraud or abuse, an existing or reasonably anticipated investigation, dispute resolution, legal compliance, or legal claims. This helps prevent the deletion function from being used to destroy or conceal potential evidence. Restoration is subject to technical availability and is not guaranteed.

10. Privacy Roles and Scanner Notices

When a business or organization uses DynamicQRS scan analytics for its own marketing, campaign measurement, or audience-analysis purposes, that QR owner determines the purpose of the processing and acts as controller where applicable. Presttige processes the scan information on the QR owner’s behalf to provide the analytics service, subject to Annex A.

QR owners are responsible for:

  • identifying an appropriate legal basis for their use of scan analytics;
  • providing scanners with any privacy notice required by applicable law;
  • responding to data-subject requests concerning their campaign analytics;
  • configuring and using the Service in a proportionate manner; and
  • complying with marketing, cookie, ePrivacy, employment, consumer, and data-protection laws applicable to their campaign.

Presttige separately acts as controller when it processes personal data for account management, billing, platform operation, service security, fraud and abuse prevention, legal compliance, support, and legal claims. Our controller processing is described in the Privacy Policy.

Where a scanner sends us a request relating to customer-controlled analytics, the scanner should provide the QR code or redirect URL and approximate scan date and time. We may forward the request or assist the relevant QR owner where appropriate and legally required.

11. Subscriptions, Billing, and Stripe

Paid features are offered as recurring monthly or yearly subscriptions, as shown before checkout. Subscriptions automatically renew for the same billing period until cancelled, unless the checkout terms state otherwise.

Stripe processes checkout, payment methods, subscription charges, invoices, and the billing portal. Payment-card details are provided to Stripe and are not stored in the DynamicQRS application database. Stripe may apply its own terms and privacy policy to its services.

By starting a paid subscription, you authorize Stripe and Presttige to charge the displayed subscription price, applicable taxes, and any clearly disclosed fees to your selected payment method at the start of each billing period. You must maintain a valid payment method.

If payment fails, we or Stripe may retry the charge, request another payment method, restrict paid features, or allow the subscription to expire. You remain responsible for undisputed amounts properly due.

12. Promotions and Free Periods

Promotional codes and free periods are subject to the conditions displayed with the offer or during checkout, including eligible plan, duration, expiry, and account limits. Unless stated otherwise:

  • a promotional code may be used once per eligible account;
  • the monthly subscription continues at the then-disclosed monthly price after the free period;
  • the payment method may be charged when the promotional period ends unless the subscription is cancelled beforehand; and
  • cancelling during a promotional period prevents future renewal but does not necessarily end access before the displayed period expires.

We may refuse or reverse a promotion obtained through fraud, duplicate accounts, technical manipulation, or material violation of its stated conditions. This does not affect mandatory consumer rights.

13. Cancellation

You may cancel a subscription at any time through the available account or Stripe billing portal controls or by contacting info@dynamic-qrs.com. Cancellation normally takes effect at the end of the current paid or promotional billing period. Pro features remain available until that time unless the account is suspended for a serious breach or the checkout information states otherwise.

Cancellation stops future renewals. It does not automatically refund charges already made. Refund and withdrawal rights are described in Section 14.

Before paid access ends, you should export any analytics you need and adjust QR configurations that rely on paid features. When an account returns to a Free plan, paid functionality may stop, and QR codes or settings exceeding Free-plan limits may be restricted until the account is upgraded or brought within the applicable limits.

14. Consumer Withdrawal and Refunds

Nothing in these Terms limits a Consumer’s mandatory rights.

14.1 EU/EEA Consumer Right of Withdrawal

Where EU or EEA consumer law applies, a Consumer normally has 14 days from conclusion of an online service contract to withdraw without giving a reason. To withdraw, send a clear statement to info@dynamic-qrs.com identifying the account and purchase.

If a Consumer expressly requests that paid services begin during the withdrawal period and later withdraws before the period ends, the Consumer may be required, where permitted by law, to pay a proportionate amount for services supplied before withdrawal. A withdrawal right may be lost after a service is fully performed or digital content is supplied only where the legal conditions, including prior express consent and acknowledgment, have been satisfied.

Where a valid withdrawal applies, we will provide the refund required by law using the original payment method unless another method is expressly agreed.

14.2 Voluntary 48-Hour Refund Policy

In addition to mandatory rights, refund requests submitted within 48 hours after a subscription charge will be accepted, provided the charge has not already been refunded, reversed, or disputed fraudulently. Requests after 48 hours may be considered at our discretion and do not limit any refund, remedy, or withdrawal right required by law.

14.3 Service Problems

Consumers may have statutory remedies if a digital service is not supplied, is defective, or does not conform to the contract. Contact info@dynamic-qrs.com with enough information for us to investigate. Nothing in these Terms replaces mandatory conformity, repair, price-reduction, termination, or refund rights.

15. Price and Plan Changes

We may change prices or plan features for valid business, technical, security, legal, or operational reasons. Price changes do not apply retroactively to a completed billing period.

We will provide reasonable advance notice of an increase affecting a recurring paid subscription. The User may cancel before the new price takes effect. Continuing the subscription after the effective date authorizes renewal at the new price, subject to mandatory law and any additional acceptance required by law.

If a material adverse feature change affects a paid subscription during a committed period, we will provide notice and an appropriate option, which may include continued access until period end, cancellation, migration, or a proportionate remedy where required by law.

16. Intellectual Property

The Service, software, source and object code, interface, designs, databases, documentation, trademarks, logos, and content provided by Presttige are owned by Presttige or its licensors and are protected by applicable intellectual-property laws.

Except for the limited right to use the Service under Section 5, these Terms do not transfer any Presttige intellectual-property rights to you.

If you voluntarily provide feedback or suggestions, you grant us a worldwide, perpetual, irrevocable, royalty-free right to use that feedback without identifying you or disclosing confidential information.

17. Third-Party Services

The Service may rely on or link to third-party services, including Stripe, Google security tools, geolocation providers, QR image providers, hosting, email, and destination websites. Third parties may change, suspend, or discontinue their services.

We are not responsible for third-party websites or services outside our reasonable control. Your use of a third-party service may be governed by that provider’s terms and privacy policy. This section does not limit liability that cannot lawfully be excluded.

18. Availability, Maintenance, and Changes to the Service

We aim to provide a reliable Service but do not guarantee uninterrupted, error-free, or permanent availability. The Service may be unavailable because of maintenance, updates, security incidents, provider outages, network conditions, legal requirements, or events outside reasonable control.

We may update, replace, or discontinue features for valid technical, security, legal, commercial, or operational reasons. We will provide reasonable notice where a change materially reduces a paid feature and advance notice is practicable.

QR owners should maintain suitable backups, exports, and alternative access arrangements for critical campaigns. The Service is not designed for emergency communications, life-safety systems, access to essential medical care, or other uses where failure could reasonably cause death, personal injury, or serious property damage.

19. Suspension and Termination

You may stop using the Service or request account closure at any time. Subscription cancellation and account deletion are separate actions unless the interface expressly combines them.

We may suspend or terminate access where:

  • you materially or repeatedly breach these Terms;
  • your use is illegal, fraudulent, malicious, or creates a serious security risk;
  • payment remains overdue after reasonable attempts to resolve it;
  • suspension is required by law, court order, regulator, or service provider; or
  • continuing the account would create material harm to users, third parties, or the Service.

For non-urgent or remediable issues, we will normally provide notice and a reasonable opportunity to correct the breach. Immediate action may be taken for phishing, malware, fraud, child exploitation, credible threats, unlawful content, active attacks, or comparable urgent risks.

When access ends, dynamic QR redirects and paid features may stop working. You should export needed analytics before closing the account.

Selecting a deletion function for a QR code deactivates that QR code and removes it and its analytics from ordinary account access. It does not represent a promise that every associated file, configuration, backup, or scan record will be immediately and irreversibly destroyed. The user cannot access or erase restricted server-side copies through ordinary account tools. Where reasonably necessary and permitted by law, those copies may be preserved so deletion does not frustrate a security, fraud, abuse, dispute, or legal investigation. Restricted server-side copies are handled under the Privacy Policy and, where applicable, Annex A. Account closure, subscription cancellation, and QR-code deletion may have different effects.

Sections that by their nature should survive termination remain effective, including payment obligations, intellectual property, disclaimers, liability, business indemnity, dispute provisions, and data-processing duties that apply after termination.

20. Warranty Disclaimers

To the maximum extent permitted by law, the Service is provided on an as available basis. We do not promise that every QR code will scan in every environment, that every destination will remain available, that analytics will be complete or precise, or that safety checks will detect every harmful destination.

Factors outside our control, including print size, damage, contrast, lighting, camera quality, connectivity, browser settings, privacy tools, destination changes, and third-party outages, may affect QR operation and analytics.

For Consumers, this Section applies only to the extent consistent with mandatory rights relating to digital services, conformity, remedies, and reasonable care. No statement in these Terms excludes an express commitment made at checkout or a warranty that cannot lawfully be excluded.

21. Limitation of Liability

21.1 Consumers

For Consumers, Presttige is responsible as required by applicable mandatory law. Nothing in these Terms excludes or limits liability for fraud, wilful misconduct, gross negligence, death or personal injury caused by negligence where applicable, breach of mandatory consumer rights, or any other liability that cannot lawfully be excluded or limited.

21.2 Business and Organizational Users

To the maximum extent permitted by law, Presttige is not liable to a business or organizational User for indirect, incidental, special, punitive, or consequential loss, or for loss of profit, revenue, goodwill, anticipated savings, business opportunity, or data, arising from use of the Service.

Presttige’s aggregate contractual and non-contractual liability to a business or organizational User arising from the Service during any 12-month period will not exceed the greater of:

  • the subscription fees paid by that User to Presttige during the 12 months preceding the event giving rise to liability; or
  • EUR 100.

The exclusions and cap do not apply to fraud, wilful misconduct, gross negligence, death or personal injury caused by negligence where applicable, obligations that cannot lawfully be limited, or liability under data-protection law to the extent limitation is prohibited.

22. Business User Indemnity

This Section applies only to Users acting for business or organizational purposes, not to Consumers.

The business User will indemnify Presttige against third-party claims, damages, and reasonable costs to the extent caused by that User’s unlawful User Content, malicious QR destination, infringement of third-party rights, unlawful marketing or analytics activity, or material breach of Sections 6, 7, or 10.

Presttige must give reasonable notice of the claim and allow the User to participate in the defence. The User is not responsible for loss caused by Presttige’s own breach, negligence, wilful misconduct, or unauthorized processing. No settlement may impose liability, admission, or non-monetary obligation on Presttige without its written consent, not to be unreasonably withheld.

23. Complaints and Alternative Dispute Resolution

Please first send complaints or requests for correction to info@dynamic-qrs.com. Include your account email, relevant transaction or QR information, and the remedy requested. We will try to resolve the matter directly.

If a Consumer is dissatisfied with our response or receives no response to a request for redress within the period provided by Slovak law, the Consumer may contact an authorized alternative dispute resolution entity. For disputes within the residual competence of the Slovak Trade Inspection:

Slovenská obchodná inšpekcia
Central Inspectorate, Department for International Relations and Alternative Dispute Resolution
Bajkalská 21/A, P. O. Box 29, 827 99 Bratislava 27, Slovakia
Email: ars@soi.sk or adr@soi.sk
Website: Slovak Trade Inspection

Alternative dispute resolution does not remove the right to seek a judicial remedy. The former EU Online Dispute Resolution platform ceased operating on 20 July 2025 and is therefore not referenced as an active filing channel.

24. Governing Law and Courts

These Terms and the agreement are governed by the laws of the Slovak Republic, without regard to conflict-of-law rules.

If you are a Consumer, this choice does not deprive you of mandatory protections provided by the law of your country of habitual residence. Consumers may bring proceedings in any court available under mandatory consumer-jurisdiction rules.

For business and organizational Users, the courts having subject-matter jurisdiction for Presttige’s registered office will have exclusive jurisdiction, unless mandatory law requires otherwise.

25. Changes to These Terms

We may update these Terms for valid legal, regulatory, security, technical, service, or commercial reasons. The updated Terms will show a new effective date.

For material changes affecting an active paid subscription, we will provide at least 30 days’ advance notice where practicable. If a change materially disadvantages the User, the User may cancel before it takes effect. Changes required urgently for law or security may take effect sooner, but we will provide notice as soon as reasonably possible.

Continued use after the effective date constitutes acceptance only to the extent permitted by law. Where fresh express consent is legally required, we will request it.

26. General Terms

Notices. We may send operational or contractual notices by email, through the account interface, or by a prominent website notice. You must keep your account email current.

Assignment. You may not assign the agreement without our written consent, except where mandatory law permits. We may assign it as part of a merger, restructuring, sale of business, or transfer of the Service, provided this does not reduce mandatory consumer or data-protection rights.

No waiver. A failure or delay in enforcing a provision is not a waiver of that provision.

Severability. If a provision is invalid or unenforceable, it will be limited or removed only to the minimum extent required, and the remaining provisions will continue to apply.

Entire agreement. These Terms and the documents incorporated under Section 1 form the entire agreement concerning the Service, without excluding statements or rights that cannot lawfully be excluded.

Contact. Questions about these Terms may be sent to info@dynamic-qrs.com.

Annex A: Data Processing Addendum

This Data Processing Addendum (DPA) forms part of the Terms where a business or organizational User (Customer) uses the Service to process personal data for which Customer is a controller and Presttige acts as processor.

A1. Roles and Instructions

Customer is the controller and Presttige is the processor for Customer Personal Data processed through customer-configured scan analytics. Each party will comply with the GDPR and other data-protection law applicable to its role.

Customer instructs Presttige to process Customer Personal Data only as necessary to provide, secure, support, and maintain the configured Service; comply with Customer’s lawful use of features; and perform obligations under the agreement. The Terms, Customer’s account configuration, support requests, and other documented directions constitute Customer’s instructions.

Presttige will inform Customer if, in its reasonable opinion, an instruction infringes applicable data-protection law, unless law prohibits that notice. Presttige may suspend the affected processing until the parties resolve the issue.

A2. Processing Details

Subject matter: Dynamic QR redirection, scan collection, historical analytics, campaign reporting, export, scan limits, device-based redirection, support, and related storage.

Duration: For the term of Customer’s account and for the period necessary to provide historical analytics and, after the relevant processing service ends, to return, delete, restrict, or anonymize Customer Personal Data in accordance with this Annex and applicable law.

Nature and purpose: Collection, transmission, organization, hashing, approximate geolocation, storage, retrieval, aggregation, display, export, restriction, deletion, and security processing needed to provide customer-controlled QR analytics.

Data subjects: People who scan Customer’s dynamic QR codes and, where relevant, Customer’s authorized account users.

Personal data: QR identifier, scan date and time, browser session identifier, hashed IP address, approximate country or region, broad device category, redirect configuration, scan-limit events, and information included by Customer in support instructions.

Special-category data: The Service is not intended for special-category or criminal-offence data. Customer must not intentionally submit or infer such data through scan analytics unless the parties have expressly agreed appropriate safeguards and the processing is lawful.

A3. Customer Obligations

Customer will:

  • ensure its instructions and use of the Service are lawful;
  • establish and document an appropriate legal basis;
  • provide required scanner and employee notices;
  • configure the Service in a proportionate and privacy-respecting manner;
  • respond to data-subject requests as controller;
  • avoid instructing Presttige to identify individual scanners from analytics; and
  • notify Presttige before using the Service for processing that presents unusual or high risks.

Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and for determining whether a data-protection impact assessment or consultation is required.

A4. Processor Obligations

Presttige will:

  • process Customer Personal Data only on documented instructions, unless EU or Member State law requires otherwise;
  • ensure persons authorized to process Customer Personal Data are bound by confidentiality;
  • implement appropriate technical and organizational measures proportionate to risk;
  • assist Customer, taking account of the nature of processing, with data-subject requests;
  • assist Customer with security, breach notification, impact assessments, and regulator consultations where reasonably required;
  • notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data;
  • make information reasonably necessary to demonstrate compliance with this DPA available to Customer; and
  • delete or return Customer Personal Data after the processing service ends, at Customer’s choice, and delete remaining copies unless applicable law requires storage.

Assistance beyond standard Service functionality may be subject to reasonable charges where permitted by law, particularly where a request is unusually complex or caused by Customer’s instructions.

A5. Security Measures

Presttige will maintain measures appropriate to the risk, including as applicable:

  • authenticated accounts and access controls;
  • password hashing and session-security measures;
  • QR ownership and authorization checks;
  • protection against cross-site request forgery for sensitive account operations;
  • temporary use of raw scan IP addresses for approximate geolocation followed by hashed storage in scan logs;
  • malicious-URL, blocked-domain, anti-bot, and abuse-prevention checks;
  • confidentiality obligations and need-based access for personnel and providers;
  • reasonable backup, logging, monitoring, update, and incident-response practices; and
  • transport encryption where supported by the Service and its providers.

No security measure eliminates all risk. Customer remains responsible for account credentials, User Content, campaign notices, and configuration decisions under its control.

A6. Subprocessors

Customer gives Presttige general authorization to engage subprocessors needed to provide the Service. These may include hosting and infrastructure providers, ipgeolocation.io for approximate location lookup, email providers, Google security services, QR image providers, support tools, and other providers identified in the Privacy Policy or a subprocessor notice.

Presttige will require subprocessors that process Customer Personal Data to provide data-protection obligations substantially equivalent to those applicable to Presttige under this DPA.

Presttige will provide reasonable notice of a new subprocessor that materially affects Customer Personal Data. Customer may object within 14 days on reasonable data-protection grounds. The parties will try to resolve the objection. If no reasonable alternative is available, Customer may stop using the affected feature or terminate the affected paid Service without penalty for future periods.

Presttige remains responsible for its subprocessors to the extent required by applicable law.

A7. International Transfers

Presttige will not transfer Customer Personal Data from the EEA to a country lacking an applicable adequacy decision unless a lawful transfer mechanism and required supplementary measures are in place. These may include the European Commission’s Standard Contractual Clauses, an adequacy decision, or another mechanism permitted by Chapter V GDPR.

Customer authorizes transfers necessary for the Service where those safeguards apply.

A8. Data-Subject Requests

If Presttige receives a request that relates to Customer-controlled processing, Presttige may direct the requester to Customer or notify Customer, unless prohibited by law. Customer remains responsible for responding as controller. Presttige will provide reasonable assistance using information available to it.

Because standard analytics are pseudonymous and do not display raw IP addresses or names, a requester may need to provide the QR code or redirect URL, approximate scan date and time, and other proportionate details needed to locate relevant data. Neither party will collect unnecessary identity information solely to handle a request.

A9. Audits

To the extent required by Article 28 GDPR, Presttige will make available information reasonably necessary to demonstrate compliance and will permit and contribute to an audit of the processing covered by this Annex.

A Customer requesting an audit must first submit a reasonable written request identifying the proposed scope and grounds. The parties will agree in good faith on the timing, method, confidentiality, security protections, and costs. Requests should normally be addressed through written responses, relevant policies or system descriptions, and remote review before an inspection is considered.

An inspection may be requested where those measures are insufficient, where there are reasonable indications of non-compliance, or where a competent supervisory authority requires it. Any inspection must, where appropriate, take place on reasonable notice, during normal business hours, and in a manner that protects other customers’ data, service security, confidential information, and legal privilege. Presttige is not required to provide access to unrelated customer data or unrestricted access to systems, source code, or premises unless applicable law or a competent authority specifically requires it. Customer bears its audit costs unless the audit identifies a material breach by Presttige.

A10. Deletion, Return, and Survival

During the account term, scan analytics are retained as described in Section 9. Selecting the ordinary QR-code deletion function deactivates the QR code and removes the related information from Customer’s ordinary account access; it is not an instruction to immediately destroy every copy. Customer cannot access or erase restricted server-side copies through ordinary account tools. Restricted recoverable server-side copies may remain available for accidental-deletion recovery as described in the Privacy Policy.

After the processing service ends, Presttige will, at Customer’s choice, delete or return Customer Personal Data and delete remaining copies, unless applicable law requires storage. Data remaining in protected backups may be isolated from ordinary use and deleted through the normal backup cycle.

Where permitted by applicable law, Presttige may independently retain the minimum information reasonably necessary for its own service security, fraud and abuse prevention, an existing or reasonably anticipated investigation, legal compliance, disputes, or the establishment, exercise, or defence of legal claims. This proportionate preservation is intended to prevent a deletion action from destroying or concealing potential evidence relevant to such a matter. Presttige acts as controller for that separate processing; retained information is access-restricted and is no longer made available as Customer analytics.

This DPA survives termination for as long as Presttige processes Customer Personal Data. If this DPA conflicts with another part of the Terms concerning processor obligations, this DPA controls.

Dynamic-qrs

A dynamic QR code is a type of QR code that allows you to change the content or target URL after it has been printed or distributed, without needing to create a new code

Copyright © 2026 dynamic-qrs. All Rights Reserved.