Qrious.
GDPR

GDPR Data Protection

This page explains how Qrious supports data protection rights under the General Data Protection Regulation (GDPR). It complements our Privacy Policy, which describes the data we process in more detail.

Controller and contact

Qrious is responsible for the account, QR code, uploaded file, billing status and support data processed through the service. GDPR and privacy requests can be sent to stefan@qrious.now or through the Contact page.

Your rights

Data we process

Qrious may process account details, authentication events, QR titles, destinations, uploaded files, design settings, subscription status, contact messages and anonymized scan analytics. Raw scanner IP addresses are not stored for QR analytics.

Legal bases

We process data to perform the service contract, protect accounts, prevent abuse, comply with legal and accounting obligations, answer support requests and improve the product through privacy-conscious operational analytics.

Processors

Qrious uses trusted providers such as Supabase for authentication, database and storage, Stripe for payments and subscription management, Resend or SMTP providers for email delivery, and hosting infrastructure for delivering the application.

Retention and deletion

Account, QR and uploaded-file data is kept while the account remains active or while needed for service, security, legal or accounting reasons. When deletion is requested, we remove or anonymize eligible data after verifying the request.

Response time

We aim to respond to GDPR requests within one month, as required by GDPR. Complex requests may take longer where the law allows it.

Complaints

If you believe your data protection rights were not respected, you may contact us first or file a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).