GDPR, privacy & cookies
QR-Database processes personal data on behalf of your organisation. This page transparently explains how we handle it.
Which data do we process?
To provide QR-Database we process: names and e-mail addresses of users, the loan and inspection history of company assets, and — only if your organisation enables it — contact details of guests when they scan and location data at the moment of scanning. We process this data solely to provide the service; it is never sold or used for advertising.
Where is your data stored?
All data is stored on servers within the European Union. We only engage sub-processors that comply with the GDPR and with whom a data processing agreement has been concluded. An up-to-date list of sub-processors is available on request via our contact form.
How long do we keep data?
Loan history is kept for 5 years by default, IP and location data for 90 days and expired access links for 30 days. Your organisation can adjust these periods. After expiry, data is automatically deleted or anonymised.
Cookies and similar technologies
QR-Database only uses cookies and similar storage techniques that are strictly necessary to make the service work. No consent is required for these, so we do not show a cookie banner.
We place a functional login cookie once you sign in (to remember your session) and store your light/dark theme preference locally in your browser. Both are necessary to use the service.
For our own, anonymous visitor statistics we do not use cookies but a temporary session ID that is only stored in your browser and disappears once you close the tab. We do not store your IP address, do not share this data with third parties, and use it solely to improve our own service.
We do not place advertising or tracking cookies from third parties, such as Google Analytics or Facebook Pixel. Should this change in the future, we will first ask for your consent via a cookie banner.
Your rights
Every user can view and export their own data from their profile. On termination, your organisation can have all data exported or fully anonymised. For access, correction or deletion requests, contact your organisation's administrator or us.
What do we do in case of a data breach?
In the event of a (suspected) data breach we inform affected organisations as soon as possible, at the latest within 72 hours, describing the nature, the scope and the measures taken. Where required we report the breach to the Dutch Data Protection Authority.
Questions about privacy?
Contact us via the contact form or e-mail info@qr-database.nl — we respond within two working days.