Privacy Policy for QRGeno by Paperphyte AB
Last updated: 2026-06-14
1. Introduction and responsibility for the processing of your personal data
Paperphyte AB ("the Company", "we", "us") is committed to protecting your personal data and strives to ensure a high level of data protection in accordance with applicable data protection legislation, including Regulation (EU) 2016/679 of the European Parliament and of the Council ("GDPR"). This privacy policy describes how we collect, process, store and protect personal data in connection with the use of our services.
2. Parties and responsibility for the processing of your personal data
Paperphyte AB is the data controller for the processing of personal data carried out within the Company's operations. This means that the Company is responsible for ensuring that processing is carried out in accordance with applicable legislation and that your rights as a data subject are upheld. In certain cases, the Company may engage data processors who process personal data on the Company's behalf. Such processors are bound by data processing agreements.
3. What categories of personal data do we process, for what purpose, storage period and on what legal basis?
The Company processes personal data such as contact details (name, email address), administrator account information (company name, organisation number, VAT registration number), technical information (IP address, device category, anonymised user-agent), geographic information derived from the IP address (country, and city/region for customers on paid plans; country lookup is performed locally on our servers using the embedded MaxMind GeoLite2 database — no IP address is transmitted to MaxMind), payment data processed via Mollie, shipping data for printed materials (where the Customer has placed a print order through the Services), submission data captured by gate rules (email address, or the fact of password entry) where the Customer has configured such rules on their QR code, contact-form messages (name, email, message content) processed via Mailgun, and other user data linked to our services. Personal data is only stored for as long as necessary to fulfil the purposes for which the data was collected, or for as long as required by applicable law or regulatory decision, including the Swedish Accounting Act (Bokföringslagen 1999:1078).
3.1 Managing orders and purchases of services
Purpose: To enable the management of orders, invoicing and payment. Categories of personal data: Name, contact details, payment information. Legal basis: Performance of a contract. Storage period: The data is stored for the duration of the contract and thereafter for up to seven (7) years in accordance with applicable accounting legislation.
3.2 Provision of services
Purpose: To deliver and administer the Company's services. Categories of personal data: Account details, user data, scan analytics (impressions). Legal basis: Performance of a contract. Storage period: Account data is retained for the duration of the contract and up to twelve (12) months after termination, unless longer storage is required by law or to establish, exercise or defend legal claims. Scan analytics (impressions) and gate-submission data are currently retained indefinitely under fair use, until the Customer requests erasure. Customers may request earlier erasure of this data by contacting the Company via our contact form; self-service erasure from the dashboard is not currently offered.
3.3 Storage of customer data after termination of contract
Purpose: To fulfil legal obligations and enable restoration of services. Categories of personal data: Customer data, user-generated content. Legal basis: Legal obligation and legitimate interest. Storage period: Up to twelve (12) months after termination of the contract, unless otherwise required by law or specific agreements.
3.4 Security purposes
Purpose: To prevent, detect and investigate security incidents. Categories of personal data: Log data, IP address. Legal basis: Legitimate interest. Storage period: Logs are normally retained for up to twelve (12) months, unless longer retention is required to investigate security incidents.
3.5 Service and product development
Purpose: To analyse usage and improve services. Categories of personal data: Usage data, technical information. Legal basis: Legitimate interest. Storage period: Data is processed in anonymised or aggregated form where possible and stored for up to twenty-four (24) months.
3.6 Marketing
Purpose: Where the Customer has explicitly opted in, to communicate product news, updates and offers from Paperphyte AB. Categories of personal data: Contact details (name, email address). Legal basis: Consent or, in the case of existing customers, legitimate interest with a clear opt-out in every message. Storage period: Data is processed until consent is withdrawn or an objection to the processing is received. Note on current practice: at the time of writing, the Company does not employ third-party marketing or advertising trackers and does not run behavioural marketing campaigns. If we adopt such tools, we will update this policy and obtain the necessary consent before any non-essential third-party tracking is enabled.
3.7 Newsletter and communications
Purpose: To send product newsletters and other product communications, where you have explicitly subscribed. Categories of personal data: Email address (and, where provided, name). Legal basis: Consent. Storage period: Data is processed until consent is withdrawn. Note: at the time of writing, the platform does not host a public newsletter signup. This section will become operative once such a channel is launched.
4. Collection of your personal data
Personal data is collected directly from you in connection with registration, use of services and via automated technologies such as cookies and similar tracking technologies.
5. What happens if you choose not to provide us with your personal data?
If you choose not to provide necessary personal data, the Company may be prevented from entering into an agreement with you or from providing some or all of its services.
6. With whom do we share your personal data?
The Company shares personal data only with the data processors necessary to operate the Services, all bound by Article 28 GDPR data processing agreements. Our current sub-processors are: • Amazon Web Services (AWS) — Infrastructure, application hosting and storage (eu-north-1, Stockholm) • Auth0 (Okta group) — Authentication and identity • Mollie B.V. — Payment processing (Netherlands) • CloudPrinter ApS — Print production and fulfilment for printed materials ordered through the Services (Denmark) • Sanity.io — Content delivery for marketing pages, legal pages, and the product catalog (EU region) • Mailgun (Sinch Email) — Transactional email for the contact form (Mailgun EU API) • Vercel Inc. — Hosting and global edge delivery for the public website and web app (United States, with EU edge locations). Processes IP addresses and request metadata for routing, caching and DDoS protection • Google LLC — Provides Google Fonts (fonts.googleapis.com / fonts.gstatic.com) used for typography on the public website. Receives the visitor's IP address and User-Agent when a font file is fetched (United States) • InnoCraft Ltd — Provides Matomo Cloud web analytics for the public website (New Zealand, covered by a European Commission adequacy decision). Used only with the visitor's consent; processes anonymised IP address, pages viewed, referrer and device/browser type We use Matomo (Matomo Cloud, provided by InnoCraft Ltd) for privacy-friendly web analytics on our public website, loaded only after the visitor has given consent (Article 6.1(a) GDPR) and never on the pages linked to dynamic QR codes. The visitor can withdraw or renew consent at any time via the "Manage cookies" control in the website footer. We do not use Google Analytics and do not share personal data with advertising platforms (such as Google Ads, Facebook Ads or LinkedIn Ads). If this changes we will update this policy and obtain consent where required. Beyond the above, the Company may share data with banks, auditors, tax authorities, or other authorities where required by law.
7. Use of tracking technology and profiling
When using the Company's services, including dynamic QR codes, certain technical information may be collected automatically. When a visitor follows the redirect for a dynamic QR code, the following information is recorded and linked to the visit (impression): • IP address • Geographic location: country derived from the IP address; city and region are also recorded for customers on paid plans • Device category (mobile, tablet, desktop) and anonymised user-agent • Referrer (where supplied by the browser) • Timestamp of the scan Where the QR code's owner has explicitly enabled precise-geo capture for that specific QR (an opt-in setting per QR), the visitor's browser is also asked for GPS coordinates (latitude, longitude, accuracy radius). The visitor sees the standard browser permission prompt and may decline; declining does not block the redirect. Where the Customer has configured an email-gate or password-gate rule on a QR, the email address (or the fact of password entry) submitted by the visitor before the redirect is recorded as a gate submission. The Customer may export this submission data on the Enterprise plan. This information is stored as part of the impression and is used by the QR code owner to understand when, from where and with which device the code was scanned. The processing is necessary to fulfil the contract with the Customer who created the QR code (Article 6.1(b) GDPR). No tracking cookies are set on the QR redirect itself. Other technical information (server logs, error reports) is used for analysis, security and service improvement, on the basis of legitimate interest. Storage period — impression and gate-submission data: currently retained indefinitely under fair use, until the Customer requests erasure. Deleting your administrator account from the dashboard (see Section 8) anonymises your account information and soft-deletes the QR codes you own, but does not by itself delete the impression records previously generated by those QR codes; to request erasure of impression records, please contact us via the contact form. Server logs are normally retained for up to twelve (12) months unless longer retention is required to investigate a security incident.
8. Your rights as a data subject
In accordance with the GDPR, you have the following rights: Right of access – You have the right to request information about what personal data we process about you. Right to rectification – You have the right to request that incorrect or incomplete data be corrected. Right to erasure ("the right to be forgotten") – You have the right to request that your personal data be deleted under certain conditions. Right to restriction of processing – You have the right to request that the processing of your personal data be restricted. Right to data portability – You have the right to receive your personal data in a structured, commonly used and machine-readable format. Right to object – You have the right to object to processing carried out on the basis of legitimate interest. Right to withdraw consent – You have the right to withdraw consent given at any time. You can delete your account yourself at any time from the dashboard (Profile → Account → "Delete account"). This cancels any active subscription, anonymises your account information, soft-deletes the QR codes you own and deletes your Auth0 identity. To exercise any of the other rights listed above — or to request erasure of impression records that remain after account deletion, as described in Section 7 — please contact the Company via the contact form. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
9. Supervisory authority
The Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) is the competent supervisory authority in Sweden. You have the right to lodge a complaint with IMY if you believe that our processing of your personal data is in breach of applicable data protection legislation.