qrgenoqrgeno

General Terms and Conditions for QRGeno by Paperphyte AB

Last updated: 2026-06-14

Definitions

In these Terms, the following terms shall have the meanings set out below: "Agreement" means these Terms including all appendices and the Company's privacy policy and cookie policy as amended from time to time, which form an integral part of the Agreement. "Services" means the digital services provided by the Company, including dynamic QR codes (link, Wi-Fi, voucher and contact types), the QR builder, scan analytics ("impression services"), bulk QR-code management, optional ordering of printed materials on behalf of the Customer, and associated APIs. "Customer" means a legal entity entering into an agreement with the Company. "Customer Data" means all data, including personal data, that the Customer or its end users contribute to the Services. "Personal Data" means data as defined in Regulation (EU) 2016/679 of the European Parliament and of the Council ("GDPR"). "Data Controller" and "Data Processor" shall have the meanings set out in the GDPR. "QRGeno API" means the Company's application programming interface, available on the Enterprise plan. "SLA" means the service level commitments set out in these Terms.

Access to the Services

The Company grants the Customer a non-exclusive, non-transferable and time-limited right to use the Services in accordance with the Agreement. The Company reserves the right to make changes to the Services at any time, provided that such changes do not materially impair the functionality.

Registering a Company

To use the Services, the Customer must register an account. The Customer must be a legal entity (company) with a valid VAT registration number. The Company does not accept private individuals as customers. The Customer is responsible for ensuring that the information provided, including VAT number, is accurate, complete and up to date. The Customer is also responsible for protecting its login credentials.

Payment of Customer Subscription

Fees shall be paid in advance via Mollie in accordance with the current price list. Listed prices are exclusive of VAT. For Swedish customers, 25% Swedish VAT is added at checkout. For other EU customers with a VAT number that the Company has been able to verify against the VIES register, reverse charge applies in accordance with applicable VAT legislation; if the VAT number cannot be verified, checkout is blocked until verification succeeds. In the event of late payment, the Company is entitled to charge late payment interest in accordance with the Swedish Interest Act (räntelagen).

Subscription and payment

The subscription runs on a rolling monthly or annual basis (depending on plan) with automatic renewal at the end of each billing period. The Customer may cancel at any time from the dashboard; the cancellation takes effect at the end of the current billing period and access to the Services remains available until then. After cancellation, the Customer's QR codes, designs, and scan history are retained but scans of the Customer's QR codes will return a 'subscription required' page until the Customer reactivates.

Procurement of Printed Materials on Behalf of the Customer

The Company provides, upon the Customer's express instruction, services relating to the ordering and procurement of printed materials. All such orders are placed exclusively on behalf of the Customer and in accordance with instructions provided by the Customer. The Customer bears full responsibility for ensuring that all specifications provided, including but not limited to material, format, print run and delivery address, are accurate and complete at the time of placing the order. The Company disclaims all liability for errors or deficiencies attributable to incomplete or incorrect instructions furnished by the Customer. All prices for printed materials quoted by the Company are exclusive of value added tax (VAT). Applicable VAT will be added and charged in accordance with the tax legislation in force from time to time.

Use of the Services

The Customer may not: • violate applicable law • attempt to circumvent security mechanisms • use the Services in a manner that causes overloading

Customer's IT environment

The Customer is responsible for the compatibility, security and function of its own IT environment.

Specifically regarding the QRGeno API

API access is included with the Enterprise plan and is made available as part of an enterprise engagement. The Company reserves the right to impose rate limits and other technical restrictions to protect the Service. Misuse may result in immediate suspension.

SLA and availability

The Company strives for high availability but does not guarantee uninterrupted operation. Planned maintenance shall be notified to the extent possible.

Support

Support is provided in accordance with the description published from time to time.

Restriction of access to the Services

The Company may restrict access in the event of a breach of the Agreement or a security risk.

Limitation of liability

The Company is only liable for direct damage. The Company is not liable for: • indirect damage • loss of data • loss of profit Maximum liability is limited to 12 months of fees.

Disclaimer for errors

The Services are provided "as is" without warranties.

Force Majeure

A party is not liable for events beyond its control.

Intellectual property rights

All rights belong to the Company.

Assignment

The Customer may not assign the Agreement without written approval.

Amendments

The Company may amend the Terms. Material changes shall be notified.

Notices

Shall be made in writing via email.

Invalidity

An invalid provision does not affect the remaining provisions.

Processing of personal data

Processing takes place in accordance with the GDPR, privacy policy and cookie policy.

Customer Data

The Customer is responsible for the lawfulness and accuracy of the data.

Storage of Customer Data

Takes place in accordance with the privacy policy.

Confidentiality

The parties shall maintain confidentiality.

Contract period and termination

The Customer may cancel the subscription at any time from the dashboard. The cancellation takes effect at the end of the current billing period; no further charges will be made. The Company may terminate the Agreement with thirty (30) days' written notice, save in the event of material breach where immediate termination may apply. The Customer's administrator may also permanently delete the account at any time from the dashboard (Profile → Account → "Delete account"). Account deletion cancels any active subscription, anonymises account information, soft-deletes the QR codes owned by the account and deletes the Auth0 identity. Bookkeeping records that the Company is required by law to retain (e.g. under the Swedish Accounting Act) will be kept for the legally required period.

Dispute resolution and applicable law

Disputes are resolved by the SCC. Swedish law applies.

Data Processing Agreement

The Company acts as data processor. (See appendices below)

Appendices

Appendix 1 – Data Processing Instructions (harmonised with the privacy policy) Appendix 2 – Security Measures (ISO/IEC 27001-aligned) Appendix 3 – Sub-processors: • Amazon Web Services • Auth0 • Mollie • CloudPrinter • Sanity.io • Mailgun • InnoCraft (Matomo Cloud) Appendix 4 – Third Country Transfers: EU residency is the default; SCC + TIA apply where US-incorporated providers are involved; New Zealand (Matomo Cloud) is covered by an adequacy decision.

Order of precedence between documents

In the event of conflict between documents, the following order of precedence shall apply: 1. Data Processing Agreement 2. These Terms 3. Privacy Policy 4. Cookie Policy This Agreement has been drawn up in accordance with Swedish law and practice.


Appendix 1 – Data Processing Instructions

1. Purpose of processing The Company shall process personal data to provide the Services, including: • Operation of dynamic QR codes • Collection and management of impression data (scan analytics) • Analysis and statistics • Optional API functionality (QRGeno API, Enterprise plan) • Optional ordering of printed materials on behalf of the Customer 2. Categories of data subjects • Customer's users (administrators) • End users interacting with QR codes • Recipients of printed materials (where the Customer has provided shipping data) 3. Categories of personal data • IP address • Technical information (device category, operating system, browser, anonymised user-agent) • Geographic information (country; city and region for paid plans) • Account information for the Customer's administrators (name, email, company, VAT) • Shipping data for printed materials (where provided by the Customer) • Data that the Customer itself contributes 4. Nature of processing • Collection • Recording • Structuring • Storage • Analysis • Erasure 5. Duration of processing Processing takes place for the duration of the agreement and in accordance with the privacy policy and applicable law. 6. Instructions Processing takes place only in accordance with: • These instructions • The Customer's documented instructions • Applicable law 7. Sub-processors The Company may engage sub-processors in accordance with Article 28 GDPR. The current list is set out in Appendix 3.

Appendix 2 – Security Measures

1. Access control • Least privilege • Secure authentication (MFA) 2. Encryption • TLS (data in transit) • Encryption at rest where applicable 3. Logging and monitoring • Logging of system access • Monitoring of security events 4. Vulnerability management • Regular security reviews • Patching and scanning 5. Backup and recovery • Regular backups • Disaster recovery processes 6. Incident management • Incident detection • Reporting without undue delay 7. Organisational measures • Internal security policies • Staff training • Confidentiality commitments Measures are continuously adapted according to risk and standards such as ISO/IEC 27001.

Appendix 3 – Sub-processors

Suppliers • Amazon Web Services EMEA SARL (AWS) – Infrastructure, application hosting and storage. Region: eu-north-1 (Stockholm). • Auth0, Inc. (Okta group) – Authentication and identity. EU tenancy. • Mollie B.V. – Payment processing. Headquartered in the Netherlands (EU). • CloudPrinter ApS – Print production and fulfilment for printed materials ordered through the Services. Headquartered in Denmark (EU). • Sanity.io – Content delivery for marketing pages, legal pages, and the product catalog. EU region. • Mailgun (Sinch Email) – Transactional email for the contact form. EU servers (Mailgun EU API). • Vercel Inc. – Hosting and global edge delivery for the public website and web app. Headquartered in the United States; serves traffic from regional edge locations including the EU. • Google LLC – Google Fonts service used to load typography on the public website. Headquartered in the United States. Personal data processed: visitor IP address and User-Agent on font fetch. • InnoCraft Ltd (Matomo Cloud) – Privacy-friendly web analytics for the public website. Headquartered in New Zealand, which is covered by a European Commission adequacy decision. Loaded only with the visitor's consent and never on QR-code (impression) pages. Personal data processed: anonymised IP address, pages viewed, referrer, device/browser type. Terms • All sub-processors are bound by Article 28 GDPR data processing agreements. • The Company is responsible for compliance. Changes The Company may update the list and will inform the Customer of material changes.

Appendix 4 – Transfer to Third Countries (EU – USA)

1. Legal basis • Standard Contractual Clauses (SCC) where applicable • Adequacy decisions where applicable 2. Default residency The Company configures all sub-processors to use EU regions wherever offered (AWS eu-north-1, Auth0 EU tenancy, Mollie NL, CloudPrinter DK, Sanity EU, Mailgun EU). Customer Data is stored and processed within the EU/EEA under normal operation. The public website is delivered via Vercel's global edge network; visitors served from EU edge locations have their requests handled within the EU. Public-website analytics (Matomo Cloud, InnoCraft Ltd) are hosted in New Zealand. 3. Safeguards • Encryption at rest and in transit • Restricted access (least privilege) • Technical and organisational controls 4. Sub-processors with US presence Where a sub-processor's parent company is incorporated in the United States (e.g. AWS, Auth0/Okta, Vercel Inc., Google LLC), data residency in the EU is contractually required wherever offered and the SCC plus a Transfer Impact Assessment (TIA) apply. Google LLC (Google Fonts) is used solely as a static-asset CDN; the only personal data transferred to the US in this case is the visitor's IP address and User-Agent at the moment a font file is fetched. Vercel Inc. serves the public website from regional edge locations; user content (account, QR codes, scan logs) is not stored on Vercel. 5. Sub-processors in adequacy countries InnoCraft Ltd (Matomo Cloud) is incorporated in New Zealand, which benefits from a European Commission adequacy decision under Article 45 GDPR; transfers therefore do not require SCC. Matomo analytics is loaded only with the visitor's consent. 6. Protection of data subjects The Company ensures that the rights of data subjects under the GDPR are upheld. Final provision These appendices form an integral part of the Data Processing Agreement and thereby of the General Terms and Conditions for Paperphyte AB.