Legal
Privacy Policy
pursuant to Art. 13/14 GDPR. This policy applies to the use of the platform (customer account). For the end-customer scan page at ppwr-qrcode.de/<slug> there is a separate policy (here).
1. Controller
Erik Eggerth · Lange Str. 22 · 76275 Ettlingen OT Schluttenbach
E-mail: info@ppwr-qrcode.de
2. Purposes and Legal Bases
- Account & Profile: Art. 6(1)(b) GDPR (performance of a contract).
- Security logs (login IP, user agent): Art. 6(1)(f) GDPR (legitimate interest in brute-force protection). Retention max. 90 days.
- Invoicing & accounting: Art. 6(1)(c) GDPR (legal obligation — Sec. 147 AO, 10 years).
- Marketing by e-mail: only with opt-in (Art. 6(1)(a) GDPR), revocable at any time via the account settings.
3. Recipients / Processors
- Supabase (hosting of Postgres + Auth, EU-Frankfurt, data processing agreement in place)
- Vercel (hosting of frontend + edge functions, EU-Frankfurt region, data processing agreement in place)
- Stripe (payment processing, EU Standards of Care + SCC, separate privacy policy)
- seven.io (SMS 2FA, German provider, data processing agreement in place)
- sevDesk (invoicing, German provider, data processing agreement in place)
- IONOS (e-mail dispatch, German provider)
- Upstash (rate limiting / abuse protection for scan requests, Redis; processed in the EU-Frankfurt data centre, only a hashed IP for max. 60 seconds; US provider → additional EU Standard Contractual Clauses, data processing agreement in place)
- Anthropic (AI-powered advisory assistant 'Hannah'; your chat inputs are processed via the Claude API by Anthropic, PBC, San Francisco, USA; data is not used for model training and deleted after max. 30 days; EU Standard Contractual Clauses + Data Processing Addendum in place). Hannah is labelled as an AI system in accordance with Art. 50 EU AI Act.
Locations & international data transfers: Supabase, Vercel, seven.io, sevDesk and IONOS process your data exclusively within the EU (Germany / Frankfurt). Stripe processes payment data partly in the USA under the EU Standard Contractual Clauses (SCCs, Art. 46 GDPR) together with supplementary technical and organisational safeguards (encryption, pseudonymisation). Upstash processes only hashed IP values in the EU-Frankfurt data centre; as a US company, Upstash additionally relies on the EU Standard Contractual Clauses (Art. 46 GDPR). Anthropic (AI assistant Hannah) processes chat inputs in the USA; EU Standard Contractual Clauses and a Data Processing Addendum apply — inputs are not used for model training. A data processing agreement (DPA) under Art. 28 GDPR is in place with each provider.
4. Storage Period
Account data: until termination of the contract plus a 30-day reactivation period. Invoice-relevant data: 10 years (Sec. 147 AO). Login attempts: 90 days. Trusted devices: until expiry of the 30-day period or manual revocation.
5. Your Rights
Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), right to lodge a complaint with a supervisory authority (Art. 77). Competent authority: State Commissioner for Data Protection of Baden-Württemberg.
6. Cookies
We use technically necessary cookies (session, language setting, dark-mode preference, trusted device), which are permitted without consent (Sec. 25(2) No. 2 TTDSG). Optionally, if you click "Accept all" in the cookie banner, a Google Ads conversion cookie is set on the registration page to measure the effectiveness of our advertisements. Details in section 6a.
6a. Google Ads Conversion Tracking
On our registration page we use — only with your explicit consent (click on "Accept all" in the cookie banner) — Google Ads conversion tracking. The script gtag.js from Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) is loaded and a cookie is set to measure whether a registration resulted from a Google advertisement. The data transmitted includes: IP address (anonymised), browser type, device type, page visited and time of conversion. Google may also transfer this data to the USA; the legal basis for this is the EU-US Data Privacy Framework (adequacy decision of the EU Commission of 10 July 2023). The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TTDSG. Without your consent, no Google script is loaded and no cookie is set. You can withdraw your consent at any time by resetting your cookie settings on the privacy page. More information: policies.google.com/privacy.
7. Data Processing as Host
If, as a business customer, you process personal data (e.g. end-consumer scans of your packaging) via our platform, you are the controller and we are your processor. Upon conclusion of the contract you simultaneously enter into a data processing agreement pursuant to Art. 28 GDPR with us — full text: annex to the GTC.
9. Data security (Art. 32 GDPR)
We protect your data through a multi-layered security concept in accordance with Art. 32 GDPR:
- Encryption in transit: all connections are encrypted exclusively via TLS 1.2/1.3 (HTTPS); HTTP is forcibly redirected via HSTS.
- Encryption at rest: database and storage contents are stored with AES-256 encryption at our processors Supabase and Vercel.
- Authentication & sessions: login via email/password (bcrypt, cost factor ≥ 12) and optional SMS-2FA; sessions handled via secure HttpOnly/Secure/SameSite cookies.
- Access control: role-based permissions via Row Level Security (RLS) in the database — records are strictly isolated per tenant/user.
- Monitoring & hardening: rate limits against brute-force, automatic logging of login attempts (max. 90 days), strict Content-Security-Policy, separated permissions for admin actions.
Despite these measures, absolute security cannot be guaranteed when transferring data over the internet. Where there is reasonable suspicion of a security incident, the procedure set out in section 10 applies.
10. Personal data breaches & notification (Art. 33/34 GDPR)
In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Art. 33 GDPR). Where the breach is likely to result in a high risk to the rights and freedoms of data subjects, we will additionally notify the affected data subjects without delay, in clear and plain language (Art. 34 GDPR). The notification will describe the nature and likely consequences of the breach, the measures taken or proposed, and a contact point for further information (email: info@ppwr-qrcode.de). Security incidents are documented internally (incident log) and are available for inspection on request under Art. 15 GDPR.
11. Email marketing & newsletter (double opt-in)
We send promotional emails (newsletter, product updates, PPWR compliance tips) only on the basis of your explicit consent (Art. 6(1)(a) GDPR, § 7(2) no. 3 UWG). Consent is obtained via a double opt-in procedure: (1) you enter your email address, (2) we send a confirmation email with an activation link, (3) only after you click this link is your consent considered validly given. We log the timestamp of consent, the IP address and the timestamp of confirmation as evidence. You may withdraw your consent at any time for the future — either via the unsubscribe link in every promotional email or by informal message to info@ppwr-qrcode.de. Your email address is stored until consent is withdrawn; thereafter it is removed from the distribution list and retained only on a suppression list to the extent necessary to prevent further messages.
12. Data portability (Art. 20 GDPR) — scope & process
You have the right to receive the personal data you have provided in a structured, commonly used and machine-readable format. The export covers: (a) profile and account data, (b) all QR codes you have created, including landing-page content and metadata, (c) PDFs and images uploaded to your media library, (d) scan/usage statistics of your codes (aggregated by day, without tracking data of end users), (e) invoice history as PDF and in the structured ZUGFeRD/XRechnung format. The format is JSON; PDFs and images are provided in their original format. Send a free-form request by email to info@ppwr-qrcode.de; we typically provide the export within 14 days, at the latest within 30 days (Art. 12(3) GDPR). Within 30 days after contract end the export is free of charge; thereafter we charge a flat handling fee of €5 per request (in line with Art. 12(5) GDPR for manifestly unfounded or excessive requests).
13. Embedded YouTube videos
On some pages we embed videos from YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). We use the extended privacy mode (domain youtube-nocookie.com) together with a two-click solution: when you open the page, no content is loaded from YouTube and no connection to Google servers is established. Only when you actively click the preview do you consent and the video is loaded. At that point data — in particular your IP address, browser type and the page visited — is transmitted to YouTube/Google, and cookies may be set. The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by clicking and may withdraw at any time for the future. Google may also transfer this data to the USA. More information: policies.google.com/privacy.
14. Registration source attribution (ppwr_utm cookie)
Purpose: To understand which marketing channel (e.g. Google Ads, organic search, referral links) brought you to our platform, we optionally store a cookie named ppwr_utm on your first visit. This cookie contains only the UTM parameters present in the page URL (utm_source, utm_medium, utm_campaign, utm_content, utm_term), a Google Click ID (gclid) if present, and the domain of the referring page (domain only — no path or search terms). No personal data such as name or email address is stored in this cookie.
Processing at registration: When you register on our platform, we read this cookie once and store the channel information in your user profile. This gives us a statistical overview of which marketing activities lead to registrations. The cookie is deleted immediately after being read.
Legal basis: Art. 6(1)(a) GDPR (consent). The cookie is only set if you select “Accept all” in the cookie banner.
Retention: The cookie has a 180-day lifespan to cover typical B2B research cycles and is deleted immediately after first registration. Channel information stored in your profile is subject to our standard account data deletion policy.
Withdrawal: You can withdraw your consent at any time by selecting “Essential only” in the cookie banner or by clearing your browser cookies. Channel information already stored in your profile can be deleted on request at info@ppwr-qrcode.de.
No third parties: This is a first-party cookie. Data is stored exclusively on our own systems (Supabase EU-Frankfurt, Germany) and is not shared with third parties.
8. Changes
We reserve the right to adapt this privacy policy to changes in the legal situation. The current version is always available at this URL.
As of: 08.09.2026
