Data Processing Agreement
Effective Date: TBD · Last Updated: April 25, 2026
Overview
This Data Processing Agreement ("DPA") is entered into between WaypointQR LLC, a Delaware limited liability company ("Processor"), and the entity identified in the applicable Order Form ("Customer" or "Controller").
This DPA forms an integral part of the Terms of Service and applies to the processing of Personal Data by WaypointQR on behalf of the Customer.
1. Scope of Processing
WaypointQR processes Personal Data on behalf of the Customer to provide the WaypointQR Service, including QR code management, redirect infrastructure, scan analytics, and related features.
The categories of data processed include: account holder data, workspace member data, scan analytics data, and billing data. The full data inventory is available upon request.
2. Processor Obligations
WaypointQR agrees to:
- Process Personal Data only on documented instructions from the Customer
- Ensure persons authorized to process Personal Data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures
- Not engage a subprocessor without prior written authorization
- Assist the Customer in responding to data subject requests
- Assist the Customer in ensuring compliance with security, breach notification, and other obligations
- Delete or return all Personal Data upon termination of the agreement
3. Subprocessors
WaypointQR engages the following categories of subprocessors:
- Cloud Infrastructure: Cloudflare, Inc. (data hosting, CDN)
- Payment Processing: Stripe, Inc.
- Email Delivery: MailChannels (transactional emails via Cloudflare Workers)
- Analytics: Google Analytics 4 (aggregated site analytics only)
A full, current list of subprocessors is maintained at docs.waypointqr.com/privacy-and-compliance/subprocessors . Customers may object to new subprocessors with 30 days' notice.
4. Data Breach Notification
WaypointQR shall notify the Customer without undue delay and no later than 48 hours after becoming aware of a Personal Data Breach. The notification will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.
5. Data Subject Rights
WaypointQR will assist the Customer in fulfilling data subject access requests, rectification, erasure, portability, and objection requests, taking into account the nature of the processing.
6. Security Measures
WaypointQR implements security measures including encryption in transit (TLS 1.3) and at rest (AES-256), access controls (RBAC), audit logging, network security, and regular security assessments.
7. International Transfers
Personal Data may be transferred to the United States. Transfers are protected by Standard Contractual Clauses (SCCs) adopted by the European Commission, supplemented by measures ensuring adequate protection.
8. Audit Rights
Business and Enterprise customers may audit WaypointQR's compliance with this DPA, subject to reasonable notice and confidentiality obligations. Enterprise customers receive one audit per year at no additional cost.
9. Contact
For DPA inquiries: privacy@waypointqr.com
For the full DPA with legal provisions and Standard Contractual Clauses, see our documentation .