Information about your rights under the General Data Protection Regulation (GDPR)
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018. It applies to all organizations that process personal data of individuals in the European Union (EU) and European Economic Area (EEA), regardless of where the organization is located.
We process your personal data under the following lawful bases:
Scanlytics was built with privacy in mind from the ground up:
As a data subject under GDPR, you have the following rights:
You have the right to obtain confirmation of whether we process your personal data and, if so, access to that data along with information about how it is processed.
You have the right to have inaccurate personal data corrected and incomplete data completed.
Also known as the "right to be forgotten", you can request deletion of your personal data when it is no longer necessary for the purpose it was collected.
You can request restriction of processing when you contest the accuracy of data, when processing is unlawful, or when we no longer need the data but you need it for legal claims.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
You have the right to object to processing based on legitimate interests or for direct marketing purposes. You can disable analytics tracking for your QR codes at any time.
| Data Type | Purpose | Retention |
|---|---|---|
| Account Data | Service provision, authentication | Until account deletion |
| QR Code Data | Core service functionality | Until deletion or account closure |
| Analytics (Aggregated) | Usage insights for customers | Based on plan (30 days - unlimited) |
| Audit Logs | Security and compliance | 30 days |
We use the following sub-processors to provide our services:
| Provider | Service | Location |
|---|---|---|
| Cloudflare, Inc. | Infrastructure, CDN, Analytics | Global (EU-US DPF certified) |
| Clerk, Inc. | Authentication, User Management | USA (EU-US DPF certified) |
| Stripe, Inc. | Payment Processing | USA (EU-US DPF certified) |
Your data may be transferred to and processed in countries outside the EU/EEA. We ensure appropriate safeguards are in place:
For any GDPR-related inquiries or to exercise your data rights, please contact us at:
Email: privacy@scanlytics.app
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. You may contact your local data protection authority or the authority in the country where we are established.
For our full privacy practices, see our Privacy Policy.