Privacy Policy
Last updated : 01/03/2026 · Cynoia SAS
This policy explains how Cynoia SAS, the publisher of QRPix, collects and processes personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable data protection law.
1. Data controller
The data controller is Cynoia SAS, Simplified joint-stock company (SAS), share capital 1 765 €, RCS Marseille 917 731 267, registered office 69 rue du Rouet, 13008 Marseille, France. Data Protection Officer (DPO): Ayoub Rabeh — [email protected].
2. Data we collect
- Account: name, email, password (encrypted).
- Newsletter: email address.
- Contact form: name, email, company, message.
- Payment: handled by our processor Stripe; we do not store card numbers.
- QR scan data: timestamp, IP address, approximate location derived from IP (country/city), device, OS and browser, campaign parameters (UTM). The IP address is truncated (anonymised) before storage.
- Browsing: cookies and trackers (see the Cookie Policy).
3. Purposes and legal bases
- Provide and run the service — performance of contract (Art. 6.1.b).
- Newsletter — your consent (Art. 6.1.a), withdrawable anytime.
- Answer contact requests — pre-contractual steps / legitimate interest (Art. 6.1.b/f).
- Scan analytics and statistics — legitimate interest, or consent where non-essential trackers are used.
- Ad retargeting (Meta, Google) — your consent (Art. 6.1.a), collected via the cookie banner.
- Payment and invoicing — performance of contract and legal obligations.
- Security and fraud prevention — legitimate interest.
4. Retention periods
- Account: for the contract term, then deletion or anonymisation within 12 months.
- Scan data / statistics: 13 months for trackers, in line with CNIL guidance.
- Newsletter: until consent is withdrawn.
- Contact requests: up to 3 years after last exchange.
- Invoicing: 10 years (legal accounting obligation).
5. Recipients and processors
We use processors acting on our instructions: Resend (email), Cloudflare (serverless function / CDN), OVH (site hosting), Amazon Web Services (app hosting, EU), Stripe (payment), Google and Meta (analytics and retargeting, subject to your consent), and Google Analytics (analytics).
6. Transfers outside the EU
Some processors (Resend, Cloudflare, Stripe, Google, Meta) are based in the United States. Transfers are framed by the European Commission’s Standard Contractual Clauses and/or the EU-US Data Privacy Framework, with appropriate safeguards.
7. Security
We implement appropriate technical and organisational measures (encryption in transit, access control, EU hosting for the application). No transmission over the Internet is fully secure, but we protect your data accordingly.
8. Your rights
You have the rights of access, rectification, erasure, objection, restriction, portability, and the right to withdraw consent at any time. To exercise them: [email protected]. You may lodge a complaint with the French authority CNIL (CNIL — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr).
9. Cookies
The use of cookies and trackers is detailed in our Cookie Policy. Non-essential trackers (analytics, marketing) are only set after your consent.
10. Minors
QRPix is not intended for persons under 16. We do not knowingly collect their data.
11. Changes
We may update this policy. The applicable version is the one published on qrpix.io. Effective date: 01/03/2026.
12. Contact
Any questions: [email protected] (DPO Ayoub Rabeh) or [email protected].