GDPR — protecting your data
Last updated : 01/03/2026 · Cynoia SAS
QRPix is built with GDPR in mind (“privacy by design”). This page summarises our commitments and your rights.
1. Our commitment
Data minimisation, transparency, application hosting in the European Union (AWS EU), and consent for non-essential trackers. No unverified compliance badges: we stick to what is genuinely in place.
2. Controller and DPO
Controller: Cynoia SAS, 69 rue du Rouet, 13008 Marseille, France. DPO: Ayoub Rabeh — [email protected].
3. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction, portability, and withdraw consent at any time.
4. How to exercise your rights
Email [email protected]. We respond within one month (extendable by two months if needed). Proof of identity may be requested in case of reasonable doubt.
5. Complaints
You can lodge a complaint with the French authority CNIL: CNIL — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr.
6. Processors and transfers
We select processors offering sufficient guarantees and frame transfers outside the EU with Standard Contractual Clauses and/or the Data Privacy Framework. The list is in the Privacy Policy.
7. Security and data breaches
In the event of a data breach likely to create a risk to your rights, we notify the CNIL within 72 hours and, where applicable, the affected individuals.
8. Learn more
See the Privacy Policy and Cookie Policy for processing details.