Privacy Policy

Effective [DD Month YYYY] · Controller: DEVOUT BV

1. Who we are

DEVOUT BV (“we”) is the controller for personal data processed through Hopp (hopp.qr-redirects.be), a dynamic QR-code redirect service. Registered address [DEVOUT BV, …, Belgium], enterprise no. [KBO 0XXX.XXX.XXX], VAT [BE 0XXX.XXX.XXX]. Contact: privacy@qr-redirects.be.

2. What we process & why (legal bases)

PurposeDataLegal basis (Art. 6 GDPR)
Account & sign-inEmail, name, magic-link/OAuthContract — 6(1)(b)
Serving redirects & storing your codesQR codes, destination URLsContract — 6(1)(b)
Cookieless scan analyticsHashed IP, coarse GeoIP, device/OS/browserLegitimate interest — 6(1)(f)
Security & abuse preventionHashed IP, account dataLegitimate interest — 6(1)(f)
Payments & subscriptionsBilling data (via Stripe)Contract — 6(1)(b)
Invoices & bookkeepingBilling recordsLegal obligation — 6(1)(c)
SupportEmails & ticket metadata (via Mailgun)Contract / legitimate interest
Marketing email (optional)Email, consent statusConsent — 6(1)(a)

Cookieless by design: we never store raw IPs (only a salted hash), use only coarse location, set no tracking cookies, and build no individual profiles. Impact on scanners is minimal.

3. Sub-processors & transfers

ProviderRoleLocationSafeguard
HetznerHostingEU (DE/FI)EU/EEA · DPA
StripePaymentsIE / USSCCs · DPA
MailgunSupport emailUSSCCs · DPA
ReplicateAI QR (optional)USSCCs
Postmark / SESSystem emailUSSCCs
MaxMind GeoLite2GeoIP (local DB)On our serversNo data sent

4. Retention

5. Your rights

Access, rectification, erasure, restriction, portability, objection (incl. to the analytics above), and withdrawing consent. Email privacy@qr-redirects.be, or use account settings. We respond within one month. No automated decision-making with legal effect.

You may complain to the Belgian DPA — Gegevensbeschermingsautoriteit / Autorité de protection des données, Rue de la Presse 35, 1000 Brussels, +32 (0)2 274 48 00, contact@apd-gba.be.

6. Children

Not intended for users under the Belgian digital-consent age (13). We don't knowingly collect their data.


Cookie Policy

Effective [DD Month YYYY]

Analytics are cookieless

We set no analytics or tracking cookies when a code is scanned, so no consent banner is required for analytics under ePrivacy and Belgian law. We use only strictly-necessary cookies, which are exempt from consent:

CookiePurposeDurationType
hopp_sessionKeeps you signed in (httpOnly, SameSite=Lax)Session / 30dStrictly necessary
hopp_csrfCSRF protectionSessionStrictly necessary
hopp_langRemembers your language~12 monthsFunctional (necessary)
__stripe_mid/sidStripe checkout & fraud~12 mo / 30 minStrictly necessary (Stripe)

No advertising or cross-site tracking cookies are used. If we ever add non-essential cookies, we'll first add a GBA-compliant consent banner.