Last updated: 22 September 2026
iloveQR is committed to protecting the privacy and security of personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and your rights as a data subject.
FLIPR GROUP LTD, the operator of iloveQR, acts as the data controller for personal data collected through our services. For any questions regarding data protection, you can contact us at:
We process personal data under the following legal bases as defined by GDPR Article 6:
As a data subject under GDPR, you have the following rights:
You have the right to request a copy of the personal data we hold about you and information about how we process it.
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
You have the right to request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected.
You have the right to request that we limit the processing of your personal data in certain circumstances.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
You have the right to object to the processing of your personal data in certain circumstances, including for direct marketing purposes.
You have the right not to be subject to a decision based solely on automated processing that significantly affects you.
We process the following categories of personal data:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected. Our retention periods are:
When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:
We implement appropriate technical and organizational measures to protect personal data, including:
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours where feasible. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
To exercise any of your GDPR rights, please contact our Data Protection Officer:
We will respond to your request within 30 days. In complex cases, this may be extended by an additional 60 days with notification.
If you are not satisfied with how we handle your request or believe we are processing your personal data unlawfully, you have the right to lodge a complaint with your local data protection authority.