iloveQR
    Plans and pricesFAQAPI
    Register
    iloveQR

    Create, customize, and track QR codes from one simple workspace.

    • QR Types
    • Dynamic QR
    • Static QR
    • Analytics
    • Templates
    • Bulk Builder
    • Custom Domains
    • API
    • About us
    • Pricing
    • Contact
    • FAQ
    • Help Center
    • Privacy Policy
    • Terms and Conditions
    • Cookies Policy
    • GDPR
    • Report Abuse

    © 2026 iloveQR. All rights reserved.

    GDPR Compliance

    Last updated: 23 September 2026

    This page summarises how iloveQR applies the General Data Protection Regulation. It complements our Privacy Policy and does not replace the detailed information provided there.

    1. Organisation and contact

    FLIPR GROUP LTD is a private limited company registered in Cyprus under company number HE 443704, with registered address at 23 Ploutonos, 3096 Limassol, Cyprus, and VAT number CY 60184306Q.

    Submit GDPR questions or rights requests through https://www.iloveqr.com/contact or write to our registered address.

    2. Controller and processor roles

    FLIPR GROUP LTD acts as controller for user accounts, billing, security, product communications, our own website measurement, and our advertising activities.

    When a customer determines the purpose and means of personal data placed in QR content or collected through their QR experience, the customer is controller and FLIPR GROUP LTD acts as processor for the relevant service processing.

    3. Data protection principles

    • Lawfulness, fairness, and transparency.
    • Purpose limitation and data minimisation.
    • Accuracy and proportionate retention.
    • Integrity, confidentiality, and accountability.

    4. Legal bases

    Depending on the activity, we rely on performance of a contract, compliance with a legal obligation, legitimate interests that are not overridden by individual rights, consent, or the establishment, exercise, or defence of legal claims. Our Privacy Policy maps these bases to the main purposes.

    5. Data and purposes

    We process account, billing, QR content, scan, technical, consent, analytics, advertising, email, and support data only for defined purposes such as providing the service, securing it, processing payment and tax, supporting users, improving reliability, and conducting consented measurement or advertising.

    6. Individual rights

    • Access, rectification, erasure, and restriction.
    • Data portability where the legal conditions apply.
    • Objection to legitimate-interest processing and direct marketing.
    • Withdrawal of consent at any time for future processing.
    • Protection from solely automated decisions producing legal or similarly significant effects, subject to legal exceptions.
    • A complaint to the Cyprus Commissioner for Personal Data Protection or another competent supervisory authority.

    7. Handling rights requests

    Send a request through https://www.iloveqr.com/contact and identify the relevant account or interaction. We may verify identity and clarify the scope. We normally respond within one month and may extend that period by up to two further months where the GDPR permits due to complexity or volume, explaining the reason.

    Requests are normally free. A reasonable fee or refusal may apply only where the GDPR permits for manifestly unfounded or excessive requests.

    8. Support for customer compliance

    When acting as processor, we process data on documented instructions, require confidentiality, apply appropriate security, control subprocessors, assist with rights and incident obligations, and delete or return data as agreed, subject to legal retention. A data processing agreement is available for qualifying customers.

    9. International transfers

    For transfers outside the European Economic Area, we use a recognised legal mechanism where required, such as an adequacy decision or Standard Contractual Clauses, together with supplementary safeguards where appropriate.

    10. Security and incidents

    We apply risk-based technical and organisational measures, including access controls, encryption in transit, monitoring, backups, provider controls, and incident procedures.

    If a personal data breach creates a legal notification duty, we notify the competent supervisory authority and affected individuals within the applicable GDPR timeframes and provide customers with relevant information when we act as processor.

    11. Retention and deletion

    We retain personal data only as long as required by the relevant purpose, customer instructions, limitation periods, security needs, and legal accounting, tax, or regulatory duties. Deletion from active systems and rolling backups follows documented operational processes.

    12. Supervision and updates

    FLIPR GROUP LTD is established in Cyprus. The Office of the Commissioner for Personal Data Protection in Cyprus is the relevant national supervisory authority, without limiting your right to approach another competent authority under the GDPR.

    We review this summary as the service and legal requirements evolve. The date above identifies the current version.

    Try our QR code generator for 7 days free.

    No credit card required. Cancel anytime.

    Get Started Free
    QR Code preview