Legal

Data processing agreement

Version 1.0 · Last updated 18 August 2026

This agreement applies where ScanSolve processes personal data on your behalf. It forms part of our terms of service and takes effect when you start using the service. We will also sign a countersigned copy on request — email support@scansolve.co.

“UK GDPR” means the retained EU General Data Protection Regulation as it applies in the UK, together with the Data Protection Act 2018.

1. Roles

You are the controller of personal data submitted through your QR labels and held in your organisation's account. We are the processor, and we act only on your documented instructions, which include your use of the service and this agreement. If we believe an instruction breaches data protection law, we will tell you.

2. What we process

Subject matterProviding QR code facility fault reporting.
DurationFor as long as your account is active, plus the deletion period in section 8.
Nature and purposeCollecting fault reports, routing them to your team, and tracking them to resolution.
Categories of dataAccount holders: name and email address. Reporters: an optional contact email, the content of the report, an optional photo, and technical data such as timestamp and browser type held for abuse prevention.
Data subjectsYour staff and team members, and any person who scans a label and chooses to submit a report.
Special category dataNone. The service is not designed for it and our terms prohibit it.

3. Our obligations

  • Process personal data only on your instructions, except where the law requires otherwise.
  • Keep the security measures described in section 6, and review them as the service changes.
  • Make sure anyone with access is bound by confidentiality.
  • Help you respond to data subject requests and, where relevant, to impact assessments and consultations with the regulator.
  • Tell you about a personal data breach without undue delay, as set out in section 7.
  • Delete or return personal data at the end of the agreement, as set out in section 8.
  • Give you the information you reasonably need to show we are meeting these obligations.

4. Your obligations

You confirm you have a lawful basis for the data you collect through the service, and that where a label is placed in a public or semi-public area, people are given the information they are entitled to. You are responsible for the categories you configure and for what your team enters into the system.

5. Subprocessors

You give general authorisation for us to use the subprocessors below. Each is bound by terms no less protective than this agreement. We will give at least 30 days' notice by email before adding or replacing one, and you may object on reasonable data protection grounds; if we cannot resolve the objection you may terminate without penalty.

SubprocessorPurposeLocation
SupabaseDatabase, authentication, file storageIreland (eu-west-1)
VercelApplication hosting, cookieless analyticsEU / US
ResendTransactional emailEU / US
StripePayment processingEU / US
GoogleGemini, support chat and category suggestionsEU / US
UpstashRate limiting, where enabledEU

6. Security measures

  • Primary data is stored in the European Union, in Ireland (eu-west-1).
  • Encryption in transit using HTTPS with HTTP Strict Transport Security, and encryption at rest by our storage providers.
  • Row-level security enabled on every table holding customer data, so a signed-in user can only reach their own organisation's rows. Server-side paths that accept reports from people without accounts are scoped to the correct organisation in application code.
  • Sign-in by emailed link or one-time code. No passwords are stored.
  • Photo uploads held in private storage and served through links that expire after seven days.
  • Rate limiting on public endpoints, and a content security policy with standard security headers.
  • Card details are handled by Stripe and never reach our systems.

Our trust and security page is kept current and lists the controls we do not yet have, including automated backups and independent certification.

7. Personal data breaches

If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 48 hours. We will describe what happened, the categories and approximate number of records involved, the likely consequences, and what we are doing about it. We will help you meet your own notification duties.

8. Deletion and return

You can export issue data as CSV at any time. On termination, or on your written request, we will delete your organisation's personal data within 30 days and confirm when it is done, unless we are required by law to keep it. Where deletion from backup media is not immediately possible, the data remains protected by this agreement until the backup cycle overwrites it.

9. Audits

On reasonable written notice, and no more than once a year unless a regulator requires otherwise, we will provide the information you need to verify our compliance and respond to a reasonable security questionnaire. Where we hold third party audit reports for our subprocessors, we will make those available instead of an on-site audit where they answer the question.

10. International transfers

Primary storage is in the UK and EU. Where a subprocessor processes data outside the UK or EEA, that transfer is made under the UK International Data Transfer Addendum or Standard Contractual Clauses, together with any additional measures required.

11. Priority and law

Where this agreement conflicts with our terms of service, this agreement takes precedence on data protection matters. It is governed by the law of England and Wales.

Questions from a data protection officer are welcome at support@scansolve.co. We will complete a security questionnaire and mark anything we do not hold as not held.