Privacy Policy

Last updated: 25 July 2026

This policy explains, in accordance with Articles 12–14 of the General Data Protection Regulation (GDPR), how personal data is processed when you visit and use Alpha QR Code.

1. Controller

Julius Ziesmann
Panoramastraße 22
72144 Dußlingen
Germany

Phone: +49 1522 217 22 85
Email: julius.ziesmann@gmx.de

No data protection officer has been appointed because there is currently no statutory obligation to do so.

2. Website access and server logs

Whenever the website is accessed, the web server processes connection data required for technical delivery. This may include the IP address, date and time, requested address, referrer URL, browser type and version, operating system, transferred data volume and HTTP status. We process this data to deliver the website, maintain stability and security and prevent misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is secure and reliable operation.

Logs are retained only for as long as needed for troubleshooting and security monitoring and are then erased or anonymised, unless a security incident requires longer retention. Recipients may include the hosting provider and technical service providers acting as processors.

3. Essential storage and consent management

We store your privacy selection on your device for six months so that the website respects your decision and does not ask again on every visit. Access to the device is based on section 25(2)(2) TDDDG; any related personal-data processing is based on Article 6(1)(f) GDPR. Our legitimate interest is user-friendly, verifiable consent management. You may change your selection at any time through “Privacy settings” in the footer. We ask again after material changes to services or the consent version.

4. Google Analytics 4

Only with your express consent do we load Google Analytics 4, a web analytics service supplied by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google processes usage and event data, technical device and browser information, approximate location information and online identifiers. We have disabled advertising signals and personalised advertising in our implementation. Information generated by Google Analytics may also be processed by Google LLC and other Google entities.

The legal bases are section 25(1) TDDDG for storing or accessing information on the device and Article 6(1)(a) GDPR for subsequent processing. Consent is voluntary and may be withdrawn at any time with future effect through the privacy settings. On withdrawal, we attempt to remove analytics cookies set by Google Analytics. Processing carried out before withdrawal remains lawful.

The consent decision is retained for six months. User-level and event data in Google Analytics is retained for two or 14 months, depending on the configuration. Google may transfer data outside the EEA, particularly to the United States, using applicable safeguards such as adequacy decisions including the EU-US Data Privacy Framework or Standard Contractual Clauses. More information: Google Privacy Policy.

5. Local libraries and external map services

Program libraries and fonts are served locally from our own server. Normal page views therefore do not connect to a content delivery network. If you expressly load the optional map, your browser retrieves tiles from OpenStreetMap; satellite view uses Esri. Selecting a point may query OpenStreetMap Nominatim. The selected provider receives connection data including your IP address and, for reverse geocoding, the requested coordinates. The legal basis is your consent under Article 6(1)(a) GDPR and, where applicable, section 25(1) TDDDG. You may instead enter coordinates manually.

6. QR code generator and scanner

QR content and logos you submit are sent to our server and processed only to produce the requested file. If you upload a QR image, the server processes it in memory to read the code; camera scanning takes place locally in your browser. We do not create a saved QR project or user profile from this material and do not retain it permanently. If you expressly provide an external image or logo URL, our server may retrieve that file; the destination server then receives our server’s IP address and usual connection data. Do not submit special-category data and use only content you are authorised to process.

The legal basis is Article 6(1)(b) GDPR where processing is required to provide a requested function, otherwise Article 6(1)(f) GDPR. Temporary processing data is erased when the operation is complete, except for technically necessary short-term caching.

7. Contact and email

If you contact us, we process your contact details, message and necessary metadata to handle the request. The legal basis is Article 6(1)(b) GDPR for contract-related enquiries and otherwise Article 6(1)(f) GDPR. Messages are erased after final resolution unless legal retention obligations or legitimate reasons require longer storage. Email communications may be processed by our email provider.

8. Recipients and international transfers

We disclose personal data only where necessary to provide the website or a requested function, where required by law, where you have consented or where a legitimate interest supports disclosure. Recipient categories include hosting and IT providers, email providers, analytics providers following consent, authorities and legal advisers where necessary. Processors are contractually bound under Article 28 GDPR.

Transfers outside the EEA comply with Articles 44 et seq. GDPR, particularly through adequacy decisions or safeguards such as Standard Contractual Clauses. Foreign public authorities may nevertheless have access rights under local law.

9. Retention

Unless a specific period is stated, we retain personal data only for as long as its purpose continues. It is then erased or anonymised unless statutory retention duties, security interests or the establishment, exercise or defence of legal claims require longer retention.

10. Your rights

Subject to the statutory requirements, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20) and objection to processing based on Article 6(1)(e) or (f) GDPR (Article 21). You may withdraw consent at any time with future effect (Article 7(3)). You may also lodge a complaint with a supervisory authority under Article 77 GDPR.

Our regular supervisory authority is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg: www.baden-wuerttemberg.datenschutz.de. You may also contact the authority at your habitual residence, place of work or place of the alleged infringement.

Right to object: where processing is based on legitimate interests, you may object at any time on grounds relating to your particular situation. We will stop processing unless we demonstrate compelling legitimate grounds or processing is required for legal claims.

11. Security, required data and automated decisions

We use HTTPS/TLS and appropriate technical and organisational safeguards, although risk-free transmission cannot be guaranteed. Providing data is generally voluntary; without essential connection data, the website cannot be provided. We do not use solely automated decision-making producing legal or similarly significant effects.

12. Changes

We update this policy when services, processing activities or legal requirements change. The version published on this page applies.