Skip to main content

Data Processing Addendum

How we process personal data on behalf of business customers under GDPR and U.S. state laws.

Last updated October 8, 2026Version 2.0Cuanto Labs LLC

On this page (17 sections)

1.About this addendum

This Data Processing Addendum ("DPA") forms part of the Terms of Service, or other written agreement, between Cuanto Labs LLC, a Florida limited liability company ("Cuanto Labs LLC", "we" or "Processor") and the business customer that has agreed to it ("Customer"), and governs our processing of Customer Personal Data. It applies automatically, without signature, when a business customer accepts the Terms. Customers who need a countersigned copy can request one from legal@qraffic.com.

If this DPA conflicts with the Terms, this DPA controls for the processing of Customer Personal Data. If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses control.

2.Definitions

  • "Data Protection Laws" means all privacy and data protection laws that apply to the processing of Customer Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the GDPR as it forms part of UK law ("UK GDPR"), the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and other U.S. state privacy laws.
  • "Customer Personal Data" means personal data contained in Customer Content that we process on Customer's behalf in providing the Service.
  • "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
  • "Standard Contractual Clauses" means the clauses approved by European Commission Decision 2021/914, and "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner.
  • "Controller", "processor", "data subject", "personal data", "processing", "business", "service provider", "sell" and "share" have the meanings given in the applicable Data Protection Laws. Other capitalized terms have the meanings given in the Terms ("Agreement").

3.Roles and details of processing

Customer is the controller (or business) and we are the processor (or service provider) of Customer Personal Data. Where Customer is itself a processor for a third-party controller, we are Customer's sub-processor.

  • Subject matter and nature: providing the Service under the Agreement, including hosting, storage, computing, support and the other operations described in the Agreement.
  • Purpose: to provide, secure and support the Service for Customer, and as further instructed by Customer in writing.
  • Duration: the term of the Agreement plus the post-termination period in the "Return and deletion" section.
  • Data subjects: Customer's authorized users and the individuals whose personal data Customer or its users submit to the Service, such as Customer's employees, contractors, customers and contacts.
  • Categories of personal data: as determined by Customer, typically including account information, customer content, scan and visit data (processed for our customers), form submissions (processed for our customers), billing information, usage and device data, communications, ai inputs and outputs and mail recipient data (processed for our customers), and any other personal data in Customer Content.
  • Sensitive data: none intended. Customer will not submit special category data unless the Service is designed for it and the parties agree in writing on any additional safeguards.

4.Details of processing

  • Subject matter and purpose: providing qraffic to the customer: redirecting scans of dynamic codes and links, hosting the customer's pages and forms, producing scan analytics and A/B test results, delivering form submissions, and printing and sending mail the customer orders.
  • Data subjects: people who scan the customer's codes or open its links and pages; people who submit its forms; leads and recipients the customer uploads; and the customer's own users.
  • Categories of personal data: approximate location (country, region, city, approximate coordinates), device type, operating system, browser, language, referrer, campaign tags, timestamps, one-way hashes derived from IP addresses (the raw IP address is not stored with scan records), form answers as configured by the customer, and recipient names and postal addresses.
  • Special categories: none intended. The customer will not configure forms to collect special category data, government identification numbers, full payment details or data of children under 13 unless the law permits it and the customer has every required consent and notice.
  • Notice at collection: the customer provides its own privacy notice to scanners, visitors and form respondents and is responsible for any consent required for the collection.
  • Duration: for the term of the agreement, until the customer deletes the data or closes its account, then as described in Section 14 (Return and deletion).

5.Processing on instructions

We will process Customer Personal Data only on Customer's documented instructions, unless required to do otherwise by law, in which case we will inform Customer of that legal requirement before processing unless the law prohibits it. The Agreement, this DPA and Customer's configuration and use of the Service are Customer's complete instructions. We will tell Customer if, in our opinion, an instruction infringes Data Protection Laws.

Customer is responsible for the lawfulness of its instructions and of the personal data it provides, including having a lawful basis for processing and giving any notices and obtaining any consents required by Data Protection Laws.

6.U.S. state privacy law terms

To the extent the CCPA or similar U.S. state laws apply, we:

  • will not sell or share Customer Personal Data;
  • will not retain, use or disclose it for any purpose, including any commercial purpose, other than the business purposes specified in the Agreement, or outside our direct business relationship with Customer;
  • will not combine it with personal information we receive from others or collect from our own interactions with individuals, except as Data Protection Laws permit;
  • will comply with applicable obligations under those laws and provide the same level of privacy protection they require, and will notify Customer if we determine we can no longer meet them; and
  • grant Customer the right, on notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use.

We certify that we understand and will comply with these restrictions.

7.Confidentiality of personnel

We will ensure that personnel authorized to process Customer Personal Data are bound by written confidentiality obligations or an appropriate statutory duty of confidentiality, receive appropriate data protection training, and access Customer Personal Data only as needed to perform the Service.

8.Security measures

We will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing and the risks to individuals. These include:

  • encryption of data in transit using TLS 1.2 or higher, and encryption of data at rest;
  • logical separation of each customer's data, enforced at the database layer with row-level security;
  • role-based, least-privilege access to production systems, protected by multi-factor authentication and reviewed periodically;
  • logging and monitoring of access to production systems, and alerting on suspicious activity;
  • regular backups with tested restoration, and infrastructure hosted in certified data centers;
  • secure development practices, including code review, dependency scanning and prompt patching; and
  • vendor due diligence for every sub-processor before engagement.

We may update these measures provided we do not materially reduce the overall level of protection.

9.Sub-processors

Customer gives general authorization for us to engage sub-processors. Our current sub-processors are listed on our Sub-processors page, and currently include Vercel, Neon, Upstash, Amazon Web Services, Sentry, Stripe, Anthropic, OpenRouter, Lob and Google. We will impose data protection terms on each sub-processor that are at least as protective as this DPA, and remain liable for its performance.

We will notify Customer at least 30 days before authorizing a new sub-processor, by updating that page and, for customers who subscribe, by email. Customer may object in writing on reasonable data protection grounds within that period. We will then work in good faith to address the objection, for example by making a change that avoids the new sub-processor. If we cannot do so within 30 days, Customer may terminate the affected part of the Service and receive a refund of prepaid fees for the remaining term.

10.Data subject requests and assistance

Taking into account the nature of the processing, we will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights. The Service lets Customer access, correct, export and delete Customer Personal Data. If we receive a request directly, we will promptly forward it to Customer and will not respond except to direct the requester to Customer, unless required by law.

We will also provide reasonable assistance with Customer's data protection impact assessments and prior consultations with supervisory authorities, to the extent required by Data Protection Laws and relating to our processing.

11.Security incidents

We will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Security Incident. Our notice will describe, to the extent known, the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it, and we will provide updates as more information becomes available. We will take reasonable steps to contain and remediate the incident. Notices go to the Customer's account owner email; Customer can send questions to security@qraffic.com. Our notification is not an acknowledgment of fault or liability.

12.International transfers

We may process Customer Personal Data in the United States and in the other locations listed for our sub-processors. For transfers of Customer Personal Data from the European Economic Area, Switzerland or the United Kingdom to a country without an adequacy decision, the parties agree that:

  • Module Two (controller to processor) of the Standard Contractual Clauses applies, and Module Three (processor to processor) applies where Customer is a processor, both incorporated by reference;
  • in Clause 7, the docking clause applies; in Clause 9, option 2 (general authorization) applies with the notice period in this DPA; in Clause 11, the optional language does not apply; in Clauses 17 and 18, the law and courts of Ireland apply;
  • Annexes I and II are completed by the "Roles and details of processing" and "Security measures" sections of this DPA, and the competent supervisory authority is that of the EU member state where Customer is established or its representative is located;
  • for UK transfers, the UK Addendum applies, with the Standard Contractual Clauses as completed above, and for Swiss transfers, references to the GDPR are read as references to the Swiss Federal Act on Data Protection.

Where we or a sub-processor are certified under the EU-U.S. Data Privacy Framework or its UK and Swiss extensions, we may rely on that certification instead.

13.Audits and compliance information

We will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including completed security questionnaires and any third-party audit reports or certifications we hold. If that information is not sufficient to demonstrate compliance, or a supervisory authority requires it, Customer may audit our compliance once a year, on at least 30 days' notice, during business hours, at its own cost, and subject to reasonable confidentiality and security conditions. Customer may use an independent auditor who is not our competitor.

14.Return and deletion

Customer may export Customer Personal Data at any time during the term using the Service. Within 30 days after termination of the Agreement, we will delete Customer Personal Data, unless Data Protection Laws require us to retain it, in which case we will protect it and process it only for that purpose. Copies in encrypted backups are deleted on their normal rotation cycle. We will confirm deletion in writing on request.

15.Liability

Each party's liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent such limitations are prohibited by Data Protection Laws or the Standard Contractual Clauses. Nothing in this DPA limits either party's liability to data subjects under Data Protection Laws.

16.Changes to this addendum

We may update this DPA to reflect changes in Data Protection Laws, guidance from regulators, or the Service. We will not make a change that materially reduces the protection of Customer Personal Data without at least 30 days' notice, and if Customer reasonably objects to such a change, it may terminate the affected part of the Service and receive a refund of prepaid fees for the remaining term.

17.Contact us

Questions about this DPA can be sent to privacy@qraffic.com or Cuanto Labs LLC, Attn: Privacy, 1314 E Las Olas Blvd, Unit #2570, Fort Lauderdale, FL 33301, USA.