Data Processing Addendum
Last updated: July 2026
This Addendum applies when Zustis Technologies Limited processes personal data on your behalf as part of ScanIQ. It forms part of our Terms of Service and reflects the requirements of the DIFC Data Protection Law No. 5 of 2020. Where you handle personal data of the people who scan your codes, you are the controller and we are your processor.
1. Roles & scope
- Controller: you (the customer).
- Processor: Zustis Technologies Limited.
- Subject matter: providing the ScanIQ Service — resolving your links and recording scan analytics on your behalf.
- Duration: for as long as you use the Service, and until data is deleted per the Terms and Privacy Policy.
2. Nature & purpose of processing
Hosting your links and recording, aggregating, and displaying scan events so you can measure engagement.
3. Categories of data & data subjects
- Data subjects: individuals who scan or click the codes and links you create.
- Personal data: limited scan signals — timestamp, country, approximate city, device type, browser, operating system, and referring source. We do not store scanners' IP addresses.
4. Our obligations as processor
- Process personal data only on your documented instructions (the Service's features and your configuration), unless required otherwise by law;
- Ensure people authorised to process the data are bound by confidentiality;
- Implement appropriate technical and organisational security measures;
- Assist you, so far as possible, in responding to data-subject rights requests;
- Assist you with security, breach notification, and impact assessments given the information available to us;
- Notify you without undue delay after becoming aware of a personal-data breach affecting your data;
- Delete or return your personal data after the Service ends, subject to legal retention;
- Make available information reasonably necessary to demonstrate compliance.
5. Sub-processors
You authorise us to use the sub-processors listed in our Privacy Policy (currently Microsoft Azure for hosting, Resend for email, and our payment provider). We remain responsible for their performance and will give notice of material changes.
6. International transfers
Any transfer of personal data outside the DIFC is made in accordance with Part 8 of the DIFC Data Protection Law, using an adequate jurisdiction or appropriate safeguards.
7. Your responsibilities
You are responsible for having a valid lawful basis for the scan data you collect and for providing any notices or obtaining any consents required from the people who scan your codes under applicable law.
8. Contact
For a countersigned copy or data-protection queries, email privacy@getscaniq.com.