Privacy Policy
Last updated: July 2026
This policy explains what personal data ScanIQ collects, why, and the rights you have. We are committed to data minimisation — collecting as little as we reasonably need to run the Service.
1. Who we are
ScanIQ is a product of Zustis Technologies Limited, a private company registered in the Dubai International Financial Centre (DIFC), Dubai, UAE (DIFC Commercial License CL10305), at IH-00-01-03-OF-05, Level 3, Innovation One, Dubai International Financial Centre (DIFC), Dubai, United Arab Emirates.
We are the data controller for your account and customer data. Our processing is governed by the DIFC Data Protection Law No. 5 of 2020 and its regulations, overseen by the DIFC Commissioner of Data Protection.
Privacy contact: privacy@getscaniq.com.
2. Our two roles
- As a controller — for the data of our account holders (you): your email, authentication data, the links you create, billing references, and support messages.
- As a processor — for the scan analytics collected when someone scans a code you created. For that data you are the controller and we process it on your behalf under our Data Processing Addendum. You are responsible for having a lawful basis and, where required, informing the people who scan your codes.
3. What we collect
- Account data: your email address and a securely hashed password (we never see your plaintext password).
- Your links: the destinations, titles, and settings you create.
- Scan analytics: when a code is scanned we record a timestamp and best-effort, limited signals — country, approximate city, device type, browser, operating system, and the referring source. We do not store scanners' IP addresses. An IP address may be processed transiently in memory only to derive approximate location, and is then discarded. (Standard infrastructure logs may briefly contain IPs for security and are rotated.)
- Billing data: handled by our payment provider. We store only subscription and customer reference IDs — never full card details.
- Support communications: messages you send us and our replies.
- Cookies & local storage: a secure session cookie to keep you signed in, and local storage for interface preferences. See our Cookie Policy.
4. Why we use it, and our lawful basis
Under the DIFC Data Protection Law we rely on the following lawful bases (Article 10):
- Performance of a contract — to create your account, resolve your links, show you analytics, and provide support.
- Legitimate interests — to secure the Service, prevent abuse and fraud, and improve the product, balanced against your rights.
- Legal obligation — to comply with applicable law, tax, and lawful requests.
- Consent — where we ask for it (e.g. optional communications); you may withdraw it at any time.
We do not sell your personal data or the scan data of your links, and we do not use it for third-party advertising.
5. Who we share it with (sub-processors)
We share data only with service providers who help us run ScanIQ, under contract and only as needed:
- Microsoft Azure — cloud hosting and database.
- Resend — transactional email delivery (e.g. password resets).
- Our payment provider — to process subscriptions and handle card data (we do not).
We may also disclose data where required by law or to protect our rights, users, or the public.
6. International transfers
Zustis Technologies Limited is established in the DIFC. Some of our providers process data outside the DIFC. Where we transfer personal data out of the DIFC, we do so in accordance with Part 8 of the DIFC Data Protection Law — to a jurisdiction with an adequate level of protection, or subject to appropriate safeguards (such as contractual data-protection clauses).
7. How long we keep it
- Account data — for as long as your account is active, and a limited period afterwards for legal, tax, and dispute-resolution purposes.
- Links & scan analytics — until you delete the link or your account. Deleting a link deletes its scan data; deleting your account deletes your data.
8. How we protect it
We use encryption in transit (HTTPS/TLS), hashed passwords, session controls, access restrictions, and validated inputs. No system is perfectly secure, but we take reasonable technical and organisational measures appropriate to the risk.
9. Your rights
Subject to the DIFC Data Protection Law, you have the right to:
- Access the personal data we hold about you;
- Correct inaccurate data (rectification);
- Delete your data (erasure) — you can delete links and your account at any time;
- Restrict or object to certain processing;
- Receive your data in a portable format;
- Withdraw consent where processing is based on consent;
- Not be subject to a decision based solely on automated processing that significantly affects you.
To exercise any right, email privacy@getscaniq.com. We aim to respond within one month.
10. Complaints
If you have a concern, please contact us first and we will try to resolve it. You also have the right to lodge a complaint with the DIFC Commissioner of Data Protection (difc.ae).
11. Children
ScanIQ is a business tool not directed to children. We do not knowingly collect data from anyone under 18.
12. Changes
We may update this policy. We will change the "last updated" date and, for material changes, notify account holders.