QRmia

Privacy policy

Updated: 21 September 2026

Controller and contact

Arbitre AI SL, NIF B10675692, Calle Quevedo 16, Dénia (Alicante), 03700, Spain, is responsible for the QRmia processing described here. For data questions and rights requests: r@arbitre.ai. Support is also available on the home page.

Data and sources

We receive your sign-in email, account identifiers and activity dates, session and security data, language preferences and submitted content: titles, descriptions, images, links and QR coordinates. Administrator authentication also uses hashed credentials. Visitors may send messages to QR owners or Support. Technical data include IP addresses, browser information and anti-bot checks; the application uses IP-derived identifiers for abuse limits and counts page openings. A QR owner may also submit information about you.

Purposes and lawful bases

Data necessary to manage accounts, store and display QR content, relay messages and handle requests are processed to provide the service (GDPR Article 6(1)(b)). Security, fraud prevention and legal claims rely on legitimate interests balanced against your rights (Article 6(1)(f)); legal obligations rely on Article 6(1)(c). Optional actions requiring consent, such as requested device location access or remembering sign-in, are enabled by your choice. You may withdraw consent without affecting earlier lawful processing. We do not use profiling to make automated decisions with legal or similarly significant effects; automated security controls may temporarily block abusive sign-in attempts.

Required data and visibility

An email is required to sign in and manage QR codes; additional content and location are optional. Public fields are accessible to anyone with the link, including people to whom it is forwarded. Hiding a field does not remove copies already made. The contact feature does not display the owner's email to the visitor, but sends the message text to its recipient. Support may receive your session email or contact details supplied in your message. Do not include information you do not wish to transmit.

Providers and international processing

Cloudflare supplies infrastructure, database, file storage, email delivery and Turnstile; see its privacy policy and data processing terms. The recipient’s email provider also handles messages. Opening OpenStreetMap sends IP and viewed area to its servers (policy). When Google map features are enabled, opening a map sends Google IP and coordinates; an organisation search sends QR coordinates and language. Results come from Google and its providers; links open external sites. The Google Privacy Policy applies. Global infrastructure may process data outside the EEA; such transfers must be covered by adequacy decisions or applicable safeguards, such as standard contractual clauses. You may request information about the relevant safeguards. We do not claim all data remain in Spain.

Retention

Account data and content are retained while necessary to provide the service and manage our relationship with you. You may request deletion or account closure. Sign-in codes expire after 10 minutes; expiration does not necessarily immediately delete all technical records. Ordinary non-remembered sessions last at most 12 hours and are not restored after reload; remembered sessions can last up to one year unless ended or revoked earlier. Security records, mailbox messages and backups follow periods necessary for their purposes and applicable obligations; instant erasure of every copy is not promised. Following a request, applicable data will be deleted or retention restricted where a legal obligation or pending claim requires preservation.

Cookies and browser storage

QRmia saves language preferences in local storage. If you choose remembered sign-in, it uses a secure session cookie; administration has a separate session. You can sign out and clear browser cookies or storage, but this can disable features. Turnstile and maps may process technical information under the linked policies. This QRmia version does not include advertising tools or third-party commercial tracking; additions requiring consent must provide a prior choice.

Your rights

You may request access, correction, erasure, portability, restriction or objection, and withdraw consent where it is the processing basis, using the contact above. Describe your request; proportionate identity information may be requested where necessary. Requests are normally addressed within one month, subject to statutory extensions and exceptions. You may complain to the Spanish Data Protection Agency (AEPD) or another competent authority. This policy will be updated as the service changes; material changes will be communicated as appropriate.

Maps and organization searches

Opening an embedded Google map sends Google the browser IP address, QR coordinates and technical request information; it loads only after permission. Nearby searches send QR coordinates, radius, selected categories and language from QRmia's server to Google Places, not the visitor's device location, email or QR title. The application does not store results; external links open Google Maps. Google's privacy policy and Maps terms apply.

Permission is for one opening by default. If you choose, QRmia saves permission in this browser's local storage until reset or browser data removal. «Privacy settings» in every page footer lets you disable or reset it, removing the saved choice and unloading the open map. This does not retract data already sent. Permission is not tied to your account and does not cover device location, OpenStreetMap or CAPTCHA. When storage is unavailable, the choice is not remembered.