Privacy Policy

Privacy Policy – QR Code Maken

Table of Contents

  1. Data Controller
  2. What personal data do we collect?
  3. Purposes and legal bases for processing
  4. Retention periods
  5. Disclosure to third parties
  6. International data transfers
  7. Security
  8. Your rights under the GDPR
  9. Cookies and similar technologies
  10. Minors
  11. Changes to this policy
  12. Contact and complaints

This privacy policy has been drafted in accordance with the General Data Protection Regulation (GDPR – Regulation (EU) 2016/679), the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data, and the Belgian Act of 13 June 2005 on electronic communications.

1. Data Controller

The data controller responsible for your personal data is:

DetailInformation
Trading nameSofie.be – Digital Solutions
Enterprise numberBE0823170308
AddressRauwakker 7, 1745 Mazenzele, Belgium (no visiting address)
Websiteqrcodemaken.be
Emailinfo@sofie.be
CountryBelgium

For all questions regarding the processing of your personal data, please contact us at the email address above.

2. What personal data do we collect?

2.1 Data you actively provide

2.2 Automatically collected data

2.3 Special categories of data

We do not process special categories of personal data (such as health data, political beliefs or biometric data).

3. Purposes and legal bases for processing

PurposeLegal basis (GDPR art. 6)
Creating and managing your accountPerformance of a contract (art. 6.1.b)
Providing QR code servicesPerformance of a contract (art. 6.1.b)
Processing paymentsPerformance of a contract (art. 6.1.b)
Customer support and communicationPerformance of a contract (art. 6.1.b)
Legal obligations (invoicing, taxes)Legal obligation (art. 6.1.c)
Service analysis and improvementLegitimate interest (art. 6.1.f)
Security and fraud preventionLegitimate interest (art. 6.1.f)
Marketing communications (newsletter)Consent (art. 6.1.a)
Cookies and tracking (non-essential)Consent (art. 6.1.a)

Where we rely on legitimate interest, we have carried out a balancing test between our interests and your rights and freedoms. You may object to such processing at any time.

4. Retention periods

CategoryRetention period
Account data (active account)For the duration of the account + 30 days after deletion
Billing data10 years (Belgian Accounting Act of 17 July 1975)
QR code content (dynamic)For as long as the QR code is active; max. 30 days after deletion
Scan statisticsDepending on your subscription plan (see plan details)
Contact form messages2 years after last contact
Technical logs (security purposes)90 days
Marketing (after unsubscribe)Immediately removed from mailing list; proof of unsubscribe kept 3 years

5. Disclosure to third parties

We never sell your personal data to third parties. We share data only in the following cases:

5.1 Processors (sub-processors)

5.2 Legal obligation

We may disclose your data to competent authorities (police, courts, regulators) where legally required or where necessary to protect our rights.

5.3 Business transfer

In the event of a merger, acquisition or sale of assets, personal data may be transferred. We will notify you before your data is transferred.

6. International data transfers

We aim to process your data within the European Economic Area (EEA). Where data is transferred outside the EEA, this is done exclusively on the basis of an adequacy decision by the European Commission, Standard Contractual Clauses (SCCs), or with your explicit consent.

7. Security of personal data

We take appropriate technical and organisational measures to protect your personal data, including: encrypted connections (HTTPS/SSL), hashed password storage (bcrypt), need-to-know access control, regular security updates, and backup procedures. In the event of a data breach posing a risk to your rights and freedoms, we will notify you and the Belgian Data Protection Authority (GBA) in accordance with art. 33–34 GDPR.

8. Your rights under the GDPR

RightDescription
Right of access (art. 15)You may request which personal data we process about you.
Right to rectification (art. 16)You may have inaccurate or incomplete data corrected.
Right to erasure (art. 17)You may in certain cases request deletion of your data ("right to be forgotten").
Right to restriction (art. 18)You may request restriction of processing in certain circumstances.
Right to data portability (art. 20)You may request your data in a structured, machine-readable format.
Right to object (art. 21)You may object to processing based on legitimate interest or direct marketing.
Rights re. automated decisions (art. 22)You have the right not to be subject solely to automated decision-making.
Right to withdraw consentYou may withdraw consent at any time, without affecting the lawfulness of prior processing.

To submit a request, contact us at info@sofie.be. We will respond within 30 calendar days.

8.1 Right to lodge a complaint

9. Cookies and similar technologies

We use cookies and similar technologies. For detailed information, please refer to our separate Cookie Policy.

10. Minors

Our services are not directed at persons under the age of 16. We do not knowingly collect personal data from minors. If you believe we may have inadvertently collected data from a child, please contact us at info@sofie.be.

11. Changes to this privacy policy

We may update this privacy policy from time to time. The date of the last update is shown at the top of this document. For material changes, we will notify you by email or via a prominent notice on our website prior to the change taking effect.

12. Contact

© 2026 Sofie.be – Digital Solutions | qrcodemaken.be
This privacy policy has been drafted in accordance with GDPR (Regulation (EU) 2016/679) and Belgian privacy legislation.