SilverQR — Privacy Policy
Version 2026-07-30.
This policy explains how Royal SoftWorks DOO Kragujevac ("SilverQR", "we") handles personal data. It covers two very different groups of people, and the distinction determines who is answerable for what:
| Who | Our role | |
|---|---|---|
| A | Account holders — venue owners, managers and staff who sign in to the SilverQR dashboard | We are the controller |
| B | Guests — people who scan a venue's QR code and open its mini-site | The venue is the controller; we are a processor acting on its instructions |
If you are a guest and want to exercise a right, you may use our self-service tools (§7) or contact the venue directly. Where we act only as processor we will refer substantive requests to the venue, which decides how they are answered.
1. Data we process about account holders (we are controller)
| Data | Why | Lawful basis | Retained |
|---|---|---|---|
| Name, email address, hashed password | Create and secure the account | Performance of contract | Life of account |
| Workspace, brand and venue names | Provide the Service | Performance of contract | Life of account |
| Email-verification and password-reset tokens | Account security | Performance of contract | ≤ 24 h / ≤ 1 h, then purged |
| Session records (hashed refresh tokens, tenant, timestamps) | Keep you signed in; revoke sessions | Legitimate interests — security | Until expiry, max 30 days |
| Terms version and acceptance timestamp | Evidence of agreement | Legal obligation / legitimate interests | Life of account + 1 year |
| Audit log of administrative actions | Security, accountability, dispute resolution | Legitimate interests | 365 days |
| Support correspondence | Answer you | Legitimate interests | 2 years |
We do not sell account-holder data, and we do not use it for advertising.
2. Data processed about guests (the venue is controller)
When a guest opens a venue's mini-site, the following is processed on that venue's behalf and on its instructions:
| Data | Why the venue collects it | Retained |
|---|---|---|
| A random identifier stored in the browser | Recognise a returning device | Until erased or the profile goes dormant |
| A device-traits hash ("signals hash") derived from GPU/renderer string, screen metrics, platform, touch capability, memory and a canvas rendering | Recognise the same device when browser storage has been cleared | As above |
| Visit timestamp, venue, area/table label, device class | Show the venue who is on site and when | 90 days |
| Hashed IP address and hashed user-agent (truncated SHA-256, never stored in raw form) | De-duplicate visits; abuse prevention | With the visit record |
| Name and email address, only if the guest types them into a service request | Fulfil the request the guest made | With the request |
| Service requests (call waiter, bill, order note) | Deliver the requested service | 30 days after being closed |
| Staff ratings, flags and free-text notes about a guest | Let the venue enforce its house rules | Until removed by the venue, or profile erasure |
| Venue or platform restrictions (bans) | Enforce the venue's house rules | While active; lifted records kept as history |
| QR scan events (hashed user-agent only, no identifier) | Anonymous venue analytics | 180 days |
Guest profiles with no activity for 365 days are deleted automatically, together with their recognition signals, unless an active restriction is attached.
These periods are enforced by an automated sweep, not by manual housekeeping, and
are published in machine-readable form at /api/privacy/disclosure.
2.1 Be clear about what the device-traits hash is
The signals hash is a fingerprinting technique. It is designed to recognise a device after browser storage has been cleared, which is precisely the behaviour that many data-protection regimes — including the EU ePrivacy rules as applied by national regulators — treat as requiring informed consent, not merely a legitimate-interests assessment.
Obtaining that consent is the venue's responsibility, not ours. We provide a notice component in every mini-site theme and a documented switch to disable recognition signals per venue. A venue that leaves recognition enabled without a lawful basis is acting outside our instructions and outside the DPA.
3. What we deliberately do not do
To keep exposure low, the platform is built without:
- third-party analytics, advertising or marketing trackers on mini-sites;
- open-rate or click tracking in our emails (all mail is plain text);
- sale, rental or brokerage of personal data to anyone, ever;
- automated decision-making producing legal effects on a guest — a restriction is always an action taken by a human member of venue staff;
- storage of raw IP addresses or raw user-agent strings against a guest;
- collection of precise location, payment data, biometrics, or any special category of data under Art. 9 GDPR.
4. Who else sees the data (sub-processors)
| Sub-processor | Purpose | Where your data is | Where the company is |
|---|---|---|---|
| Momentum Minds LLC, trading as LuxVPS | Server hosting, database, cache, object storage | Frankfurt, Germany (EU) | United States |
| Cloudflare, Inc. | CDN, DNS, TLS termination, DDoS protection, where enabled | Global edge; EU-first routing | United States |
| SMTP relay provider | Transactional email delivery | Ask us — see below | Ask us — see below |
Your data is stored in Germany. The servers that run SilverQR, hold the database and store uploaded files are in Frankfurt. We do not routinely copy personal data anywhere else.
But the companies involved are not all in the EU, and we would rather say so plainly than bury it. Our hosting provider is a US company operating German servers, and we are a Serbian company. EU law treats access from outside the EEA as a transfer even when the hardware never leaves Europe. Those transfers rely on the European Commission's Standard Contractual Clauses together with supplementary technical measures (TLS in transit, encryption at rest, administrator access limited to named individuals). The detail is in §5 of the DPA.
We will tell you the current SMTP provider and where it is established if you ask at [email protected]. Service email carries account messages only, not guest records.
We may also disclose data where required by binding legal process, to protect our rights, or in connection with a merger or acquisition, in which case the acquirer is bound by terms no less protective.
5. Security
Passwords are hashed with bcrypt (cost 12). Session, invitation, verification and reset tokens are stored only as SHA-256 hashes, so a database read cannot be replayed. Distinct cryptographic keys are used for session tokens, refresh tokens, QR signatures and venue-access cookies, so compromise of one does not extend to the others. QR signatures are encrypted at rest. Transport is TLS throughout. Access to production is limited to named administrators.
We will notify the relevant supervisory authority and, where required, affected individuals of a personal-data breach in accordance with Art. 33–34 GDPR. Where we act as processor we will notify the venue without undue delay so that it can discharge its own notification duties.
6. Rights of account holders
If you hold a SilverQR account you may request access to, rectification of, erasure of, restriction of, or portability of your personal data, and may object to processing based on legitimate interests. Contact [email protected]. We respond within one month, extendable by two further months for complex requests.
Deleting your workspace deletes the account data; audit records and the terms acceptance record are retained for the periods in §1, because they are what evidence lawful operation of the platform.
7. Rights of guests
Guests have the same rights, exercisable against the venue as controller. To make it practical, we operate self-service tooling that does not require you to identify the venue:
- Access — request a copy of what is held against your email address.
- Erasure — request deletion of what is held against your email address.
Both are available at /legal/data-request. Because a guest has no account, the
only way to verify a request is control of the email address: we send a
single-use link valid for 30 minutes and act only when it is returned. Requests
for addresses not on file receive the same response as those on file, so the tool
cannot be used to discover whether someone has visited a venue.
What erasure removes: visit history, service requests, staff ratings, device recognition signals, and the guest profile itself.
What erasure does not remove: where a venue has an active restriction against a profile, the profile and the opaque recognition signal needed to make that restriction work are retained under the venue's legitimate interests in enforcing its house rules and protecting its staff and customers (Art. 6(1)(f), Art. 17(1)(c) GDPR). Everything contactable — name, email, IP and user-agent hashes — is stripped even in that case. You may object to this retention with the venue, which must weigh your objection against its interest and decide.
If a guest asks us for something only the venue can decide, we will pass the request to the venue and tell you we have done so.
8. Complaints
You may lodge a complaint with a supervisory authority. In Serbia this is the Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs). In the EU/EEA you may complain to the authority in your country of residence or workplace. We would prefer the chance to resolve it first: [email protected].
9. Children
The Service is not directed at children and we do not knowingly process the personal data of anyone under 16. A venue must not use the Service to profile children. If you believe a child's data has been collected, contact [email protected] and we will remove it.
10. Beta status
During the open beta the platform is under active development, data may be reset
or migrated, and features affecting what is collected may change. Material changes
to this policy raise the version string above and are announced in the dashboard.
The current version is always published at /legal/privacy.
Controller for account-holder data Royal SoftWorks DOO Kragujevac, Kragujevac, Republic of Serbia [email protected]
For guest data, the controller is the venue whose QR code was scanned. Its identity is shown on the mini-site.