Data Processing Agreement
Last updated 11 August 2026
Applies automatically whenever QRtub processes personal data on your behalf. No signature needed.
Before you read on
This agreement is already in force. It forms part of our Terms of Service and applies from the moment you start using QRtub — you do not need to sign or request anything.
If your procurement process needs a countersigned copy, or your own template instead of ours, email hi@qrtub.com and we will work through it.
1. Roles
You are the controller of the personal data you put into QRtub. You decide what goes in and why.
We — Teralis Pty Ltd (ABN 76 152 898 649) — are the processor. We handle that data on your instructions and for no other purpose.
Separately, we are the controller of the account information we hold about the people who sign in. That is covered by our privacy policy, not by this agreement.
2. What we process, and for how long
| Subject matter | Providing QRtub: storing your records, resolving your Links, and displaying the Pages you build |
|---|---|
| Duration | For as long as your account is open, plus the retention period in section 9 |
| Nature and purpose | Storage, retrieval, display and deletion, carried out on your instructions |
| Types of personal data | Whatever you choose to enter — typically names, roles, email addresses or phone numbers attached to a record, and any personal data in images you upload. QRtub is designed for information about physical things and places, so this is usually incidental rather than the point |
| Categories of data subject | Your staff, contractors, suppliers and contacts, as determined by you |
| Special category data | Not expected. Do not put health, biometric or similar sensitive data into QRtub without agreeing it with us first |
3. Our obligations
We will:
- Process personal data only on your documented instructions, including for transfers, unless the law requires otherwise — in which case we will tell you first unless the law prevents us
- Make sure anyone we allow to access it is under a duty of confidentiality
- Apply the security measures described in section 6
- Respect the conditions in section 4 before engaging another processor
- Help you respond to requests from individuals exercising their rights
- Help you meet your own obligations on security, breach notification and impact assessments, taking account of what we know and can reasonably do
- Delete or return the data at the end, as set out in section 9
- Give you the information you need to show you are complying, and allow audits as described in section 8
If we think an instruction from you breaches data protection law, we will tell you rather than quietly carry it out.
4. Sub-processors
You give us general authorisation to use sub-processors. The current list is published at qrtub.com/legal/subprocessors, with what each one does and where it operates.
Each sub-processor is bound by written terms that impose data protection obligations no weaker than these. We remain responsible to you for what they do.
That page is the notice. We update it before a new sub-processor begins processing personal data, so checking it tells you the current position at any time. If you object on reasonable data protection grounds, tell us at hi@qrtub.com — we will try to find a workable alternative, and if we cannot you may stop using the service.
5. International transfers
QRtub is hosted in AWS ap-southeast-2 (Sydney, Australia). Some sub-processors operate elsewhere — see the list.
Australia has no UK or EU adequacy decision, so where you are in the United Kingdom or the European Economic Area, transfers to us rely on standard contractual protections:
- For UK personal data — the EU Standard Contractual Clauses (controller-to-processor, Module Two) together with the UK International Data Transfer Addendum, or the UK International Data Transfer Agreement
- For EEA personal data — the EU Standard Contractual Clauses (Module Two)
By accepting these terms you and we enter into those clauses, with this agreement supplying the annex information: the parties are you as data exporter and Teralis Pty Ltd as data importer, the description of processing is in section 2, and the security measures are in section 6. Where the clauses and this agreement conflict, the clauses prevail.
If you need a signed copy of the clauses for your records, or a transfer risk assessment for your own files, ask and we will provide one.
6. Security measures
What we actually do, rather than what sounds reassuring:
- Personal data encrypted in transit (TLS) and at rest
- Row-level security in the database, so one customer’s records cannot be reached from another’s account
- Authentication sessions held in HTTP-only, secure cookies
- Rate limiting on sign-in and other sensitive actions
- Access to production systems restricted to people who need it
- Regular patching through our hosting providers
- Backups managed by our database provider, encrypted at rest
We do not currently hold ISO 27001 or SOC 2 certification, and we would rather say so than imply otherwise. If your procurement requires either, tell us and we will be straight with you about timelines.
7. Personal data breaches
If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any event within 72 hours, with what we know at the time: what happened, which categories and roughly how many records are affected, the likely consequences, and what we are doing about it.
We will keep you updated as we learn more, and help you meet your own notification obligations to regulators and individuals. We will not make a public statement about a breach affecting your data without talking to you first, unless the law requires it.
8. Audits and information
We will give you the information you reasonably need to show you are meeting your obligations, including answering security questionnaires.
You may audit our compliance with this agreement once in any 12 months, on at least 30 days’ written notice, during business hours, in a way that does not disrupt the service or compromise other customers’ data. You cover your own costs and ours. If a regulator requires more, we will cooperate.
9. What happens at the end
When your account closes, you can export your records as CSV at any point beforehand. After closure we keep the data for 30 days so you can retrieve it or restart, then delete it.
If you would like it deleted sooner, or want written confirmation once it is done, email hi@qrtub.com.
Backups age out on their own cycle, after which the data is gone from those too.
10. Helping you answer individuals
If someone asks us directly to access, correct or delete personal data that belongs to your account, we will not action it ourselves — it is yours to decide. We will point them to you and let you know.
Most of what an individual might ask for, you can do yourself in the product. Where you cannot, we will help.
11. Liability
Liability under this agreement is subject to the limits in our Terms of Service, except where the law does not allow that — including under the Standard Contractual Clauses, which set their own liability position between the parties.
12. Changes
We may update this agreement to reflect changes in law or in how the service works. For anything that materially affects your rights we will give account holders at least 30 days’ notice by email.
13. Contact
hi@qrtub.com — for data protection questions, a countersigned copy, our transfer risk assessment, or a security questionnaire.