Legal document
Privacy policy
EnglishRomână
Last updated: · Effective version
This privacy policy explains how Alexandru Jungean (“the operator”, “I”, “me”) processes personal data in connection with QR Generator at https://qr.alexjungean.com (the “service”). It is issued under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR), Law no. 190/2018, and Law no. 506/2004.
The service is built so QR payloads, optional logos, previews, and exports stay in your browser memory and are not uploaded to an application server. Visiting any public page still creates ordinary technical connection data at the hosting layer. This policy describes both facts. It does not claim that loading a website processes no personal data.
1. Who is the controller
The controller is Alexandru Jungean, a natural person established in Cluj-Napoca, Romania.
- Email: alex.jungean@gmail.com
- Phone: +40 757 673 677
- Public contact page: https://alexjungean.com/contact
- Portfolio: https://alexjungean.com
A complete postal street address is not published on this site. It will be provided without delay to a supervisory authority, a court, or a data subject who sends a legitimate request to the contact email.
No data protection officer is appointed. The operator’s core activity is not large-scale regular and systematic monitoring of individuals and is not large-scale processing of special-category data.
2. Scope of this policy
This policy applies to:
- the public pages of the service, including the generator and the legal documents;
- technical data created when your browser requests those pages or their same-origin bundled assets;
- personal data you send if you contact the operator about the service.
This policy does not apply to:
- websites you encode in a QR code, or any destination a third party reaches by scanning a code you created;
- the alexjungean.com portfolio, contact form, or any other site linked from the footer, which have their own processing;
- your device, browser extensions, operating system, printer, or camera apps, which the operator does not control.
3. Two layers of processing
Application layer. After the page and its same-origin scripts, styles, fonts, and images load, QR generation, logo checks, preview, and PNG/SVG export run in your browser. Tool routes do not include analytics, telemetry, an error-reporting SDK, third-party scripts, remote fonts, uploads, accounts, or a runtime application API. Payloads and logo bytes are not written to cookies, localStorage, sessionStorage, or IndexedDB by the service.
Hosting layer. The static site is served over HTTPS by Netlify, Inc. from the project published at https://qr.alexjungean.com. A request for a document or a bundled asset is an ordinary HTTPS request. The host necessarily processes technical data needed to deliver the file, keep TLS working, and operate a public website.
Those layers must not be confused. “Browser-local generation” means the operator does not receive the text, URLs, Wi-Fi credentials, vCards, phone numbers, or logo files you type or attach. It does not mean that the host logs no IP address when the page is fetched.
4. Data the operator does not receive
The operator does not receive, store, or have access to:
- URL, text, email, phone, SMS, Wi-Fi, or vCard fields you enter;
- optional JPEG, PNG, or WebP logo files;
- preview images or PNG/SVG exports;
- derived encoder metadata, warning results, or object URLs created in the page.
Those materials exist in ephemeral browser memory on your device. Closing the tab, using Reset, or leaving the page discards them from the application’s working state. The operator cannot fulfil an access or erasure request for content that was never transmitted.
If you later send a generated file, a screenshot, or a payload to another person, that disclosure is your act, not processing by this service.
5. Data created when you load the site
When your browser requests https://qr.alexjungean.com or a same-origin asset, the hosting infrastructure may process typical HTTP(S) technical data, such as:
- IP address and approximate network location derived from it;
- date and time of the request;
- requested path and query string of the page or asset;
- user-agent and other standard request headers;
- referrer, if your browser sends one (this service emits
Referrer-Policy: no-referrerand does not add tracking parameters); - TLS and delivery metadata used to serve HTTPS.
The generator does not put payload or logo data into the address bar, request headers, or request bodies of subsequent asset loads. A query marker used only in automated tests is not used as a product analytics identifier.
The operator does not run a first-party analytics product, advertising pixel, session replay, or A/B testing tool on the service.
6. Purposes and legal bases
| Processing | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Hosting and delivery of public pages and bundled assets | Make the service available over HTTPS and return the requested file | Art. 6(1)(f) legitimate interests in offering a public information-society service; where you use the generator, also Art. 6(1)(b) as steps needed to provide that service |
| Security, abuse, and availability logs at the host | Detect attacks, overload, and misuse of the public origin | Art. 6(1)(f) legitimate interests in securing a public website; Art. 6(1)(c) where a legal obligation requires retention |
| Correspondence you send to the contact email or phone | Answer questions, handle rights requests, and keep a record of the exchange | Art. 6(1)(f) legitimate interests in communication; Art. 6(1)(c) for data-subject requests and legal claims; Art. 6(1)(b) if the message concerns a contract |
| Publication of this policy and related legal pages | Meet transparency duties | Art. 6(1)(c) legal obligation |
Legitimate interests are limited to delivering, securing, and documenting a free public tool. They do not include advertising, profiling, or sale of data. You may object under Article 21 GDPR. If the processing is necessary to deliver the site itself, an objection may mean the service cannot be provided to you.
The operator does not process special-category data as part of the service. If you choose to encode health, biometric, or other sensitive information in a QR code, that content remains on your device and is your responsibility.
7. Recipients and processors
The hosting processor is Netlify, Inc., which serves the published site. See https://www.netlify.com/privacy/ and https://www.netlify.com/gdpr-dpa/.
Email sent to alex.jungean@gmail.com is carried by Google LLC as the inbox provider. Phone calls use the public telephone network.
Data may also be disclosed to professional advisers, a court, or a competent authority when the operator is legally required or entitled to do so, or to defend a legal claim.
The operator does not sell personal data and does not share it with advertisers or data brokers.
8. International transfers
Netlify, Inc. is established in the United States and may process hosting data outside the European Economic Area. Google LLC may process email outside the EEA.
Where a transfer occurs, it relies on an adequacy decision where one applies (including the EU–US Data Privacy Framework for a certified organisation) or on standard contractual clauses and supplementary measures described by the recipient. You may ask the operator for further information about the relevant safeguards.
9. Retention
- Application-layer payloads, logos, previews, and exports are not retained by the operator.
- Hosting logs are retained only for the period kept by Netlify, Inc. in the ordinary operation of the site. The operator does not run a separate log warehouse for this service.
- Correspondence is kept for as long as needed to finish the request and for the limitation period of related legal claims, then deleted or archived with reduced access.
11. If you contact the operator
If you email, call, or write through the public contact page, the operator processes the identity and contact details you provide, the content of the message, and technical metadata of the communication. Do not send passwords, full payment card numbers, or unnecessary special-category data.
The portfolio contact form on alexjungean.com is a different website. It may use its own processors, including bot-protection tools. Use the email address in this policy if you want the request to be handled as a QR Generator privacy request.
12. Security measures
The following measures are implemented in the published service. They reduce specific risks. They are not a certification and they do not make the service safe on a compromised device.
- HTTPS with HSTS on the published origin.
- Content-Security-Policy that limits scripts, fonts, and connections to the same origin, with
connect-src 'none'after document navigation. - Referrer-Policy
no-referrer, frame denial, and a permissions policy that disables camera, microphone, geolocation, and payment APIs. - Local logo checks: magic-byte validation, size bounds, decode and re-encode in the browser, rejection of AVIF, SVG, and mismatched types.
- SVG export limited to generated QR geometry and embedded re-encoded raster data, without scripts or external references.
The operator cannot protect you from a malicious extension, a shared computer, or a code you choose to print or forward.
13. Automated decisions
The service does not make automated decisions that produce legal or similarly significant effects about you. Contrast and logo-coverage messages are on-device heuristics about the current preview. They are not a credit, identity, or eligibility decision.
14. Children
The service is a general-purpose tool. It is not directed at children under 16, which is the age of digital consent in Romania under Article 8 GDPR. The operator does not knowingly collect contact data from a child. If you believe a child has sent personal data by email, contact the operator so it can be deleted.
15. Your rights
Where GDPR applies, you may request:
- access to personal data the operator holds about you;
- rectification of inaccurate data;
- erasure, where a ground in Article 17 applies;
- restriction of processing;
- objection to processing based on legitimate interests;
- portability of data you have provided, where the basis is contract or consent and processing is automated;
- withdrawal of consent, if consent was the basis used.
These rights apply to data the operator actually holds, such as an email you sent. They cannot be used to retrieve a QR payload that never left your browser.
16. How to exercise your rights
Email alex.jungean@gmail.com with the subject line “QR Generator privacy request”. Describe the request and enough information to identify the relevant correspondence. The operator may ask for additional information to confirm it is you.
A response will be sent without undue delay and in any event within one month, extendable by two further months for complex or numerous requests, with notice of the extension.
17. Complaints
You may lodge a complaint with Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, București, România. Website: https://www.dataprotection.ro/. If you live in another EEA country, you may also complain to your local supervisory authority. ANSPDCP is the lead authority for this operator.
18. Other websites
Links to https://alexjungean.com, Netlify, Inc., authorities, and licence texts leave this origin. Those sites set their own cookies and policies. The required footer attribution opens https://alexjungean.com in a new tab. That site is not the QR Generator application and is not covered by the local-processing boundary described here.
19. Users outside the EU
The operator is established in Romania and designs this notice for GDPR. If you use the service from the United Kingdom, the UK GDPR and the Information Commissioner’s Office may also be relevant. If you are in a US state with a consumer privacy law, the operator does not sell or “share” personal information for cross-context behavioural advertising, and does not use the service to profile you. Hosting logs are technical data held by the host for delivery and security.
20. Changes
This policy may change when the service, the host, or the law changes. The date at the top of this page is the effective date. The current text on https://qr.alexjungean.com is the only operative version. Material changes will remain readable on this page.
Effective date of this version: 20 August 2026.
21. Contact
Controller: Alexandru Jungean, Cluj-Napoca, Romania. Email: alex.jungean@gmail.com. Phone: +40 757 673 677.
Related documents: terms of use, cookie policy, legal notice, acceptable use.
The English and Romanian texts describe the same service. If they differ, the English text at /privacy prevails, without limiting any mandatory consumer or data-protection rights that apply in Romania or the European Union.
