Privacy Notice for the Qard™ scan Application

iOS and Android

Effective date: 11 August 2026
Version: 1.1
Application identifier: eu.qard.scanapp

This notice explains the processing of personal data associated with the use of the Qard™ scan application for iOS and Android. It supplements the general privacy notice of the Qard™ SaaS platform and the privacy notice of the accepting place or other organisation using the application; it does not replace either notice.

1. Purpose of the application

Qard™ scan is an operational application for authorised staff of Qard accepting places. It allows a user to identify a Qard card, check the permitted operations, record a Qard use or wallet operation, review transaction history, change their password and sign out.

There is no public registration in the application. Access is provisioned by the accepting place or an authorised administrator of the Qard system. The provider username is a separate system identifier and is not an email address. The application processes an email address only if the person provides it separately, for example in a support request.

In the application, the word “transaction” means a record of a use, admission, point, occasion or balance change associated with a Qard card or Qard wallet. The current application does not request or process payment-card details, bank-account details or payment credentials, does not initiate money transfers, and does not perform actual payment processing or settlement.

2. Controllers and roles

2.1 Application publisher

Gábor Kaderavek, sole proprietor
Registered office and postal address: 8600 Siófok, Pipitér u. 1., Hungary
Sole proprietor registration number: 22205519
Tax number: 60705079-2-34
EU VAT number: HU60705079
Privacy contact: info@kaderavek.hu
Telephone: +36 30 606 6646
Web: https://kaderavek.hu
Support: https://support.qard.eu

The Publisher acts as an independent controller for support requests received directly by the Publisher, technical and security administration related to the release of the application, and compliance with the Publisher's own legal obligations. Installing the application does not by itself give the Publisher access to an accepting place's Qard account, scanned QR codes, card data or transaction data held in the Qard backend.

2.2 Organisation using the application

The accepting place, employer or other Qard customer (the tenant) generally acts as controller where it determines:

  • who may use the application and with which permissions;
  • which card, membership, admission or other service data it processes; and
  • the purposes, legal bases and retention periods for that processing.

The tenant's own privacy notice identifies the tenant, provides its contact details, and explains its specific purposes, legal bases and retention rules. A data-subject request relating to a staff account, a particular card or a Qard operation should first be sent to the tenant.

2.3 Qard platform operator

Qilaq Solutions Kft.
Registered office and postal address: 8623 Balatonföldvár, Móricz Zs. u. 26/b/3., Hungary
Email: info@qilaq.hu
Web: www.qilaq.hu

Qilaq Solutions Kft. generally operates the Qard platform as a processor for processing determined by a tenant. It may act as an independent controller for limited activities, for example the administration of the service contract and tenant administrator accounts, support, information security, prevention of abuse and compliance with legal obligations. The Qard™ SaaS platform notice explains these roles in more detail.

3. What data does the application process?

3.1 Sign-in and session data

  • the normalised domain name of the Qard backend;
  • the accepting-place identifier (provider GUID);
  • the provider username, which is not an email address;
  • password;
  • authentication key, its expiry and technical state required for controlled session recovery.

These data identify and authenticate an authorised user, maintain the session, allow the user to change their password and support secure sign-out.

3.2 Camera, QR and manual-search data

  • camera frames while a QR code is being recognised;
  • the raw content of the QR code or a manually entered card number/encoded value;
  • the internal card reference and masked card identifier returned by the server.

Camera frames and QR-code content are processed on the device. The application does not upload the image, save it as a photo or send it to the Qard backend. Only the decoded QR content is sent to the configured Qard backend as a card identifier. The application does not open the web address encoded in the QR code and does not send a network request to that address.

If a card check started from the scanner cannot be completed because of a network failure, the QR content may be placed in an encrypted offline scan list bound to the signed-in user and accepting place for later online processing. This is not a transaction queue: it stores no operation, amount, wallet or PIN, and it performs no automatic submission. The device scan time does not become the time of a later transaction.

3.3 Card and Qard-operation data

Depending on the tenant's configuration and the user's permissions:

  • masked card identifier, internal card reference and usability status;
  • available provider or wallet operation, its direction, unit, limits and PIN requirement;
  • Qard balance, change, wallet identifier and wallet name;
  • transaction identifier, client transaction identifier, time, status and history data;
  • in the case of an uncertain network outcome, minimal reconciliation data required to prevent the operation from being recorded twice.

The application treats the server as the authoritative source of business state. Transaction history is fetched from the Qard backend whenever it is opened; the device does not maintain a persistent transaction database.

3.4 PIN and password-change data

The card PIN, current password, new password and password confirmation remain in application memory only for as long as required for the operation. A PIN is never placed in persistent storage, a URL, logs or support material.

3.5 Technical and security data

As part of network operation and security, the Qard backend may process an IP address, timestamp, application and backend version, session and authentication event, request identifier, endpoint, response code, and security or error category.

The application's own diagnostics retain no more than 100 payload-free network events in memory. These events do not contain request or response bodies, queries, headers, raw error text, passwords, PINs, authentication keys, complete QR content or complete card data. The application does not integrate Sentry, Firebase Crashlytics or an external in-app analytics service.

3.6 Support data

If a user requests support, the request may include a name or contact detail provided by the user, the app version and build number, platform, approximate time of the event, and a random support or correlation identifier. A password, PIN, authentication key, complete QR code or complete card data must not be sent to support.

3.7 Sources of data

Data may be obtained directly from the application user, from the user account and permissions created by the tenant, from a Qard card or QR code presented by the cardholder, from business responses returned by the Qard backend, and from technical events generated during operation of the device and application.

4. Android QR recognition and Google ML Kit

The Android version uses the bundled Google ML Kit barcode scanning SDK. QR recognition takes place on the device; Qard™ scan does not send raw camera images or decoded QR content to Google.

According to Google's disclosure, ML Kit may nevertheless collect the following technical data for diagnostics and usage analytics:

  • device manufacturer, model, operating system and available ML accelerators;
  • application package name and application version;
  • a per-installation identifier not intended to uniquely identify a user or physical device;
  • performance metrics such as processing latency;
  • API configuration, input and output size, and feature version; and
  • event types and error codes related to initialisation, detection and resource release.

ML Kit auto-zoom is disabled. Therefore, the scan-session identifier, zoom changes and barcode bounding-box information separately listed by Google for auto-zoom are not part of the intended processing. Google states that ML Kit transmits this data using HTTPS and does not share it with third parties. See Google's ML Kit Android data disclosure and Google's Privacy Policy.

This ML Kit processing applies only to Android. The iOS version does not include a Google ML Kit dependency.

Purpose Typical legal basis and responsible party
User access, authentication, card validation and Qard operation The legal basis determined by the tenant. This may be performance of a contract where the data subject is a party to that contract (Article 6(1)(b) GDPR), the tenant's legitimate interest in operating the service securely (Article 6(1)(f) GDPR), or a legal obligation applicable to the relevant service. When acting as processor, Qilaq follows the tenant's documented instructions.
Availability and protection of the Qard platform and application, error prevention and abuse handling The relevant controller's legitimate interest in maintaining a secure and reliable service (Article 6(1)(f) GDPR).
Support and handling user requests Depending on the request, performance of a contract or the legitimate interests of the controller and the user in resolving the issue or request.
Legal obligations, authority requests and legal claims Compliance with a legal obligation (Article 6(1)(c) GDPR) or a legitimate interest in establishing, exercising or defending legal claims.
Android ML Kit technical diagnostics Legitimate interests in reliable and compatible QR recognition and diagnostics; Google's terms and privacy notice also apply to Google's own processing.

The operating system's camera permission controls access to the device camera; it is not general consent to data processing. The user may refuse or later revoke the permission, in which case manual card search remains available.

The backend domain, provider GUID, username and password are required for sign-in; the protected functions of the application cannot be used without them. A card cannot be checked without a card identifier, and an operation for which the server requires a PIN cannot be completed without that PIN. Use of the camera and submission of a support request are optional; manual search may be used instead of the camera.

The application does not use personal data for advertising, cross-app or cross-site tracking, user profiling or sale of data. There is no advertising profiling or advertising-related automated decision-making. Machine-readable business rules in the Qard backend check whether a particular card operation is permitted; the tenant determines the purposes and legal basis of those rules.

6. Permissions and storage on the device

The application uses the following access permissions:

  • camera: requested only when the user opens the QR scanner;
  • internet and network state: used to reach the Qard backend and, on Android, for the technical operation of ML Kit.

The application does not request access to location, microphone, contacts, photo library or general file storage.

The backend domain, provider GUID, username, password, authentication key and expiry are stored using platform-protected storage: Keychain on iOS and Keystore-backed storage on Android. PINs, complete card data, transaction receipts and history responses remain in memory only. Raw QR content also normally remains in memory; after a network failure it may be retained for no more than 72 hours in an owner-isolated offline list of at most 100 records in the same platform-protected storage.

On Android, application data is excluded from operating-system cloud backup and device transfer. On iOS, the device-bound Keychain record is not synchronised to another device, but may remain on the same device after the application is uninstalled. Users should therefore sign out before uninstalling the application; after reinstallation, the client validates the session again.

7. Recipients, processors and transfers

To the extent necessary, the data may be accessed by:

  • authorised users and administrators of the tenant;
  • authorised personnel and contracted processors of Qilaq Solutions Kft., including hosting, infrastructure and technical service providers;
  • the application Publisher, solely to the extent required for a support, release or security matter handled by the Publisher;
  • on Android, the provider of Google ML Kit in relation to the technical data listed in section 4;
  • Apple or Google when operating the app store, operating system and technical reports they provide, under their own privacy terms; and
  • a competent authority, court or other legally authorised body where required by law.

We do not sell personal data or disclose it to advertising networks or data brokers.

Where a service provider processes data outside the European Economic Area, the transfer must rely on a basis and safeguards permitted by applicable data protection law, such as an adequacy decision or standard contractual clauses. The tenant's notice, the Qard platform notice and applicable contracts provide more information about the specific processors and transfers used for tenant and platform data.

8. Retention and deletion

Data category Retention rule
Sign-in profile stored on the device For the duration of the active profile and controlled recovery; erased upon sign-out, user/backend change or credential reset.
Raw QR content, manual card input and complete card response Normally only for the active search or operation. After a scanner network failure, raw QR content may remain as an encrypted offline scan for up to 72 hours, with no more than 100 records in total; it is erased after definite success, explicit deletion, expiry, sign-out or credential reset. Manual input and complete card responses are not stored in this list.
PIN and password input fields Only until the required validation; erased when the application enters the background, on route exit, success or sign-out.
Transaction and history data on the device Only for the active authenticated screen; there is no persistent offline cache.
Minimal reconciliation record for an uncertain transaction Until the outcome is safely confirmed and acknowledged by the user. To prevent duplicate recording there is no automatic time-based deletion; the record is erased after a definitive result, sign-out or credential reset.
Payload-free in-app diagnostics Until the application process ends or the diagnostics are manually cleared.
Backend session For no more than 24 hours, or until an earlier sign-out, revocation or password change.
Backend ledger, history and idempotency record For the duration of the tenant contract or until the relevant card is deleted, whichever occurs first. At that point, records containing a personal link are erased or irreversibly anonymised unless applicable law requires mandatory retention. An idempotency record must not be erased before its underlying operation.
Access, application and security logs For 1 month from creation of the log event, after which they are erased or irreversibly anonymised, unless a specific incident or applicable law requires mandatory further retention.
Qard platform or Publisher support data For the duration of the tenant contract; erased or irreversibly anonymised when that contract ends, unless mandatory statutory retention applies.
Backup Daily backups are created and the daily backups from the most recent 1 month are retained on a rolling basis. Erased data disappears from backups no later than the end of that one-month backup cycle, unless applicable law requires mandatory retention.

At the end of the periods above, data must be erased or irreversibly anonymised. If a backup is restored, deletions that had already been completed must be reapplied. Any statutory exception must be documented, access-restricted and erased when the exception ends.

The application does not allow users to create an account, so there is no separately created in-app account to delete. A request to deactivate a user account or delete backend data must be made to the tenant. Uninstalling the application does not automatically erase contractual or lawfully retained data from the Qard backend.

9. Data security

The application and Qard platform use technical and organisational measures appropriate to the risk, including:

  • HTTPS-only networking in release builds;
  • platform-protected credential storage;
  • access control and expiring/revocable sessions;
  • exclusion of sensitive fields, QR content, PINs, authentication and card data from in-app diagnostics;
  • screenshot and recent-app image protection on Android and an app-switcher privacy shield on iOS;
  • stopping the camera when the application enters the background or leaves the scanner;
  • a client transaction identifier and controlled reconciliation to prevent duplicate transactions; and
  • access controls, logging, backup and incident-handling procedures on the Qard platform.

No electronic system can guarantee complete absence of risk. Operating-system protections may be bypassed on a rooted, jailbroken or otherwise compromised device.

10. Your rights

Subject to the applicable conditions, a data subject may request:

  • information about and access to their personal data;
  • rectification of inaccurate data;
  • erasure of data;
  • restriction of processing;
  • data portability;
  • the right to object to processing based on legitimate interests; and
  • where processing is based on consent, withdrawal of consent at any time, without affecting the lawfulness of earlier processing.

These rights are not absolute. A legal obligation, the rights of others, a security incident or a legal claim may justify partial restriction of a request. Proportionate verification of the requester's identity may be required before fulfilling a request.

  • For a request relating to a tenant account, card or Qard operation, contact the relevant accepting place or other tenant first.
  • For the Publisher's own support or application-security processing, contact info@kaderavek.hu.
  • For processing controlled by Qilaq Solutions Kft. or where the tenant cannot be identified, contact info@qilaq.hu.

A data subject may lodge a complaint with a supervisory authority and seek a judicial remedy.

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
Postal address: 1363 Budapest, PO Box 9, Hungary
Email: ugyfelszolgalat@naih.hu
Web: www.naih.hu

11. Children's data

The application is not intended for children; it is intended for authorised staff of accepting places. It does not request age information and does not perform child-directed advertising or profiling. If a Qard card associated with a child may be used as part of a tenant's service, the tenant must explain the purposes, legal basis and safeguards for that processing in its own privacy notice.

12. Changes to this notice

This notice may be updated if the application's functionality, an embedded SDK, the data-protection roles or the legal environment changes. The current version and its effective date will remain available on this page. Where required by applicable law, material changes will also be communicated in the application or through another appropriate channel.