Privacy Notice
Privacy should be simple.
Last updated: 12 August 2026 · Version 2026-08-12
QRTOGRAPHY collects only the information needed to provide, secure and support the service.
- We do not sell personal data.
- We do not use behavioural advertising.
- We do not use marketing trackers on this public website.
- We do not use scan, workspace or account activity to build advertising profiles.
- Cookies or similar technologies used by the QRTOGRAPHY application are limited to essential operation, authentication, session management, security, necessary preferences and abuse prevention.
This privacy notice explains how CISLO Solutions Ltd collects, uses and protects personal data when you use QRTOGRAPHY, visit our website, access a demonstration environment or contact us.
1. Who we are
QRTOGRAPHY is operated by CISLO Solutions Ltd.
- Company name: CISLO Solutions Ltd
- Company number: 09633549
- Registered office: South Building, Upper Farm, Wootton St Lawrence, Basingstoke, Hampshire, United Kingdom, RG23 8PE
- Registered in: England and Wales
- Privacy contact: privacy@cislosolutions.com
For the public website, our own account administration, enquiries, billing, security and demonstration environments operated by CISLO Solutions Ltd, CISLO Solutions Ltd is the controller of personal data.
For customer content within a customer-controlled QRTOGRAPHY workspace, the roles may differ. Where a customer determines why and how personal data in its workspace is processed, the customer may act as controller and CISLO Solutions Ltd may act as processor under the applicable contract.
2. Personal data we may collect
Depending on how you use QRTOGRAPHY, we may collect and process:
- account details, such as name, email address, username and authentication status;
- contact details provided when you contact us, request a demo or start a trial;
- technical information, such as IP address, browser type, device type and security logs;
- usage information, such as sign-in activity, scan activity, selected links, audit events and application actions;
- workspace access information, such as assigned roles and permissions;
- information submitted through forms, reports, notes or support requests;
- billing and business contact information where required to provide a paid service.
Demonstration data within QRTOGRAPHY is intended to be synthetic and should not include real client, project, asset or confidential information unless this has been expressly agreed in writing.
3. How we use personal data
We use personal data where necessary to:
- provide access to QRTOGRAPHY and related services;
- authenticate users and protect accounts;
- manage workspaces, permissions and link configurations;
- record audit events, including scans, clicks, changes and administrative actions;
- investigate errors, security issues, misuse, abuse or suspected unauthorised access;
- respond to enquiries, demo requests, trial requests and support requests;
- improve the reliability, security and usability of the service;
- administer subscriptions, invoices and business records;
- comply with legal, regulatory, accounting or contractual obligations.
4. Lawful basis for processing
Depending on the activity, we rely on one or more of the following lawful bases:
- Contract: where processing is necessary to provide QRTOGRAPHY, a trial, a quotation or related services requested by you or your organisation.
- Legitimate interests: where processing is necessary to operate, secure, audit and improve the service, provided those interests are not overridden by individual rights.
- Legal obligation: where processing is necessary to meet legal, regulatory, tax, accounting or security obligations.
- Consent: where we specifically ask for consent for an optional purpose.
5. Cookies and similar technologies
The public qrtography.com website is designed without advertising cookies, behavioural tracking or marketing analytics.
The QRTOGRAPHY application may use strictly necessary cookies or similar technologies for essential functions such as sign-in, authentication, session management, security, access control, necessary preferences and abuse prevention. These technologies are used to operate and protect the service, not for advertising or behavioural marketing.
We do not currently use non-essential analytics, advertising or tracking technology. If that changes, we will update this notice clearly and obtain consent where required before using it.
6. Who we share personal data with
Where necessary, we may share personal data with:
- hosting, infrastructure, authentication, email, payment or support service providers;
- professional advisers, such as accountants, insurers or legal advisers;
- customers or workspace administrators where access is provided as part of an organisation or project environment;
- law enforcement, regulators or public authorities where required by law.
We do not sell personal data to advertisers or data brokers.
7. International transfers
Where personal data is transferred outside the United Kingdom, we take steps intended to ensure that appropriate safeguards are in place where required by applicable data protection law.
8. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the purposes described in this notice, including to provide the service, maintain security and audit records, resolve disputes, meet legal obligations and maintain business records.
Account, audit and security records may be retained for a reasonable period after access ends where necessary for security, contractual, legal or evidential purposes.
9. Your rights
Depending on the circumstances and the lawful basis being used, you may have rights including the right to:
- access your personal data;
- ask for inaccurate data to be corrected;
- ask for data to be erased;
- ask for processing to be restricted;
- object to processing;
- request data portability;
- withdraw consent where processing is based on consent.
To exercise your rights, email privacy@cislosolutions.com.
Where we rely on legitimate interests, you may have the right to object to that processing. Contact us at privacy@cislosolutions.com and we will consider your request in accordance with applicable data protection law.
10. Security and abuse prevention
We use technical and organisational measures intended to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. We may also use security and bot-protection services where needed to distinguish legitimate use from automated or abusive traffic.
Security and abuse-prevention information is used to protect QRTOGRAPHY, its users and its infrastructure. It is not used by CISLO Solutions Ltd for behavioural advertising or marketing profiles.
No online system can be guaranteed to be completely secure, but we take security seriously and review our approach as the service develops.
11. Data portability and leaving QRTOGRAPHY
Our product philosophy is based on customer control. Workspace mappings and configuration can be exported using the capabilities provided by the service, subject to the applicable subscription and contractual terms. The physical asset identifier remains in the QR code and is not replaced with a proprietary QRTOGRAPHY identifier.
12. Complaints
If you have concerns about how we use personal data, please contact us first so we can try to resolve the issue.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection matters.
13. Changes to this notice
We may update this privacy notice from time to time as QRTOGRAPHY develops or legal requirements change. The latest version will be made available on this page.