Legal
Data Processing Addendum
Last updated: 30 August 2026
1. Roles of the parties
For the personal data you upload or generate about your recipients (the "Customer Personal Data"), you are the controller and we are your processor. For your own account data, we act as an independent controller as described in our Privacy Policy.
2. Subject matter, duration, nature & purpose
- Subject matter — processing of Customer Personal Data to provide the Service.
- Duration — for the term of your account, plus any retention period you configure or that applies by default.
- Nature & purpose — storing recipient records, minting per-recipient tracked links and QR codes, resolving redirects, and producing individualised analytics.
- Types of personal data — those you choose to upload (e.g. names, email addresses, your own reference identifiers) and click analytics (hashed IP, approximate location, device/browser/OS).
- Categories of data subjects — your recipients and end users who click your links.
3. Our obligations as processor
- Process Customer Personal Data only on your documented instructions, including for transfers, unless required by law (in which case we will tell you where permitted).
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (section 6).
- Respect the conditions for engaging sub-processors (section 5).
- Assist you, taking into account the nature of processing, to respond to data-subject requests and to meet your security, breach-notification and data-protection-impact-assessment obligations.
- Notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data.
- At your choice, delete or return Customer Personal Data at the end of the services, and delete existing copies unless retention is required by law.
- Make available information necessary to demonstrate compliance and allow for and contribute to reasonable audits (section 8).
4. Your obligations as controller
You warrant that you have a lawful basis to collect and share the Customer Personal Data with us, that you have given any required notices to your recipients, and that your instructions to us comply with data-protection law. Do not place personal data directly in a link. The Service is built so personal data is stored privately and mapped by a non-identifying reference; both our import tools and API guard against personal data being placed in URL-bound fields.
5. Sub-processors
You authorise us to engage the sub-processors below to process Customer Personal Data. Each is bound by data-protection terms no less protective than this DPA. We will give reasonable notice of any intended addition or replacement so you can object on reasonable data-protection grounds.
- Supabase — database hosting (US / EU).
- Vercel — application hosting, delivery and cron (US / global edge).
- Cloudflare — DNS, custom-domain routing and edge delivery (global).
- Twilio SendGrid — transactional and notification email (US).
- Stripe — subscription billing and payments (US / global).
- Upstash — caching and rate limiting (US / EU).
- Google Analytics — website analytics via Google Consent Mode: cookieless, anonymous signals before consent; analytics cookies only after the visitor accepts (US).
6. Security measures
- Encryption in transit (TLS) for all traffic, including redirects and the API.
- Visitor IPs are stored only as a salted, non-reversible hash — never in raw form.
- API secrets and other credentials are stored hashed; access to production is restricted.
- Per-plan retention controls, with the ability to shorten retention, export, or delete data on request.
7. International transfers
Where a sub-processor processes personal data outside the UK/EEA, we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses (with the UK Addendum where relevant).
8. Audit & information
On reasonable written request, and no more than once a year (or following a personal-data breach), we will provide information reasonably necessary to demonstrate compliance with this DPA. Audits must be conducted on reasonable notice, during business hours, and without disrupting the Service.
9. Precedence & changes
If there is a conflict between this DPA and the Terms on the processing of Customer Personal Data, this DPA prevails. We may update this DPA to reflect changes in law or our sub-processors; material changes will be notified in the Service or by email.
10. Contact
For any data-protection question, to request a signed copy of this DPA, or to object to a sub-processor, use the contact page.