Back to home

Data Processing Agreement

Last updated: [DATE]

This agreement under Art. 28 GDPR is concluded between Nordility UG (haftungsbeschränkt), Volksdorfer Damm 56a, 22359 Hamburg ("Processor") and the customer ("Controller").

It forms part of the Terms of Service and applies to all plans, including the free plan. Customers on paid plans can request a countersigned copy by emailing privacy@linkgravity.io with their company name, address and authorised signatory.

The German version is the operative text; this translation is provided for convenience.

1. Subject matter and duration

The Processor processes personal data on behalf of the Controller in order to provide the LinkGravity services: link shortening and redirection, deep-link routing, campaign attribution and analytics.

The term matches the term of the main contract.

2. Nature and purpose of processing

Collection, storage, analysis and deletion of click and attribution data, solely to provide the contractually agreed services.

3. Categories of data and data subjects

Data subjects are end users who open links created by the Controller.

DataNote
Hashed IP addressSalted HMAC-SHA256 with a key that rotates daily. The address itself is not stored.
Country, cityDerived from the IP before it is discarded
User agent, platform, browser, operating system, device typeSent by the browser
ReferrerSent by the browser
Campaign parameters (UTM)Chosen by the Controller
Device fingerprint (hash)Used only to match an install
Timestamp, link and project association

Names, contact details, payment data and special categories under Art. 9 GDPR are not processed — unless the Controller submits such data itself via campaign parameters, which is expressly discouraged.

4. Instructions

Processing takes place solely on the documented instructions of the Controller. The main contract, this agreement and the configuration in the product (links created, parameters chosen, plan) constitute those instructions.

If the Processor considers an instruction unlawful, it informs the Controller without undue delay and may suspend execution.

5. Confidentiality

Persons authorised to process the data are bound to confidentiality. Access to production systems is limited to the management.

6. Technical and organisational measures

See Annex 1. The Processor may develop measures further, provided the level of protection is not reduced.

7. Sub-processors

The Controller grants general authorisation for the providers published on the Sub-processors page.

Changes are notified at least 30 days in advance. The Controller may object, in which case a right of termination applies.

Paddle is deliberately not listed: it acts as Merchant of Record and processes payment data as an independent controller, not on our instructions.

8. Assistance to the Controller

The Processor assists with data subject requests, data protection impact assessments and notification obligations.

Requests from end users that reach the Processor are not answered by it, but forwarded to the Controller without undue delay.

9. Breach notification

The Processor reports personal data breaches without undue delay after becoming aware of them, and at the latest within 48 hours, with the information available under Art. 33(3) GDPR.

10. Deletion and return

Before termination the Controller can export its click analytics as CSV.

After termination the Processor deletes the data within 30 days, unless a statutory retention obligation applies. Deleting the account removes the associated data by cascade.

11. Evidence and audits

On request the Processor provides information demonstrating compliance. On-site audits are possible with reasonable notice and to a reasonable extent.

12. Place of processing

Processing takes place exclusively within the European Union, in data centres in Germany. No transfer to a third country occurs.

Annexes

Annex 1 — Technical and organisational measures (Art. 32 GDPR)

  • Pseudonymisation: IP addresses in click data are hashed on arrival with a salted HMAC-SHA256; the key rotates daily. The raw address is not stored. Device fingerprints are hashes.
  • Encryption: transport exclusively over TLS. Passwords hashed with bcrypt.
  • Confidentiality: role-based access control (Owner, Admin, Editor, Viewer). Access to production systems limited to the management. Authentication via JWT with limited validity. Login attempts are logged.
  • Integrity: server-side input validation, SSRF protection on outbound webhook delivery, rate limiting.
  • Availability: operated in German data centres of Hetzner Online GmbH. Database backups. Separate development and production environments.
  • Deletion: automated deletion of expired deep-link data (every 15 minutes) and of login history after 90 days (nightly). Account deletion removes associated data by cascade.

Note on retention: the plan-based retention periods for click data are not yet technically enforced. We state this expressly and will update this annex once enforcement is active.

Annex 2 — Contact

Processor: Nordility UG (haftungsbeschränkt), Volksdorfer Damm 56a, 22359 Hamburg, Germany · info@nordility.eu

Controller: the details held in the customer account.