Last updated: [DATE]
This agreement under Art. 28 GDPR is concluded between Nordility UG (haftungsbeschränkt), Volksdorfer Damm 56a, 22359 Hamburg ("Processor") and the customer ("Controller").
It forms part of the Terms of Service and applies to all plans, including the free plan. Customers on paid plans can request a countersigned copy by emailing privacy@linkgravity.io with their company name, address and authorised signatory.
The German version is the operative text; this translation is provided for convenience.
The Processor processes personal data on behalf of the Controller in order to provide the LinkGravity services: link shortening and redirection, deep-link routing, campaign attribution and analytics.
The term matches the term of the main contract.
Collection, storage, analysis and deletion of click and attribution data, solely to provide the contractually agreed services.
Data subjects are end users who open links created by the Controller.
| Data | Note |
|---|---|
| Hashed IP address | Salted HMAC-SHA256 with a key that rotates daily. The address itself is not stored. |
| Country, city | Derived from the IP before it is discarded |
| User agent, platform, browser, operating system, device type | Sent by the browser |
| Referrer | Sent by the browser |
| Campaign parameters (UTM) | Chosen by the Controller |
| Device fingerprint (hash) | Used only to match an install |
| Timestamp, link and project association |
Names, contact details, payment data and special categories under Art. 9 GDPR are not processed — unless the Controller submits such data itself via campaign parameters, which is expressly discouraged.
Processing takes place solely on the documented instructions of the Controller. The main contract, this agreement and the configuration in the product (links created, parameters chosen, plan) constitute those instructions.
If the Processor considers an instruction unlawful, it informs the Controller without undue delay and may suspend execution.
Persons authorised to process the data are bound to confidentiality. Access to production systems is limited to the management.
See Annex 1. The Processor may develop measures further, provided the level of protection is not reduced.
The Controller grants general authorisation for the providers published on the Sub-processors page.
Changes are notified at least 30 days in advance. The Controller may object, in which case a right of termination applies.
Paddle is deliberately not listed: it acts as Merchant of Record and processes payment data as an independent controller, not on our instructions.
The Processor assists with data subject requests, data protection impact assessments and notification obligations.
Requests from end users that reach the Processor are not answered by it, but forwarded to the Controller without undue delay.
The Processor reports personal data breaches without undue delay after becoming aware of them, and at the latest within 48 hours, with the information available under Art. 33(3) GDPR.
Before termination the Controller can export its click analytics as CSV.
After termination the Processor deletes the data within 30 days, unless a statutory retention obligation applies. Deleting the account removes the associated data by cascade.
On request the Processor provides information demonstrating compliance. On-site audits are possible with reasonable notice and to a reasonable extent.
Processing takes place exclusively within the European Union, in data centres in Germany. No transfer to a third country occurs.
Note on retention: the plan-based retention periods for click data are not yet technically enforced. We state this expressly and will update this annex once enforcement is active.
Processor: Nordility UG (haftungsbeschränkt), Volksdorfer Damm 56a, 22359 Hamburg, Germany · info@nordility.eu
Controller: the details held in the customer account.