Data Processing Agreement (DPA)

Last Updated: February 6, 2026

Effective Date: February 6, 2026

In Plain English

This Data Processing Agreement (DPA) ensures that Sniplink processes your data securely and in compliance with data protection regulations like GDPR. Here's what it means:

  • We act as your data processor. You remain the data controller of your users' data. We only process data according to your instructions.
  • GDPR-compliant by design. We follow strict security measures to protect personal data and respect data subject rights.
  • Sub-processors listed transparently. We use trusted infrastructure providers and notify you of any changes.
  • Data deletion on request. You can request deletion of all personal data at any time.
  • Security certifications. Our infrastructure meets ISO 27001 and SOC 2 standards.

1. Definitions

This Data Processing Agreement ("DPA") forms part of the agreement between you ("Customer," "you," or "Data Controller") and sniplink.co ("Sniplink," "we," "us," or "Data Processor") governing the use of our Service.

For the purposes of this DPA, the following terms have the meanings set out below:

  • "GDPR" means the General Data Protection Regulation (EU) 2016/679.
  • "Personal Data" has the meaning given in the GDPR and includes any personal data relating to end-users of your links and your workspace members.
  • "Processing" has the meaning given in the GDPR.
  • "Data Subject" means an identified or identifiable natural person whose Personal Data is processed.
  • "Sub-processor" means any third-party service provider engaged by Sniplink to process Personal Data on your behalf.

2. Scope and Roles

2.1 Parties' Roles

For the purposes of data protection law, you are the Data Controller and Sniplink is the Data Processor.

2.2 Nature and Purpose of Processing

Sniplink processes Personal Data on your behalf for the following purposes:

  • Providing link shortening and management services
  • Collecting and analyzing click analytics
  • Generating QR codes
  • Managing workspaces and user accounts
  • Sending notifications and webhooks
  • Providing customer support

2.3 Types of Personal Data

The categories of Personal Data processed by Sniplink include:

  • Account Data: Name, email address, profile information
  • Click Analytics Data: IP addresses, device information, browser type, referrer URL, geolocation data
  • Link Data: URLs, slugs, titles, descriptions, tags
  • Usage Data: Service usage statistics, API requests

2.4 Data Subjects

The categories of Data Subjects include:

  • Your workspace members and administrators
  • End-users who click on your shortened links
  • API users accessing your links programmatically

3. Processor Obligations and Data Controller Instructions

3.1 Processing Instructions

Sniplink will process Personal Data only in accordance with your documented instructions provided through:

  • The Sniplink Terms of Service
  • This Data Processing Agreement
  • Your configuration and settings within the Service
  • Written instructions provided via email to Loading contact information

3.2 Lawful Processing

Sniplink will not process Personal Data for any purpose other than as instructed by you unless required by applicable law. If Sniplink is required by law to process Personal Data in a manner inconsistent with your instructions, we will notify you before processing (unless prohibited by law).

3.3 Confidentiality

Sniplink ensures that all personnel authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4. Security Measures

4.1 Technical and Organizational Measures

Sniplink implements appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure. These measures include:

  • Encryption: Data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256 encryption.
  • Access Controls: Role-based access control (RBAC) with least privilege principles. Multi-factor authentication (MFA) for administrative access.
  • Network Security: Firewall protection, DDoS mitigation, and intrusion detection systems.
  • Vulnerability Management: Regular security audits, penetration testing, and security patching.
  • Monitoring: 24/7 security monitoring and incident response procedures.
  • Data Backup: Regular automated backups with disaster recovery procedures.
  • Secure Development: Security-focused development practices, code reviews, and dependency scanning.

4.2 Certifications and Compliance

Sniplink's infrastructure providers maintain the following security certifications:

  • ISO 27001 (Information Security Management)
  • SOC 2 Type II (Security, Availability, Confidentiality)
  • PCI DSS (Payment Card Industry Data Security Standard)

4.3 Security Incident Response

In the event of a Personal Data breach, Sniplink will:

  • Notify you without undue delay (within 72 hours of becoming aware)
  • Provide details of the breach, including categories and approximate number of Data Subjects affected
  • Describe measures taken to address the breach and mitigate harm
  • Cooperate with you in investigating and remediating the breach

5. Sub-processors

5.1 Authorized Sub-processors

You authorize Sniplink to engage the following sub-processors to process Personal Data on your behalf:

Sub-processorServiceLocation
Hostinger International Ltd.VPS Hosting, Database HostingFrance (EU)
Stripe, Inc.Payment ProcessingUnited States, Ireland (EU)
Resend, Inc.Transactional Email DeliveryUnited States
Upstash, Inc.Redis Database (Session & Cache)United States, Global
Cloudflare, Inc.R2 Storage (QR Codes), CDNUnited States, Global CDN

5.2 Sub-processor Changes

Sniplink will provide you with at least 30 days' advance notice of any intended changes to the list of sub-processors (addition or replacement) via email to your account email address or through a notice posted on our website.

You may object to the engagement of a new sub-processor within 15 days of receiving notice by contacting Loading contact information. If you reasonably object to a new sub-processor, we will work with you in good faith to find a mutually acceptable solution. If no solution can be reached, you may terminate your subscription without penalty.

5.3 Sub-processor Obligations

Sniplink ensures that all sub-processors are bound by data protection obligations no less protective than those set out in this DPA, including:

  • Processing Personal Data only on documented instructions
  • Maintaining confidentiality of Personal Data
  • Implementing appropriate technical and organizational security measures
  • Assisting with Data Subject requests and security incidents

6. Data Subject Rights

6.1 Assistance with Requests

Sniplink will assist you in responding to Data Subject requests exercising their rights under data protection law, including:

  • Right of access
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing

6.2 Self-Service Tools

The Sniplink Service provides self-service tools to help you respond to Data Subject requests:

  • Data Export: Export all Personal Data associated with a user account or workspace in machine-readable format (JSON, CSV)
  • Data Deletion: Delete individual links, analytics data, or entire user accounts
  • Data Correction: Update user profiles and account information
  • Access Controls: Manage user permissions and workspace access

6.3 Response Timeline

If you require assistance from Sniplink to respond to a Data Subject request, please contact Loading contact information. We will respond to your request for assistance within 5 business days and provide commercially reasonable cooperation.

7. Data Transfers

7.1 International Transfers

Sniplink primarily processes Personal Data within the European Union. However, certain sub-processors may process data in countries outside the EU/EEA, including the United States.

7.2 Transfer Mechanisms

For transfers of Personal Data outside the EU/EEA, Sniplink relies on the following safeguards:

  • Standard Contractual Clauses (SCCs): EU Commission-approved SCCs with sub-processors located outside the EU/EEA
  • Adequacy Decisions: Transfers to countries recognized by the EU Commission as providing adequate data protection (e.g., UK)
  • Data Protection Framework: Where applicable, certification under the EU-U.S. Data Privacy Framework

7.3 Customer Consent

By accepting this DPA, you consent to the international transfer of Personal Data as described above and acknowledge that Sniplink has implemented appropriate safeguards.

8. Data Retention and Deletion

8.1 Retention Periods

Sniplink retains Personal Data as follows:

  • Account Data: For the duration of your active subscription plus 30 days after cancellation
  • Link Data: Until you delete the link or close your account
  • Click Analytics: According to your plan limits (e.g., 7 days for Free, 90 days for Pro, 1 year for Business)
  • Backups: Up to 30 days in encrypted backup storage, then automatically deleted

8.2 Deletion on Request

Upon your written request or termination of the Service, Sniplink will:

  • Delete or anonymize all Personal Data within 30 days
  • Provide written confirmation of deletion upon request
  • Retain only such Personal Data as required by law (e.g., tax records, audit logs) for the minimum period required

8.3 Return of Data

Before deletion, you may request that Sniplink return all Personal Data to you in a machine-readable format. You must make this request within 30 days of subscription termination.

9. Audits and Compliance

9.1 Audit Rights

Upon reasonable written notice (at least 30 days in advance) and subject to confidentiality obligations, you may audit Sniplink's compliance with this DPA once per calendar year during regular business hours.

Audits may be conducted by you or an independent third-party auditor appointed by you. You are responsible for all costs associated with the audit.

9.2 Compliance Documentation

Upon request, Sniplink will provide reasonable evidence of compliance with this DPA, including:

  • Security certifications and audit reports (e.g., SOC 2)
  • Documentation of technical and organizational security measures
  • Evidence of sub-processor due diligence and compliance

9.3 Regulatory Cooperation

Sniplink will reasonably cooperate with you in responding to inquiries from data protection authorities and will not obstruct your compliance with data protection laws.

10. Liability and Indemnification

10.1 Limitation of Liability

Each party's liability arising out of or related to this DPA will be subject to the limitations and exclusions of liability set out in the Sniplink Terms of Service.

10.2 Indemnification

Sniplink will indemnify and hold you harmless from any third-party claims, damages, or losses arising from Sniplink's breach of this DPA or failure to comply with data protection laws, except to the extent caused by your instructions or breach of this DPA.

10.3 Data Protection Impact Assessments

If required by law, Sniplink will provide reasonable assistance in conducting Data Protection Impact Assessments (DPIAs) and prior consultations with supervisory authorities.

11. Term and Termination

11.1 Term

This DPA takes effect on the date you accept it or begin using the Sniplink Service, whichever is earlier. It remains in effect for the duration of your subscription and for 30 days thereafter to allow for data deletion.

11.2 Termination

This DPA will terminate automatically upon termination of the Sniplink Terms of Service. Sections 4 (Security), 7 (Data Transfers), 8 (Data Deletion), and 10 (Liability) will survive termination.

11.3 Effect of Termination

Upon termination, Sniplink will cease all processing of Personal Data and will delete or return all Personal Data in accordance with Section 8.

12. General Provisions

12.1 Amendments

Sniplink may update this DPA from time to time to reflect changes in law, regulatory guidance, or our processing activities. We will notify you of material changes via email or through a notice in the Service at least 30 days before the changes take effect.

12.2 Governing Law

This DPA is governed by the same law as the Sniplink Terms of Service. For GDPR compliance, this DPA will be interpreted in accordance with EU data protection law.

12.3 Order of Precedence

In the event of any conflict between this DPA and the Sniplink Terms of Service, this DPA will prevail to the extent of the conflict with respect to data processing.

12.4 Severability

If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions will continue in full force and effect.

13. Contact Information

For questions or requests regarding this Data Processing Agreement, please contact:

Email: Loading contact information

Data Protection Officer: Loading contact information

Address: [Company Legal Address - To Be Added]

14. Related Documents

This DPA should be read in conjunction with:

Acknowledgment: By using the Sniplink Service, you acknowledge that you have read, understood, and agree to be bound by this Data Processing Agreement. If you are accepting this DPA on behalf of a company or other legal entity, you represent and warrant that you have the authority to bind that entity to this DPA.