Skip to content
iink.click
FeaturesPricingAPI docsResources
Log in↗Get started free
IINK.CLICK

Data processing agreement

Effective 11 October 2026 · Version 1.2

PrivacyTermsData processing

Service provider: Yevgeniy Kovalev, ul. Okólnik 11A/77, 00-368 Warsaw, Poland. NIP: 5272991183. REGON: 521331015. Contact: support@iink.click.

Scope and roles

This agreement describes processing carried out by Yevgeniy Kovalev, operating iink.click, on behalf of the customer identified by the account and its service instructions. It applies to customer-controlled link and visitor data for which the customer determines the purpose and we provide processing on their instructions. It takes priority over conflicting service terms for that processing.

Our account administration, support, payment and legal obligations are separate activities described in the Privacy notice. This agreement does not make every operation processor work, provide a customer's lawful basis, or serve as an international-transfer instrument.

Processing instructions

ServiceShort-link delivery, custom-domain routing, click history and account-scoped IP lookup.
People concernedPeople who open the customer's short links.
DataFull normalized IP address; historical source URL, target URL and link ending; click time; supplied device type, brand, model, operating system, browser and preferred language; full HTTP(S) Referer URL; optional browser-reported CSS screen width and height, device pixel ratio and estimated physical screen dimensions; bounded User-Agent, Accept-Language and supported UA Client Hints headers; account, link and domain identifiers; erasure generation.
OperationsReceive, route, record, store, display, search, produce usage counts, expire and erase.
DurationService use and necessary completion of return/deletion instructions. Click history expires 365 days after the click unless earlier account-wide erasure applies.
Customer instructionsLink configuration, authenticated history/API requests, erasure requests and verified support instructions within this agreement.

The customer must identify its specific purpose, lawful basis, visitor notice and contact, and ensure the service's collection and retention are suitable for that purpose. Recordings occur automatically; there is no pre-collection consent gate, no-recording mode or shorter per-link setting. Uses requiring these controls must not be carried out through the current service. Do not intentionally submit sensitive personal information, secrets or unnecessary identifiers in URLs.

We process customer data for the service instructions above. We do not combine customers' histories into an identity product, sell their visitor records or use them for our advertising or model training. Materially different instructions must be discussed before processing. We will notify the customer if an instruction appears incompatible with applicable data-protection requirements and may pause it while the issue is resolved.

Security and authorized access

Service safeguards include HTTPS, private storage, encryption at rest, authenticated account-scoped access, hashed API keys and protected account sessions. Click snapshots are immutable. Duplicate processing is controlled, late events do not replace newer matches, and account history erasure prevents older queued events from restoring it. Visitor addresses are taken from trusted request context rather than arbitrary client headers.

Access to customer data is limited to authorized people with a work-related need and confidentiality obligations. The customer is responsible for protecting credentials, controlling account access, choosing lawful destinations and maintaining rights over connected domains. Neither party should disclose another customer's records when investigating a request.

Service providers and locations

AWS provides infrastructure for customer-data processing, storage and recovery. The application database is in Stockholm; global delivery and provider operations can involve additional locations. Infomaniak carries support messages, which may include customer data the customer chooses to send. Avoid attaching entire histories when a smaller example is sufficient.

Stripe provides payments, Google and Apple provide optional sign-in, and Porkbun provides domain registration/DNS. Those functions do not make them recipients of the full click-history database. Their roles depend on the particular function.

The customer authorizes the infrastructure and support processing described here for the requested service. We will use appropriate written protections for processing performed on our behalf and remain responsible for that processor service. Before a material addition or replacement, we will notify affected customers of the function and relevant safeguards and provide an opportunity to raise a reasoned objection. We will work through an alternative, mitigation or termination of the affected processing if an objection cannot be resolved. This agreement alone does not authorize a transfer without applicable safeguards; contact support for the relevant provider and transfer information.

Requests, incidents and assistance

We will help the customer address requests concerning its data, including access, correction, restriction, erasure and authorized return, with proportionate verification and account isolation. We will route requests to the responsible customer where appropriate. Supplying a shared IP address alone does not authorize disclosure of every associated record.

If we become aware of a personal-data breach affecting customer data, we will notify the customer without undue delay and supply available facts, likely impact, containment steps and a contact, with updates as the investigation develops. The customer determines its own required notifications. We will provide information reasonably needed for its security and data-protection assessments concerning our service.

We will make relevant processing and safeguard information available and cooperate with reasonable verification, including an audit where required. The process must protect other customers' information and preserve confidentiality without preventing effective verification.

Retention, return and deletion

Click retention runs from the original click. Optional screen measurements follow the same retention and erasure; measurements without a corresponding click are removed after 24 hours. Editing a link, deleting it, retrying an event or changing a domain owner does not restart the period. Account-wide erasure immediately hides earlier history and starts physical cleanup. Data past its retention limit is excluded from normal service results while physical expiry completes.

Event queues may retain pending processing for up to four days, or failed deliveries for up to fourteen days. Recovery copies use a rolling window of up to 35 days. These copies remain restricted and are not used for ordinary history access; erasure decisions must be preserved when data is recovered.

At the end of processing, the customer can request return of available data or deletion through support@iink.click. We will verify the instruction and confirm its scope and completion process. An applicable legal retention requirement may require specific records to remain, restricted to that purpose. A request does not extend the ordinary click-history retention period.

Customer contact and notices to visitors

Keep an up-to-date customer privacy/security contact with the account and use support to record additional processing instructions. Put a clear notice beside a shared link or printed QR code, with a readable address for your fuller notice. Explain full-IP collection, optional screen collection where enabled, your purpose, possible matching, 365-day retention and how visitors can contact you. A destination-only notice may arrive after initial collection.

Where your purpose needs consent or other controls, provide an appropriate process before collection or choose another delivery method. The service does not infer consent from a click or from the customer's acceptance of these terms.


Questions about this document? Contact support@iink.click.

iink.click

Small links. A clearer picture.

© 2026 iink.click

Product

Short linksCustom domainsQR codesPricing

Explore

Click historyAPI documentationHelp & FAQReport a link

Company

PrivacyTermsData processingYour account