Version of Art. 28 GDPR

Data Processing Addendum

The processor agreement (Auftragsverarbeitungsvertrag, AVV) for customers who use useClick to process personal data of their own visitors and contacts. Accepting the Terms of Service includes this DPA. For a countersigned copy, email [email protected].

1. Scope and roles

This Data Processing Addendum ("DPA") is part of the agreement between the customer who holds a useClick account ("Customer", "you") and Peter Csipkay, Ringstr. 6, 82319 Starnberg, the operator of useClick ("useClick", "we", "us"). It applies whenever we process personal data on your behalf while providing the service described in the Terms of Service ("Service").

  • Roles: you are the controller and useClick is the processor for Customer Personal Data, which is the personal data of your visitors and contacts listed in section 3: link-click data, website analytics data, Link in bio data and email addresses collected through email capture. If you act as a processor for someone else, useClick is your subprocessor and your instructions to us are given on behalf of that controller.
  • Not covered: data about you and your team as account holders (sign-in, billing, support). We process that as a controller, as described in our Privacy Policy.
  • Conclusion: accepting the Terms of Service includes this DPA. It meets the written-form requirement of Art. 28(9) GDPR in electronic form. If you need a signed copy, see section 15.

2. Subject matter, duration, nature and purpose

  • Subject matter: providing the Service: short links and QR codes with click analytics, geo-targeting and A/B tests, website analytics with conversion goals, Link in bio pages, and email capture forms, as you configure them in the dashboard, the REST API or the MCP server.
  • Duration: for as long as you have a useClick account, and afterwards until the data is deleted as set out in section 12.
  • Nature of the processing: receiving requests from visitors' browsers, deriving coarse location and parsed browser, OS and device data at request time, computing visitor hashes, storing, aggregating and displaying the results to you, exporting them on request, sending double opt-in emails, and deleting data.
  • Purpose: only to provide the Service to you. We do not use Customer Personal Data for advertising, do not sell it, and do not combine it with data from other customers.

3. Types of personal data

Depending on the features you use, the Service processes the following. IP addresses and full user agent strings are never stored.

Link clicks and QR code scans

  • Which link was clicked and when
  • Country, region and city, derived at request time from the edge provider's location headers
  • Browser, operating system and device type, parsed from the user agent (the user agent itself is discarded)
  • Browser language and referrer URL
  • Whether the request came from a known bot
  • A visitor hash for counting unique clicks: a SHA-256 hash of the first 100 characters of the user agent, the language header and the time zone, shortened to 16 characters. It contains no IP address

Website analytics (only if you install the useClick script on your site)

  • Page path, UTM parameters, referrer, screen width and browser language
  • Country, region and city; browser, operating system and device type
  • A daily visitor hash: a keyed SHA-256 hash (HMAC with a secret held only by useClick) of your website ID, the visitor's IP address, user agent and the current date, shortened to 16 characters. The IP address is used only in memory to compute it, and because the date is part of the input, visits on different days cannot be linked
  • An attribution token that connects a visit to the short-link click that led to it. The script keeps it in the browser's session storage for the current tab and sets no cookies
  • Custom events, event properties and revenue values, only if you send them

Link in bio pages

  • The content you publish on the page, which may include personal data you choose to show
  • Click counts on page blocks; links on the page that are useClick short links record clicks as described above

Email capture links

  • The email address a visitor submits, its status (pending, confirmed or unsubscribed), a confirmation token and timestamps. An address is kept as confirmed only after the visitor confirms it through the double opt-in email

Special categories of personal data (Art. 9 GDPR) are not needed for the Service. Do not send them to us, for example in custom event properties or link destinations.

4. Categories of data subjects

  • People who click your short links or scan your QR codes
  • Visitors to websites on which you have installed the useClick analytics script
  • Visitors to your Link in bio pages
  • People who submit their email address through your email capture links
  • People named or shown in content you publish on your Link in bio pages

5. Your responsibilities as controller

You decide which features to use and for what purpose, so you are responsible for having a legal basis for the processing, for informing your visitors (for example in your own privacy notice) and for the content and destinations of your links. For email capture, the rules in section 15 of the Terms of Service apply in addition. You can give further instructions in writing by email; we will tell you without undue delay if we think an instruction infringes data protection law.

6. Our obligations as processor

As required by Art. 28(3) GDPR, useClick:

  • (a) Instructions: processes Customer Personal Data only on your documented instructions, including with regard to transfers to third countries. Your instructions are these Terms and this DPA, and the settings you make in the dashboard, API or MCP server. If EU or Member State law requires other processing, we inform you before processing unless that law prohibits it.
  • (b) Confidentiality: ensures that everyone authorised to access Customer Personal Data is bound by confidentiality, by contract or by law.
  • (c) Security: takes the measures required by Art. 32 GDPR, described in section 7.
  • (d) Subprocessors: engages other processors only as set out in section 8.
  • (e) Data subject rights: helps you, as far as possible, to respond to requests from data subjects under Chapter III GDPR, as set out in section 10.
  • (f) Assistance: helps you meet your obligations under Art. 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to us.
  • (g) Deletion or return: deletes or returns Customer Personal Data at the end of the Service, as set out in section 12.
  • (h) Information and audits: makes available the information needed to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits, including inspections, as set out in section 13.

7. Security measures

We maintain these technical and organisational measures (Art. 32 GDPR) and may improve them over time without lowering the level of protection:

  • Data minimisation by design: IP addresses and full user agent strings are never written to the database; location is kept at country, region and city level; unique visitors are counted with hashes instead of cookies.
  • Encryption in transit: the dashboard, API, redirects and analytics endpoint are served over HTTPS (TLS). Custom domains receive TLS certificates automatically.
  • Tenant separation: Row Level Security is enabled on the database tables, so every query from the app is limited to the rows of the signed-in user or their organisation. The service role key that bypasses it is used only on the server.
  • Access control: roles within an organisation (owner, admin, member); sign-in through Supabase Auth with hashed passwords; a Cloudflare Turnstile bot check on sign-in, sign-up and password reset.
  • Secrets: API keys are stored only as SHA-256 hashes and are rate limited per plan; link passwords are stored as bcrypt hashes; passes for password and content-warning gates are short-lived and HMAC-signed.
  • Storage limitation: click and page-view records are deleted automatically every day once they are older than the retention window of your plan (Free 30 days, Starter 12 months, Growth 24 months, Pro and Business 3 years). Website analytics queries are also limited to that window on the server.
  • Application security: security headers (Content Security Policy, frame blocking, no MIME sniffing, a restrictive Permissions Policy); new link destinations are checked against Google Safe Browsing; errors are monitored with Sentry in its EU data region.
  • Location: the database is hosted in Frankfurt, Germany.

8. Subprocessors

You give us general authorisation (Art. 28(2) GDPR) to engage the subprocessors on our subprocessor list (Supabase, Vercel, Cloudflare, Sentry, Resend, Google at the date of this version).

  • Notice: before a new subprocessor starts processing Customer Personal Data, we update the list and email the owner of your account at least 30 days in advance.
  • Objection: you can object on reasonable data protection grounds by email within those 30 days. We will try to find a solution with you; if we cannot, you may end the affected subscription before the change takes effect.
  • Same obligations: we bind each subprocessor by contract to data protection obligations that give the same level of protection as this DPA (Art. 28(4) GDPR), and we remain responsible to you for their performance.

9. International transfers

Customer Personal Data is stored in the EU (Frankfurt, Germany). Some subprocessors are companies based in the USA or handle requests on a worldwide edge network, so data can be processed outside the EU in transit or for support. We transfer personal data to a third country only with a safeguard under Chapter V GDPR: the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR) where the recipient is certified, and the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). The safeguard for each provider is named on the subprocessor list.

10. Data subject requests

You can handle most requests yourself: delete a link together with its click data and captured email addresses, delete a website with its analytics, and export data as CSV (Starter and above) or through the API. Visitors can remove their own email address at any time through the unsubscribe link in the confirmation email, and we delete a single address for you on request.

If a data subject contacts us directly about Customer Personal Data, we forward the request to you without undue delay and do not answer it ourselves beyond saying that we did so. Because the Service stores no IP addresses, no cookies and no names for link clicks and website visits, it is often not possible to find one person's records (Art. 11 GDPR). Where it is possible, we help you on request.

11. Personal data breaches

We notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, by email to the account owner. The notice describes, as far as we know at that time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed, and names a contact. We add information as it becomes available, so that you can meet your obligations under Art. 33 and 34 GDPR.

12. Deletion and return

During the Service you can export your data at any time. When you delete your account in Account Settings, your links, click data, websites and their analytics, Link in bio pages, captured email addresses and the account itself are deleted immediately. You can request deletion by email instead. We keep Customer Personal Data after the end of the Service only where EU or Member State law requires us to store it.

13. Information and audits

On request we provide the information needed to show that we meet this DPA, including this document, the subprocessor list, a description of our security measures and the relevant certifications and agreements of our subprocessors. If that information is not enough, you or an auditor you appoint who is bound to confidentiality may carry out an audit, including an inspection. Audits are arranged at least 30 days in advance, take place during normal business hours, and happen no more than once a year unless a supervisory authority requires it or a personal data breach gives reason for one. Each party bears its own costs.

14. Term, precedence and governing law

  • Term: this DPA applies for as long as we process Customer Personal Data for you.
  • Precedence: if this DPA and the Terms of Service conflict on the processing of personal data, this DPA prevails. Liability follows the Terms of Service, subject to Art. 82 GDPR.
  • Changes: we may update this DPA, for example when the law or the Service changes. Changes will not reduce the protection of Customer Personal Data. The date of the current version is shown at the top of this page.
  • Governing law: this DPA is governed by the law of the country in which the operator of useClick is established (Germany), the same law that governs the Terms of Service.

15. Countersigned copy and contact

How to get a countersigned copy

Accepting the Terms of Service includes this DPA; email [email protected] to receive a countersigned copy. Include your company name, address and the email address of your useClick account.

Questions about this DPA or about how the Service processes personal data can go to the same address. The operator of useClick is Peter Csipkay, Ringstr. 6, 82319 Starnberg.