Legal

Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Linkora, Inc. (“Processor”) and the customer (“Controller”). It reflects the parties' agreement on the processing of Personal Data in connection with the Services.

Last updated · August 1, 2026

1. Definitions

Capitalized terms not defined here have the meaning given in the GDPR (Regulation (EU) 2016/679) or the UK GDPR, as applicable.

  • Controller — the customer who determines the purposes and means of processing.
  • Processor — Linkora, which processes Personal Data on behalf of the Controller.
  • Sub-processor — a third party engaged by Linkora to process Personal Data.

2. Subject matter and duration

Linkora processes Personal Data to provide the Services described in the Terms, for the duration of the Controller's subscription.

3. Nature and purpose of processing

Hosting, transmitting, caching and analyzing short links, bio pages, QR codes, files and related metadata submitted by Controller and its end users.

4. Categories of data subjects and Personal Data

  • Controller's employees, contractors and administrators.
  • Controller's end users (visitors of short links, bio pages, QR codes, download pages).
  • Personal Data may include: name, email address, IP address (hashed after 30 days), coarse geo, device/browser family, timestamps, referrers.

5. Controller instructions

Linkora will process Personal Data only on documented instructions from the Controller, including as necessary to provide the Services and to comply with law. If Linkora is required by law to process outside those instructions, it will notify the Controller unless prohibited.

6. Confidentiality

Linkora ensures that persons authorized to process Personal Data are bound by written confidentiality obligations.

7. Security

Linkora implements appropriate technical and organizational measures to protect Personal Data, including:

  • Encryption in transit (TLS 1.3) and at rest (AES-256).
  • Least-privilege access controls, SSO/MFA and quarterly access reviews.
  • Independent penetration testing at least annually.
  • SOC 2 Type II controls (report available under NDA).

8. Sub-processors

Linkora may engage sub-processors provided that (a) Linkora imposes data protection obligations at least as protective as this DPA, and (b) Linkora remains liable for their performance. A current list is maintained at /subprocessors. Linkora will provide at least 30 days' prior notice of any intended change and allow the Controller to object on reasonable grounds.

9. International transfers

Where Personal Data is transferred outside the EEA/UK, the parties incorporate the Standard Contractual Clauses (SCCs) 2021/914 and the UK IDTA, as applicable, into this DPA.

10. Data subject requests

Linkora will assist the Controller, insofar as possible, to respond to requests from data subjects exercising rights under applicable law. Linkora will notify the Controller within 5 business days of any request received directly.

11. Personal Data breach notification

Linkora will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data breach, providing available details and a description of remedial actions.

12. Deletion and return

Upon termination of the Services, Linkora will delete or return all Personal Data within 90 days, except where retention is required by law.

13. Audits

Once per calendar year, the Controller may audit Linkora's compliance with this DPA, with 30 days' written notice, subject to reasonable confidentiality and security obligations.

14. Signing

This DPA is automatically incorporated into the Terms for all customers subject to GDPR or UK GDPR. For a countersigned copy, email support@linkora.solutions.