Definitions
For the purposes of this DPA, capitalized terms have the meanings set out below or in the applicable data protection laws. "Customer" means the SocialPulse partner, business or organization entering into this DPA. "Processor" means SpLink.pro™. "Personal Data", "Controller", "Processor", "Data Subject", "Processing", and "Sub-processor" have the meanings given in the General Data Protection Regulation (Regulation (EU) 2016/679) and other applicable data protection laws.
Scope & Roles
This DPA applies to the Processing of Personal Data by SpLink.pro on behalf of the Customer in connection with the SpLink.pro™ URL shortening, QR code and analytics services. The Customer acts as the Controller of Personal Data and SpLink.pro acts as the Processor.
Subject Matter, Duration, Nature & Purpose
The subject matter of Processing is the provision of URL shortening, QR code generation, click and scan tracking, and related analytics for the Customer. The duration of Processing is for the term of the Customer's use of the services, and thereafter for the retention period described in Section 10. The nature and purpose of Processing is to enable the Customer to shorten URLs, generate QR codes and receive analytics related to their audience.
Categories of Data Subjects & Personal Data
Data Subjects may include: end-users of the Customer's own websites and communications who click Customer's short links or scan Customer's QR codes; the Customer's own personnel who administer the account.
Categories of Personal Data may include:
- Account data: name, email address, business/organization details supplied by Customer.
- Technical event data: IP address, browser and device information, operating system, referrer, coarse geographic location, timestamps of link clicks and QR scans.
- URL content: long URLs and any Personal Data the Customer chooses to encode in short links or QR codes.
Obligations of the Processor
SpLink.pro shall:
- Process Personal Data only on documented instructions from the Customer, including with regard to transfers to third countries.
- Ensure that persons authorized to Process Personal Data are subject to appropriate confidentiality obligations.
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (see Section 8).
- Assist the Customer, taking into account the nature of Processing, in fulfilling requests from Data Subjects.
- Make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA.
Sub-processors
The Customer provides a general authorization for SpLink.pro to engage Sub-processors to Process Personal Data, provided that SpLink.pro imposes on each Sub-processor data protection obligations no less protective than those in this DPA. SpLink.pro maintains an up-to-date list of Sub-processors and will provide the Customer with reasonable prior notice of changes.
Data Subject Rights
Taking into account the nature of the Processing, SpLink.pro shall assist the Customer by appropriate technical and organizational measures, insofar as this is possible, in responding to requests from Data Subjects exercising their rights under applicable data protection laws (including access, rectification, erasure, restriction, portability, and objection).
Security Measures
SpLink.pro maintains a written information security program that includes, at minimum:
- Encryption of Personal Data in transit over public networks (TLS).
- Access controls limiting production access to authorized personnel only.
- Hashing of user account passwords using an industry-standard adaptive algorithm.
- Regular backups and disaster-recovery procedures.
- Vulnerability management and periodic patching of underlying infrastructure.
- Logging of administrative actions on the platform.
Breach Notification
SpLink.pro shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and shall provide the Customer with the information reasonably required to comply with its notification obligations under applicable data protection laws.
Data Transfers
Where SpLink.pro transfers Personal Data outside the European Economic Area or the United Kingdom, such transfers will be subject to an appropriate transfer mechanism (such as the EU Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum), which are incorporated into this DPA by reference where required by applicable law.
Return & Deletion
Upon termination of the services, SpLink.pro will, at the Customer's choice, delete or return all Personal Data Processed on behalf of the Customer, and delete existing copies, unless applicable law requires further storage. Analytics event data older than the standard retention period may be aggregated or deleted in the ordinary course of operations.
Audit Rights
SpLink.pro shall make available to the Customer information reasonably necessary to demonstrate compliance with this DPA. On written request and no more than once per year, the Customer may audit SpLink.pro's compliance under this DPA, subject to reasonable confidentiality and security obligations, or accept third-party audit reports where available.
Governing Law
This DPA is governed by the same law as the underlying Terms of Service between the Customer and SpLink.pro, unless applicable data protection law requires otherwise.
Signatures
By signing below, each party agrees to be bound by the terms of this DPA.
Changes to this document
We keep every published version so partners can reference the exact wording in force when they signed.
| Version | Date | Changes |
|---|---|---|
| v1.0 | 2026-08-05 | Initial publication. |
