1. Definitions
“Applicable Data Protection Law” means laws governing the processing covered by this DPA, including POPIA and, where applicable, the GDPR or UK GDPR. “Customer Personal Data” means personal information processed by Linkify on Customer’s behalf through the service. “Process”, “controller”, “processor”, “responsible party”, “operator”, and “data subject” have the meanings given by applicable law.
2. Roles and instructions
Customer is the controller or responsible party and Linkify is the processor or operator for Customer Personal Data. Customer instructs Linkify to process that data to provide, secure, maintain, support, and improve the subscribed service, and as further documented through Customer’s use and configuration of Linkify.
Customer is responsible for the lawfulness of its instructions, notices, consent, data collection, destinations, tracking, and use of results. Linkify will notify Customer if an instruction appears to violate applicable data-protection law unless prohibited from doing so.
3. Processing details
| Item | Description |
|---|---|
| Subject matter | Provision of Linkify link management, QR, public-page, form, campaign, collaboration, and analytics services. |
| Duration | For the term of the agreement and any limited deletion, backup, legal, or security retention period. |
| Nature and purpose | Hosting, organising, publishing, redirecting, transmitting, securing, supporting, and analysing Customer-configured assets and submissions. |
| Data subjects | Customer users, workspace members, visitors, subscribers, leads, campaign audiences, contacts, and individuals represented in Customer content. |
| Data types | Identifiers, contact details, account and role data, submitted form fields, online identifiers, event data, device and referrer signals, campaign data, uploaded content, and support communications. |
| Sensitive data | Not intended unless expressly agreed in writing and appropriately configured. Customer must not upload sensitive or special-category data without prior approval. |
4. Confidentiality and personnel
Linkify will ensure that personnel authorised to process Customer Personal Data are subject to confidentiality obligations and receive access only as needed for their responsibilities.
5. Security measures
Linkify will maintain measures appropriate to the risk, considering the state of the art, implementation cost, processing context, and potential impact on individuals.
- Role-based workspace and administrative access controls.
- Password hashing, secure session controls, CSRF protection, and authentication rate limiting.
- Workspace scoping, audit logging, abuse controls, and administrative activity records.
- Upload type and size validation and protected application configuration.
- Database backup procedures, recovery planning, patching, and vulnerability management.
- Incident response, access review, and secure deletion practices appropriate to the service.
6. Subprocessors
Customer authorises Linkify to use subprocessors for hosting, storage, email, payments, security, support, and other service operations. Linkify remains responsible for their processing obligations to the extent required by law and will impose data-protection terms appropriate to the services they provide.
Linkify will make current subprocessor information available to Customer and provide reasonable notice of a material new subprocessor where required. Customer may object on reasonable data-protection grounds before the change takes effect. The parties will work in good faith to resolve the objection; if no reasonable solution is available, Customer may terminate the affected service.
7. Data-subject and compliance assistance
Taking into account the nature of processing, Linkify will provide reasonable assistance for verified data-subject requests, security assessments, consultations, and Customer obligations relating to data protection. If Linkify receives a request concerning Customer Personal Data, it will direct the requester to Customer unless legally required to respond.
8. Security incidents
Linkify will notify Customer without undue delay after confirming unauthorised access to, acquisition of, or disclosure of Customer Personal Data that requires notice under applicable law. Notice will include available information reasonably needed for Customer’s response. Linkify’s notice is not an admission of fault or liability.
9. Cross-border processing
Customer authorises processing in countries where Linkify or its subprocessors operate, provided a lawful transfer mechanism and appropriate safeguards are used where required. If GDPR transfer restrictions apply and no adequacy decision or other mechanism is available, the applicable European Commission Standard Contractual Clauses are incorporated by reference using the module appropriate to the parties’ roles.
10. Return and deletion
During the agreement, Customer may use available service features to access or export Customer Personal Data. After termination, Linkify will delete or return Customer Personal Data within a commercially reasonable period unless retention is required by law. Data may remain in protected backups until overwritten under the applicable backup cycle.
11. Information and audits
Linkify will provide information reasonably necessary to demonstrate compliance with this DPA. Audits must be proportionate, protect other customers and Linkify confidentiality, avoid unreasonable disruption, and generally rely first on available reports, documentation, and written responses. On-site audits require reasonable notice and may be subject to cost recovery unless a material breach is identified.
12. Order of precedence and liability
If this DPA conflicts with the main agreement on processing Customer Personal Data, this DPA controls. All other terms remain in effect. Liability arising from this DPA is subject to the exclusions and limits in the main agreement unless applicable law requires otherwise.
13. Contact and execution
Privacy and DPA requests may be sent to privacy@linkify.global. Customers requiring a countersigned DPA, completed transfer annexes, or a current subprocessor schedule should contact privacy@linkify.global.