European Union Regulation (EU) 2016/679
Effective Date: October 07, 2026 | Version: 3.0
Commitment to European Privacy Standards: FreeURLShort is fully committed to operating in rigorous compliance with the European Union General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018 (UK GDPR). This statement outlines our governance structure, technical measures, and clear pathways for data subjects to exercise their statutory rights.
1. Executive Summary & Philosophy
The General Data Protection Regulation (GDPR) sets the gold standard for personal data governance, privacy rights, and corporate transparency. At FreeURLShort, we embrace these principles not merely as regulatory obligations, but as foundational engineering values. Our infrastructure is designed following the core principles of Privacy by Design and Privacy by Default (GDPR Article 25).
2. Our Role: Data Controller vs. Data Processor
In accordance with GDPR Articles 4(7) and 4(8), our legal classification depends upon the specific category of interaction:
A. FreeURLShort as Data Controller
We act as a Data Controller regarding:
- Account registration details (Full name, email address, password hashes, and profile settings).
- Customer billing and payment transaction records.
- Direct communications through support tickets, inquiries, and customer feedback.
- Website browsing logs and authenticated dashboard session state.
B. FreeURLShort as Data Processor
We act as a Data Processor when processing short links, custom branded domain redirection routes, and click analytics on behalf of our registered business and enterprise customers. In this capacity:
- Our customer is the Data Controller deciding the destination URLs and audience.
- FreeURLShort processes click requests solely under customer configuration and contractual instructions.
- We offer a comprehensive Data Processing Addendum (DPA) incorporating the European Commission's Standard Contractual Clauses (SCCs).
3. Lawful Bases for Processing (GDPR Article 6)
We strictly govern all processing under the six lawful grounds articulated in Article 6:
- Contractual Performance (Art. 6(1)(b)): Processing necessary to provide link shortening, custom domain routing, QR generation, and customer account administration.
- Legitimate Interests (Art. 6(1)(f)): Processing necessary to maintain platform uptime, monitor network latency, identify distributed DDoS attacks, prevent phishing scams, and provide aggregated click counts.
- Legal Obligation (Art. 6(1)(c)): Retaining financial records, tax invoices, and responding to statutory court subpoenas.
- Explicit Consent (Art. 6(1)(a)): Used when you explicitly opt in to optional marketing newsletters or non-essential telemetry.
4. Exercising Your Data Subject Rights (Articles 15–22)
The GDPR provides individuals within the European Economic Area (EEA) and the United Kingdom with robust rights regarding their personal data. Below is how you can exercise each right on FreeURLShort:
| GDPR Article & Right | What It Means | How to Execute on FreeURLShort |
|---|---|---|
| Art. 15: Right of Access | You can request confirmation of whether your data is processed and obtain a full copy. | Email privacy@freeurlshort.com or use the Data Export option in your dashboard. |
| Art. 16: Right to Rectification | You have the right to correct inaccurate or incomplete personal information. | Self-service directly via Customer Profile Settings or contact support. |
| Art. 17: Right to Erasure ("To Be Forgotten") | You can request permanent deletion of your account and associated personal data. | Initiate account deletion via Customer Dashboard or email our Data Protection Team. |
| Art. 18: Right to Restriction | You can request that we freeze processing of your data while a dispute is resolved. | Submit a written notice to privacy@freeurlshort.com citing Article 18 grounds. |
| Art. 20: Right to Data Portability | Receive your personal and link data in a structured, commonly used machine-readable format. | Export your links, QR assets, and analytics in standardized JSON/CSV formats. |
| Art. 21: Right to Object | Object at any time to processing based on legitimate interests or direct marketing. | Unsubscribe via any email footer or adjust your telemetry settings in account preferences. |
| Art. 22: Automated Decision-Making | Right not to be subject to decisions based solely on automated processing. | FreeURLShort does not conduct automated profiling producing legal effects on users. |
5. Technical & Organizational Security Measures (TOMs - Article 32)
To ensure security appropriate to risk, FreeURLShort implements the following Technical and Organizational Measures:
- Transport Encryption: Mandatory TLS 1.3 encryption across all public endpoints, dashboard interactions, and REST API calls.
- Pseudonymization & Minimization: IP addresses captured during link redirections are automatically truncated and hashed, stripping the last octet before analytics computation.
- Access Governance: Multi-factor authentication (MFA) and strict role-based access control (RBAC) governing access to production infrastructure.
- Resilience & Redundancy: Distributed database replication with automated real-time backups and geographic failover.
- Continuous Testing: Regular automated security scanning, penetration tests, and vulnerability assessments.
6. Mandatory 72-Hour Data Breach Notification Protocol (Article 33)
In the unlikely event of a personal data breach posing a risk to the rights and freedoms of natural persons, FreeURLShort has established incident response protocols to notify relevant supervisory authorities within seventy-two (72) hours of becoming aware of the breach. Affected data subjects will be notified without undue delay in accordance with Article 34.
7. Data Processing Addendum (DPA)
For European enterprise customers, organizations, and marketing agencies requiring a formal contract governing data processing, we provide our standardized FreeURLShort Data Processing Addendum (DPA) containing the latest European Commission Standard Contractual Clauses (SCCs). To execute a DPA with our legal team, please email dpa@freeurlshort.com.
8. Contacting Our Data Protection Officer
If you have any questions regarding our GDPR compliance program or wish to lodge a formal data subject rights request, please contact:
FreeURLShort Data Protection Officer (DPO)
DPO Lead: Alex Mercer
Dedicated Email: dpo@freeurlshort.com
Response SLA: Verified requests are acknowledged within 48 hours and fulfilled within 30 calendar days.
Supervisory Authority Recourse: You maintain the right to lodge a complaint with your national Data Protection Authority (e.g., CNIL in France, BfDI in Germany, ICO in the UK, or DPC in Ireland).