This Data Processing Agreement ("DPA") forms an integral part of the Terms and Conditions between VcareAll Business Services LLC ("LinksTrackly," "Data Processor," "we," or "us") and you, the user or client ("Data Controller," "you," or "your").
This agreement outlines the terms, requirements, and conditions under which LinksTrackly processes Personal Data on your behalf in compliance with the General Data Protection Regulation (GDPR) and other applicable global data privacy laws.
1. Definitions
- Data Protection Laws refers to the GDPR (EU 2016/679), the UK GDPR, the California Consumer Privacy Act (CCPA), and any other applicable national or regional data privacy legislation
- Personal Data means any information relating to an identified or identifiable natural person (the "Data Subject") processed by the Data Processor on behalf of the Data Controller
- Sub-processor means any third party engaged by LinksTrackly to process Personal Data on your behalf
- "Controller," "Processor," "Data Subject," and "Processing" shall have the meanings given to them in the GDPR
2. Roles and Scope of Processing
- Role of the Parties: For the purposes of this DPA, you are the Data Controller of the Personal Data collected from your end-users (visitors clicking your tracked links), and LinksTrackly is the Data Processor.
- Nature and Purpose of Processing: LinksTrackly processes Personal Data solely to provide link tracking, traffic analytics, and click fraud protection services as outlined in our Terms and Conditions.
- Categories of Data: Processing includes, but is not limited to, IP addresses, device fingerprints, browser types, referrer URLs, timestamps, and Google Click Identifiers (gclid).
- Duration: We will process Personal Data for the duration of your active subscription and as necessary to fulfill our obligations under the Terms and Conditions.
3. Obligations of the Data Processor (LinksTrackly)
As the Data Processor, LinksTrackly agrees to:
- Process Personal Data only on documented written instructions from you, unless required otherwise by applicable law
- Ensure that persons authorized to process the Personal Data have committed themselves to strict confidentiality or are under an appropriate statutory obligation of confidentiality
- Assist you, insofar as this is possible, in fulfilling your obligation to respond to requests for exercising Data Subjects' rights (e.g., access, rectification, erasure, or data portability)
- Assist you in ensuring compliance with obligations regarding security, breach notifications, and data protection impact assessments
4. Sub-processors
You grant LinksTrackly general authorization to engage Sub-processors (e.g., cloud hosting providers, infrastructure partners) to deliver the Service.
We will execute written agreements with all Sub-processors that impose data protection obligations no less protective than those in this DPA.
We will notify you of any intended changes concerning the addition or replacement of Sub-processors, giving you the opportunity to object to such changes.
5. Security Measures
We implement and maintain appropriate Technical and Organizational Measures (TOMs) to ensure a level of security appropriate to the risk, including:
- Encryption of Personal Data in transit (TLS) and at rest
- Strict role-based access controls and authentication protocols for our staff
- Regular vulnerability testing and security audits of the LinksTrackly platform
- Physical security measures at the data centers of our Sub-processors
6. Personal Data Breaches
In the event of a confirmed Personal Data breach affecting your data, LinksTrackly will:
- Notify you without undue delay (and in any event within 48 hours) after becoming aware of the breach
- Provide you with sufficient information to allow you to meet your obligations to report to regulatory authorities or Data Subjects
- Take reasonable commercial steps to mitigate the effects and minimize the damage resulting from the breach
7. International Data Transfers
As LinksTrackly operates in the United States, Personal Data originating from the European Economic Area (EEA), Switzerland, or the UK may be transferred to our servers in the US.
Any transfer of Personal Data outside the EEA/UK will be subject to appropriate safeguards, primarily the Standard Contractual Clauses (SCCs) approved by the European Commission, which are hereby incorporated by reference into this DPA.
8. Data Deletion and Return
Upon termination or expiration of your LinksTrackly account:
- We will, at your choice, delete or return all Personal Data to you.
- We will delete existing copies of the Personal Data unless applicable law (or valid accounting/legal requirements) requires the prolonged storage of the data.
- Aggregated and fully anonymized telemetry data, which no longer constitutes Personal Data, may be retained for system training and security improvements.
9. Audits and Inspections
LinksTrackly will make available to you all information strictly necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR. Upon reasonable written notice, we will allow for and contribute to audits or inspections conducted by you or an independent auditor mandated by you, provided such audits do not disrupt our standard business operations or compromise the security of other clients.
Contact Information
If you have questions regarding this DPA or wish to exercise your rights under this agreement, please contact our Privacy Team: