Legal
Data Processing Addendum
How ivlink processes personal data on behalf of its customers. It forms part of the Terms of Service; no signature needed.
Effective 3 October 2026 · Last updated 3 October 2026
1. Scope and roles
This Addendum applies when iVrs.app ("ivlink") processes personal data on behalf of a customer ("Customer") to provide the service under the Terms of Service. The Customer is the data fiduciary / controller and ivlink is the data processor. It is designed to meet India's DPDP Act, 2023 and, where they apply, Article 28 of the EU and UK GDPR. If you need a countersigned copy, email help@ivrs.app.
2. Details of processing
| Subject matter and purpose | Routing link clicks, link analytics, app open and install attribution, app event measurement, and link creation through the API and SDKs. |
|---|---|
| Data subjects | People who click the Customer's links; users of the Customer's apps that include an ivlink SDK. |
| Categories of data | Daily-salted IP hash; approximate location (country, region, city); OS, OS version, device type, browser; referring domain; link, time and query parameters; SDK device identifier (stored hashed), device model, app version, locale; user IDs, events and properties the Customer sends; any personal data the Customer puts in links or link data. |
| Special categories | None intended. The Customer must not send sensitive data (see the Acceptable Use Policy). |
| Duration | For the term of the agreement and the retention period of the Customer's plan, then deletion. |
3. Instructions
ivlink processes Customer personal data only on the Customer's documented instructions: the agreement, the Customer's configuration of the service, and other written instructions we accept. We will tell the Customer if we believe an instruction breaks applicable law. The Customer is responsible for the lawfulness of the data it collects and for giving the notices and obtaining the consents its users require.
4. Confidentiality
Everyone at ivlink with access to Customer personal data is bound by confidentiality obligations and has access only as needed.
5. Security measures
ivlink keeps appropriate technical and organisational measures in place, described on our Security page. They include encryption in transit, IP hashing with a daily-rotating salt, hashing of passwords and keys, tenant isolation in a single data-access layer, role-based access and audit logging. We may update these measures if the overall level of protection does not decrease.
6. Subprocessors
The Customer authorises the subprocessors on our Subprocessors page. ivlink binds each subprocessor to data-protection obligations at least as protective as this Addendum and remains responsible for them. We give at least 30 days' notice of new subprocessors; the Customer may object on reasonable grounds, and if we can't address the objection, may terminate the affected service and receive a pro-rata refund of prepaid fees.
7. International transfers
Customer personal data is processed in the United States (US West) and on Cloudflare's global network. For transfers out of India, ivlink transfers only to countries not restricted by the Government of India. For transfers of EEA or UK personal data to countries without an adequacy decision, the EU Standard Contractual Clauses (Module 2 or 3, as applicable) and the UK Addendum are incorporated by reference.
8. Assistance and data subject requests
ivlink will promptly forward requests it receives from the Customer's users and help the Customer respond to access, correction, deletion and similar requests, and with data protection impact assessments where reasonably required.
9. Personal data breaches
ivlink will notify the Customer without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting Customer data, with the information the Customer reasonably needs to meet its own obligations (including to the Data Protection Board of India), and will take reasonable steps to contain it.
10. Deletion and return
The Customer can export its links through the API at any time. On termination, ivlink deletes Customer personal data within 90 days, except where law requires us to keep it. Analytics are deleted automatically at the end of the plan's retention period.
11. Audits
ivlink will provide the information reasonably needed to show compliance with this Addendum, including written answers to security questionnaires once a year. On-site audits may be agreed for Enterprise customers with reasonable notice and confidentiality protections.
12. Liability and precedence
Liability under this Addendum is subject to the limits in the Terms of Service. If this Addendum conflicts with the Terms on the processing of personal data, this Addendum prevails; the Standard Contractual Clauses prevail over both where they apply.