Data processing agreement (DPA)
TIPIT SRL's commitments when Bref processes, for your organisation, the data of your links' visitors (Article 28 GDPR).
Updated 30 September 2026
1. Parties and purpose
This agreement binds Bref's customer organisation (the “Controller”) and TIPIT SRL, CBE 1007.088.147 (the “Processor”). It is part of the terms and conditions and applies as soon as an organisation uses Bref.
It describes how the Processor processes, on the Controller's behalf, the personal data related to visits to its short links and to the members of its organisation, in accordance with Article 28 of the General Data Protection Regulation (GDPR).
2. Description of the processing
| Item | Detail |
|---|---|
| Purpose | Redirecting short link visitors and producing visit analytics |
| Nature | Collection, recording, aggregation, consultation, export and erasure |
| Data subjects | Short link visitors; members and invitees of the organisation |
| Data | Date and time, link, source (click or scan), country, device type, system, browser, referring domain, A/B variant; email and name of members and invitees |
| Sensitive data | None |
| Duration | For as long as the organisation uses Bref |
No IP address and no visitor identifier is kept.
3. Processor's obligations
The Processor undertakes to:
- process the data only on the Controller's documented instructions (these terms and the use of the service constitute instructions), and inform it if an instruction appears to infringe the GDPR;
- ensure confidentiality: only people who need the data to run the service have access, under a duty of confidentiality;
- implement the security measures in section 5;
- help the Controller respond to data subject requests, in particular through export and deletion from the dashboard;
- notify the Controller of any personal data breach affecting it without undue delay, and at the latest 48 hours after becoming aware of it, with the information it needs for its own notifications;
- assist it, where needed, with impact assessments and prior consultation of the supervisory authority;
- make available the information needed to demonstrate compliance with this agreement, and allow reasonable audits, announced at least 30 days in advance, at the Controller's expense.
4. Sub-processors
The Controller authorises the following sub-processors:
| Sub-processor | Role | Location |
|---|---|---|
| Leaf | Platform that runs and hosts the service | On Cloudflare's infrastructure |
| Cloudflare, Inc. | Hosting, database, network | Worldwide, including the EU; headquartered in the US |
| Sendinblue SAS (Brevo) | Invitation emails to members | France |
Google (Web Risk) is not a sub-processor: only the destination addresses of links are sent to it, without personal data.
The Processor informs the Controller of any addition or replacement at least 30 days in advance, by email to the organisation's owner. The Controller may object on reasonable grounds and, failing agreement, end its subscription. The Processor imposes on each sub-processor obligations equivalent to those of this agreement.
5. Security measures
- Encrypted communications (HTTPS, TLS).
- An organisation's data accessible only to its authenticated members, checked on every request.
- Data minimisation: no IP address, identifier or tracking cookie for visitors.
- Passwords of protected links stored hashed (PBKDF2).
- Destinations checked against Google Web Risk, dangerous links disabled.
- Automatic erasure of visits older than 3 years.
6. Transfers outside the European Union
Where data is processed outside the European Economic Area (in particular by Cloudflare), the transfer relies on an adequacy decision (EU-US Data Privacy Framework) or on the European Commission's standard contractual clauses.
7. End of processing
When the organisation stops using Bref or is deleted, the data is erased within 30 days, unless the law requires it to be kept. Before that, the Controller can export its links and analytics as CSV from the dashboard.
8. Controller's obligations
The Controller confirms it has a legal basis for processing visits to its links, informs data subjects where required, and does not use Bref to process special categories of data.
9. Signature
This agreement applies without a separate signature. A signed copy is available on request at contact@bref.timour.me.