Skip to content
bref

Data processing agreement (DPA)

TIPIT SRL's commitments when Bref processes, for your organisation, the data of your links' visitors (Article 28 GDPR).

Updated 30 September 2026

1. Parties and purpose

This agreement binds Bref's customer organisation (the “Controller”) and TIPIT SRL, CBE 1007.088.147 (the “Processor”). It is part of the terms and conditions and applies as soon as an organisation uses Bref.

It describes how the Processor processes, on the Controller's behalf, the personal data related to visits to its short links and to the members of its organisation, in accordance with Article 28 of the General Data Protection Regulation (GDPR).

2. Description of the processing

Item Detail
Purpose Redirecting short link visitors and producing visit analytics
Nature Collection, recording, aggregation, consultation, export and erasure
Data subjects Short link visitors; members and invitees of the organisation
Data Date and time, link, source (click or scan), country, device type, system, browser, referring domain, A/B variant; email and name of members and invitees
Sensitive data None
Duration For as long as the organisation uses Bref

No IP address and no visitor identifier is kept.

3. Processor's obligations

The Processor undertakes to:

  • process the data only on the Controller's documented instructions (these terms and the use of the service constitute instructions), and inform it if an instruction appears to infringe the GDPR;
  • ensure confidentiality: only people who need the data to run the service have access, under a duty of confidentiality;
  • implement the security measures in section 5;
  • help the Controller respond to data subject requests, in particular through export and deletion from the dashboard;
  • notify the Controller of any personal data breach affecting it without undue delay, and at the latest 48 hours after becoming aware of it, with the information it needs for its own notifications;
  • assist it, where needed, with impact assessments and prior consultation of the supervisory authority;
  • make available the information needed to demonstrate compliance with this agreement, and allow reasonable audits, announced at least 30 days in advance, at the Controller's expense.

4. Sub-processors

The Controller authorises the following sub-processors:

Sub-processor Role Location
Leaf Platform that runs and hosts the service On Cloudflare's infrastructure
Cloudflare, Inc. Hosting, database, network Worldwide, including the EU; headquartered in the US
Sendinblue SAS (Brevo) Invitation emails to members France

Google (Web Risk) is not a sub-processor: only the destination addresses of links are sent to it, without personal data.

The Processor informs the Controller of any addition or replacement at least 30 days in advance, by email to the organisation's owner. The Controller may object on reasonable grounds and, failing agreement, end its subscription. The Processor imposes on each sub-processor obligations equivalent to those of this agreement.

5. Security measures

  • Encrypted communications (HTTPS, TLS).
  • An organisation's data accessible only to its authenticated members, checked on every request.
  • Data minimisation: no IP address, identifier or tracking cookie for visitors.
  • Passwords of protected links stored hashed (PBKDF2).
  • Destinations checked against Google Web Risk, dangerous links disabled.
  • Automatic erasure of visits older than 3 years.

6. Transfers outside the European Union

Where data is processed outside the European Economic Area (in particular by Cloudflare), the transfer relies on an adequacy decision (EU-US Data Privacy Framework) or on the European Commission's standard contractual clauses.

7. End of processing

When the organisation stops using Bref or is deleted, the data is erased within 30 days, unless the law requires it to be kept. Before that, the Controller can export its links and analytics as CSV from the dashboard.

8. Controller's obligations

The Controller confirms it has a legal basis for processing visits to its links, informs data subjects where required, and does not use Bref to process special categories of data.

9. Signature

This agreement applies without a separate signature. A signed copy is available on request at contact@bref.timour.me.