App Opener Logo

Data Processing Agreement (DPA)

Effective date: 11 August 2026

This Data Processing Agreement (“DPA”) is entered into by and between App Opener, operated by an individual sole proprietor (“Processor,” “we,” “us,” or “our”), and the entity or individual subscribing to or using the App Opener Service (“Controller,” “Customer,” or “you”). This DPA forms an integral part of the App Opener Terms and Conditions and governs the processing of Customer Personal Data in connection with the Service.

1. Definitions

"Customer Personal Data" means any personal data processed by App Opener on behalf of the Customer in the course of providing the Service.

"Data Controller" means the Customer, who determines the purposes and means of processing Customer Personal Data.

"Data Processor" means App Opener, which processes Customer Personal Data on behalf of the Data Controller.

"Data Protection Laws" means all applicable privacy and data protection laws and regulations, including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and the Digital Personal Data Protection Act (DPDP Act, India).

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.

"Sub-processor" means any third-party entity engaged by App Opener to process Customer Personal Data in connection with the Service.

2. Scope and Roles of the Parties

Role of the Parties:

The parties acknowledge and agree that with respect to the processing of Customer Personal Data (such as link visitor click data, analytics, and end-user metadata), Customer is the Data Controller and App Opener is the Data Processor.

Purpose of Processing:

App Opener shall process Customer Personal Data solely for the purpose of providing, maintaining, securing, and optimizing the Service as documented in the Terms and Conditions and this DPA, or as otherwise instructed in writing by the Customer.

3. Categories of Data and Data Subjects

Categories of Data Subjects: Individuals who click on short links generated by the Customer ("Link Visitors") and authorized users of the Customer's App Opener account.

Categories of Customer Personal Data:

  • Link Visitor Metadata: Cryptographically hashed IP addresses, approximate geographic location (country, region, city derived via MaxMind), browser type, operating system, referrer URL, and language preferences.
  • Account & Billing Data: Email address, name, billing address, and account activity logs.
  • API & Security Data: Request IP addresses and rate-limiting metrics.

4. Obligations of the Data Processor

App Opener agrees to:

Process Data on Instructions:

Process Customer Personal Data strictly in accordance with documented instructions from the Customer, including providing the core SaaS functionality, URL shortening, and analytics.

Confidentiality:

Ensure that personnel authorized to process Customer Personal Data are bound by strict contractual or statutory duties of confidentiality.

Technical and Organizational Security Measures:

Implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against unauthorized access, loss, or destruction. These measures include:

  • Cryptographic hashing of visitor IP addresses before database storage.
  • Encryption of data in transit (TLS/HTTPS).
  • Secure database hosting on Google Cloud Infrastructure in India.
  • Storage of account-generated media on Cloudflare R2 using temporary, signed access links.

Assistance to Data Controller:

Reasonably assist the Customer, taking into account the nature of processing, in fulfilling Customer’s obligations to respond to Data Subjects exercising their rights (such as access, rectification, or deletion requests) under applicable Data Protection Laws.

5. Sub-processors

Authorized Sub-processors: Customer grants general authorization to App Opener to engage Sub-processors to assist in delivering the Service. A list of current Sub-processors is set forth below:

Sub-processorPurposeLocation
Google CloudCore Infrastructure & Database HostingIndia
CloudflareMedia Storage (R2) & Edge DeliveryGlobal
MaxMindIP-to-Location Geolocation EngineUnited States
Google Analytics / FirebaseWeb & App Performance MonitoringGlobal
Google reCAPTCHA / hCaptchaBot Protection & SecurityGlobal
Razorpay / PayPalPayment ProcessingIndia / Global
OneSignalMobile Push NotificationsUnited States

Sub-processor Obligations: App Opener shall enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those set out in this DPA.

6. Personal Data Breach Management

In the event of a confirmed Personal Data Breach affecting Customer Personal Data, App Opener shall:

  • Notify the Customer without undue delay after becoming aware of the breach.
  • Provide timely information regarding the nature of the breach, the categories of data affected, and the mitigation measures taken.
  • Take immediate reasonable steps to contain and minimize the effects of the Personal Data Breach.

7. Data Return, Retention, and Deletion

Retention Periods: App Opener retains data in accordance with our Privacy Policy:

  • Account Security Logs: Retained for 90 days.
  • API Logs: IP addresses automatically deleted after 30 days.
  • General System Logs: Retained for 15 days.

Account Deletion:

Upon Customer-initiated account deletion:

  • An immediate soft delete hides the profile and renders associated links inaccessible.
  • A permanent hard delete occurs 7 days after the soft delete request, permanently removing all associated account data from active databases.

8. International Data Transfers

Where Customer Personal Data is transferred outside the European Economic Area (EEA), United Kingdom, or the country of origin, App Opener ensures that appropriate safeguards are implemented in compliance with applicable Data Protection Laws (such as standard contractual clauses or equivalent legal frameworks).

9. Governing Law

This DPA shall be governed by and construed in accordance with the governing law specified in the App Opener Terms and Conditions, except where mandatory Data Protection Laws dictate otherwise for specific Data Subjects.

10. Contact

For privacy or data processing inquiries related to this DPA, please contact:

Background Grid LeftBackground Grid Right

Ready to Create App Opener Links?

Create your link in a few seconds and share it wherever you normally share links.

Unique Views Analytics
Increase Sales Analytics
Rating Statistics