Data Processing Agreement
Scope & roles
This Data Processing Agreement (DPA) forms part of the OneLink Terms of Service. OneLink acts as Processor; you act as Controller in respect of Personal Data submitted to or generated by the service on your behalf.
Data categories & subjects
- End users who click your links — hashed IP, User-Agent, country (from IP), referrer
- Your team members — name, email, role, account events
- Your account billing — name, billing address, payment method (tokenized via Stripe)
Sub-processors
OneLink uses the sub-processors listed at oneli.nk/legal/sub-processors. We notify you of additions at least 30 days in advance; you have the right to object.
International transfers
Where data is transferred outside the EU/UK, transfers are governed by the EU Standard Contractual Clauses (2021/914) and the UK IDTA addendum, incorporated by reference. We have completed a Transfer Impact Assessment available on request.
Security measures
- TLS 1.3 in transit, AES-256 at rest
- SOC 2 Type II (annual) and ISO 27001
- Role-based access control with mandatory SSO + 2FA for staff
- Quarterly penetration testing by an external firm
- 24/7 paging on the edge resolver and ingestion pipeline
Breach notification
We notify you without undue delay and in any event within 72 hours of becoming aware of a Personal Data breach affecting your data, by email to the security contacts in your account.
Audit rights
You may request a copy of our most recent SOC 2 and ISO 27001 reports under NDA. On-site audits are available to Scale plan customers with reasonable notice.