Roles of the Parties
Roles of the Parties
This Data Processing Agreement (DPA) forms part of the Terms of Service between you (the customer) and GLINR Studios. It applies whenever we process personal data on your behalf in the course of providing the Services.
For your account and billing data, GLINR Studios acts as a controller. For data you or your users submit into the Services (for example, contacts you shorten links for in Glink, or transaction data you route through Quarter), you are the controller and GLINR Studios acts as your processor.
As processor, we process personal data only on your documented instructions, which include your use of the Services and any written instruction you send to [email protected], unless a law we are subject to requires otherwise.
Definitions
Definitions
Terms such as "personal data", "processing", "controller", "processor", and "data subject" carry the meaning given to them in the EU General Data Protection Regulation (GDPR) and equivalent frameworks (UK GDPR, CCPA/CPRA).
"Sub-processor" means any third party engaged by GLINR Studios to process personal data on your behalf. Our current sub-processors are listed at /legal/subprocessors.
Scope and Purpose of Processing
Scope and Purpose of Processing
Subject matter: provision of the Services you have signed up for (glinr.com and the products built under it, including Glink, Label, and Quarter).
Duration: for the term of your subscription, plus the retention and deletion periods described below.
Nature and purpose: hosting, storing, transmitting, and displaying the data required to operate the Services, and generating the outputs you request (short links, QR codes, tax estimates, invoices).
Types of data subjects: your end users, contacts, and any individuals whose data you choose to submit.
Categories of Personal Data
Categories of Personal Data
Account and identity data: names, email addresses, authentication metadata.
Usage and technical data: IP addresses (hashed), device and browser metadata, event logs.
Product-specific data: destination URLs and click metadata (Glink), scan metadata (Label), and, for Quarter, read-only bank transaction data and invoice records.
We do not intentionally process special-category data (health, biometrics, political opinions). Do not submit special-category data into the Services unless we have agreed the specific safeguards in writing.
Sub-Processors
Sub-Processors
You authorize us to engage the sub-processors listed at /legal/subprocessors to process personal data on your behalf. Each sub-processor is bound by data-protection obligations no less protective than those in this DPA.
We maintain the current sub-processor list on that page and will give notice of intended additions or replacements before the new sub-processor begins processing, so you have the opportunity to object on reasonable data-protection grounds.
[TODO: confirm the exact advance-notice window for new sub-processors (for example 30 days) with the studio owner before publishing.]
Security Measures
Security Measures
We maintain technical and organizational measures appropriate to the risk, including encryption in transit (TLS 1.3) and at rest (AES-256), least-privilege access controls, row-level security on the database, peer-reviewed code changes, and dependency vulnerability scanning. See /legal/security for the full overview.
We ensure that personnel authorized to process personal data are bound by confidentiality.
Personal Data Breach Notification
Personal Data Breach Notification
We maintain an incident-response process (see /legal/security). On becoming aware of a personal data breach affecting data we process on your behalf, we will notify you without undue delay and provide the information you reasonably need to meet your own notification obligations.
[TODO: confirm the committed breach-notification window (for example, without undue delay and no later than 72 hours after becoming aware) with the studio owner before publishing, and align it with the figure stated on /legal/security.]
International Transfers
International Transfers
GLINR Studios and its sub-processors operate in the USA. Where personal data is transferred out of the EEA or UK, the transfer relies on the EU Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum, together with supplementary measures where required.
[TODO: confirm which SCC module(s) apply for the controller-to-processor relationship and attach the executed clauses before treating this as the operative transfer mechanism.]
Assisting with Data Subject Requests
Assisting with Data Subject Requests
Taking into account the nature of the processing, we assist you by appropriate technical and organizational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data-subject rights (access, rectification, erasure, portability, restriction, and objection).
If a data subject contacts us directly about data we process on your behalf, we will refer them to you unless you have instructed us otherwise.
Return and Deletion of Data
Return and Deletion of Data
On termination of the Services, we delete or return personal data processed on your behalf, and delete existing copies, unless retention is required by law.
Backups are purged on our standard backup rotation after account deletion. See /legal/privacy for the specific retention periods.
Audits and Compliance
Audits and Compliance
We make available the information reasonably necessary to demonstrate compliance with this DPA, including third-party certifications held by our sub-processors (for example SOC 2 Type II for hosting and database providers, PCI DSS Level 1 for payments).
For direct audits beyond documentation review, contact [email protected] to agree scope, timing, and confidentiality in advance.
Contact
Contact
Data protection questions and DPA execution requests: [email protected].
GLINR Studios, incorporated in Delaware, USA.
Questions about this policy?
Email [email protected] and we will respond within 30 days. For security reports use [email protected].