GDPR Compliance
European Union & United Kingdom — General Data Protection Regulation
Last updated 25 July 2026
Template. This document describes how WhizzLink is built and configured, but it has not been reviewed by a lawyer. Have counsel review and adapt it for your jurisdiction before relying on it.
WhizzLink is a product of WhizzAct Private Limited. Where we process the personal data of individuals in the European Economic Area or the United Kingdom, we do so in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR. This page maps our processing onto the Regulation; our Privacy Policy sets out the underlying detail.
Controller and processors
WhizzAct Private Limited is the data controller for the personal data described in our Privacy Policy. Our sub-processors — hosting, email delivery, and, where configured, IP geolocation — act as data processors and are bound by Article 28 data-processing terms.
Lawful bases for processing
We rely on the following Article 6 bases:
- Contract (Art. 6(1)(b)) — to provide the Service to account holders: managing your links, redirecting visitors, generating QR codes, and producing analytics.
- Legitimate interests (Art. 6(1)(f)) — for privacy-preserving click analytics, security, abuse prevention, and rate limiting. We minimise this data by design: raw IPs are not stored (a salted hash is used instead), and location is coarse.
- Legal obligation (Art. 6(1)(c)) — where we must retain or disclose data to comply with the law.
- Consent (Art. 6(1)(a)) — where we ask for it explicitly, such as non-essential cookies. Consent can be withdrawn at any time.
The first-party uniqueness cookie (24-hour window) is strictly necessary to count a visitor once; it carries no personal data and is not used for advertising.
Your rights as a data subject
Under the GDPR you have the right to:
- Access your personal data (Art. 15);
- Rectification of inaccurate data (Art. 16);
- Erasure — the “right to be forgotten” (Art. 17);
- Restriction of processing (Art. 18);
- Data portability — account holders can export their analytics as CSV (Art. 20);
- Object to processing based on legitimate interests (Art. 21);
- Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22). We do not carry out such automated decision-making.
To exercise any right, email support@whizzact.com. We respond within one month, as required by Article 12, and will not charge a fee for a reasonable request.
International transfers
WhizzAct Private Limited operates from India. Where personal data of EEA or UK individuals is transferred outside those regions, we rely on an appropriate safeguard under Chapter V — such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) — together with supplementary measures where needed.
Retention
We keep personal data no longer than necessary. Individual click events are deleted after 180 days, aggregated statistics after up to 365 days, and our operational logs (sign-in history, API request logs, audit logs, resolved abuse reports) on their own windows. Account data is kept while your account is open; a deleted account is recoverable for 30 days and then permanently erased along with its links and analytics. Scheduled jobs enforce these windows automatically.
Breach notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it (Art. 33), and affected individuals without undue delay where the risk is high (Art. 34).
Contact and complaints
For any data-protection question or request, contact support@whizzact.com. You also have the right to lodge a complaint with your local supervisory authority (in the EEA) or the Information Commissioner's Office (in the UK) — though we would welcome the chance to resolve your concern first.