Data Processing Agreement (DPA)

Working template for informational purposes only. This text must be reviewed by qualified legal counsel before publication. Company details marked as placeholders ([RAZÓN SOCIAL / CIF / DIRECCIÓN]) must be completed.

Last updated: 23 August 2026.

This Data Processing Agreement (“DPA”) forms part of the contract between the YoLink customer (“Controller”) and [RAZÓN SOCIAL / CIF / DIRECCIÓN] (“Processor”, “YoLink”) under Article 28 GDPR when Controller uses YoLink Services to process personal data of end users (for example click analytics, YoPage visitors, UTM-linked campaign data).

1. Subject matter and duration

Processor will process personal data solely to provide short links, QR, YoPage hosting, analytics dashboards, UTM tooling, account administration and related support for the term of the Services agreement and any post-termination retention strictly required for legal defence, backups wind-down or statutory duties.

2. Nature and purpose of processing

Processing includes collection, storage, organisation, retrieval, transmission (redirects), aggregation, pseudonymisation where applied, erasure and restriction of technical identifiers and content metadata necessary to operate the Services as configured by Controller.

3. Types of data and data subjects

  • Data subjects: visitors clicking short links/QR, YoPage viewers, and other end users of Controller’s campaigns.
  • Data types: IP addresses, device/browser signals, timestamps, referrers, destination URLs, approximate geolocation, cookie IDs if used, and content published by Controller that may include personal data.
  • Special categories are not intended; Controller must not instruct processing of special-category data unless a valid Art. 9 basis exists and is documented.

4. Controller instructions

Processor processes data only on documented instructions from Controller (including configuration in the product UI and this DPA), unless required by EU/Member State law. Unlawful instructions will be flagged without undue delay.

5. Confidentiality and security

Processor ensures persons authorised to process personal data are bound by confidentiality and implements appropriate technical and organisational measures under Art. 32 GDPR (access control, encryption in transit, logging, vulnerability management, backup integrity).

6. Subprocessors

Controller authorises use of subprocessors listed at /subprocessors. Processor will impose equivalent data-protection obligations and inform Controller of material additions in advance, allowing objection on reasonable grounds where contractually agreed.

7. International transfers

Where processing involves transfers outside the EEA/UK, Processor relies on adequacy decisions or Standard Contractual Clauses (and UK addenda where needed) with supplementary measures as appropriate.

8. Assistance with data-subject rights and DPIA

Taking into account the nature of processing, Processor assists Controller by appropriate technical measures to respond to data-subject requests and with DPIAs/prior consultations where required, at Controller’s reasonable request and subject to fair cost recovery for disproportionate effort.

9. Personal data breaches

Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller data, providing information reasonably available to help Controller meet Art. 33/34 duties.

10. Deletion and return

Upon termination of Services, Processor will delete or return personal data (at Controller’s choice where feasible) within a commercially reasonable period, except copies retained under legal obligation or isolated backup archives pending rotation.

11. Audits

Processor will make available information necessary to demonstrate Art. 28 compliance and allow audits (including via questionnaires, certifications or on-site review under reasonable notice, confidentiality and frequency limits) as agreed in writing.

12. Liability and order of precedence

Liability remains as in the Terms of Service except where mandatory data-protection law requires otherwise. If conflict arises between this DPA and other terms regarding data protection, this DPA prevails for that subject. Contact: privacy@yolink.es · legal@yolink.es.

Published: 11.09.2026 04:28