Snpurl Snpurl
GDPR compliant since May 10, 2026 · Data centre: AWS ap-south-1 (Mumbai, India)
shield GDPR

GDPR Compliance Centre

EU Regulation 2016/679 · Full compliance since May 2026

policy

Your GDPR Rights

Submit a request: email support@snpurl.com with subject "GDPR Request [Right Name]". We respond within 30 days (Article 12).

visibility
Right to Access
Get a copy of all data we hold about you.
Article 15
edit
Rectification
Correct any inaccurate personal data.
Article 16
delete_forever
Erasure
Request deletion of your personal data.
Article 17
download
Portability
Export your data in JSON or CSV format.
Article 20
block
Right to Object
Opt out of marketing or profiling.
Article 21
pause_circle
Restrict Processing
Pause processing during a dispute.
Article 18
01
verified_user

Our GDPR Commitment

Snpurl has been GDPR-compliant since May 10, 2026 the regulation effective date. We view GDPR not as a burden but as a framework for building trust with our European users.

Our engineering and product teams treat data protection by design (Article 25) as a core principle, not an afterthought.

DPO: Our Data Protection Officer is Md Aftab contact at support@snpurl.com
02
gavel

Lawful Basis for Processing

We rely on the following lawful bases under Article 6 GDPR:

  • Contract (Art 6(1)(b)): processing necessary to provide the service you subscribed to
  • Legitimate interests (Art 6(1)(f)): security monitoring, fraud prevention, product analytics
  • Legal obligation (Art 6(1)(c)): tax records, legal compliance
  • Consent (Art 6(1)(a)): marketing communications you can withdraw any time
03
sync_alt

International Data Transfers

All user data is stored on Snpurl data center. We do not transfer personal data to the USA or other third countries except:

  • Stripe (USA): covered by Standard Contractual Clauses (SCCs)
  • Sentry (USA): error monitoring anonymised error traces only; covered by SCCs
  • Postmark (USA): transactional email email address and metadata only; covered by SCCs
SCCs: All US sub-processors are bound by the EU Standard Contractual Clauses (2021/914) for controller-to-processor transfers.
04
fact_check

Data Protection Impact Assessments

We conduct DPIAs (Article 35) for any new feature or processing activity that may result in high risk to data subjects. Our DPIA register is available to supervisory authorities upon request.

Our last DPIA was conducted in May 2026 for the link analytics geo-tracking feature.
05
security

Data Breach Response

In the event of a personal data breach, Snpurl will:

  • Notify the relevant supervisory authority within 72 hours (Article 33)
  • Notify affected data subjects without undue delay if the breach poses a high risk (Article 34)
  • Document the breach, its effects, and remediation steps
  • Conduct a post-incident review within 14 days
06
contact_support

Supervisory Authority Complaints

If you are not satisfied with our response to a GDPR request or concern, you have the right to lodge a complaint with your local supervisory authority.

  • EU: your national Data Protection Authority (find yours at edpb.europa.eu)
  • UK: Information Commissioner Office (ICO) at ico.org.uk
  • India: CERT-In and forthcoming PDPB Data Protection Board
We prefer to resolve issues directly. Please contact support@snpurl.com before filing a supervisory complaint.
shield

Need GDPR assistance?

Our Data Protection Officer is here to help. Contact us at support@snpurl.com.