Transparency about the processing of your personal data
Last updated: 15 July 2026
EU.PE ("we", "us", "our") is a professional URL shortening and link management service for business users, operated by Digital Marketing Agency ROMBEY (sole proprietorship, owner: Christopher Rombey). We take the protection of your personal data very seriously and comply with the European General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the German Telecommunications Digital Services Data Protection Act (TDDDG), and other applicable data protection laws.
This privacy policy informs you about how we collect, use, share, and protect personal data when you visit our website, use our service, or when individuals click on links managed through our service.
Our platform collects extensive data about both our registered customers and end users who click on shortened links in order to provide analytics and advanced features. Please read this policy carefully to understand our data processing practices.
Data controller within the meaning of the GDPR:
Digital Marketing Agency ROMBEY
Owner: Christopher Rombey
Theodor-Körner-Str. 29
41812 Erkelenz
Germany
For data protection inquiries, you can reach us at:
Email: privacy@eu.pe
Mail: Digital Marketing Agency ROMBEY, Attn. Data Protection, Theodor-Körner-Str. 29, 41812 Erkelenz
Role distribution under the GDPR:
Competent supervisory authority:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW)
Postfach 20 04 44, 40102 Düsseldorf
https://www.ldi.nrw.de
We collect various categories of personal data depending on how you interact with EU.PE:
When you register for an account or purchase a plan, we collect information provided by you:
Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) or pre-contractual measures.
Necessity of provision: Providing the contact, login, and billing data is necessary for the conclusion and performance of the usage agreement. Without this information, registration or the use of paid plans is not possible. Providing a phone number is voluntary. There is no statutory obligation to provide the data.
Whenever our service is used -- either by you as a logged-in customer creating links, or by an end user clicking on a shortened link, scanning a QR code, or viewing a "link-in-bio" page -- we automatically collect data about this interaction. This may include personal data of the link visitor. Specifically, for each link access we collect:
When you click on a short link, we set no cookies and no other persistent identifiers in the visitor's browser and do not create cross-device profiles of link visitors. The assignment of A/B test variants is also performed purely server-side via a cryptographically hashed value (SHA-256 with a secret key derived from the IP address and link identifier), without any data being stored in the browser.
Roles and legal bases:
(a) Processing on behalf of our business customers: Insofar as this data serves to provide the respective link creator with analytics about their links, we process it as a data processor (Art. 28 GDPR) on behalf of the business customer. The controller for this processing is the respective business customer; the legal basis follows from their privacy notice (typically Art. 6(1)(f) GDPR). For information about this processing, please contact the operator of the link you followed.
(b) Processing for our own purposes: Insofar as we use the same data for the security and stability of our systems, for the detection and prevention of abuse (e.g., malware and phishing detection, fake-click detection), and in aggregated, anonymized form to improve our service, we act as a controller. Legal basis: Art. 6(1)(f) GDPR -- our legitimate interest in a secure, abuse-free operation of the platform.
We exclusively use technically necessary first-party cookies. No third-party cookies and no cookies for analytics, tracking, or advertising purposes are used. A cookie consent banner is therefore not required (Section 25(2)(2) TDDDG).
Specifically, we use the following cookies:
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
| PHP Session ID (PHPSESSID) | Maintaining your session and login status (including temporary storage of referral or coupon codes during a registration or ordering process) | Technically necessary | Browser session, server-side maximum 24 hours |
| Language selection (lang) | Storing your preferred language (DE/EN) | Technically necessary | 1 year |
Cookies are only set in the logged-in customer area or on our website -- not upon merely clicking a short link (see Section 3.2).
Legal basis: Section 25(2)(2) TDDDG -- these cookies are strictly necessary for us to provide the service you have expressly requested. Consent is not required for this purpose.
You can delete or block cookies at any time through your browser settings. Please note that disabling technically necessary cookies may limit the functionality of our service.
All cookies are first-party cookies and are set with the security attributes HttpOnly, Secure, and SameSite=Strict.
Our servers automatically maintain logs of incoming requests. These logs contain the data mentioned in Section 3.2 (IP address, timestamp, user agent, etc.) for each request to our system (including API calls). We use these logs for debugging, security monitoring, and maintaining service integrity. Log data is routinely deleted or anonymized after 14 days, unless required for security analysis.
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) -- security and stability of our systems.
| Purpose | Role | Legal Basis (GDPR) |
|---|---|---|
| Provision of the service (account management, link creation, redirects) | Controller | Art. 6(1)(b) -- performance of a contract |
| Analytics and reporting for business customers (link visitor data) | Data processor | The legal basis lies with the respective business customer as controller (see Section 3.2 (a)) |
| Security and abuse prevention (including analysis of access data) | Controller | Art. 6(1)(f) -- legitimate interest |
| Service improvement and product development (aggregated/anonymized only) | Controller | Art. 6(1)(f) -- legitimate interest |
| Technically necessary cookies | Controller | Section 25(2)(2) TDDDG (no consent required) |
| Customer support (helpdesk/ticket system, email) | Controller | Art. 6(1)(b) -- performance of a contract |
| Transactional and system messages (registration confirmation, invoice notifications, security and service notices) | Controller | Art. 6(1)(b) -- performance of a contract |
| Newsletter and marketing communications | Controller | Art. 6(1)(a) -- consent (revocable at any time) |
| Invoicing and accounting | Controller | Art. 6(1)(c) -- legal obligation (HGB, AO) |
| Affiliate program (referral tracking, commission calculation, payout) | Controller | Art. 6(1)(b) -- performance of a contract |
| Fulfillment of legal obligations | Controller | Art. 6(1)(c) -- legal obligation |
Where we rely on legitimate interests, we have conducted a balancing test and determined that our interests do not override the rights of the data subjects. You have the right to object to processing based on legitimate interests at any time (see Section 8).
Note on emails:
We send registered customers exclusively transactional and system messages that are necessary for the performance of the contract (e.g., registration confirmation, invoice notifications, security-relevant notices, announcements of material changes to the contract or service). We only send promotional emails and newsletters if you have expressly consented to them (opt-in). Every promotional email contains an unsubscribe option; you can withdraw your consent at any time with effect for the future.
We handle your data with care and do not sell personal data. We only share data in the following situations:
If you as an end user click on a shortened link, certain analytics information about your click becomes visible in the link creator's dashboard. This consists of aggregated statistics (e.g., "100 clicks from Berlin, Germany" or "60% mobile users"). We do not share your raw IP address, name, or email address directly with the business customer.
Note: The business customer who uses our service to collect analytics about link visitors is considered an independent Data Controller for this visitor data. We act as a Data Processor in this regard (see Section 9).
Personal data is only accessed by authorized personnel who need it to fulfill their duties. All employees and contractors are bound by confidentiality and data protection obligations.
We use carefully selected service providers with whom we have concluded data processing agreements pursuant to Art. 28 GDPR:
| Category | Provider | Location | Purpose |
|---|---|---|---|
| Server infrastructure | Serverprofis GmbH, Otto-Lilienthal-Ring 34-36, 85622 Feldkirchen | Germany (EU) | Server hosting (reseller hosting), provision of physical server infrastructure |
All other services (email sending, helpdesk/ticket system, affiliate management, GeoIP resolution) are operated on our own infrastructure. No external service providers are used for these purposes.
The purchase of paid plans is carried out through our authorized reseller (Wiederverkäufer):
CopeCart GmbH, Rosenstr. 2, 10178 Berlin, Germany
CopeCart GmbH sells the Pro plan licenses in its own name, concludes a separate contract with you for this purpose, and handles invoicing and payment processing. For the data collected and processed in this context (e.g., name, billing address, payment data), CopeCart GmbH is an independent controller within the meaning of Art. 4(7) GDPR -- not our data processor. The privacy policy of CopeCart GmbH applies in this respect (available at copecart.com).
In the course of contract processing, we exchange the data required for this purpose with CopeCart GmbH: we receive order and payment confirmations from CopeCart (name, email address, plan purchased, payment method, transaction ID, payment status) in order to activate and manage your access; we do not receive or store complete credit card numbers or bank details. Legal basis for this data exchange: Art. 6(1)(b) GDPR (performance of a contract).
We may disclose personal data to law enforcement agencies, regulatory authorities, courts, or other bodies when we are legally required to do so or when it is necessary to enforce our rights, protect our safety, or the safety of others.
Legal basis: Art. 6(1)(c) GDPR (legal obligation) or Art. 6(1)(f) GDPR (legitimate interest).
If our company is involved in a merger, acquisition, or sale of assets, personal data may be transferred to the parties involved. We will inform you in advance in such a case.
We do not sell or rent your personal data to third-party marketers. Any sharing occurs only as described above.
Insofar as necessary for the fulfillment of our tax and commercial law obligations, invoicing and accounting data (including customer data contained therein, such as name, address, and invoice amounts) may be shared with our tax advisor and, in the event of an audit, with tax authorities. Legal basis: Art. 6(1)(c) GDPR (legal obligation, Sections 147 AO, 257 HGB) and Art. 6(1)(f) GDPR (legitimate interest in proper bookkeeping).
We are based in Germany and store and process all data exclusively on servers in Germany. Our service provider Serverprofis GmbH, as well as CopeCart GmbH (an independent controller for purchase and payment processing, see Section 5.4), are likewise based in Germany.
We do not actively transfer personal data to third countries outside the EU or EEA. We will continue to use exclusively service providers based in the EU.
We retain personal data only for as long as necessary for the respective purposes or as required by statutory retention obligations:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account data | Duration of the business relationship + 3 years (statute of limitations) | Art. 6(1)(b), (f) GDPR |
| Two-factor authentication – authenticator app secret (encrypted) | Until two-factor authentication is deactivated, then deleted immediately | Art. 6(1)(b) GDPR in conjunction with Art. 32 GDPR |
| Two-factor authentication – recovery codes (stored as hashes only) | Until redeemed, reissued or deactivated | Art. 6(1)(b) GDPR in conjunction with Art. 32 GDPR |
| Link analytics -- raw IP addresses (all plans) | 30 days, then automated pseudonymization (hashing/truncation) | Art. 6(1)(f) GDPR or instruction of the controller |
| Link analytics -- detailed data (Free plan) | 30 days detailed, then aggregated/anonymized | Instruction of the controller (business customer) |
| Link analytics -- detailed data, pseudonymized (Pro plan) | As long as the account is active; deletion after account closure pursuant to the DPA | Instruction of the controller (business customer) |
| Invoices and payment data | 10 years | Section 147 AO, Section 257 HGB |
| Support communications (tickets, emails) | 3 years after completion of the matter | Art. 6(1)(f) GDPR |
| Server logs | 14 days (unless required for security analysis) | Art. 6(1)(f) GDPR |
| Affiliate data | Duration of participation in the affiliate program + 3 years | Art. 6(1)(b) GDPR |
After the respective retention period expires, personal data is securely deleted or irreversibly anonymized.
Where the GDPR applies, you have the following rights:
| Right | Description | Legal Basis |
|---|---|---|
| Access | Request a copy of your stored data | Art. 15 GDPR |
| Rectification | Correction of inaccurate or incomplete data | Art. 16 GDPR |
| Erasure | Request deletion of your data ("right to be forgotten") | Art. 17 GDPR |
| Restriction | Restriction of processing under certain circumstances | Art. 18 GDPR |
| Data portability | Receive your data in a common, machine-readable format | Art. 20 GDPR |
| Objection | Object to processing based on legitimate interests | Art. 21 GDPR |
| Withdrawal of consent | Withdraw given consents at any time with effect for the future | Art. 7(3) GDPR |
Important: Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
Automated decision-making: We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).
To exercise your rights, contact us at privacy@eu.pe. We will verify your identity and respond within one month (Art. 12(3) GDPR). In complex cases, this period may be extended by a further two months, of which we will inform you.
Right to lodge a complaint:
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW)
Postfach 20 04 44, 40102 Düsseldorf
https://www.ldi.nrw.de
For most data processing activities, we have a dual role:
The Data Processing Agreement (DPA) pursuant to Art. 28 GDPR forms part of our General Terms and Conditions and is validly agreed upon registration (Section 4.4 of the Terms). You can view the version applicable to you at any time in the customer portal, countersign it electronically, and download it as a PDF document. The DPA governs:
If you use EU.PE to collect analytics about your users, you are responsible as the data controller for ensuring a valid legal basis for this data collection (e.g., legitimate interest or consent) and for informing your end users accordingly in your own privacy policy. The DPA is already part of the contract upon your registration; countersigning it in the customer portal serves as your own evidence pursuant to Art. 28(9) and Art. 5(2) GDPR.
We implement appropriate technical and organizational measures (TOMs) pursuant to Art. 32 GDPR:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours (Art. 33 GDPR) and inform affected individuals without undue delay if a high risk exists (Art. 34 GDPR).
Our service is intended exclusively for business customers and is not designed for use by minors. We do not knowingly collect personal data from individuals under the age of 18. Should we become aware that a minor has submitted personal data to us, we will delete it without undue delay. Please contact us at privacy@eu.pe if you believe that data of a minor has been collected.
We may update this privacy policy from time to time to reflect changes in our service, our data processing practices, or legal requirements.
In the event of material changes, we will:
Continued use of the service after the publication of changes constitutes acknowledgment of the revised policy. We recommend that you review this privacy policy regularly.
If you have questions, concerns, or requests regarding this privacy policy or the processing of your personal data:
Via our ticket system on the website
Digital Marketing Agency ROMBEY
Attn. Data Protection
Theodor-Körner-Str. 29
41812 Erkelenz, Germany
We are happy to assist you and will handle your inquiry as promptly as possible.