EU.PE Premium URL Shortener
Features Security Pricing Affiliate Deutsch Login Get Started

Privacy Policy

Transparency about the processing of your personal data

Last updated: 15 July 2026

1. Introduction

EU.PE ("we", "us", "our") is a professional URL shortening and link management service for business users, operated by Digital Marketing Agency ROMBEY (sole proprietorship, owner: Christopher Rombey). We take the protection of your personal data very seriously and comply with the European General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the German Telecommunications Digital Services Data Protection Act (TDDDG), and other applicable data protection laws.

This privacy policy informs you about how we collect, use, share, and protect personal data when you visit our website, use our service, or when individuals click on links managed through our service.

Important Notice:

Our platform collects extensive data about both our registered customers and end users who click on shortened links in order to provide analytics and advanced features. Please read this policy carefully to understand our data processing practices.

2. Data Controller and Contact

Data controller within the meaning of the GDPR:

Digital Marketing Agency ROMBEY
Owner: Christopher Rombey
Theodor-Körner-Str. 29
41812 Erkelenz
Germany

For data protection inquiries, you can reach us at:

Email: privacy@eu.pe
Mail: Digital Marketing Agency ROMBEY, Attn. Data Protection, Theodor-Körner-Str. 29, 41812 Erkelenz

Role distribution under the GDPR:

  • For personal data that we collect directly (e.g., account information, website visits), we act as the Data Controller (Art. 4(7) GDPR).
  • For data that we process on behalf of our business customers (e.g., information about individuals who click on their links), we act as a Data Processor (Art. 4(8) GDPR) according to their instructions.

Competent supervisory authority:

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW)
Postfach 20 04 44, 40102 Düsseldorf
https://www.ldi.nrw.de

3. Personal Data We Collect

We collect various categories of personal data depending on how you interact with EU.PE:

3.1 Account Registration and Profile Data (Business Customer Data)

When you register for an account or purchase a plan, we collect information provided by you:

  • Contact information: Name, company name, business address, and email address. We may also collect a phone number for support or verification purposes, if provided.
  • Login credentials: Username and password (passwords are stored exclusively in cryptographically hashed form and are not accessible to us).
  • Billing details: Legal company name, billing address, VAT ID (if applicable) for invoicing purposes.
  • Payment information: Payment data is collected and processed through CopeCart GmbH (Rosenstr. 2, 10178 Berlin, Germany). CopeCart acts as a reseller (Wiederverkäufer) and serves as the contractual partner for payment processing and invoicing during the order process. We do not store complete credit card numbers or bank details. We only receive payment confirmations and basic details such as payment method, transaction ID, and payment status.
  • Affiliate program data: If you join our affiliate program, we collect your affiliate account details (such as payout information, e.g., PayPal email) and track referrals generated by you. A referral is attributed via the referral code in the registration URL and, for logged-in users, server-side; no cookies are used for this. For statistical purposes, clicks on affiliate links are counted solely via a cryptographically hashed IP value (SHA-256 with a secret key) – the IP address itself is not stored and cannot be reconstructed from the hash.
  • Communications: When you contact support through our helpdesk ticket system or reach us by email, we collect your contact details and all information you provide in the inquiry.

Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) or pre-contractual measures.

Necessity of provision: Providing the contact, login, and billing data is necessary for the conclusion and performance of the usage agreement. Without this information, registration or the use of paid plans is not possible. Providing a phone number is voluntary. There is no statutory obligation to provide the data.

3.2 Service Usage and Analytics Data

Whenever our service is used -- either by you as a logged-in customer creating links, or by an end user clicking on a shortened link, scanning a QR code, or viewing a "link-in-bio" page -- we automatically collect data about this interaction. This may include personal data of the link visitor. Specifically, for each link access we collect:

  • IP address: The IP address of the device used. Raw IP addresses are automatically pseudonymized after 30 days (cryptographically hashed or truncated) and can no longer be attributed to a person thereafter.
  • Geolocation: An approximate location (country, region, city) derived from the IP address. Resolution takes place locally on our own servers using a GeoIP database held there -- the IP address is not transmitted to any external service for this purpose. We do not determine exact addresses.
  • Date and time: Timestamp of the click or visit, used for time-based analytics and to distinguish visits.
  • Device and browser information: Information from the browser's user agent string, such as browser type (e.g., Chrome), version, operating system (e.g., iOS, Windows), and device type (mobile/desktop). We also capture the browser language setting.
  • Referrer URL: If available, the URL of the page that led the user to the short link.
  • Interaction details: If a link has special settings, we log the outcome (e.g., A/B testing variants, deep linking, geo-targeting rules).

When you click on a short link, we set no cookies and no other persistent identifiers in the visitor's browser and do not create cross-device profiles of link visitors. The assignment of A/B test variants is also performed purely server-side via a cryptographically hashed value (SHA-256 with a secret key derived from the IP address and link identifier), without any data being stored in the browser.

Roles and legal bases:

(a) Processing on behalf of our business customers: Insofar as this data serves to provide the respective link creator with analytics about their links, we process it as a data processor (Art. 28 GDPR) on behalf of the business customer. The controller for this processing is the respective business customer; the legal basis follows from their privacy notice (typically Art. 6(1)(f) GDPR). For information about this processing, please contact the operator of the link you followed.

(b) Processing for our own purposes: Insofar as we use the same data for the security and stability of our systems, for the detection and prevention of abuse (e.g., malware and phishing detection, fake-click detection), and in aggregated, anonymized form to improve our service, we act as a controller. Legal basis: Art. 6(1)(f) GDPR -- our legitimate interest in a secure, abuse-free operation of the platform.

3.3 Cookies and Similar Technologies

We exclusively use technically necessary first-party cookies. No third-party cookies and no cookies for analytics, tracking, or advertising purposes are used. A cookie consent banner is therefore not required (Section 25(2)(2) TDDDG).

Specifically, we use the following cookies:

Cookie Purpose Type Duration
PHP Session ID (PHPSESSID) Maintaining your session and login status (including temporary storage of referral or coupon codes during a registration or ordering process) Technically necessary Browser session, server-side maximum 24 hours
Language selection (lang) Storing your preferred language (DE/EN) Technically necessary 1 year

Cookies are only set in the logged-in customer area or on our website -- not upon merely clicking a short link (see Section 3.2).

Legal basis: Section 25(2)(2) TDDDG -- these cookies are strictly necessary for us to provide the service you have expressly requested. Consent is not required for this purpose.

You can delete or block cookies at any time through your browser settings. Please note that disabling technically necessary cookies may limit the functionality of our service.

All cookies are first-party cookies and are set with the security attributes HttpOnly, Secure, and SameSite=Strict.

3.4 Server Logs

Our servers automatically maintain logs of incoming requests. These logs contain the data mentioned in Section 3.2 (IP address, timestamp, user agent, etc.) for each request to our system (including API calls). We use these logs for debugging, security monitoring, and maintaining service integrity. Log data is routinely deleted or anonymized after 14 days, unless required for security analysis.

Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) -- security and stability of our systems.

4. Purposes of Data Processing and Legal Bases

Purpose Role Legal Basis (GDPR)
Provision of the service (account management, link creation, redirects) Controller Art. 6(1)(b) -- performance of a contract
Analytics and reporting for business customers (link visitor data) Data processor The legal basis lies with the respective business customer as controller (see Section 3.2 (a))
Security and abuse prevention (including analysis of access data) Controller Art. 6(1)(f) -- legitimate interest
Service improvement and product development (aggregated/anonymized only) Controller Art. 6(1)(f) -- legitimate interest
Technically necessary cookies Controller Section 25(2)(2) TDDDG (no consent required)
Customer support (helpdesk/ticket system, email) Controller Art. 6(1)(b) -- performance of a contract
Transactional and system messages (registration confirmation, invoice notifications, security and service notices) Controller Art. 6(1)(b) -- performance of a contract
Newsletter and marketing communications Controller Art. 6(1)(a) -- consent (revocable at any time)
Invoicing and accounting Controller Art. 6(1)(c) -- legal obligation (HGB, AO)
Affiliate program (referral tracking, commission calculation, payout) Controller Art. 6(1)(b) -- performance of a contract
Fulfillment of legal obligations Controller Art. 6(1)(c) -- legal obligation

Where we rely on legitimate interests, we have conducted a balancing test and determined that our interests do not override the rights of the data subjects. You have the right to object to processing based on legitimate interests at any time (see Section 8).

Note on emails:

We send registered customers exclusively transactional and system messages that are necessary for the performance of the contract (e.g., registration confirmation, invoice notifications, security-relevant notices, announcements of material changes to the contract or service). We only send promotional emails and newsletters if you have expressly consented to them (opt-in). Every promotional email contains an unsubscribe option; you can withdraw your consent at any time with effect for the future.

5. Sharing of Personal Data

We handle your data with care and do not sell personal data. We only share data in the following situations:

5.1 With the Business Customer (Link Creator)

If you as an end user click on a shortened link, certain analytics information about your click becomes visible in the link creator's dashboard. This consists of aggregated statistics (e.g., "100 clicks from Berlin, Germany" or "60% mobile users"). We do not share your raw IP address, name, or email address directly with the business customer.

Note: The business customer who uses our service to collect analytics about link visitors is considered an independent Data Controller for this visitor data. We act as a Data Processor in this regard (see Section 9).

5.2 Within Our Organization

Personal data is only accessed by authorized personnel who need it to fulfill their duties. All employees and contractors are bound by confidentiality and data protection obligations.

5.3 Service Providers (Data Processors)

We use carefully selected service providers with whom we have concluded data processing agreements pursuant to Art. 28 GDPR:

Category Provider Location Purpose
Server infrastructure Serverprofis GmbH, Otto-Lilienthal-Ring 34-36, 85622 Feldkirchen Germany (EU) Server hosting (reseller hosting), provision of physical server infrastructure

All other services (email sending, helpdesk/ticket system, affiliate management, GeoIP resolution) are operated on our own infrastructure. No external service providers are used for these purposes.

5.4 Purchase and Payment Processing via CopeCart GmbH

The purchase of paid plans is carried out through our authorized reseller (Wiederverkäufer):

CopeCart GmbH, Rosenstr. 2, 10178 Berlin, Germany

CopeCart GmbH sells the Pro plan licenses in its own name, concludes a separate contract with you for this purpose, and handles invoicing and payment processing. For the data collected and processed in this context (e.g., name, billing address, payment data), CopeCart GmbH is an independent controller within the meaning of Art. 4(7) GDPR -- not our data processor. The privacy policy of CopeCart GmbH applies in this respect (available at copecart.com).

In the course of contract processing, we exchange the data required for this purpose with CopeCart GmbH: we receive order and payment confirmations from CopeCart (name, email address, plan purchased, payment method, transaction ID, payment status) in order to activate and manage your access; we do not receive or store complete credit card numbers or bank details. Legal basis for this data exchange: Art. 6(1)(b) GDPR (performance of a contract).

5.5 Legal Disclosures

We may disclose personal data to law enforcement agencies, regulatory authorities, courts, or other bodies when we are legally required to do so or when it is necessary to enforce our rights, protect our safety, or the safety of others.

Legal basis: Art. 6(1)(c) GDPR (legal obligation) or Art. 6(1)(f) GDPR (legitimate interest).

5.6 Business Transfers

If our company is involved in a merger, acquisition, or sale of assets, personal data may be transferred to the parties involved. We will inform you in advance in such a case.

We do not sell or rent your personal data to third-party marketers. Any sharing occurs only as described above.

5.7 Tax Advisory and Accounting

Insofar as necessary for the fulfillment of our tax and commercial law obligations, invoicing and accounting data (including customer data contained therein, such as name, address, and invoice amounts) may be shared with our tax advisor and, in the event of an audit, with tax authorities. Legal basis: Art. 6(1)(c) GDPR (legal obligation, Sections 147 AO, 257 HGB) and Art. 6(1)(f) GDPR (legitimate interest in proper bookkeeping).

6. International Data Transfers

We are based in Germany and store and process all data exclusively on servers in Germany. Our service provider Serverprofis GmbH, as well as CopeCart GmbH (an independent controller for purchase and payment processing, see Section 5.4), are likewise based in Germany.

We do not actively transfer personal data to third countries outside the EU or EEA. We will continue to use exclusively service providers based in the EU.

7. Data Retention and Deletion

We retain personal data only for as long as necessary for the respective purposes or as required by statutory retention obligations:

Data Category Retention Period Basis
Account data Duration of the business relationship + 3 years (statute of limitations) Art. 6(1)(b), (f) GDPR
Two-factor authentication – authenticator app secret (encrypted) Until two-factor authentication is deactivated, then deleted immediately Art. 6(1)(b) GDPR in conjunction with Art. 32 GDPR
Two-factor authentication – recovery codes (stored as hashes only) Until redeemed, reissued or deactivated Art. 6(1)(b) GDPR in conjunction with Art. 32 GDPR
Link analytics -- raw IP addresses (all plans) 30 days, then automated pseudonymization (hashing/truncation) Art. 6(1)(f) GDPR or instruction of the controller
Link analytics -- detailed data (Free plan) 30 days detailed, then aggregated/anonymized Instruction of the controller (business customer)
Link analytics -- detailed data, pseudonymized (Pro plan) As long as the account is active; deletion after account closure pursuant to the DPA Instruction of the controller (business customer)
Invoices and payment data 10 years Section 147 AO, Section 257 HGB
Support communications (tickets, emails) 3 years after completion of the matter Art. 6(1)(f) GDPR
Server logs 14 days (unless required for security analysis) Art. 6(1)(f) GDPR
Affiliate data Duration of participation in the affiliate program + 3 years Art. 6(1)(b) GDPR

After the respective retention period expires, personal data is securely deleted or irreversibly anonymized.

8. Your Rights as a Data Subject

Where the GDPR applies, you have the following rights:

Right Description Legal Basis
Access Request a copy of your stored data Art. 15 GDPR
Rectification Correction of inaccurate or incomplete data Art. 16 GDPR
Erasure Request deletion of your data ("right to be forgotten") Art. 17 GDPR
Restriction Restriction of processing under certain circumstances Art. 18 GDPR
Data portability Receive your data in a common, machine-readable format Art. 20 GDPR
Objection Object to processing based on legitimate interests Art. 21 GDPR
Withdrawal of consent Withdraw given consents at any time with effect for the future Art. 7(3) GDPR

Important: Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.

Automated decision-making: We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).

To exercise your rights, contact us at privacy@eu.pe. We will verify your identity and respond within one month (Art. 12(3) GDPR). In complex cases, this period may be extended by a further two months, of which we will inform you.

Right to lodge a complaint:

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW)
Postfach 20 04 44, 40102 Düsseldorf
https://www.ldi.nrw.de

9. Data Controller and Data Processor (Art. 28 GDPR)

For most data processing activities, we have a dual role:

  • As Data Controller: For data about our direct customers and website visitors, we determine the purposes and means of processing.
  • As Data Processor: For data that our customers collect through their use of our service (e.g., information about individuals who click on their links), we act on behalf of the customer.

The Data Processing Agreement (DPA) pursuant to Art. 28 GDPR forms part of our General Terms and Conditions and is validly agreed upon registration (Section 4.4 of the Terms). You can view the version applicable to you at any time in the customer portal, countersign it electronically, and download it as a PDF document. The DPA governs:

  • Nature, purpose, and duration of processing
  • Type of personal data and categories of data subjects
  • Our technical and organizational measures (TOMs)
  • Our obligations as a data processor
  • Regulations regarding sub-processors
  • Deletion and return of data after contract termination
Notice for business customers:

If you use EU.PE to collect analytics about your users, you are responsible as the data controller for ensuring a valid legal basis for this data collection (e.g., legitimate interest or consent) and for informing your end users accordingly in your own privacy policy. The DPA is already part of the contract upon your registration; countersigning it in the customer portal serves as your own evidence pursuant to Art. 28(9) and Art. 5(2) GDPR.

10. Security Measures

We implement appropriate technical and organizational measures (TOMs) pursuant to Art. 32 GDPR:

  • Encryption: HTTPS/TLS encryption for all data transmissions (website, API, redirects). Encryption of sensitive data at rest.
  • Access controls: Firewalls, role-based access controls -- only authorized personnel have access to systems containing personal data.
  • Password security: Cryptographic hashing of all passwords (bcrypt/Argon2).
  • Regular updates: Timely security patches and software updates.
  • Backups: Regular, encrypted data backups.
  • Monitoring: Monitoring for suspicious activities with defined incident response processes.
  • Two-factor authentication: For administrative access to our systems and optionally for all user accounts – either by email code or via an authenticator app (TOTP, RFC 6238). The app option is more privacy-friendly: the code is computed offline on your device, nothing is transmitted to us or to third parties, and no sign-in record is created at your email provider.
  • Server location Germany: All data is stored on servers in Germany.

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours (Art. 33 GDPR) and inform affected individuals without undue delay if a high risk exists (Art. 34 GDPR).

11. Children's Privacy

Our service is intended exclusively for business customers and is not designed for use by minors. We do not knowingly collect personal data from individuals under the age of 18. Should we become aware that a minor has submitted personal data to us, we will delete it without undue delay. Please contact us at privacy@eu.pe if you believe that data of a minor has been collected.

12. Changes to This Privacy Policy

We may update this privacy policy from time to time to reflect changes in our service, our data processing practices, or legal requirements.

In the event of material changes, we will:

  • Post a prominent notice on our website
  • Inform registered account holders by email
  • Update the "Last updated" date at the top of the page

Continued use of the service after the publication of changes constitutes acknowledgment of the revised policy. We recommend that you review this privacy policy regularly.

13. Contact

If you have questions, concerns, or requests regarding this privacy policy or the processing of your personal data:

Email: privacy@eu.pe
Helpdesk:

Via our ticket system on the website

Postal address:

Digital Marketing Agency ROMBEY
Attn. Data Protection
Theodor-Körner-Str. 29
41812 Erkelenz, Germany

We are happy to assist you and will handle your inquiry as promptly as possible.

Legal Notice Terms Contact

100% GDPR Compliant

All data is stored and processed exclusively on German servers.

GDPR Made in DE

Your Data is Secure

TLS encryption and ISO 27001 certified data centers.

Questions About Privacy?

Our data protection team is happy to assist you.

Contact Us
EU.PE

EU.PE is the premium URL shortener for professionals and businesses. With servers exclusively located in Germany, we guarantee the highest data protection standards and GDPR compliance.

GDPR Compliant Made in Germany

Product

Pricing Features API Documentation

Company

About Us Become an Affiliate Legal Notice Privacy Terms

Support

Help Center Contact support@eu.pe

Premium URL Shortener for Business & Enterprise

EU.PE offers professional link management with the highest security standards. As a German URL shortener with servers exclusively in Germany, we are the first choice for businesses that value data protection and GDPR compliance. Take advantage of advanced analytics, custom branding, QR code generation, and our powerful API for your marketing campaigns. Rely on lightning-fast redirects, ISO-certified data centers, and German support. Ideal for marketing teams, agencies, and enterprise customers.

© 2026 EU.PE - Premium URL Shortener. All rights reserved.