Data Processing Agreement
Effective date: June 2, 2026 · Last updated: June 26, 2026
Draft, pending legal review. This document is provided for transparency and is not yet a binding agreement. Bracketed items are placeholders to be finalized with counsel. For a countersigned copy, contact legal@warplink.app.
1. Introduction
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the WarpLink Terms of Service (the "Terms") between you (the "Customer") and Stojanovski Industries Inc., a corporation organized under the laws of the Province of Ontario, Canada, operating the WarpLink service ("WarpLink"). Where this DPA and the Terms conflict on the protection of personal data, this DPA prevails.
This DPA applies where WarpLink processes personal data on the Customer's behalf and the Customer is subject to the GDPR, the UK GDPR, or comparable law and acts as a Controller. It governs only WarpLink's role as a Processor of the Customer's end-user data. WarpLink's processing of account-holder data as a Controller is governed by the Privacy Policy and not by this DPA.
2. Definitions
Capitalized terms not defined here have the meaning given in the Terms or in applicable data protection law.
- Controller / Processor / Sub-processor: as defined in the GDPR. The Customer is the Controller, WarpLink is the Processor, and any third party WarpLink engages to process personal data is a Sub-processor.
- Personal Data: information relating to an identified or identifiable natural person (a "Data Subject") processed by WarpLink on the Customer's behalf under this DPA.
- Applicable Data Protection Law: the GDPR, the UK GDPR, and, for WarpLink as a recipient, Canada's PIPEDA.
- SCCs: the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, and the "UK Addendum" is the UK International Data Transfer Addendum issued by the UK Information Commissioner.
3. Roles of the Parties
For personal data processed under this DPA, the Customer is the Controller, WarpLink is the Processor, and WarpLink engages Sub-processors as permitted in Section 6. Where the Customer is itself a processor for a third-party controller, the Customer warrants it is authorized to instruct WarpLink and enter into this DPA on that controller's behalf, and WarpLink acts as a sub-processor.
4. Scope and Details of Processing
WarpLink processes personal data only to provide the service: link infrastructure for mobile applications, namely deep linking, install attribution, and click analytics. The subject matter, duration, nature, purpose, types of personal data, and categories of Data Subjects are set out in Annex I.
5. Processor Obligations
As Processor, WarpLink undertakes the obligations in Article 28(3) of the GDPR and the equivalent provisions of the UK GDPR. WarpLink shall:
- process personal data only on the Customer's documented instructions, including for transfers, unless required by law (in which case WarpLink informs the Customer first, where permitted), and inform the Customer if an instruction appears to infringe the law;
- ensure personnel authorized to process the data are bound by confidentiality;
- implement the technical and organizational security measures in Annex II (Article 32);
- engage Sub-processors only under Section 6, with flow-down of equivalent obligations;
- assist the Customer, by appropriate measures and insofar as possible, to respond to Data Subject requests under Articles 12 to 23;
- assist the Customer with its obligations under Articles 32 to 36 (security, breach notification, data protection impact assessments);
- at the Customer's choice, delete or return the personal data at the end of the services, per Section 10; and
- make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, per Section 11.
6. Sub-processing
The Customer provides a general written authorization for WarpLink to engage Sub-processors, subject to this Section. The current list is the WarpLink Sub-processor List. WarpLink gives at least 30 days' advance notice before adding or replacing a Sub-processor that processes the Customer's end-user personal data, and the Customer may object on reasonable data-protection grounds. WarpLink imposes data-protection obligations equivalent to those in this DPA on each Sub-processor by written contract and remains liable for its Sub-processors' performance.
7. International Data Transfers
WarpLink and its Sub-processors are located in Canada and the United States, outside the EEA and the United Kingdom. Where processing involves a transfer from the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, the parties incorporate by reference the SCCs and, for UK transfers, the UK Addendum:
- Module Two (Controller to Processor) applies where the Customer is a Controller and WarpLink its Processor;
- Module Three (Processor to Sub-processor) applies where the Customer is a processor, and to onward transfers to WarpLink's Sub-processors;
- where the SCCs require an EU Member State's law, the governing law and forum are those of the Republic of Ireland, and Annex I and Annex II populate the corresponding SCC annexes.
For the leg where WarpLink (Ontario, Canada) is the recipient, the parties note Canada's partial adequacy decision for commercial organizations subject to PIPEDA. WarpLink applies supplementary measures including pseudonymization of IP addresses and encryption of personal data in transit. WarpLink will designate an EU and a UK representative under Article 27 GDPR and UK GDPR where and when required, and identify them here.
8. Data Subject Rights
Taking into account the nature of processing, WarpLink assists the Customer by appropriate measures, insofar as possible, in responding to Data Subject requests. If WarpLink receives a request directly from a Data Subject relating to data processed on the Customer's behalf, it will not respond itself (except to confirm the request was forwarded) and will forward the request to the Customer without undue delay, unless otherwise required by law.
9. Personal Data Breach
WarpLink notifies the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA, describing, as information becomes available, the nature of the breach, the categories and approximate numbers affected, the likely consequences, and the measures taken. WarpLink provides reasonable assistance with the Customer's obligations under Articles 33 and 34. Notification is not an acknowledgment of fault.
10. Deletion and Return
On termination or expiry of the subscription, and at the Customer's choice, WarpLink deletes or returns the personal data processed on the Customer's behalf and deletes existing copies, unless retention is required by law. During the term, click-level personal data is retained only for the plan's retention window (Free 90 days, Starter 180 days, Growth 365 days, Scale and Unlimited up to 1,095 days), then deleted by an automated process. Personal data in routine backups is overwritten on the normal backup rotation cycle.
11. Audit Rights
WarpLink makes available information reasonably necessary to demonstrate compliance with this DPA and Article 28. On reasonable written request, and no more than once in any twelve-month period (except where required by a supervisory authority or following a breach), WarpLink provides responses to a reasonable security questionnaire and any available third-party reports. Where that is insufficient, the Customer may mandate an audit on at least 30 days' notice, during business hours, without unreasonably disrupting WarpLink's operations or compromising other customers' data, subject to confidentiality.
12. Liability and Relationship to the Terms
This DPA is part of and subject to the Terms. In the event of a conflict on the processing of personal data, this DPA prevails over the Terms, and the SCCs prevail over this DPA for the transfers they govern. Each party's aggregate liability under this DPA is subject to the limitations and exclusions of liability in the Terms.
13. Governing Law
This DPA is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, and the parties submit to the courts of the Province of Ontario, except that, where the SCCs apply and require the law of an EU Member State, that law governs the SCCs for the relevant transfer. Questions about this DPA may be directed to legal@warplink.app.
Annex I. Details of Processing
A. Parties. Data exporter: the Customer, as identified in its WarpLink account, acting as Controller (or as a processor for a third-party controller). Data importer: WarpLink, operated by Stojanovski Industries Inc., Suite 603, 130 Spadina Avenue, Toronto, Ontario M5V 2L4, Canada, acting as Processor. Contact: privacy@warplink.app.
B. Description of processing. Categories of Data Subjects: the Customer's end users who click WarpLink-powered links and/or install the Customer's mobile apps. Categories of personal data:
- hashed IP address, for click deduplication and analytics;
- coarse user-agent-derived fields (device type, operating system, major.minor OS version, browser);
- approximate geolocation (country, region, city);
- referrer, click timestamps, and event metadata;
- a device fingerprint (a hash of device signals), for deferred deep linking and install attribution; and
- on iOS, the Identifier for Vendor (IDFV). WarpLink does not process the advertising identifier (IDFA).
No special-category data and no data knowingly relating to children is processed. Frequency: continuous, for the term of the subscription. Nature and purpose: operation of the redirect and click pipeline, deduplication and aggregation, install attribution and deferred deep linking, and the related dashboard and reporting. Duration and retention are as set out in Section 10.
C. Competent supervisory authority. Determined in accordance with the SCCs, generally the authority of the EEA Member State in which the Customer is established, or the UK Information Commissioner's Office for UK transfers. [Confirm based on Customer establishment.]
Annex II. Technical and Organizational Security Measures
WarpLink maintains the following measures, which it may update provided the overall level of security is not materially reduced:
- encryption of personal data in transit using TLS;
- pseudonymization of IP addresses by hashing before storage, so stored analytics do not retain raw IP addresses;
- data minimization: only coarse, derived signals are collected, and the advertising identifier and special-category data are not processed;
- access controls restricting systems and personal data to authorized personnel on a need-to-know basis;
- plan-tiered retention with automated deletion of click-level data;
- error monitoring configured to minimize personal data; and
- written sub-processor contracts with equivalent data-protection obligations, and personnel bound by confidentiality.
These measures are described at a level appropriate for a public register and are not intended to overstate WarpLink's security posture. Additional detail is available to Customers on request under Section 11.