Data processing terms
The processor terms, for customers who need them on file.
Last updated 24 September 2026. Brevily is operated by Psionic Ventures LLP ("we", "us"). Read this page with our Terms of service, Privacy notice and Acceptable use policy.
These terms apply where we process personal data on your behalf — principally the click data belonging to your links. For that data you are the controller (or data fiduciary) and we are the processor (or data processor). Where we process data about you as our customer, we are the controller and the Privacy notice governs.
These terms form part of the Terms of service. If you need them as a signed document on your own paper, write to help@brevily.com.
1. Subject matter and duration
We process personal data for as long as your account is open, and for the retention windows set out in the Privacy notice, in order to provide Brevily.
2. Nature and purpose
Resolving short links, counting and reporting clicks, checking destinations for malware and phishing, and providing support.
3. Types of personal data
Truncated and hashed visitor identifiers, country, device type, browser family, referring site, and encrypted IP addresses. Plus the account data of the users you invite.
4. Categories of data subject
The people who click your links, and the members of your team you invite.
5. Our obligations
We will:
- process personal data only on your documented instructions, which these terms and your use of the product constitute, unless the law requires otherwise, in which case we will tell you unless prohibited;
- ensure the people who handle it are bound by confidentiality;
- apply appropriate technical and organisational security measures, including encryption at rest for identifiers, hashed passwords, access control and logging;
- help you respond to data subject requests, and to your obligations on security, breach notification and impact assessments, taking into account what we know;
- tell you without undue delay, and in any event within 48 hours, if we become aware of a personal data breach affecting your data;
- delete or return the personal data at the end of the agreement, as described in the Privacy notice, except where the law requires us to keep it.
6. Sub-processors
You give us general authorisation to appoint sub-processors. The current list is in section 6 of the Privacy notice. We will give you at least 30 days' notice before adding or replacing one, and you may object on reasonable data-protection grounds; if we cannot resolve the objection you may cancel without penalty for the remainder of the term.
Every sub-processor is bound by terms no less protective than these, and we remain liable to you for their performance.
7. Audits
We will give you the information reasonably needed to demonstrate compliance with these terms. Where you need more, you may audit us once in any twelve months, on 30 days' written notice, during business hours, at your cost, and subject to confidentiality — or we may satisfy the request with an independent report where we have one.
8. International transfers
Redirects are served from edge locations worldwide, so a click may be processed in the region it originated before the record reaches our primary database. Where we transfer personal data out of India or the European Economic Area we rely on the transfer mechanisms our providers offer, including standard contractual clauses.
9. Liability
Our liability under these terms is subject to the limitation of liability in the Terms of service.