Data protection and GDPR
Last updated 10.08.2026
This page describes how 0.mk handles personal data belonging to people in the European Economic Area (EEA), the United Kingdom, and Switzerland, and what rights you have over it. It is written to describe what actually happens rather than to assert a compliance status: 0.mk is a small independent service, and where our practice differs from a formal requirement of the regulation, this page says so instead of glossing over it.
1. Who is responsible for your data
0.mk has no staff. The platform is operated by automated systems on behalf of its owner, who is the data controller. The registered holder of the 0.mk domain is a matter of public record in the Macedonian .mk registry, which is the authoritative place to identify the legal entity behind the service. For anything concerning your data,contact us here; that channel reaches the operator directly.
2. Legal bases for processing
We process personal data under the following legal bases:
| Processing activity | Legal basis |
|---|---|
| Account creation and authentication | Performance of contract — Art. 6(1)(b) |
| URL shortening and link management | Performance of contract — Art. 6(1)(b) |
| Click analytics (aggregated) | Legitimate interest — Art. 6(1)(f) |
| Abuse prevention and security | Legitimate interest — Art. 6(1)(f) |
| Transactional emails (magic link, invites) | Performance of contract — Art. 6(1)(b) |
| Product and reactivation email to people who already hold an account | Legitimate interest — Art. 6(1)(f), with one-click unsubscribe in every message |
| Any other marketing | Consent — Art. 6(1)(a) |
3. Your rights under GDPR
As a data subject in the EEA/UK/Switzerland, you have the following rights:
| Right | Description | Article |
|---|---|---|
| Access | Request a copy of the personal data we hold about you | Art. 15 |
| Rectification | Correct inaccurate or incomplete personal data | Art. 16 |
| Erasure | Request deletion of your personal data (“right to be forgotten”) | Art. 17 |
| Restrict processing | Request that we limit how we use your data | Art. 18 |
| Data portability | Receive your data in a structured, machine-readable format | Art. 20 |
| Object | Object to processing based on legitimate interest | Art. 21 |
| Withdraw consent | Withdraw consent at any time where processing is based on consent | Art. 7(3) |
| Lodge complaint | File a complaint with your local data protection authority | Art. 77 |
4. Sub-processors
We use the following providers to deliver the service. Each publishes a data processing addendum that applies to our use of it; we rely on those standard terms rather than on separately negotiated agreements:
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare | Edge redirects, DNS, DDoS protection | Global |
| Vercel | Application hosting | United States |
| DigitalOcean | Database hosting | United States |
| Resend | Transactional and product email delivery, inbound replies | United States |
5. International data transfers
As our infrastructure is primarily based in the United States, personal data from EEA/UK/Switzerland users may be transferred internationally. We safeguard these transfers through:
- Standard Contractual Clauses (SCCs): the data processing terms published by the providers above incorporate the EU SCCs, which is the basis we rely on
- EU-US Data Privacy Framework (DPF): several of these providers self-certify under the DPF; we depend on their certification rather than holding one ourselves
- Data minimization: only the data needed to run the service is transferred, and visitor IP addresses are never stored at all
6. Data protection by design
We implement privacy by design and by default throughout our service:
- IP anonymization: visitor IP addresses are never stored; country is derived at the edge and only the country code is retained
- Aggregation: click analytics are aggregated daily, individual visitor journeys are not tracked
- Minimal cookies: only essential and one first-party analytics cookie; no third-party cookies
- Least privilege: workspace members only reach data inside their own workspace, limited further by their role
- Workspace isolation: each workspace's data is logically separated at the database level
7. If there is a data breach
In the event of a personal data breach, we will:
- Tell affected people directly and without undue delay, which is the commitment we will stand behind
- Document what happened: the nature of the breach, the data involved, the consequences, and what was done about it
- Cooperate with any supervisory authority that contacts us about it
Art. 33 sets a 72-hour deadline for notifying a supervisory authority, and we treat that as the target. To be straight with you: 0.mk does not maintain a standing regulatory filing process, so we would rather promise you the direct notification we can actually deliver than a formal filing deadline we might miss.
8. Reviewing new processing
Before a change ships that handles personal data in a new way, it is reviewed for what it collects, whether that is necessary, and how long it is kept. This is an internal review, not a formal Data Protection Impact Assessment under Art. 35. Nothing 0.mk currently does amounts to the kind of high-risk processing that would require a full DPIA, and if that changed, this page would change with it.
9. Exercising your rights
To exercise any of your GDPR rights:
- Submit a request via our contact page
- We may verify your identity before processing the request
- We will respond within 30 days (extendable by 60 days for complex requests, with notice)
- Requests are fulfilled free of charge unless manifestly unfounded or excessive
10. Contact
For GDPR-related inquiries or to exercise your data protection rights, reach out via our contact page.