Data protection and GDPR

Last updated 10.08.2026

This page describes how 0.mk handles personal data belonging to people in the European Economic Area (EEA), the United Kingdom, and Switzerland, and what rights you have over it. It is written to describe what actually happens rather than to assert a compliance status: 0.mk is a small independent service, and where our practice differs from a formal requirement of the regulation, this page says so instead of glossing over it.

1. Who is responsible for your data

0.mk has no staff. The platform is operated by automated systems on behalf of its owner, who is the data controller. The registered holder of the 0.mk domain is a matter of public record in the Macedonian .mk registry, which is the authoritative place to identify the legal entity behind the service. For anything concerning your data,contact us here; that channel reaches the operator directly.

2. Legal bases for processing

We process personal data under the following legal bases:

Processing activityLegal basis
Account creation and authenticationPerformance of contract — Art. 6(1)(b)
URL shortening and link managementPerformance of contract — Art. 6(1)(b)
Click analytics (aggregated)Legitimate interest — Art. 6(1)(f)
Abuse prevention and securityLegitimate interest — Art. 6(1)(f)
Transactional emails (magic link, invites)Performance of contract — Art. 6(1)(b)
Product and reactivation email to people who already hold an accountLegitimate interest — Art. 6(1)(f), with one-click unsubscribe in every message
Any other marketingConsent — Art. 6(1)(a)

3. Your rights under GDPR

As a data subject in the EEA/UK/Switzerland, you have the following rights:

RightDescriptionArticle
AccessRequest a copy of the personal data we hold about youArt. 15
RectificationCorrect inaccurate or incomplete personal dataArt. 16
ErasureRequest deletion of your personal data (“right to be forgotten”)Art. 17
Restrict processingRequest that we limit how we use your dataArt. 18
Data portabilityReceive your data in a structured, machine-readable formatArt. 20
ObjectObject to processing based on legitimate interestArt. 21
Withdraw consentWithdraw consent at any time where processing is based on consentArt. 7(3)
Lodge complaintFile a complaint with your local data protection authorityArt. 77

4. Sub-processors

We use the following providers to deliver the service. Each publishes a data processing addendum that applies to our use of it; we rely on those standard terms rather than on separately negotiated agreements:

Sub-processorPurposeLocation
CloudflareEdge redirects, DNS, DDoS protectionGlobal
VercelApplication hostingUnited States
DigitalOceanDatabase hostingUnited States
ResendTransactional and product email delivery, inbound repliesUnited States

5. International data transfers

As our infrastructure is primarily based in the United States, personal data from EEA/UK/Switzerland users may be transferred internationally. We safeguard these transfers through:

  • Standard Contractual Clauses (SCCs): the data processing terms published by the providers above incorporate the EU SCCs, which is the basis we rely on
  • EU-US Data Privacy Framework (DPF): several of these providers self-certify under the DPF; we depend on their certification rather than holding one ourselves
  • Data minimization: only the data needed to run the service is transferred, and visitor IP addresses are never stored at all

6. Data protection by design

We implement privacy by design and by default throughout our service:

  • IP anonymization: visitor IP addresses are never stored; country is derived at the edge and only the country code is retained
  • Aggregation: click analytics are aggregated daily, individual visitor journeys are not tracked
  • Minimal cookies: only essential and one first-party analytics cookie; no third-party cookies
  • Least privilege: workspace members only reach data inside their own workspace, limited further by their role
  • Workspace isolation: each workspace's data is logically separated at the database level

7. If there is a data breach

In the event of a personal data breach, we will:

  • Tell affected people directly and without undue delay, which is the commitment we will stand behind
  • Document what happened: the nature of the breach, the data involved, the consequences, and what was done about it
  • Cooperate with any supervisory authority that contacts us about it

Art. 33 sets a 72-hour deadline for notifying a supervisory authority, and we treat that as the target. To be straight with you: 0.mk does not maintain a standing regulatory filing process, so we would rather promise you the direct notification we can actually deliver than a formal filing deadline we might miss.

8. Reviewing new processing

Before a change ships that handles personal data in a new way, it is reviewed for what it collects, whether that is necessary, and how long it is kept. This is an internal review, not a formal Data Protection Impact Assessment under Art. 35. Nothing 0.mk currently does amounts to the kind of high-risk processing that would require a full DPIA, and if that changed, this page would change with it.

9. Exercising your rights

To exercise any of your GDPR rights:

  • Submit a request via our contact page
  • We may verify your identity before processing the request
  • We will respond within 30 days (extendable by 60 days for complex requests, with notice)
  • Requests are fulfilled free of charge unless manifestly unfounded or excessive

10. Contact

For GDPR-related inquiries or to exercise your data protection rights, reach out via our contact page.