battiiinnovate

Privacy policy

Last updated 2 September 2026 · UK GDPR & Data Protection Act 2018

The controller is Battiinnovate, 27 Old Gloucester Street, London WC1N 3AX, ICO registration ZB612744. Data protection contact: dpo@btti.uk. We do not sell personal data and we do not track visitors across other websites.

1. What we collect

Data
Why
Kept
Account email, name, password hash
To run your account (contract)
Account life + 30 days
Destination URLs and slugs
To provide redirects (contract)
Account life + 90 days
Click country, referrer, device class, timestamp
Analytics for the link owner (contract)
24 months
Truncated IP (last octet removed) + salted hash
Fraud and bot filtering (legitimate interests)
30 days
Billing name, address, card token
Payment and VAT records (contract, legal obligation)
7 years
Support messages
To answer you (contract, legitimate interests)
24 months

We never store a full visitor IP address for analytics, and we do not build visitor profiles.

2. Cookies

The shortener sets one strictly necessary session cookie when you sign in, and one 24-hour cookie used to cap how often a free-plan interstitial is shown to the same browser. Neither is used for advertising profiles or shared with third parties, so no consent banner is required. We use no analytics cookies of our own.

3. Advertising on free-plan links

Advertising on free links is sold directly and served from our own infrastructure. Creatives are static files; third-party scripts and tracking pixels are not permitted. Advertisers receive aggregate delivery counts only, never personal data about a visitor.

4. Processors we use

  • Hosting and CDN in UK and Republic of Ireland regions
  • Payments through Stripe Payments UK Ltd (we never see full card numbers)
  • Transactional email from an EU-hosted provider under standard contractual clauses
  • Error monitoring, self-hosted with no third-party access

A current list with locations and safeguards is available from dpo@btti.uk. Where data leaves the UK we rely on the UK International Data Transfer Addendum.

5. When we disclose data

To processors above; to law enforcement or a regulator where we are legally required or where content breaches our terms; to a buyer if the business is sold, under equivalent protection; and to you.

6. Your rights

Under UK GDPR you may request access, correction, erasure, restriction, portability, and object to processing based on legitimate interests. Email dpo@btti.uk; we respond within one month and never charge for a first request.

If you are unhappy with our response you may complain to the Information Commissioner’s Office (ico.org.uk, 0303 123 1113).

7. Security

TLS 1.3 in transit and AES-256 at rest; passwords hashed with Argon2id; least-privilege access with mandatory two-factor authentication for staff; encrypted backups retained 35 days. Reportable breaches are notified to the ICO within 72 hours and to affected users without undue delay.

8. Children

The service is not intended for anyone under 16. If we learn that an account belongs to a child under 16 we delete it and its data.

9. Changes

Material changes are announced by email and in the dashboard at least 14 days before they take effect. The date at the top of this page always reflects the current version.