Privacy policy
Last updated 2 September 2026 · UK GDPR & Data Protection Act 2018
The controller is Battiinnovate, 27 Old Gloucester Street, London WC1N 3AX, ICO registration ZB612744. Data protection contact: dpo@btti.uk. We do not sell personal data and we do not track visitors across other websites.
1. What we collect
We never store a full visitor IP address for analytics, and we do not build visitor profiles.
2. Cookies
The shortener sets one strictly necessary session cookie when you sign in, and one 24-hour cookie used to cap how often a free-plan interstitial is shown to the same browser. Neither is used for advertising profiles or shared with third parties, so no consent banner is required. We use no analytics cookies of our own.
3. Advertising on free-plan links
Advertising on free links is sold directly and served from our own infrastructure. Creatives are static files; third-party scripts and tracking pixels are not permitted. Advertisers receive aggregate delivery counts only, never personal data about a visitor.
4. Processors we use
- Hosting and CDN in UK and Republic of Ireland regions
- Payments through Stripe Payments UK Ltd (we never see full card numbers)
- Transactional email from an EU-hosted provider under standard contractual clauses
- Error monitoring, self-hosted with no third-party access
A current list with locations and safeguards is available from dpo@btti.uk. Where data leaves the UK we rely on the UK International Data Transfer Addendum.
5. When we disclose data
To processors above; to law enforcement or a regulator where we are legally required or where content breaches our terms; to a buyer if the business is sold, under equivalent protection; and to you.
6. Your rights
Under UK GDPR you may request access, correction, erasure, restriction, portability, and object to processing based on legitimate interests. Email dpo@btti.uk; we respond within one month and never charge for a first request.
If you are unhappy with our response you may complain to the Information Commissioner’s Office (ico.org.uk, 0303 123 1113).
7. Security
TLS 1.3 in transit and AES-256 at rest; passwords hashed with Argon2id; least-privilege access with mandatory two-factor authentication for staff; encrypted backups retained 35 days. Reportable breaches are notified to the ICO within 72 hours and to affected users without undue delay.
8. Children
The service is not intended for anyone under 16. If we learn that an account belongs to a child under 16 we delete it and its data.
9. Changes
Material changes are announced by email and in the dashboard at least 14 days before they take effect. The date at the top of this page always reflects the current version.