Home / Data Processing Addendum
Data Processing Addendum
We handle personal data under GDPR (EU/UK) and CCPA/CPRA (California). See the sections below and our Cookie Policy.
This Data Processing Addendum (“DPA”) forms part of the agreement between RabbitFoot Tech (“lit.onl”, “Processor”, “we”) and the customer organization using paid features (“Customer”, “Controller”, “you”) when we process personal data on your behalf — for example document viewers, link click analytics, and related dashboard data. If you use the Service only as an individual without acting for an organization, the Privacy Policy applies instead.
Roles
For account and billing data, RabbitFoot Tech is the controller. For personal data about your recipients (people who open your links or documents), you are the controller and we act as processor, processing data only on your documented instructions through the Service configuration (gates, sharing settings, retention by plan).
Subject matter & duration
Processing lasts for the subscription term (or free use period) plus retention described in the Privacy Policy and your plan. We process data to provide URL redirects, analytics, secure document viewing, notifications you enable, and security.
Categories of data subjects & data
- Link visitors — request metadata (referrer, coarse geo from CDN headers, user agent, hashed IP/cluster fields); optional device fingerprint when you enable enriched clicks, password gates, or confirm-before-leave on a link.
- Document viewers — email when you require it; coarse browser fingerprint (user-agent snippet); country and device class; session cookie; time on each page; click coordinates aggregated for heatmap analytics; optional watermark text you configure.
- Your team — account identifiers needed to operate workspaces (covered also as controller data).
Processor obligations
- Process personal data only on your instructions via the Service, unless law requires otherwise.
- Ensure personnel with access are bound by confidentiality.
- Implement appropriate technical and organizational measures (see Privacy Policy — Security).
- Assist with data subject requests you receive, to the extent applicable to processor-held data.
- Notify you without undue delay after becoming aware of a personal data breach affecting your data.
- Delete or return personal data when you delete content, close an account, or upon expiry per plan retention, unless law requires storage.
Subprocessors
We use the subprocessors listed in our Privacy Policy (hosting, CDN, payments, email). We will inform Customers of material changes where required by law.
International transfers
Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms, as described in the Privacy Policy.
Audits
On reasonable notice, we will provide information necessary to demonstrate compliance with this DPA, subject to confidentiality and security limits. On-site audits may be agreed in writing for Enterprise customers.
How to execute or ask questions
By using Growth+ document sharing or analytics for your organization, you instruct us to process viewer/click data as configured in your account. For a signed copy or enterprise terms, contact [email protected].