Security & Compliance

Your data never leaves
Europe

All your data is stored exclusively on EU-based infrastructure. No exceptions. No fine print.

SOC 2 Type II
GDPR Compliant
EU Data Residency

EU-only infrastructure

Klinky runs entirely on European infrastructure. Your link data, click analytics, and account information never leave the EU. We don't use US-based servers, don't replicate data to other regions, and don't transfer your information across borders.

This isn't a feature you pay extra for. It's how Klinky works.

Database: Frankfurt, Germany

All persistent data stored in Supabase's EU region with AES-256 encryption at rest.

Compute: Amsterdam, Netherlands

Application servers run on Fly.io's European infrastructure.

Backups: EU Jurisdiction

All backups stored within the European Union.

We only store what we need

No tracking. No profiling. No data selling.

What we store

  • Your email address

    For account access and billing notifications

  • Billing information

    Handled securely by Stripe. We don't store card details.

  • Link data

    Your short links, destination URLs, and click counts

  • Click analytics

    Timestamp, referrer, and country (anonymized IP addresses)

What we don't store

  • Personal identifiable information

    We don't collect names, addresses, or phone numbers

  • Visitor tracking data

    No cookies for tracking individual users across sites

  • Marketing data

    No behavior profiling or advertising identifiers

  • Third-party sharing

    Your data never leaves our EU infrastructure stack

We store the minimum needed to run the service and charge you fairly. Nothing more.

Built on certified EU infrastructure

Your data is protected by enterprise-grade security and compliance standards.

Supabase

Database & Authentication

  • SOC 2 Type II certified
  • GDPR compliant with DPA
  • EU-based (Frankfurt)
  • AES-256 encryption at rest
  • TLS 1.2+ in transit

Fly.io

Application Hosting

  • SOC 2 Type II certified
  • GDPR compliant with DPAs
  • EU-based (Amsterdam)
  • Automatic security patches
  • HIPAA support available

Cloudflare

Edge Network & Security

  • DDoS protection and WAF
  • 275+ global edge locations
  • TLS encryption for all traffic
  • No persistent data at edge
  • ISO 27001 certified

Note on edge processing: While link redirects process at Cloudflare's global edge for speed, no persistent data is stored outside the EU. Edge processing is transient— your data stays in Europe.

Security by default

256-bit SSL/TLS

All traffic encrypted in transit

AES-256 Encryption

Data encrypted at rest

DDoS Protection

Cloudflare shields against attacks

Automatic Updates

Security patches applied automatically

Questions about security?

We're happy to provide additional information or discuss your specific compliance requirements.