Skip to content

Legal

Privacy Policy

Effective date

Introduction

This policy explains how Optolink handles personal data when people visit the Optolink website, administer a customer account, click an Optolink link, or use a customer app that includes the Optolink SDK. The data and legal relationship differ in each context, so they are described separately.

Optolink is operated by Optomatica. Optolink personal-data processing and storage take place in the European Union.

Who decides how data is used

Optomatica acts as controller for personal data used to operate the Optolink website, administer customer relationships, protect the service, prevent abuse, and meet legal obligations.

When a customer configures Optolink to route, resolve, and report interactions involving that customer's link clickers or app users, the customer is the controller and Optomatica acts as processor under the customer's documented instructions.

Customers are responsible for their privacy notices, lawful bases, consent choices, link destinations, event design, and responses to their users. Optomatica remains controller for the limited business-administration, security, abuse-prevention, and legal-compliance records it determines are necessary for its own purposes.

Who this policy covers

Website visitors
People who browse the Optolink website.
Customer administrators
People who configure an organisation, apps, domains, API keys, links, and related settings for a customer.
Link clickers
People who open a short link, branded link, Universal Link, App Link, or QR-code destination handled by Optolink.
Customer app end users
People who open or install an app in which a customer has integrated the Optolink SDK.

Data we handle

The relevant categories depend on how a person interacts with Optolink.

Customer accounts and customer content

Customer administration data may include business contact details, organisation identifiers, roles and access records, and account communications.

Customer content and configuration can include organisation keys, link short codes, paths, parameters, fallback destinations, deferred-link settings, match windows, tags, expiry settings, Open Graph metadata, app identifiers and store destinations, custom-domain settings, and API-key metadata.

When a link is opened, Optolink handles the link and organisation identifiers, requested destination, request time and outcome, and the device or network signals available for routing and deferred matching.

A direct link can open an installed app. For a deferred link, Optolink attempts to connect the earlier click with a later first app open. Each deferred match attempt records the method used and a confidence level of exact, high, medium, or low, including attempts that do not produce a match.

Deferred-match signals and methods

Optolink uses a priority chain and stops when a method produces an answer. The result states the match method and confidence. Some methods are deterministic and others are probabilistic; a probabilistic result indicates similarity between signals, not certainty about a person's identity.

  1. Clipboard token when enabled

    Method type
    Deterministic
    Confidence
    exact

    On a genuine user gesture, the redirect flow may place an Optolink token on the clipboard. After installation, the SDK can read that token to recover the intended link. Customers can disable clipboard matching; platform paste notices or permissions may apply.

  2. Android Play Install Referrer

    Method type
    Platform-provided referral signal
    Confidence
    high

    On supported Android installations, the SDK can use the Google Play Install Referrer to associate the installation with the earlier referral.

  3. Exact device fingerprinting

    Method type
    Probabilistic device-signal comparison
    Confidence
    high

    Optolink can compare device and request characteristics available at click and app open and treat an exact signal-set match as high confidence.

  4. Weighted device fingerprinting

    Method type
    Probabilistic device-signal comparison
    Confidence
    medium

    When the available characteristics do not match exactly, Optolink can score their similarity and accept a weighted match at medium confidence.

  5. IP-fuzzy matching

    Method type
    Probabilistic network-level comparison
    Confidence
    low

    As a lower-priority fallback, Optolink can compare IP or network proximity between the click and app open. Shared networks, carrier routing, VPNs, and changing addresses can reduce accuracy.

Operational records

Optolink handles operational records needed to authenticate requests, diagnose errors, enforce limits, secure customer organisations, and investigate misuse.

These records may include timestamps, request or actor identifiers, IP or network information, user-agent or device information, actions taken, response outcomes, and error details.

Purposes and lawful bases

For customer-directed processing, the customer determines the lawful basis and Optomatica processes the data on the customer's documented instructions.

  1. Provide and administer the service

    Create and administer customer access, store customer configuration, resolve links, route users, generate requested link outputs, and provide service records.

    Lawful basis
    Performance of a contract or steps requested before entering one; for customer-directed service data, processing on the customer's documented instructions.
  2. Resolve direct and deferred links

    Use link, device, clipboard, install-referrer, network, and match data to connect a click to the intended app destination and describe match confidence.

    Lawful basis
    The customer determines the lawful basis. Consent or another permission may be required for clipboard, device-storage, SDK, or similar technologies.
  3. Protect and operate Optolink

    Authenticate requests, apply limits, detect misuse, troubleshoot failures, maintain auditability, and protect customers, users, and the service.

    Lawful basis
    Legitimate interests in service security and reliability, performance of a contract, and legal obligations where applicable.
  4. Meet legal obligations and establish legal claims

    Respond to valid legal process, keep records required by law, and exercise or defend legal rights.

    Lawful basis
    Compliance with legal obligations and legitimate interests in establishing, exercising, or defending legal claims.

Cookies, storage, clipboard access, and SDKs

The Optolink website may use cookies or browser storage to provide requested website functions and remember browser choices.

A customer app can include the Optolink Flutter SDK. The SDK handles direct and deferred links and may use device-side storage as part of that flow. When a customer enables clipboard matching, the redirect and SDK can use the clipboard token described above. On Android, the SDK can use the Play Install Referrer.

Customers choose how they configure the SDK and are responsible for disclosing that configuration and obtaining consent where required.

Who may receive data

Customer-authorised administrators may receive link, routing, match, and service records for their organisation. Customer apps and destinations receive the resolved path, parameters, match method, confidence, deferred status, and link identifier needed to handle the journey.

Service providers may process personal data where needed to support Optolink infrastructure, communications, support, or service operations.

Personal data may also be disclosed when required by valid law or legal process or when necessary to protect rights, users, customers, or the service.

Where data is processed

Optolink processes and stores personal data in the European Union.

How long data is kept

Optolink keeps personal data only for as long as needed to provide and protect the service, follow the customer's instructions, meet legal obligations, or establish, exercise, or defend legal claims.

The relevant period depends on the type of data and context. Customer content, link interactions, device and network signals, match attempts, account records, and operational records may follow different retention periods. Configured link match windows also limit how long deferred-match data remains relevant.

Privacy rights and choices

Depending on applicable law, a person may have rights to request access, correction, deletion, restriction, or portability; object to certain processing; withdraw consent without affecting earlier processing; and complain to a privacy regulator. Legal exceptions may apply.

For data Optolink handles on a customer's instructions, link clickers and customer app end users should contact that customer first. Optomatica supports the customer in responding as required by applicable law. For data Optomatica controls directly, requests can be made through the contact channel provided with the relevant Optolink service or customer relationship.