Privacy Notice
Last updated 17 August 2026
Effective date: 17 August 2026. This notice explains how DOLIX SOFTWARE UTILITIES PVT LTD ("Dolix", "the Company", "we", "us") handles personal data in connection with the Dolix link shortening service at dolix.co.
1. Who we are and our role
DOLIX SOFTWARE UTILITIES PVT LTD is the data controller for personal data processed through the service. We decide why and how that data is processed. We are a private limited company registered in the Republic of Maldives under company number C32862026. You can reach our global operations hub at ops@dolix.co.
2. Data we collect and why
- Account data (email address, password hash, display name, workspace name) — to create and secure your account and provide the service. Legal basis: performance of a contract.
- Link data (short-link destination URLs, short codes, creation timestamps) — to operate the shortening and redirect engine. Legal basis: performance of a contract.
- Click and usage telemetry (click timestamps, referring hosts, browser User Agents, IP address and approximate geolocation metadata) — to produce real-time analytics reporting for link owners, prevent abuse, and improve the product. Legal basis: performance of a contract and our legitimate interests in security and product improvement.
- API credentials (hashed API keys, truncated key prefixes) — to authenticate programmatic requests. Legal basis: performance of a contract.
- Support messages — to answer your enquiries. Legal basis: legitimate interests.
- Marketing emails, where you have opted in — legal basis: consent, which you may withdraw at any time.
3. How we protect and process data
Dolix processes analytics telemetry — including link click counts, timestamp logs, anonymized browser User Agents, and referring hosts — strictly through encrypted, globally distributed edge server infrastructure. This architecture is designed to guarantee maximum loading performance, system speed, and resilience while maintaining strict access controls and encryption in transit and at rest.
We apply appropriate technical and organisational measures, including encryption in transit, hashed credentials, row-level database access controls, and least-privilege access for administrators. No system can be guaranteed perfectly secure.
4. Who we share data with
- Service providers / subprocessors — hosting, database, email delivery, and error monitoring providers acting on our instructions.
- Paddle.com Market Ltd, our authorised global Merchant of Record, for the sale of subscriptions, subscription management, payments, tax compliance, and invoicing. Paddle handles payment data under its own privacy notice.
- Professional advisers — legal and accounting advisers where necessary.
- Authorities — where we are required to disclose data by law or to protect our legal rights.
We never sell, distribute, or expose personal user identifiers or customer campaign data to third-party advertising networks or ad brokers. All enterprise credential storage runs securely through encrypted database layers.
5. International transfers
Our providers may process data outside your country, including outside the UK and EEA. Where that happens, we rely on appropriate safeguards such as UK/EU Standard Contractual Clauses or an adequacy decision.
6. Retention
Account, link, and analytics data are kept for as long as your account is active. After account closure we delete or anonymise personal data within 90 days, except where we must retain records longer to meet legal, tax, or accounting obligations. Revoked API keys are retained only as hashes for audit purposes.
7. Your rights
Subject to applicable law, you may request access to your data, correction, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time. Email ops@dolix.co and we will respond within one month. If you are in the UK or EEA you also have the right to complain to your local supervisory authority.
8. Cookies
We use strictly necessary cookies and local storage to keep you signed in, remember your recent links, and secure the service. These are required for the site to function. Our payment provider may set cookies during checkout. You can clear or block cookies in your browser, but parts of the service may then stop working. We do not use advertising cookies.
9. Changes and contact
We may update this notice; the date above shows the latest revision. Questions? Email ops@dolix.co. See also our Terms & Conditions and Refund Policy.