A GDPR-compliant URL shortener, hosted in the EU
94.si is a URL shortener and QR code generator run by CNJ d.o.o. in Ljubljana, Slovenia, since 2016. Your data and your visitors' data stay in the European Union and are processed under the GDPR, and every destination is checked with Google Web Risk before a link is saved. The app is available in English and Slovenian.
Privacy by default
- No cookies on clicks. Opening a short link or scanning a QR code sets no cookies, and visitors are not recognised across different links. The public website uses no cookies either; the app uses only the session and form-protection cookies it needs.
- Aggregated statistics only. Link owners see clicks by day, country, device, operating system and referrer, never the IP address of an individual visitor.
- Short IP retention. The full IP address of a click is kept for at most 30 days, then deleted or truncated so it no longer identifies anyone.
- Data processing agreement. When an organisation uses 94.si for its links, it is the controller of the click data and CNJ d.o.o. is its processor. We sign a DPA under Article 28 GDPR on request.
- Your rights. Delete links and QR codes yourself at any time. Request a machine-readable export or account closure at info@94.si; we reply within one month.
Advertising pixels are the one exception to the cookie rule: if a Business Pro customer enables a Meta, Google Ads or LinkedIn pixel on a link with their own domain, the pixel may set cookies, and the customer has to inform visitors.
Servers and processors in the EU
| Purpose | Processor | Location |
|---|---|---|
| Hosting and storage | Hetzner Online GmbH | EU data centres |
| Sign-in codes and notifications | Amazon Web Services EMEA SARL (Amazon SES) | Luxembourg |
| Payments | Stripe Payments Europe, Ltd. | Ireland |
| Website font | Google Fonts, Google Ireland Limited | Ireland |
| Destination safety checks | Google Web Risk | receives the destination URL only |
We do not sell data or pass it to third parties for their own purposes. Website statistics run on a self-hosted Plausible Analytics instance, without cookies or cross-site tracking.
Every destination checked with Google Web Risk
Scammers like short links because they hide where a link goes. 94.si checks every new destination, and every change to an existing one, against Google Web Risk, the business service built on the same lists as Google Safe Browsing. A destination listed for malware, phishing or unwanted software cannot be saved, and the form says so while you type. Only the destination URL is sent to Google, nothing about you or your visitors.
Direct links to Windows programs, installers, scripts and disk images (.exe, .msi, .bat, .ps1, .vbs, .iso and similar) are refused too; link to the page that offers the download instead.
Domains that filters trust
Every day we check that the 94.si domains are on no block list: Google Web Risk and the security DNS filters used by companies, carriers and home networks, including Cloudflare, Quad9, DNS4EU, AdGuard, OpenDNS, CleanBrowsing, Control D and Mullvad. That keeps short links opening in browsers, mail clients and corporate networks.
Passwordless sign-in and encryption
Accounts have no password to steal: each sign-in uses a one-time link or code sent by email. All traffic, including redirects on short links and custom domains, runs over HTTPS with TLS. Business plans add per-project access, user roles, an audit trail of changes and single sign-on (SSO) on request.
Frequently asked questions
Is 94.si GDPR compliant?
Yes. 94.si is run by CNJ d.o.o. in Ljubljana, Slovenia, under Slovenian law and the GDPR. Data is stored in the EU, no cookies are set when someone clicks a short link, link owners see only aggregated statistics, and organisations can sign a data processing agreement under Article 28 GDPR.
Where is the data stored?
On servers of Hetzner Online GmbH in data centres in the European Union. Email delivery (Amazon SES, Luxembourg) and payments (Stripe, Ireland) are also handled by EU entities.
Does 94.si set cookies when a short link is clicked?
No. No cookies are set on a click and visitors are not recognised across links. The exception is a link on which a Business Pro customer enables an advertising pixel on their own domain; the customer then has to inform visitors about cookies.
Try 94.si for free
Up to 20 links, QR codes and click statistics on the free plan. No password, no credit card. Questions about a DPA or a team plan: info@94.si.
Create a free accountPrivacy policy (Slovenian)In Slovenian: Varnost in zasebnost pri 94.si.