GDPR Questions + Answers

Legal basis & consent management

Do you rely on explicit opt‑in, legitimate interest, or other lawful grounds for processing EU data? How and where is consent documented and stored?

By using Linq services you consent to the collection and processing of data necessary to provide the services agreed upon. This acts as lawful grounds to fulfill contractual obligations.

 

Data processing addendum (DPA)

Do you offer a GDPR-compliant DPA? Is it up‑to‑date and signed by both parties?

We do have a publicly available DPA in place that outlines the GDPR compliance steps we follow and it is updated as needed. The DPA is agreed upon after the purchase of the product.

 

Encryption & Security

What encryption do you use in‑transit and at‑rest? What access controls, monitoring, and breach notification processes are in place?

All data in transit is encrypted using TLS 1.2 or higher, all data at rest is encrypted using aes 256 block-level storage encryption. Breaches shall be reported to customers, consumers, data subjects and regulators without undue delay and in accordance with all contractual commitments.

 

Support for Data Subject Rights

How do you handle GDPR requests such as access, portability, rectification, and erasure, including for phone numbers and message content?

GDPR requests for access, portability, erasure and rectification must be done through the customer reaching out to data-privacy@linqapp.com and the request will be responded to within 30 days.

 

Consent Tracking & Opt-out Management

How are consents captured, stored, and enforced? Is opt‑out (e.g. “STOPˮ) supported automatically, with audit trails?

Linq gives users the right to withdraw consent, if users want to restrict the processing of their personal information they can email a request to data-privacy@linqapp.com.

 

Data Retention & Deletion

What happens upon contract termination or data deletion request? Are backups, logs, and message data fully purged within a guaranteed timeframe?

Customer accounts and data shall be deleted within 60 days of contract termination through manual data deletion processes. A data deletion request will be responded to within 30 days.