Data Processing Agreement

The processor agreement (GDPR art. 28) governing how Linqr processes personal data on behalf of its customers: scope, security measures and sub-processors.

Last updated: June 25, 2026

This Data Processing Agreement ("DPA") forms an integral part of the contract between the Customer (the "Controller") and HLR, operating Linqr (the "Processor"), for the use of the Service. It governs the processing of personal data carried out by the Processor on behalf of the Customer, in accordance with article 28 of the GDPR.

1. Purpose

The DPA sets out the conditions under which the Processor processes, on behalf of and on the instructions of the Customer, the personal data necessary to provide the Service. In the event of a conflict with the contract on data protection matters, the DPA prevails.

2. Definitions

The terms "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given to them by the GDPR.

3. Roles of the parties

The Customer acts as controller (or as processor of its own customer) and determines the purposes and means of the processing. The Processor processes the data solely on behalf of the Customer. The Customer warrants that it relies on an appropriate legal basis and has met its information obligations towards the data subjects.

4. Description of the processing

The characteristics of the processing are detailed in Annex 1. They cover in particular the nature, the purposes, the duration of the processing, the categories of data subjects and the categories of data.

5. Documented instructions

The Processor processes the data only on the Customer's documented instructions, including for transfers outside the EU, unless required by a law to which it is subject. The Processor informs the Customer if, in its opinion, an instruction infringes the GDPR.

6. Confidentiality

The Processor ensures that persons authorised to process the data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality, and access the data only strictly as necessary.

7. Security of processing

The Processor implements the appropriate technical and organisational measures provided by article 32 of the GDPR to ensure a level of security appropriate to the risk. These measures are described in Annex 2.

8. Sub-processors

The Customer gives a general authorisation for the Processor to engage sub-processors to provide the Service. The categories of sub-processors are set out in Annex 3.

The Processor imposes on each sub-processor data-protection obligations equivalent to those of this DPA and remains responsible for their performance. In the event of an intended change of sub-processor, the Customer is informed and may object on legitimate grounds, in writing to dpo@linqr.ai.

9. Assistance to the Customer

Taking into account the nature of the processing, the Processor assists the Customer, by appropriate measures:

  • in responding to requests to exercise data subjects' rights;
  • in ensuring the security of the processing and the notification of personal data breaches;
  • in carrying out, where applicable, data protection impact assessments (DPIAs) and prior consultations.

10. Personal data breach

The Processor notifies the Customer of any personal data breach without undue delay after becoming aware of it, and provides the relevant information to enable the Customer to meet its notification obligations towards the supervisory authority and, where applicable, the data subjects.

11. Transfers outside the EU

Any transfer of data outside the European Union carried out by the Processor is governed by appropriate safeguards within the meaning of articles 44 et seq. of the GDPR, in particular standard contractual clauses, supplemented where necessary by additional measures.

12. Fate of the data at the end of the contract

At the end of the provision of services, the Processor, at the Customer's choice, deletes or returns the personal data and destroys existing copies, unless legally required to retain them. Deletion takes place within a reasonable period after the end of the contract.

13. Liability

The liability of each party under the DPA is assessed in accordance with article 82 of the GDPR and within the limits of liability set out in the main contract.

14. Governing law

This DPA is governed by French law and interpreted in accordance with the GDPR.

Annex 1 - Details of the processing

Nature of the processing
Collection, organisation, structuring, enrichment, consultation and hosting of data, as part of the provision of the Service.
Purposes
Identification of companies and professional contacts, preparation and personalisation of outreach messages, management of the Customer's campaigns.
Categories of data subjects
The Customer's prospects and professional contacts, the Customer's account users.
Categories of data
Professional identification and contact data (name, job title, employer, business email and phone, public professional profiles), the Customer's interaction data.
Sensitive data
No data falling under article 9 of the GDPR is required or solicited.
Duration of the processing
For the duration of the contract, then deletion or return in accordance with article 12.

Annex 2 - Security measures

  • Encryption of data in transit (TLS) and at rest;
  • Least-privilege access control and user authentication;
  • Logical isolation of data between customers (multi-tenant architecture);
  • Logging of access and sensitive operations;
  • Regular backups and restoration procedures;
  • Access-rights management and periodic access reviews;
  • Incident and data-breach management procedure.

Annex 3 - Categories of sub-processors

  • Hosting and cloud infrastructure;
  • Delivery of the website and application;
  • Payment processing and billing;
  • Transactional emails;
  • Customer support and internal tooling;

A question about this document? Write to us at dpo@linqr.ai.