Data Processing Agreement
The processor agreement (GDPR art. 28) governing how Linqr processes personal data on behalf of its customers: scope, security measures and sub-processors.
Last updated: June 25, 2026
This Data Processing Agreement ("DPA") forms an integral part of the contract between the Customer (the "Controller") and HLR, operating Linqr (the "Processor"), for the use of the Service. It governs the processing of personal data carried out by the Processor on behalf of the Customer, in accordance with article 28 of the GDPR.
1. Purpose
The DPA sets out the conditions under which the Processor processes, on behalf of and on the instructions of the Customer, the personal data necessary to provide the Service. In the event of a conflict with the contract on data protection matters, the DPA prevails.
2. Definitions
The terms "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given to them by the GDPR.
3. Roles of the parties
The Customer acts as controller (or as processor of its own customer) and determines the purposes and means of the processing. The Processor processes the data solely on behalf of the Customer. The Customer warrants that it relies on an appropriate legal basis and has met its information obligations towards the data subjects.
4. Description of the processing
The characteristics of the processing are detailed in Annex 1. They cover in particular the nature, the purposes, the duration of the processing, the categories of data subjects and the categories of data.
5. Documented instructions
The Processor processes the data only on the Customer's documented instructions, including for transfers outside the EU, unless required by a law to which it is subject. The Processor informs the Customer if, in its opinion, an instruction infringes the GDPR.
6. Confidentiality
The Processor ensures that persons authorised to process the data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality, and access the data only strictly as necessary.
7. Security of processing
The Processor implements the appropriate technical and organisational measures provided by article 32 of the GDPR to ensure a level of security appropriate to the risk. These measures are described in Annex 2.
8. Sub-processors
The Customer gives a general authorisation for the Processor to engage sub-processors to provide the Service. The categories of sub-processors are set out in Annex 3.
The Processor imposes on each sub-processor data-protection obligations equivalent to those of this DPA and remains responsible for their performance. In the event of an intended change of sub-processor, the Customer is informed and may object on legitimate grounds, in writing to dpo@linqr.ai.
9. Assistance to the Customer
Taking into account the nature of the processing, the Processor assists the Customer, by appropriate measures:
- in responding to requests to exercise data subjects' rights;
- in ensuring the security of the processing and the notification of personal data breaches;
- in carrying out, where applicable, data protection impact assessments (DPIAs) and prior consultations.
10. Personal data breach
The Processor notifies the Customer of any personal data breach without undue delay after becoming aware of it, and provides the relevant information to enable the Customer to meet its notification obligations towards the supervisory authority and, where applicable, the data subjects.
11. Transfers outside the EU
Any transfer of data outside the European Union carried out by the Processor is governed by appropriate safeguards within the meaning of articles 44 et seq. of the GDPR, in particular standard contractual clauses, supplemented where necessary by additional measures.
12. Fate of the data at the end of the contract
At the end of the provision of services, the Processor, at the Customer's choice, deletes or returns the personal data and destroys existing copies, unless legally required to retain them. Deletion takes place within a reasonable period after the end of the contract.
13. Liability
The liability of each party under the DPA is assessed in accordance with article 82 of the GDPR and within the limits of liability set out in the main contract.
14. Governing law
This DPA is governed by French law and interpreted in accordance with the GDPR.
Annex 1 - Details of the processing
- Nature of the processing
- Collection, organisation, structuring, enrichment, consultation and hosting of data, as part of the provision of the Service.
- Purposes
- Identification of companies and professional contacts, preparation and personalisation of outreach messages, management of the Customer's campaigns.
- Categories of data subjects
- The Customer's prospects and professional contacts, the Customer's account users.
- Categories of data
- Professional identification and contact data (name, job title, employer, business email and phone, public professional profiles), the Customer's interaction data.
- Sensitive data
- No data falling under article 9 of the GDPR is required or solicited.
- Duration of the processing
- For the duration of the contract, then deletion or return in accordance with article 12.
Annex 2 - Security measures
- Encryption of data in transit (TLS) and at rest;
- Least-privilege access control and user authentication;
- Logical isolation of data between customers (multi-tenant architecture);
- Logging of access and sensitive operations;
- Regular backups and restoration procedures;
- Access-rights management and periodic access reviews;
- Incident and data-breach management procedure.
Annex 3 - Categories of sub-processors
- Hosting and cloud infrastructure;
- Delivery of the website and application;
- Payment processing and billing;
- Transactional emails;
- Customer support and internal tooling;