Privacy Policy
How Linqr collects, uses and protects your personal data under the GDPR: purposes, retention periods, processors and how to exercise your rights.
Last updated: July 17, 2026
This policy describes how Linqr ("we", "us") processes personal data through the linqr.ai website and the Linqr platform (the "Service"), in accordance with Regulation (EU) 2016/679 ("GDPR") and the French Data Protection Act of 6 January 1978 as amended.
Data controller
The controller for the processing described in this policy is Linqr, a brand operated by HLR (EURL, Paris Trade & Companies Register (RCS) No. 921 812 541).
For any question about your data or to exercise your rights: dpo@linqr.ai.
Our dual role
Depending on the processing concerned, we act in two distinct capacities:
- Controller for the data of our visitors, prospects, waitlist sign-ups, customers and users of the Service (account management, billing, support, communication). This is the subject of this policy.
- Processor for the prospect and professional contact data that our customers search for, enrich and organise using the Service: in that case our customer is the controller and we act on their instructions, under our Data Processing Agreement (DPA). See the "Data of prospected individuals" section below.
Data we process
Account and identification data
- First and last name, business email address, job title, company, professional profile (e.g. LinkedIn).
- Login credentials and account preferences.
Billing data
- Company name, billing address, VAT number, subscribed plan and payment history.
- Card details are never stored by us: they are processed directly by our secure payment provider.
Usage and technical data
- Connection logs, IP address, device and browser type, pages viewed, actions taken within the Service.
- Cookies and trackers (see the "Cookies" section).
Communication data
- The content of your exchanges with us (support, emails, contact or waitlist forms).
Purposes and legal bases
We process your data for the following purposes, each relying on a legal basis under article 6 of the GDPR:
- Provide and manage the Service and your account
- Performance of the contract (art. 6.1.b)
- Handle billing and payments
- Contract & legal obligation (art. 6.1.b and c)
- Answer your requests and provide support
- Contract & legitimate interest (art. 6.1.b and f)
- Manage the waitlist and sign-ups
- Consent (art. 6.1.a)
- Send Service-related communications
- Legitimate interest, with a right to object (art. 6.1.f)
- Email marketing
- Consent or legitimate interest as applicable (art. 6.1.a/f)
- Improve and secure the Service, prevent fraud
- Legitimate interest (art. 6.1.f)
- Comply with our legal and accounting obligations
- Legal obligation (art. 6.1.c)
Data of prospected individuals
The Service allows our customers to identify companies and professional contacts relevant to their business. When we process such prospect data on behalf of a customer, that customer is the controller and we act as a processor, on their instructions, under our Data Processing Agreement.
The data concerned is professional data (professional identity and contact details, job title, employer). It is for the customer, as controller, to rely on an appropriate legal basis (generally legitimate interest), to inform the data subjects and to honour their right to object.
Recipients and processors
Your data is accessible to our authorised staff and, strictly as necessary, to technical providers acting as processors. These providers operate in particular for the following categories of services:
- Hosting and cloud infrastructure;
- Payment processing and billing;
- Transactional and communication emails;
- Customer support and internal tooling;
- Audience measurement and Service improvement.
These processors are bound by contract and act only on our instructions. We do not sell your personal data. An up-to-date list of our processors is available on request at dpo@linqr.ai. Your data may also be disclosed where required by law (administrative or judicial authority).
Transfers outside the European Union
Service data is hosted within the European Union (Paris, France). Some of our technical providers (in particular for the delivery of the website and certain infrastructure components) may however operate from, or rely on infrastructure located, outside the European Union.
Where such a transfer occurs, it is governed by appropriate safeguards within the meaning of articles 44 et seq. of the GDPR: an adequacy decision of the European Commission, or standard contractual clauses (SCCs) supplemented, where necessary, by additional measures.
Retention periods
We keep your data only for as long as strictly necessary for the relevant purposes, after which we delete or anonymise it:
- Account and Service data
- For the duration of the relationship, then up to 3 years after the last contact
- Billing and accounting data
- 10 years (legal obligation)
- Waitlist / prospects
- Up to 3 years after the last contact or until consent is withdrawn
- Cookies and trackers
- 13 months maximum
- Technical logs
- 12 months maximum
Security
We implement appropriate technical and organisational measures to protect your data, including:
- Encryption of data in transit (TLS) and at rest;
- Strict access control and tenant isolation between customers (multi-tenant);
- Authentication, logging and regular backups;
- Security reviews and access-rights management.
Your rights
In accordance with the GDPR, you have the following rights over your data:
- Right of access, rectification and erasure;
- Right to restriction and right to object to processing;
- Right to data portability;
- Right to withdraw your consent at any time, without retroactive effect;
- Right to set instructions regarding the fate of your data after your death.
To exercise these rights, write to us at dpo@linqr.ai. We may ask for proof of identity and will respond within one month. You also have the right to lodge a complaint with the French data protection authority, the CNIL (www.cnil.fr).
Minors
The Service is intended exclusively for professional use and is not designed for minors. We do not knowingly collect data relating to minors.
Changes
We may update this policy to reflect legal or operational changes. In the event of a material change, we will inform you by appropriate means. The date of the last update appears at the top of the page.