Última atualização · 24 August 2026
Política de privacidade
Proteção de dados sem PII. Esta política abrange a plataforma LINK, o site e o formulário de pedido de acesso: o que recolhemos, porquê, durante quanto tempo guardamos e como pedir a eliminação.
Esta página é publicada em inglês. As traduções deste site são apenas por conveniência — a versão inglesa é a juridicamente vinculativa.
1. Data collection (zero PII)
LINK does not collect, expose, or require personal phone numbers, private email addresses, or personal social accounts. Users operate exclusively under managed enterprise usernames issued by their organisation.
2. Message content & E2EE
All direct communications operate under end-to-end encryption, or encrypted-in-transit parameters where E2EE is not technically possible. LINK servers function solely as a transport layer and do not scan, read, or profile your messages.
3. Compliance & audit trails
To deter workplace harassment, LINK provides a cryptographic reporting tool. Reports are stored encrypted and can only be decrypted and viewed by your organisation’s authorised HR or compliance officers. Reporter identity is withheld by default and protected unless voluntarily surrendered by the user or compelled by a binding legal mandate — reporting is therefore pseudonymous, not absolutely anonymous.
4. Who we are
LINK ("we", "us") operates this website and reviews applications for access to the LINK platform. For information submitted through the application form, LINK is the data controller. Contact: privacy@linkprivacy.app.
Where LINK is deployed inside a customer organisation, that organisation is the controller of its users' communications and LINK acts as processor under a written data processing agreement.
5. What we collect on this website
When you submit the access application form we store:
- Full name
- Work email address
- Organisation name and organisation type / sector
- Your role
- Country
- Anticipated number of users (seat band)
- Your described intended use case (free text)
- How you heard about LINK (optional)
- Your consent choices and the exact consent wording shown to you
- Submission timestamp and application status
To prevent abuse of the form we also store a salted, irreversible hash of your IP address for 60 minutes. We do not store raw IP addresses, and this hash is not linked to your application record.
We do not use advertising cookies, analytics scripts, tracking pixels or session replay on this website. Fonts are served from our own domain, so no third party receives your IP address when the page loads.
6. Automated decision-making and AI
We do not use artificial intelligence, machine learning, profiling or any other automated decision-making to evaluate applications. Every application is read and decided by a person. If this ever changes, this policy will be updated before the change takes effect.
7. Legal basis
- Processing your application: legitimate interests and steps taken at your request prior to entering a contract (GDPR Art. 6(1)(b) and 6(1)(f)).
- Marketing emails: your separate, optional, opt-in consent (GDPR Art. 6(1)(a)). You can withdraw it at any time via the unsubscribe link or by emailing us.
8. Who we share it with (subprocessors)
We do not sell personal data. We use the following subprocessors to run this website and store applications:
- Supabase — database hosting for application records.
- Cloudflare — edge hosting and delivery of this website.
- Lovable — build and deployment platform for this website.
The current list is maintained on our Security & Compliance page. Data may be processed outside the EEA/UK; where it is, transfers are covered by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
9. How long we keep it
Application records are deleted automatically 12 months after submission, or sooner on request. Abuse-prevention hashes are deleted after 60 minutes. Marketing consent records are kept for as long as you remain subscribed, plus 24 months as proof of consent.
10. Your rights
You have the right to access, correct, erase, restrict, port and object to the processing of your data, and to withdraw consent at any time. Email privacy@linkprivacy.app and we will respond within 30 days. Erasure requests remove the record from the live database and from backups on the next backup rotation cycle (maximum 35 days). You may also complain to your national supervisory authority (in the UK, the ICO).
11. Children
This website is intended for adult professionals evaluating LINK on behalf of an organisation. We do not knowingly collect data from anyone under 16 through this site, and no one may create a LINK account themselves. Where LINK is used in a school setting, accounts are provisioned by the institution, which is responsible for obtaining any parental or institutional consent required under local law, and the institution is the data controller for those accounts.
12. Security
Application data is stored with row-level access restrictions and is not readable through the public interface. Access is restricted to authorised personnel. We will notify affected controllers of a personal data breach without undue delay and in any event within 72 hours of becoming aware of it.