最後更新 · 24 August 2026

隱私權政策

零個人身分資訊 (PII) 資料保護和隱私標準。本政策涵蓋 LINK 平台、行銷網站和存取申請表:我們確切收集了什麼、為什麼收集、保留多久以及如何擦除。

Frosted glass privacy pane obscuring faint points of light

此頁面以英文發布。本網站上的翻譯僅為方便之用,英文文本具有法律約束力。

1. Data collection (zero PII)

LINK does not collect, expose, or require personal phone numbers, private email addresses, or personal social accounts. Users operate exclusively under managed enterprise usernames issued by their organisation.

2. Message content & E2EE

All direct communications operate under end-to-end encryption, or encrypted-in-transit parameters where E2EE is not technically possible. LINK servers function solely as a transport layer and do not scan, read, or profile your messages.

3. Compliance & audit trails

To deter workplace harassment, LINK provides a cryptographic reporting tool. Reports are stored encrypted and can only be decrypted and viewed by your organisation’s authorised HR or compliance officers. Reporter identity is withheld by default and protected unless voluntarily surrendered by the user or compelled by a binding legal mandate, reporting is therefore pseudonymous, not absolutely anonymous.

4. Who we are

LINK ("we", "us") operates this website and reviews applications for access to the LINK platform. For information submitted through the application form, LINK is the data controller. Contact: privacy@linkprivacy.app.

Where LINK is deployed inside a customer organisation, that organisation is the controller of its users' communications and LINK acts as processor under a written data processing agreement.

5. What we collect on this website

When you submit the access application form we store:

  • Full name
  • Work email address
  • Phone number (optional)
  • Organisation name and organisation type / sector
  • Your role
  • Country
  • Anticipated number of users (seat band)
  • Your described intended use case (free text)
  • How you heard about LINK (optional)
  • Your consent choices and the exact consent wording shown to you
  • Submission timestamp and application status

To prevent abuse of the form we also store a salted, irreversible hash of your IP address for 60 minutes. We do not store raw IP addresses, and this hash is not linked to your application record.

Cookies and analytics: this website sets no advertising cookies and no session replay. We use Google Analytics only if you actively accept analytics in the cookie banner. Until you accept, Google Consent Mode keeps analytics, advertising and personalisation storage denied and the Google script is not loaded at all. If you accept, Google receives your IP address and standard page-view data, and you can withdraw consent at any time from the cookie settings in the footer. The only cookie or local storage we set without consent records your own language, theme and consent choices.

Typography uses the DM Sans family with a system font fallback. No web font is requested from a third-party font service, so no font provider receives your IP address.

6. Automated decision-making and AI

We do not use artificial intelligence, machine learning, profiling or any other automated decision-making to evaluate applications. Every application is read and decided by a person. If this ever changes, this policy will be updated before the change takes effect.

7. Legal basis

  • Processing your application: legitimate interests and steps taken at your request prior to entering a contract (GDPR Art. 6(1)(b) and 6(1)(f)).
  • Marketing emails: your separate, optional, opt-in consent (GDPR Art. 6(1)(a)). You can withdraw it at any time by emailing privacy@linkprivacy.app.

8. Who we share it with (subprocessors)

We do not sell personal data. We use the following subprocessors to run this website and store applications:

  • Supabase, database hosting for application records.
  • Cloudflare, edge hosting and delivery of this website.
  • Lovable, build and deployment platform for this website.
  • Amazon Web Services (Amazon SES), delivery of the notification email that contains the details you submit in the form.
  • Klev Tech Ltd, the company that operates LINK and whose staff mailbox receives and reviews your application.
  • Google (Google Analytics), website analytics, used only if you accept analytics cookies.

The current list is maintained on our Security & Compliance page. Data may be processed outside the EEA/UK; where it is, transfers are covered by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.

9. How long we keep it

Application records are deleted automatically 12 months after submission, or sooner on request. Abuse-prevention hashes are deleted after 60 minutes. Marketing consent records are kept for as long as you remain subscribed, plus 24 months as proof of consent.

10. Your rights

You have the right to access, correct, erase, restrict, port and object to the processing of your data, and to withdraw consent at any time. Email privacy@linkprivacy.app and we will respond within 30 days. Erasure requests remove the record from the live database and from backups on the next backup rotation cycle (maximum 35 days). You may also complain to your national supervisory authority (in the UK, the ICO).

11. Children

This website is intended for adult professionals evaluating LINK on behalf of an organisation. We do not knowingly collect data from anyone under 16 through this site, and no one may create a LINK account themselves. Where LINK is used in a school setting, accounts are provisioned by the institution, which is responsible for obtaining any parental or institutional consent required under local law, and the institution is the data controller for those accounts.

12. Security

Application data is stored with row-level access restrictions and is not readable through the public interface. Access is restricted to authorised personnel. We will notify affected controllers of a personal data breach without undue delay and in any event within 72 hours of becoming aware of it.