Data Processing Agreement
Linqed · last updated 2026-08-22
This Data Processing Agreement ("DPA") forms part of the agreement between Linqed ([registered legal entity name and address — to be added once Linqed completes business registration], "Processor") and the agency customer ("Controller") for the LinkedIn export data of the subjects the Controller uploads. It applies automatically to every agency account and is accepted at signup; a countersigned copy will be available for download from your account settings once the acceptance-tracking feature ships (in development).
1. Subject matter and duration
The Processor processes personal data contained in LinkedIn data exports uploaded by the Controller for the duration of the Controller’s subscription, plus the 30-day deletion window described in the Privacy Policy.
2. Nature and purpose of processing
Parsing, storage, computation of analytics metrics, and generation of AI-written commentary from the uploaded LinkedIn export data, for the purpose of providing analytics to the Controller about the subjects it manages.
3. Categories of data subjects
Individuals whose LinkedIn export the Controller uploads ("Subjects"), and, incidentally and in pseudonymised form only, the Subjects’ LinkedIn connections (company and role only, identified by a one-way hash, never by name or email).
4. Categories of personal data
As described in full in the Privacy Policy: profile and career data, post content and engagement activity, network composition (pseudonymised), and LinkedIn’s own inferred scoring about the Subject. Explicitly excluded by design: private messages, login/security history, phone numbers, email address books, and job-application answers.
5. Processor obligations
- Process personal data only on documented instructions from the Controller, including regarding international transfers, unless required otherwise by law.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational measures, including per-tenant database-level access control (row-level security), encryption of stored files, and pseudonymisation of connection data.
- Not engage a new sub-processor without giving the Controller at least 30 days’ prior notice by email or in-product notice; the current list is maintained at /subprocessors.
- Assist the Controller in responding to data subject rights requests and in fulfilling its obligations regarding data breach notification, security, and data protection impact assessments, to the extent this depends on information held by the Processor.
- At the Controller’s choice, delete or return all personal data at the end of the provision of services, subject to the standard retention window described in the Privacy Policy.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as described in §6a.
6. Sub-processing
The Controller provides general authorisation for the Processor to engage the sub-processors listed at /subprocessors. If the Controller objects to a new sub-processor on reasonable data-protection grounds within the 30-day notice period, the parties will work in good faith to address the objection; if unresolved, the Controller may terminate the affected service without penalty by written notice before the sub-processor is engaged.
6a. Audits
The Processor will make available the information described in §5 to support the Controller’s compliance obligations, including relevant security certifications and summary audit reports where available. The Controller may request an on-site or remote audit no more than once per 12 months (or at any time following a personal data breach affecting its data), on at least 30 days’ written notice, during business hours, and at the Controller’s own cost unless the audit identifies a material breach of this DPA by the Processor.
7. International transfers
Primary processing occurs within the EU. Where a sub-processor is located outside the EU, the Processor relies on the European Commission’s Standard Contractual Clauses or an equivalent adequacy mechanism, details of which are available on request.
8. Breach notification
The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting the Controller’s data, with sufficient information to allow the Controller to meet its own notification obligations.
9. Liability
Liability under this DPA is governed by the liability provisions of the underlying Terms of Service.
10. Contact
Data protection queries relating to this DPA: privacy@linqed.pro. As a company of our current size we are not required to appoint a Data Protection Officer under GDPR Art. 37, and have not appointed one; the contact above is handled directly by the team responsible for data protection.