Data processing addendum

How we handle personal data you put into Linkubit, where you are the controller and we are the processor.

Draft — review required before launch

This text is written against what the system actually does, and every company-specific detail is left as a {{PLACEHOLDER}} to be filled in. It has not been reviewed by a lawyer, and DPDP and GDPR exposure here is real. Do not publish it as-is.

Last updated 16 August 2026

On this page
  1. Roles
  2. Scope
  3. Our obligations
  4. Your obligations
  5. Security measures
  6. Transfers
  7. Deletion
  8. Audit
  9. Contact

At a glance

  • For your contacts and conversations, you are the controller and we are the processor — we act only on your instructions.
  • We give notice before adding a subprocessor, help with data-subject requests, and notify you of breaches without undue delay.
  • Security rests on database-enforced tenant isolation, encryption, managed secrets, and audit logging.
  • Customer data is stored in India (ap-south-1); transfers elsewhere use a recognised mechanism where one is required.
  • On termination everything is deleted within the stated window — except opt-out hashes, which protect the data subject.