Linkubit
LegalLast updated 20 September 2026

Data processing addendum

How we handle personal data you put into Linkubit, where you are the controller and we are the processor.

On this page
  1. Roles
  2. Scope
  3. Our obligations
  4. Your obligations
  5. Security measures
  6. Sub-processors
  7. Transfers
  8. Deletion
  9. Audit
  10. Contact

At a glance

  • For your contacts and conversations, you are the controller and we are the processor — we act only on your instructions.
  • We give notice before adding a subprocessor, help with data-subject requests, and notify you of breaches without undue delay.
  • Security rests on database-enforced tenant isolation, encryption, managed secrets, and audit logging.
  • Customer data is stored in Mumbai, India. Producing an AI reply sends that conversation to our AI model provider, which processes it outside India and does not train on it.
  • Sub-processors are listed below by category and country; the named list is provided on request, with notice of changes to customers who ask for it.
  • On termination everything is deleted within the stated window — except opt-out hashes, which protect the data subject.

1. Roles

For the contacts and conversations in your account, you are the controller and we are the processor. You decide who is contacted and why; we hold and move that data on your instructions. For your own account and billing data we are the controller — see the privacy policy.

2. Scope

Subject matterProviding the Linkubit platform
DurationFor as long as your account is active, plus the deletion window in the terms
Categories of data subjectYour contacts and prospects, and your staff users
Categories of dataContact details, message content, consent records, activity history, and any qualification information you choose to capture
Special categoriesNone expected. Linkubit is not designed for special-category data and you should not put it here

3. Our obligations

  • Process personal data only on your documented instructions
  • Keep the measures described in section 5 in place
  • Bind everyone with access to confidentiality
  • Give notice before engaging a new subprocessor, so you can object
  • Help you respond to data-subject requests, and to regulators
  • Notify you without undue delay if we become aware of a personal data breach
  • Delete or return the data when the agreement ends

4. Your obligations

  • Have a lawful basis for the people whose data you upload or contact
  • Give the notices your own privacy law requires — Linkubit can send a consent notice on the first agent reply, and the wording is yours
  • Respond to your own data subjects; we will help

5. Security measures

  • Row-level tenant isolation in the database. Every row carries its owner, policies are enabled and forced, and the application connects with a role that cannot bypass them
  • Encryption in transit and at rest
  • Credentials in a managed secrets store, referenced not copied
  • Audit logging of access and of every erasure
  • Suppression stored as a one-way hash, so an opt-out contains no readable address
  • Automated, encrypted database backups retained for 14 days; a deleted record ages out of them on that schedule
  • Dependencies audited for known vulnerabilities on every build

6. Sub-processors

These are the categories of third party that process personal data on our behalf, and where each runs. Rows marked if connected only apply once you connect that account from your workspace; until then nothing reaches them. The current list of sub-processors by name is available on request at help@linkubit.com; a customer who asks to be notified receives 30 days' notice before a sub-processor is added or replaced, and may object.

Sub-processorPurposeWhat reaches themWhereWhen
Cloud hostingDatabase, file storage, compute, email delivery and receiptEverything in your workspaceMumbai, Indiaalways
AI model providerThe model behind agent replies, knowledge search and onboardingMessage content, knowledge documents and catalogue text, at the moment a reply or search is producedUnited Statesalways
Identity providerSign-in, sessions, invitations and MFA for your staff usersYour staff users' names, email addresses and sign-in activity — never your contactsUnited Statesalways
Website hosting and edge securityServing this website and the dashboard's pages, bot protection on public forms, cookieless page-view countsRequest logs (IP, URL); a daily-rotating hash of IP and browser for page views — no cookie, no customer dataUnited States, with a global edge networkalways
Payment processorSubscription billing for your accountYour billing contact and payment details — never your contactsUnited States / Irelandalways
Meta PlatformsWhatsApp, Instagram and Messenger delivery; Meta AdsMessages you send and receive on those channels; hashed identities for ad audiencesUnited States / Irelandif connected
Google AdsGoogle Ads campaigns, Customer Match and conversion uploadHashed identities and conversion eventsUnited States / Irelandif connected
Your payment gatewayPayment links your customers pay, on your own gateway accountThe amount, description and the customer's contact details for the linkIndiaif connected
Your prospect-data providerProspect search and enrichment, on your own accountSearch criteria you enter; the prospects returnedUnited Statesif connected
On AI training. Linkubit uses its AI model provider on paid terms under which prompts and the model's responses are not used to train or improve its models, and are retained only transiently for abuse detection. We do not train models on your data ourselves.

7. Transfers

Customer data is stored in Mumbai, India. It is processed outside India in two cases: when an AI reply, knowledge search or onboarding step sends content to our AI model provider, and when your staff sign in through our identity provider — both in section 6. The channels themselves — WhatsApp, Instagram, Messenger, email — are operated by their providers wherever they run. Where a transfer requires a mechanism such as standard contractual clauses, that mechanism applies.

8. Deletion

On request or on termination we delete personal data within 30 days, except suppression hashes. Those contain no readable identifier and exist solely to stop someone who opted out from being contacted again — which is a protection for the data subject, not a retention of their data.

Both halves of this are things your workspace administrator can do from the product, today, without a ticket:

  • Return. Export every record in the workspace — one file per table, every column — as a single archive.
  • Delete. Erase the workspace: every table, the files you uploaded, and the channel credentials you connected, in one audited operation. Erase a single person the same way, from their record. Both leave suppression hashes and nothing else.

Encrypted backups retain a deleted record for up to 14 days, after which it is gone from those too.

9. Audit

We will respond to reasonable information requests about our processing. On-site audits are by arrangement and at your cost.

10. Contact

help@linkubit.com