Juridique

Privacy Policy

Dernière mise à jour: August 12, 2026

Effective Date: 9 June 2025
Last Updated: 12 August 2026

Linkx.ee ("we," "us," "our"), operated by MCR One Oy, respects your privacy and is committed to protecting your personal information. This Privacy Policy details how we collect, use, disclose, and safeguard your data when you access our website at linkx.ee, or use our link-in-bio, short link, QR code and analytics services (collectively, "Services").

This policy is written to comply with the EU General Data Protection Regulation (GDPR). It also addresses the California Consumer Privacy Act/California Privacy Rights Act (CCPA/CPRA, USA) and the Personal Information Protection and Electronic Documents Act (PIPEDA, Canada) where those laws apply to you.

Please read this Privacy Policy carefully.

1. Information We Collect

Information You Provide Directly

We collect personal information you voluntarily provide, including:

  • Identity Data: Name, username, profile photo.
  • Contact Data: Email address, and where you provide them, phone number and mailing address.
  • Professional Information: Company name, job title, industry, where you choose to provide these.
  • Billing Information: Payment method and billing details, handled by our payment processors as described below.
  • Account and Profile Content: Preferences, settings, the links, text, images and other content you publish on your bio pages and short links.
  • AI Feature Input: Text you enter into our AI-assisted features, described in section 3 below.
  • Customer Support Communications: Interactions through support or feedback.

Information Collected Automatically

When you use the Linkx.ee Services, we collect certain information automatically from your device. In the European Economic Area and the UK, this information is generally considered personal data. It may include:

  • IP address, browser type, operating system, device details, geographic location (city/country level), usage patterns, page interactions, and click data.
  • Analytics on the performance of your short links and bio pages, including click counts and referrer data.
  • Cookies and similar tracking technologies. Please see our Cookie Policy for detailed information.

Information from Third Parties

We may receive personal information about you from third-party sources, including payment processors, analytics providers, and social media platforms where you connect an account. In all cases, we require that these third parties have your consent or are otherwise legally permitted to share your personal information with us.

2. Automated Scanning and Automated Decision-Making

We may undertake automatic scanning of User Profiles and linked content to support compliance with our Terms and Conditions and Community Standards. This scanning may determine whether sensitive content warnings should be applied and presented to people accessing a User Profile or linked content. The results may also inform decisions about whether content should be removed, whether a User Profile should be suspended, and eligibility for certain features including monetisation opportunities.

Legal basis: We carry out this scanning on the basis of our legitimate interest in maintaining the safety, legality and integrity of our Services and protecting our users (Article 6(1)(f) GDPR), and to comply with our legal obligations (Article 6(1)(c) GDPR).

Human review: [[CONFIRM 1: Describe accurately what happens. If a decision to suspend an account or restrict monetisation can be taken automatically with no human involved, GDPR Article 22 applies and you must offer the right to obtain human intervention, to express a point of view, and to contest the decision. If a person always reviews before such a decision takes effect, say so here instead. Do not publish this section until this is settled.]]

If your account or content is affected by such a decision, you may contact us at [email protected] to request that a member of our team review it.

3. Artificial Intelligence Features

Linkx.ee offers optional AI-assisted features. Where you use them, the text you enter is transmitted to third-party AI providers who act as our processors.

AI Bio Generator. When you describe a style for your bio page, that description is sent to OpenAI to generate page content, layout and design suggestions. Please do not enter personal information about yourself or other people into this field, as the text is transmitted to the provider. Content generated this way is stored with your bio page.

Translation. We use DeepL and machine translation services to translate our own interface text, marketing copy and blog articles between the languages we support. This processes our published content rather than your personal data.

Legal basis. Where you choose to use an AI feature, we process your input in order to perform our contract with you (Article 6(1)(b) GDPR). Our use of translation services rests on our legitimate interest in offering our Services in multiple languages (Article 6(1)(f) GDPR).

Use of your input for model training. [[CONFIRM 2: Do not publish any statement here until you have checked your OpenAI and DeepL account terms and hold them in writing. If inputs are excluded from training under your API agreement, say: "Our agreements with these providers prohibit the use of your input to train their models." If you have not confirmed this, delete this paragraph entirely rather than making the claim.]]

Retention. [[CONFIRM 3: State how long AI prompts and generated outputs are retained. Decide a period before publishing. If you do not yet have one, the honest options are to set one now or to omit this paragraph — not to state a period you do not enforce.]]

International transfers. These providers may process data outside the European Economic Area. [[CONFIRM 4: Only state that transfers are made under Standard Contractual Clauses if you hold executed SCCs or a Data Processing Addendum incorporating them. If you do not, obtain them before publishing this sentence.]]

4. How We Use Your Information

We process your data for the following purposes:

  • Service Delivery: Providing, maintaining and improving our Services, including creating and serving your short links, QR codes and bio pages.
  • Billing and Payment Processing: Managing payments, subscriptions, and preventing fraud.
  • Communication: Responding to your inquiries, providing service updates and notifications, and sending promotional offers where you have opted in.
  • Customer Support: Managing support requests and troubleshooting.
  • Analytics: Understanding how our Services are used so we can improve them.
  • AI-Assisted Features: Generating content where you request it, as described in section 3.
  • Security and Compliance: Ensuring security, detecting fraud and abuse, and complying with legal obligations and our Terms.

5. Legal Bases for Processing

We process your personal data on the following legal bases under the GDPR:

  • Contractual necessity (Article 6(1)(b)): Processing required to provide the Services you have signed up for, including account management, link and page delivery, and AI features you choose to use.
  • Consent (Article 6(1)(a)): Marketing communications and non-essential cookies. You may withdraw consent at any time.
  • Legitimate interests (Article 6(1)(f)): Securing and improving our Services, analytics, preventing abuse, and content scanning as described in section 2. You may object to processing on this basis.
  • Legal obligation (Article 6(1)(c)): Complying with accounting, tax and other legal and regulatory requirements.

6. Sharing Your Personal Information

We do not sell your personal data. We may disclose your personal information to the following categories of recipients:

  • Service providers: Hosting, payment, analytics, email delivery, AI and security providers who process data on our behalf under written agreements. Our key providers are listed in section 14.
  • Other Linkx.ee users: If you subscribe to, join, or purchase content from another user, that user receives the information necessary to provide what you requested.
  • Social login providers: Where you choose to sign in using a third-party account.
  • Legal authorities: Any competent law enforcement body, regulator, government agency or court where disclosure is necessary as a matter of applicable law, to establish or defend our legal rights, or to protect the vital interests of any person.
  • Business transfers: In connection with a merger, acquisition or sale of assets, subject to confidentiality and on condition that any buyer uses your information only for the purposes disclosed here.
  • With your consent: Where you have explicitly asked us to share information.

7. Payment Processing

We do not store or collect your payment card or bank account details. This information is provided directly to our third-party payment service providers, who act as controllers for those processing activities under their own privacy policies. These providers adhere to the Payment Card Industry Data Security Standards (PCI-DSS). The payment processors we work with are:

8. International Transfers

Our servers are located in the European Union. However, some of our service providers may process personal information outside the European Economic Area, including in the United States.

Where such transfers occur, we rely on adequacy decisions of the European Commission or on Standard Contractual Clauses approved by the European Commission, together with additional safeguards where required. Further details of the safeguards applied to a specific transfer can be provided on request by contacting [email protected].

9. Cookies and Tracking Technologies

We use cookies and similar technologies to operate our Services, remember your preferences and understand usage. For full details of the cookies we use, their purposes and durations, and how to control them, please see our Cookie Policy.

10. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes described in this policy, or for as long as required by applicable law. When data is no longer needed, we securely delete or anonymise it.

Account data is retained for the life of your account. Following account deletion, we retain data only where required for legal, accounting or dispute-resolution purposes. Analytics data associated with your links is retained [[CONFIRM 7: state the period]].

11. Data Security

We employ technical and organisational security measures, including:

  • TLS encryption for data in transit.
  • Role-based access control and authentication measures.
  • Regular security review of our systems.
  • Incident response and breach notification processes.

No system can guarantee absolute security. We encourage you to use a strong, unique password and to keep your login details confidential.

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected individuals, in accordance with Articles 33 and 34 GDPR.

12. Your Rights

If you are in the European Economic Area or the UK, you have the right to:

  • Access the personal data we hold about you.
  • Have inaccurate personal data corrected.
  • Request erasure of your personal data.
  • Restrict or object to processing, including processing based on our legitimate interests.
  • Receive your personal data in a portable, machine-readable format.
  • Withdraw consent at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • Opt out of marketing communications, including by using the unsubscribe link in any marketing email.
  • Lodge a complaint with a data protection supervisory authority.

To exercise any of these rights, contact us at [email protected]. We will respond within one month, as required by Article 12(3) GDPR. We may need to verify your identity before acting on a request.

Supervisory authority. Our lead supervisory authority is the Office of the Data Protection Ombudsman of Finland (Tietosuojavaltuutetun toimisto), Lintulahdenkuja 4, 00530 Helsinki, tietosuoja.fi. If you are located in another EEA country, you may also complain to your local supervisory authority.

13. Additional Information for United States Residents

If you are a resident of California or another US state with a comprehensive privacy law, you may have the right to know what personal information we collect and why, to obtain a copy of it, to request correction or deletion, and not to be discriminated against for exercising these rights.

We do not sell or share your personal information as those terms are defined under the CCPA/CPRA. We do not sell or share the personal information of individuals under 16 years of age. We do not use sensitive personal information for purposes other than those permitted by the CCPA and its regulations.

To exercise these rights, contact us at [email protected]. We will verify your identity before responding. You may designate an authorised agent to act on your behalf, subject to proof of authorisation.

Our website recognises the Global Privacy Control (GPC) signal and treats it as a valid opt-out request. Because there is no industry standard for Do Not Track (DNT) signals, we do not currently respond to them.

14. Service Providers

Our key third-party service providers include:

  • Hosting and infrastructure: Hetzner (EU), Cloudflare
  • Payments: Stripe, PayPal
  • Analytics: Google Analytics
  • Email delivery: SendGrid
  • AI and translation: OpenAI, DeepL

15. Children's Privacy

Our Services are not intended for children under the age of 18. If you are under 18, please do not use the Linkx.ee Services or provide us with your personal information. We do not knowingly collect personal data from individuals under this age.

If you are a parent or legal guardian and believe your child has provided us with personal data, please contact us at [email protected]. On becoming aware that we have collected personal data from a minor, we will take prompt steps to delete it in accordance with applicable law.

16. Third-Party Links

Our Services allow users to create and share links to third-party websites, and may contain integrations that we do not operate. We are not responsible for the privacy practices of external sites. Please review their privacy policies before engaging with them.

17. Changes to This Privacy Policy

We may update this Privacy Policy in response to legal, technical or business developments. When we make material changes, we will take appropriate measures to inform you, and will obtain your consent where required by applicable law. You can see when this policy was last updated from the date at the top of this page.

18. Contact Us

For privacy questions, requests or complaints, contact us:

Privacy contact: [email protected]
General support: [email protected]

Postal address:
MCR One Oy
Tainionkoskentie 68
55120 Imatra
Finland
Business ID: 3513953-9

We will confirm receipt of any complaint and, where we consider it necessary, open an investigation and report the outcome to you. If we cannot resolve your complaint to your satisfaction, you may contact the Office of the Data Protection Ombudsman of Finland or your local supervisory authority.