Before you hand us access to anything, you deserve to know exactly where it goes, who can see it, and what happens if something goes wrong. This page is the plain-English version. The full legal text is in our Privacy Policy and Terms.
Your Accounts
You own everything. We borrow access.
Every system we build runs in your own accounts — your Google Workspace, your CRM, your telephony, your cloud. We never spin up parallel infrastructure that holds your data hostage. When a project ends, you keep all the tools, all the data, and all the credentials. We hand over full ownership and revoke our own access.
Data Minimization
We request the minimum permissions, every time.
When we connect a tool, we request only the scopes needed for the specific automation you asked for. We don't ask for domain-wide admin to set up a single sheet sync. If a scope is optional, we flag it and let you decide.
- Google APIs: scoped per-service (Sheets, Calendar, Gmail) — never blanket access
- CRM access: read-only or scoped to specific pipelines unless write is required
- Telephony: call configuration and routing only — never call content storage beyond what your provider retains
Encryption
In transit and at rest.
- In transit: TLS 1.2+ for all connections. No plaintext APIs, no exceptions.
- At rest: Credentials are stored in an encrypted vault (AES-256). We never store passwords in plaintext, in spreadsheets, or in config files.
- Key management: Encryption keys are managed through the cloud provider's KMS — not hard-coded.
Access Control
Need-to-know, with an audit trail.
Access to client systems is granted per-project and per-engineer. We maintain a log of who has access to what, and we revoke access within 48 hours of project completion or team member offboarding. No standing access to client production systems outside of active work.
AI & LLM Data
Your data doesn't train anyone's model.
When we deploy AI features (voice agents, lead scoring, chatbots), the models we use are:
- Not trained on your data. We do not fine-tune foundation models on client data unless you explicitly request it and approve the data pipeline.
- Self-hosted or API-based with zero-retention contracts where available. When using third-party inference, we select providers with no-training-on-input policies.
- Logged only in your infrastructure — conversation transcripts, lead data, and PII stay in your systems, not ours.
Lead & Customer Data
Your leads are your assets.
- Lead capture forms, WhatsApp widgets, and speed-to-lead pipelines all write to your CRM, your sheets, your database.
- We do not retain copies of lead data after deployment. During development, we use synthetic or anonymized test data.
- We do not cross-pollinate leads between clients. Ever.
Incident Response
If something breaks, you hear it from us first.
If we discover a security issue affecting client data, we notify affected clients within 24 hours — not when it's convenient. We provide: what happened, what data was exposed (if any), what we've done to contain it, and what we recommend you do next.
Compliance Posture
What we align with.
- GDPR: Data Processing Addenda available on request. EU client data stays in EU regions where applicable.
- Google OAuth: We follow Google's API Services User Data Policy, including limited use requirements.
- WhatsApp Business: We deploy through the official WhatsApp Business Platform, not unofficial APIs.
- SOC 2: Not yet certified. Our controls map to SOC 2 Trust Services Criteria and we're working toward formal certification.
Sub-processors
Who we rely on (and why).
We use the following categories of sub-processors. A detailed list with specific vendors is available on request.
- Cloud infrastructure — hosting and compute (e.g., Cloudflare, AWS)
- Communication platforms — telephony, SMS, email (e.g., Twilio, SendGrid)
- AI inference — self-hosted models and vetted API providers
- Analytics — privacy-respecting, aggregate-only analytics
We do not use sub-processors for storing or processing client personal data without a Data Processing Agreement in place.
Questions? Email
hello@linkrra.com and we'll get you a specific, written answer — not a form letter. If you need a DPA, security questionnaire response, or technical detail before signing, just ask.