The compliance story, end-to-end.
At-a-glance.
- Data roles
- Controller (for account data) · Processor (for customer-ingested data)
- Legal basis
- Legitimate interest + contract (for processing)
- Data residency
- EU (primary) · US (replicas)
- Data retention
- 30 days default · configurable per customer
- Breach SLA
- Customer notified within 60 minutes of discovery
- Contact
- info@linkfetch.io
User is the principal.
Every profile lookup runs through the end-user's own LinkedIn session via our Chrome extension. We never impersonate, never rent accounts, never store session tokens.
End-user installs the extension. It passively observes public LinkedIn responses while the user browses. No background fetches.
Raw responses are normalised into typed records with provenance stamps (source, fetched_at, freshness). Session tokens never leave the browser.
Normalised records are served back through the API, keyed to the ingesting user. DSR-erased rows are filtered at response time, not deleted immediately, so audit trails survive.
Everyone in the chain.
| processor | purpose | legal basis · region |
|---|---|---|
| AWS (EU-Central-1) | Infrastructure, Postgres, S3 | GDPR · Frankfurt |
| Cloudflare | Edge + DNS | GDPR · Multi-region |
| Paddle | Merchant of Record (billing) | GDPR · UK + EU |
| PostHog (EU) | Product analytics | GDPR · Frankfurt |
| Resend | Transactional email | GDPR · US/EU |
| Sentry (EU) | Error monitoring | GDPR · Frankfurt |
list maintained in real time · subscribe to updates · info@linkfetch.io
How to exercise yours.
- AccessDSAR via `info@linkfetch.io` · resolved within 30 days
- RectificationInline edits in dashboard or email support · same-day
- ErasureSoft delete on request; hard delete 30 days later per retention
- PortabilityJSON export of all user-owned data · 7 business days
- ObjectionOpt-out from processing · acknowledged within 5 business days
Need our DPA before your security review?
Pre-signed, standard-contractual-clauses compliant, downloadable as PDF. Or request custom edits — we respond within 24 hours.