GDPR transparency Version 1.0 Updated 12 July 2026

EU privacy rights, explained clearly.

This centre explains how Aerlinked approaches lawful processing, transparency, data-subject rights, retention, security and international transfers under the General Data Protection Regulation.

Regulation (EU) 2016/679 Applies where GDPR territorial scope is met EU/EEA privacy framework
EU
Aerlinked EU Privacy Centre

Lawful use. Clear choice. Enforceable rights.

Lawful basisEvery processing purpose mapped
TransparencyPlain-language privacy information
SecurityRisk-based safeguards
RightsAccessible request process
Hello@aerlinked.com

GDPR enquiries and data-subject requests.

Within one month

Subject to lawful extensions and identity verification.

🛡
Risk-based safeguards

Access controls, encryption, logs and backups.

Protected transfer tools

Adequacy, safeguards or lawful derogations.

ScopeRolesDataLawful basesRightsTransfersSecurityComplaints
Territorial scope

When the GDPR may apply to Aerlinked

The GDPR can apply to organisations established in the EU/EEA and, in certain circumstances, to organisations outside the EU/EEA that offer goods or services to people in the Union or monitor their behaviour there.

Public version 1.0
Scope depends on actual activity

This page describes Aerlinked’s intended GDPR controls where the Regulation applies. Merely making a website accessible from the EU does not by itself establish that services are offered to people in the Union.

EU

EU/EEA establishment

GDPR applies to processing in the context of an EU/EEA establishment, regardless of where the processing takes place.

Offering services

GDPR may apply where Aerlinked intentionally offers goods or services to people located in the Union.

Behaviour monitoring

GDPR may apply where behaviour in the Union is monitored, including certain tracking or profiling activities.

Responsibility

Aerlinked may act as controller or processor

The role depends on who decides the purpose and essential means of processing.

C

Controller

Aerlinked is generally a controller for account registration, platform security, billing, service analytics, marketing choices, support and its own lead-directory operations.

P

Processor

Aerlinked may act as a processor where an organisation determines why and how personal data is entered into or managed through CRM features, subject to the applicable agreement.

Customer responsibility

Users and organisations must have an appropriate legal basis for personal data they upload, enrich, contact or manage through Aerlinked and must provide required notices to the individuals concerned.

Data inventory

Personal data Aerlinked may process

CategoryExamplesTypical context
Identity and accountName, business email, mobile number, identifiers, role and verification records.Registration, account management, authentication and support.
Organisation dataBusiness name, domain, team membership, organisation settings and ownership.Organisation grouping, collaboration and duplicate-protection controls.
Lead-directory dataProfessional contact details, business role, employer, location, source and validation status.Business lead search and related compliance, accuracy and objection handling.
CRM contentContacts, notes, deal information, tasks, follow-up history and communications metadata.User-controlled relationship management and sales workflows.
Billing dataPlan, payment status, billing address, tax identifiers, invoices and refund references.Contract administration, payment, accounting and legal compliance.
Support dataTickets, messages, attachments, grievances, replies and evidence.Customer support, dispute resolution and rights handling.
Technical and security dataIP address, browser, device, session, timestamps, request IDs, logs and risk signals.Security, authentication, fraud prevention, audit and service reliability.
Consent and preferencesConsent records, withdrawals, cookie choices, objections and marketing preferences.Demonstrating and respecting user choices.
Purposes

Why Aerlinked processes personal data

Provide the platform

Create accounts, deliver lead search and CRM, maintain organisation access and provide requested features.

Administer contracts

Manage plans, payments, credits, invoices, renewals and related customer communication.

🛡

Protect users and systems

Prevent misuse, detect suspicious activity, maintain audit evidence and respond to incidents.

?

Support and rights

Answer questions, resolve complaints, investigate data quality and fulfil privacy requests.

Improve the service

Measure reliability, diagnose errors, improve workflows and develop product features.

Communicate

Send essential service messages and optional updates or offers where lawful and selected.

Article 6

Lawful bases used for processing

Aerlinked maps each processing purpose to an appropriate lawful basis. The applicable basis depends on the data, purpose and relationship.

Lawful basisHow Aerlinked may use itImportant limitation
ContractProviding requested account, CRM, subscription, billing and support services.Used only where processing is objectively necessary to perform or enter into a contract.
Legitimate interestsPlatform security, fraud prevention, service improvement, limited B2B operations and internal administration.Subject to necessity, balancing and the individual’s interests, rights and reasonable expectations.
ConsentOptional marketing, certain cookies, optional analytics or another purpose requiring freely given choice.Consent can be withdrawn without affecting earlier lawful processing.
Legal obligationTax, accounting, lawful authority requests and other mandatory record-keeping.The obligation must arise under applicable EU or Member State law where GDPR is relied upon.
Vital interestsExceptional situations involving protection of life or serious physical safety.Not intended as a routine basis for Aerlinked services.
Public taskOnly where a specific task in the public interest or official authority lawfully applies.Not intended as a routine basis for Aerlinked’s commercial operations.
Special-category data

Aerlinked is not designed for intentional processing of special-category data through ordinary lead-search or CRM workflows. Users should not upload health, biometric, political, religious, trade-union, sexual-orientation or similar sensitive information unless a valid Article 9 condition and appropriate safeguards clearly apply.

Sources

Where personal data may come from

You

Directly from individuals

Registration, support, billing, consent, CRM use and data-subject requests.

Org

Customers and organisations

Team invitations, contact imports, CRM records, ownership and organisation settings.

Web

Public or authorised sources

Lawful professional and business sources, subject to transparency and objection controls.

Sys

Automatically

Device, usage, session, security and operational data generated through the service.

Pay

Service providers

Payment status, delivery confirmations, verification and technical integration events.

Ref

Referrals or authorised users

Information submitted through referral, invitation or authorised collaboration features.

Data-subject rights

Your GDPR rights

Rights are subject to verification, scope, exemptions and lawful retention requirements.

01

Right to be informed

Receive clear information about the controller, purposes, lawful bases, recipients, retention, transfers and rights.

02

Access

Obtain confirmation, a copy of personal data and information about the processing.

03

Rectification

Correct inaccurate personal data and complete information that is incomplete.

04

Erasure

Request deletion in applicable circumstances, subject to legal grounds for continued processing.

05

Restriction

Request restricted processing while accuracy, lawfulness or an objection is being assessed.

06

Data portability

Receive qualifying data in a structured, commonly used and machine-readable format.

07

Object

Object to processing based on legitimate interests or public task and object at any time to direct marketing.

08

Automated decisions

Seek safeguards relating to qualifying decisions based solely on automated processing with legal or similarly significant effects.

09

Withdraw consent

Withdraw consent at any time for future consent-based processing.

10

Complain

Lodge a complaint with the competent EU/EEA supervisory authority.

Article 12 process

How Aerlinked handles GDPR requests

1Submit

Use the GDPR request form or email Hello@aerlinked.com.

2Verify

We may request proportionate proof where identity is reasonably uncertain.

3Assess

Locate data, review controller roles, exemptions, retention and third-party impacts.

4Respond

Normally within one month, with reasons and next steps where action is limited.

Complex or multiple requests

The response period may be extended by up to two further months where necessary because of complexity or the number of requests. The individual should be informed of the extension and reasons within the initial one-month period.

Storage limitation

Retention linked to purpose and legal need

InformationGeneral approachRelevant considerations
Account and organisationRetained during the relationship and for a limited period after closure.Recovery, security, legal claims, billing and required records.
CRM contentControlled by the customer or organisation, subject to account and backup cycles.Customer instructions, contract, deletion settings and processor obligations.
Lead-directory dataReviewed for relevance, accuracy, objection, source and business need.Professional context, transparency, suppression and objection records.
Billing recordsRetained for applicable tax, accounting, payment and dispute periods.Legal obligation and establishment, exercise or defence of claims.
Support and rights requestsRetained through resolution and for a proportionate accountability period.Identity checks, decision evidence, recurrence prevention and complaints.
Security logsRetained for a defined period based on security and investigation needs.Threat detection, fraud prevention, incident response and audit.
Recipients

Who may receive personal data

Cloud

Infrastructure providers

Hosting, storage, monitoring, communications and support providers under processor terms.

Payment and finance

Payment gateways, banks, tax, accounting and fraud-prevention providers.

API

Authorised integrations

Applications connected through customer or Aerlinked-approved integration scopes.

Law

Authorities and advisers

Courts, regulators, law enforcement and professional advisers where lawful.

Org

Customer organisations

Authorised organisation members where access, ownership or collaboration is configured.

M&A

Business transactions

Protected disclosure in connection with financing, restructuring, merger or acquisition.

Chapter V

International data transfers

Because Aerlinked may operate from India and use global providers, covered EU/EEA personal data may be transferred outside the EEA.

A

Adequacy decisions

Transfers to a country, territory or organisation recognised by the European Commission as providing adequate protection.

SCC

Standard Contractual Clauses

Commission-approved clauses, supported by transfer assessments and supplementary measures where needed.

BCR

Other safeguards

Binding corporate rules, approved codes, certification or another Article 46 mechanism where available.

49

Limited derogations

Article 49 exceptions used only where their specific conditions are met and not as a routine transfer mechanism.

TIA

Transfer assessment

Assessment of destination-country law, practical access risk, data sensitivity and additional safeguards.

Min

Data minimisation

Limit transferred data, control access, encrypt or pseudonymise where appropriate and monitor providers.

Request transfer information

Where applicable, a data subject may request information about the transfer safeguard relevant to their personal data, subject to confidentiality and security restrictions.

Article 32

Risk-based technical and organisational measures

EEncryption and masking

Appropriate encryption, tokenisation, masking or pseudonymisation based on system risk.

AAccess management

Authentication, MFA, role permissions, least privilege and privileged-action controls.

LLogging and detection

Audit logs, anomaly signals, security monitoring and investigation support.

BResilience and backups

Encrypted backups, restore testing, continuity planning and service recovery controls.

VProcessor assurance

Security due diligence, written terms, sub-processor controls and incident obligations.

TTesting and review

Periodic evaluation, vulnerability management and effectiveness review of safeguards.

DPrivacy by design

Data minimisation, default restrictions, purpose controls and lifecycle management.

RIncident response

Detection, containment, assessment, notification, remediation and lessons learned.

Articles 33 and 34

Personal-data breach response

1Contain

Validate the incident, restrict exposure and preserve evidence.

2Assess risk

Identify affected data, people, scope, likelihood and severity of harm.

3Notify

Notify the competent authority within 72 hours where required and communicate high-risk breaches to individuals without undue delay.

4Remediate

Reduce impact, prevent recurrence and document the decision and measures.

Processor notification

Where Aerlinked acts as a processor, it should notify the relevant controller without undue delay after becoming aware of a personal-data breach, in accordance with the data-processing agreement.

Automated processing

Profiling and automated decision-making

No intended solely automated legal decisions

Aerlinked is not designed to make decisions about individuals based solely on automated processing that produce legal or similarly significant effects. Risk signals, lead-quality indicators and recommendations are intended to support human review and platform security.

1

Meaningful information

Where Article 22 applies, provide appropriate information about the logic involved and expected consequences.

2

Human intervention

Provide a route to obtain human review, express a point of view and contest a qualifying decision.

3

Bias and accuracy

Review data quality, proportionality and the risk of unfair or discriminatory outcomes.

Children

Aerlinked is a business platform for adults

Not directed to children

Aerlinked is not intended for children. Where consent-based online services are offered directly to a child, applicable Member State age rules and parental-authorisation requirements would need to be addressed before processing.

Governance contacts

EU representative and Data Protection Officer

27

EU representative

Where Article 27 requires Aerlinked to appoint an EU representative, the representative’s identity and contact details will be published here before covered EU-facing processing begins.

37

Data Protection Officer

Aerlinked will appoint and publish a DPO where Article 37 or applicable Member State law requires one. Until then, privacy enquiries are handled through Hello@aerlinked.com.

Production requirement

Do not publish invented representative or DPO details. The final live page must identify Aerlinked’s legal entity, registered address, and any formally appointed EU representative or DPO.

Supervisory authority

Questions, complaints and regulatory contact

Aerlinked encourages individuals to contact the Privacy Team first so the concern can be investigated promptly. This does not remove the right to complain to a competent supervisory authority.

Aerlinked Privacy Team

For GDPR questions, objections, rights requests, transfer information or a privacy complaint.

Hello@aerlinked.comSubject: GDPR Privacy RequestResponse target: one month
Right to lodge a complaint

You may lodge a complaint with the supervisory authority in the EU/EEA country of your habitual residence, place of work, or the place of the alleged infringement. You may also seek a judicial remedy where applicable.

Official references

EU GDPR resources

Not legal advice

This page is a public-facing explanation of Aerlinked’s intended GDPR approach. It does not replace the official Regulation, national law or legal advice. The production version must match Aerlinked’s real legal entity, systems, vendors, locations and processing records.

Frequently asked questions

GDPR answers in plain language

Not automatically. Accessibility alone is generally insufficient. GDPR scope depends on factors such as an EU/EEA establishment, intentional offering of goods or services to people in the Union, or monitoring their behaviour there.
The normal GDPR response period is one month after receipt. It may be extended by up to two further months where necessary because of complexity or the number of requests, with notice during the first month.
You may submit an objection or erasure request. Aerlinked will assess the lawful basis, source, professional context, your circumstances and any overriding legitimate grounds. Direct-marketing objections must be respected for that purpose.
In some cases, yes. GDPR recognises exceptions, including legal obligations, freedom of expression, public-interest grounds and the establishment, exercise or defence of legal claims. Restricted suppression records may also be needed to prevent reintroduction of removed data.
Where covered EU/EEA data is processed in India or another non-EEA country, Aerlinked must use a valid transfer mechanism such as an adequacy decision or appropriate safeguards, commonly Standard Contractual Clauses, together with any necessary supplementary measures.
A DPO is mandatory only in the circumstances described by Article 37 or applicable law, such as certain large-scale systematic monitoring or large-scale processing of special-category or criminal-offence data. Aerlinked will publish DPO details if formally required and appointed.