Data Processing Agreement
When LinkScout handles data about the people you contact, it does so on your instruction and on your behalf. This sets out the terms - what we may do with it, who else touches it, how it is protected and what happens when you leave.
1Parties, and when this applies
This agreement is between you, the customer (the controller), and Pavlovic Media, Fischerweg 4, 4222 Zwingen, Switzerland (the processor).
It takes effect when you create a LinkScout account and applies for as long as we process personal data on your behalf. It forms part of the Terms of Service. Where this agreement and the Terms conflict on the processing of personal data, this agreement wins.
It is written to satisfy Article 28 of the GDPR and Article 9 of the Swiss Federal Act on Data Protection. Version of 10 August 2026.
2What is being processed
| Detail | |
|---|---|
| Subject matter | Providing the LinkScout service: finding websites, identifying a contact, sending outreach from your mailbox, handling replies, drafting content and monitoring links |
| Duration | For as long as your account is open, plus the retention periods in clause 10 |
| Nature and purpose | Collection, storage, organisation, retrieval, transmission by email, automated text generation and classification, and erasure |
| Categories of data subject | Editors, writers and other staff at the websites you target, and anyone who replies to your outreach |
| Categories of personal data | Name, business email address, job title or role, employer website, and the content of email correspondence with them |
| Special category data | None. The service is not designed for it and you must not use it to process it |
3Your instructions, and your obligations
We process this data only on your documented instructions. Your instructions are: these terms, the configuration you set in the app - the websites, the keywords, the competitors, the approvals, the automatic-approval setting - and any request you make through our API or in writing.
Setting the service to approve prospects automatically is itself an instruction. Email sent under it is sent on your instruction exactly as if you had approved each one by hand.
As the controller, you are responsible for:
- having a lawful basis for the outreach under the law applying to each recipient, and being able to demonstrate it;
- meeting the information duty owed to people whose data you did not collect from them directly - Article 14 GDPR - including telling them where their data came from;
- the accuracy and lawfulness of the data and the instructions you give us.
If we think an instruction breaches data protection law, we will tell you and may decline to act on it.
4Confidentiality
Everyone we allow to access this data is bound by a duty of confidentiality, and access is limited to those who need it to run the service or to support you.
For message content received through Gmail, LinkScout personnel do not read a message unless you specifically authorise support for that conversation, or access is necessary for security or legal compliance. Automated processing is limited to the user-facing reply matching, classification and editable drafting features described in this agreement.
5Security
We maintain technical and organisational measures appropriate to the risk, including:
- encryption of all traffic in transit;
- encryption at rest of mailbox credentials, with a key held separately from the database, and no path that displays them back to anyone;
- API keys stored only as a hash, so a copy of the database contains no usable credential;
- access to each account’s data enforced in the application layer on every query, so one customer’s data cannot be reached from another’s session or key;
- logging of processing activity, with a standing rule that message bodies, credentials and contact details are never written to logs;
- regular backups, held on a defined rotation.
We may change these measures as the service develops, provided the level of protection is not reduced.
6Sub-processors, and the two shared stores
You give general authorisation for us to engage sub-processors. The current list is at Sub-processors. Each is bound by written terms imposing obligations no weaker than these, and we remain responsible to you for what they do.
We will publish a new sub-processor on that page and notify you by email at least 30 days before it begins processing. If you object on reasonable data protection grounds, write to us; if we cannot resolve it, you may terminate the affected part of the service and we will refund any prepaid fees covering the period after termination.
Two ways data is shared across customers
Clause 3 says we act only on your instruction, and clause 7 says we do not use your data for our own purposes. There are two carve-outs. They are deliberate, and we would rather set them out here than have them found later.
The search cache. Search results are cached and reused across customers for one week. The cache is keyed on the search phrase alone and holds only public search results - page titles, URLs, positions. It contains no personal data and nothing identifying who searched. Nothing about you or your prospects is inferable from it.
The suppression list. When a recipient unsubscribes, asks not to be contacted, or their address hard bounces, we add that email address to a suppression list shared across every account on the platform, and no customer can send to it again through LinkScout. This is processing we carry out as controller, in our own legitimate interest and in the interest of the person concerned, in order to honour an objection across the whole service rather than only within the account that provoked it. It is kept indefinitely and is not deleted on termination - see clause 10.
7No use for our own purposes
Apart from the suppression list in clause 6, we do not use the personal data we process for you for any purpose of our own. We do not sell it, we do not disclose it to anyone other than the sub-processors listed, we do not use it to train models - ours or anyone else’s - and we do not make one customer’s prospects, contacts or messages available to another.
8Helping you meet your obligations
Taking account of the nature of the processing and the information available to us, we will give you reasonable assistance with:
- requests from data subjects - access, correction, erasure, restriction, objection and portability. Most of these you can action yourself in the app; where you cannot, ask us;
- data protection impact assessments and prior consultation with an authority;
- your own security obligations and breach notifications.
If a data subject contacts us directly about data we hold for you, we will not respond substantively on your behalf. We will pass the request to you promptly - except that we will always act on a request not to be contacted, by adding the address to the suppression list, because honouring an objection should not wait on anyone.
9Breaches
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting data we process for you. The notification will describe what happened, the categories and approximate number of records affected, the likely consequences and the measures taken. Notifying the supervisory authority and the people affected is your responsibility as controller; we will give you what you need to do it.
10Deletion and return
You can export your data while your account is open. On termination, and at your choice, we will delete the personal data we process for you or return it, and delete existing copies - subject to the following.
- Twelve months. By default, prospects, contacts, messages, drafts and links are deleted twelve months after the account closes, so an account reopened by mistake can be restored and a dispute can be investigated. Ask and we will delete sooner.
- In-life deletion. While your account is open, a prospect never approved and never contacted is deleted after six months, and the contact record for a prospect you reject is deleted immediately, leaving only the domain on your blocklist.
- Suppression records are kept indefinitely and are not deleted on termination. If they were, closing and reopening an account would make everyone who asked to be left alone contactable again.
- Billing records are kept for ten years under Art. 958f of the Swiss Code of Obligations. This is a legal obligation and applies regardless of a deletion request.
Deletion is scheduled rather than instantaneous, and backups expire on their own rotation. We do not edit backups selectively and will not promise erasure from them at a given moment; data restored from a backup has the deletion re-applied.
11Audits
On reasonable written request, and no more than once a year unless a supervisory authority or a breach requires otherwise, we will make available the information necessary to demonstrate compliance with this agreement and allow an audit conducted by you or an independent auditor you appoint. Audits are at your cost, arranged with at least 30 days’ notice, conducted during business hours, and must not disrupt the service or expose another customer’s data.
12International transfers
Some sub-processors are outside Switzerland and the EEA, including in the United States. Where a transfer is not covered by an adequacy decision, it is made under the European Commission’s Standard Contractual Clauses with the Swiss adaptations recognised by the Federal Data Protection and Information Commissioner, and you authorise us to enter into those clauses with sub-processors on your behalf.
13Liability, law and jurisdiction
The liability provisions of the Terms of Service apply to this agreement. It is governed by the substantive law of Switzerland, and the exclusive place of jurisdiction is the courts of Basel-Landschaft, Switzerland.
14Contact
For anything under this agreement, including a signed counterpart for your records, write to support@linkscout.io.