GDPR enquiries and data-subject requests.
When the GDPR may apply to Aerlinked
The GDPR can apply to organisations established in the EU/EEA and, in certain circumstances, to organisations outside the EU/EEA that offer goods or services to people in the Union or monitor their behaviour there.
This page describes Aerlinked’s intended GDPR controls where the Regulation applies. Merely making a website accessible from the EU does not by itself establish that services are offered to people in the Union.
EU/EEA establishment
GDPR applies to processing in the context of an EU/EEA establishment, regardless of where the processing takes place.
Offering services
GDPR may apply where Aerlinked intentionally offers goods or services to people located in the Union.
Behaviour monitoring
GDPR may apply where behaviour in the Union is monitored, including certain tracking or profiling activities.
Aerlinked may act as controller or processor
The role depends on who decides the purpose and essential means of processing.
Controller
Aerlinked is generally a controller for account registration, platform security, billing, service analytics, marketing choices, support and its own lead-directory operations.
Processor
Aerlinked may act as a processor where an organisation determines why and how personal data is entered into or managed through CRM features, subject to the applicable agreement.
Users and organisations must have an appropriate legal basis for personal data they upload, enrich, contact or manage through Aerlinked and must provide required notices to the individuals concerned.
Personal data Aerlinked may process
| Category | Examples | Typical context |
|---|---|---|
| Identity and account | Name, business email, mobile number, identifiers, role and verification records. | Registration, account management, authentication and support. |
| Organisation data | Business name, domain, team membership, organisation settings and ownership. | Organisation grouping, collaboration and duplicate-protection controls. |
| Lead-directory data | Professional contact details, business role, employer, location, source and validation status. | Business lead search and related compliance, accuracy and objection handling. |
| CRM content | Contacts, notes, deal information, tasks, follow-up history and communications metadata. | User-controlled relationship management and sales workflows. |
| Billing data | Plan, payment status, billing address, tax identifiers, invoices and refund references. | Contract administration, payment, accounting and legal compliance. |
| Support data | Tickets, messages, attachments, grievances, replies and evidence. | Customer support, dispute resolution and rights handling. |
| Technical and security data | IP address, browser, device, session, timestamps, request IDs, logs and risk signals. | Security, authentication, fraud prevention, audit and service reliability. |
| Consent and preferences | Consent records, withdrawals, cookie choices, objections and marketing preferences. | Demonstrating and respecting user choices. |
Why Aerlinked processes personal data
Provide the platform
Create accounts, deliver lead search and CRM, maintain organisation access and provide requested features.
Administer contracts
Manage plans, payments, credits, invoices, renewals and related customer communication.
Protect users and systems
Prevent misuse, detect suspicious activity, maintain audit evidence and respond to incidents.
Support and rights
Answer questions, resolve complaints, investigate data quality and fulfil privacy requests.
Improve the service
Measure reliability, diagnose errors, improve workflows and develop product features.
Communicate
Send essential service messages and optional updates or offers where lawful and selected.
Lawful bases used for processing
Aerlinked maps each processing purpose to an appropriate lawful basis. The applicable basis depends on the data, purpose and relationship.
| Lawful basis | How Aerlinked may use it | Important limitation |
|---|---|---|
| Contract | Providing requested account, CRM, subscription, billing and support services. | Used only where processing is objectively necessary to perform or enter into a contract. |
| Legitimate interests | Platform security, fraud prevention, service improvement, limited B2B operations and internal administration. | Subject to necessity, balancing and the individual’s interests, rights and reasonable expectations. |
| Consent | Optional marketing, certain cookies, optional analytics or another purpose requiring freely given choice. | Consent can be withdrawn without affecting earlier lawful processing. |
| Legal obligation | Tax, accounting, lawful authority requests and other mandatory record-keeping. | The obligation must arise under applicable EU or Member State law where GDPR is relied upon. |
| Vital interests | Exceptional situations involving protection of life or serious physical safety. | Not intended as a routine basis for Aerlinked services. |
| Public task | Only where a specific task in the public interest or official authority lawfully applies. | Not intended as a routine basis for Aerlinked’s commercial operations. |
Aerlinked is not designed for intentional processing of special-category data through ordinary lead-search or CRM workflows. Users should not upload health, biometric, political, religious, trade-union, sexual-orientation or similar sensitive information unless a valid Article 9 condition and appropriate safeguards clearly apply.
Where personal data may come from
Directly from individuals
Registration, support, billing, consent, CRM use and data-subject requests.
Customers and organisations
Team invitations, contact imports, CRM records, ownership and organisation settings.
Public or authorised sources
Lawful professional and business sources, subject to transparency and objection controls.
Automatically
Device, usage, session, security and operational data generated through the service.
Service providers
Payment status, delivery confirmations, verification and technical integration events.
Referrals or authorised users
Information submitted through referral, invitation or authorised collaboration features.
Optional choices are separated from essential processing
Where consent is the lawful basis, Aerlinked aims to make the choice specific, informed, unambiguous and as easy to withdraw as to give.
Explain the controller, purpose, data and withdrawal route.
No pre-ticked consent for optional purposes.
Store version, context, timestamp and preference.
Stop future consent-based processing promptly.
Non-essential cookies or tracking technologies should be activated only after the required consent under applicable ePrivacy and national rules. Essential security, login and service cookies are managed separately.
Your GDPR rights
Rights are subject to verification, scope, exemptions and lawful retention requirements.
Right to be informed
Receive clear information about the controller, purposes, lawful bases, recipients, retention, transfers and rights.
Access
Obtain confirmation, a copy of personal data and information about the processing.
Rectification
Correct inaccurate personal data and complete information that is incomplete.
Erasure
Request deletion in applicable circumstances, subject to legal grounds for continued processing.
Restriction
Request restricted processing while accuracy, lawfulness or an objection is being assessed.
Data portability
Receive qualifying data in a structured, commonly used and machine-readable format.
Object
Object to processing based on legitimate interests or public task and object at any time to direct marketing.
Automated decisions
Seek safeguards relating to qualifying decisions based solely on automated processing with legal or similarly significant effects.
Withdraw consent
Withdraw consent at any time for future consent-based processing.
Complain
Lodge a complaint with the competent EU/EEA supervisory authority.
How Aerlinked handles GDPR requests
Use the GDPR request form or email Hello@aerlinked.com.
We may request proportionate proof where identity is reasonably uncertain.
Locate data, review controller roles, exemptions, retention and third-party impacts.
Normally within one month, with reasons and next steps where action is limited.
The response period may be extended by up to two further months where necessary because of complexity or the number of requests. The individual should be informed of the extension and reasons within the initial one-month period.
Retention linked to purpose and legal need
| Information | General approach | Relevant considerations |
|---|---|---|
| Account and organisation | Retained during the relationship and for a limited period after closure. | Recovery, security, legal claims, billing and required records. |
| CRM content | Controlled by the customer or organisation, subject to account and backup cycles. | Customer instructions, contract, deletion settings and processor obligations. |
| Lead-directory data | Reviewed for relevance, accuracy, objection, source and business need. | Professional context, transparency, suppression and objection records. |
| Billing records | Retained for applicable tax, accounting, payment and dispute periods. | Legal obligation and establishment, exercise or defence of claims. |
| Support and rights requests | Retained through resolution and for a proportionate accountability period. | Identity checks, decision evidence, recurrence prevention and complaints. |
| Security logs | Retained for a defined period based on security and investigation needs. | Threat detection, fraud prevention, incident response and audit. |
Who may receive personal data
Infrastructure providers
Hosting, storage, monitoring, communications and support providers under processor terms.
Payment and finance
Payment gateways, banks, tax, accounting and fraud-prevention providers.
Authorised integrations
Applications connected through customer or Aerlinked-approved integration scopes.
Authorities and advisers
Courts, regulators, law enforcement and professional advisers where lawful.
Customer organisations
Authorised organisation members where access, ownership or collaboration is configured.
Business transactions
Protected disclosure in connection with financing, restructuring, merger or acquisition.
International data transfers
Because Aerlinked may operate from India and use global providers, covered EU/EEA personal data may be transferred outside the EEA.
Adequacy decisions
Transfers to a country, territory or organisation recognised by the European Commission as providing adequate protection.
Standard Contractual Clauses
Commission-approved clauses, supported by transfer assessments and supplementary measures where needed.
Other safeguards
Binding corporate rules, approved codes, certification or another Article 46 mechanism where available.
Limited derogations
Article 49 exceptions used only where their specific conditions are met and not as a routine transfer mechanism.
Transfer assessment
Assessment of destination-country law, practical access risk, data sensitivity and additional safeguards.
Data minimisation
Limit transferred data, control access, encrypt or pseudonymise where appropriate and monitor providers.
Where applicable, a data subject may request information about the transfer safeguard relevant to their personal data, subject to confidentiality and security restrictions.
Risk-based technical and organisational measures
Appropriate encryption, tokenisation, masking or pseudonymisation based on system risk.
Authentication, MFA, role permissions, least privilege and privileged-action controls.
Audit logs, anomaly signals, security monitoring and investigation support.
Encrypted backups, restore testing, continuity planning and service recovery controls.
Security due diligence, written terms, sub-processor controls and incident obligations.
Periodic evaluation, vulnerability management and effectiveness review of safeguards.
Data minimisation, default restrictions, purpose controls and lifecycle management.
Detection, containment, assessment, notification, remediation and lessons learned.
Personal-data breach response
Validate the incident, restrict exposure and preserve evidence.
Identify affected data, people, scope, likelihood and severity of harm.
Notify the competent authority within 72 hours where required and communicate high-risk breaches to individuals without undue delay.
Reduce impact, prevent recurrence and document the decision and measures.
Where Aerlinked acts as a processor, it should notify the relevant controller without undue delay after becoming aware of a personal-data breach, in accordance with the data-processing agreement.
Profiling and automated decision-making
Aerlinked is not designed to make decisions about individuals based solely on automated processing that produce legal or similarly significant effects. Risk signals, lead-quality indicators and recommendations are intended to support human review and platform security.
Meaningful information
Where Article 22 applies, provide appropriate information about the logic involved and expected consequences.
Human intervention
Provide a route to obtain human review, express a point of view and contest a qualifying decision.
Bias and accuracy
Review data quality, proportionality and the risk of unfair or discriminatory outcomes.
Aerlinked is a business platform for adults
Aerlinked is not intended for children. Where consent-based online services are offered directly to a child, applicable Member State age rules and parental-authorisation requirements would need to be addressed before processing.
EU representative and Data Protection Officer
EU representative
Where Article 27 requires Aerlinked to appoint an EU representative, the representative’s identity and contact details will be published here before covered EU-facing processing begins.
Data Protection Officer
Aerlinked will appoint and publish a DPO where Article 37 or applicable Member State law requires one. Until then, privacy enquiries are handled through Hello@aerlinked.com.
Do not publish invented representative or DPO details. The final live page must identify Aerlinked’s legal entity, registered address, and any formally appointed EU representative or DPO.
Questions, complaints and regulatory contact
Aerlinked encourages individuals to contact the Privacy Team first so the concern can be investigated promptly. This does not remove the right to complain to a competent supervisory authority.
Aerlinked Privacy Team
For GDPR questions, objections, rights requests, transfer information or a privacy complaint.
You may lodge a complaint with the supervisory authority in the EU/EEA country of your habitual residence, place of work, or the place of the alleged infringement. You may also seek a judicial remedy where applicable.
EU GDPR resources
This page is a public-facing explanation of Aerlinked’s intended GDPR approach. It does not replace the official Regulation, national law or legal advice. The production version must match Aerlinked’s real legal entity, systems, vendors, locations and processing records.