Questions, requests and grievances.
Where this Privacy Policy applies
This policy applies when you visit Aerlinked websites, create or use an account, search or unlock business leads, manage CRM records, purchase a plan, contact support, participate in referrals or otherwise interact with Aerlinked.
Additional notices may apply to a specific form, feature, campaign or jurisdiction. The Aerlinked DPDP and GDPR centres provide more detailed regional information where those frameworks apply.
Aerlinked may act in different privacy roles
The role depends on who determines why personal data is processed and the essential means used.
Aerlinked as controller or Data Fiduciary
Aerlinked generally determines the purposes of account registration, platform security, billing, support, service analytics, marketing preferences and its own lead-directory operations.
Aerlinked as processor
For certain customer-controlled CRM content, Aerlinked may process information on behalf of the customer organisation under its instructions and the applicable service agreement.
Before publication, this policy should identify Aerlinked’s registered legal entity, registered address and any formally appointed privacy representative or Data Protection Officer.
Personal data we may collect and process
The information depends on the features you use, your organisation settings, your relationship with Aerlinked and applicable law.
| Category | Examples | Typical use |
|---|---|---|
| Account and identity | Name, business email, mobile number, login identifier, verification information and profile details. | Registration, authentication, account administration and communication. |
| Organisation information | Business name, email domain, role, team membership, organisation settings and access permissions. | Organisation grouping, collaboration, ownership and duplicate-protection controls. |
| Lead-search activity | Search filters, viewed records, unlock activity, credit usage, saved searches and organisation-sharing history. | Providing lead search, managing credits, preventing repeat unlocks and improving relevance. |
| Professional lead data | Name, professional role, employer, business email, business phone, website, location, industry and source information. | Business lead discovery, quality review, correction, suppression and lawful B2B use. |
| CRM content | Contacts, notes, deals, task details, follow-up history, ownership and communications metadata. | Customer-controlled relationship and sales-workflow management. |
| Billing and tax | Plan, payment status, billing address, tax information, invoice details and refund references. | Subscription, payment, invoicing, accounting, taxation and dispute resolution. |
| Support and grievance data | Tickets, messages, attachments, complaints, replies, evidence and request references. | Support, data-quality review, rights handling, grievance redressal and service improvement. |
| Device and security data | IP address, browser, device, operating system, session, timestamps, request identifiers, logs and risk signals. | Authentication, fraud prevention, monitoring, audit, incident response and reliability. |
| Consent and preferences | Marketing choices, cookie preferences, withdrawals, objections, suppression and consent records. | Honouring choices and demonstrating how and when a preference changed. |
| Referral and campaign data | Referral code, inviter, invited business email, reward status and campaign engagement. | Operating authorised referral, promotion and reward programmes. |
How professional and business contact data is handled
Aerlinked may provide professional and business information from lawful public, licensed, contributed or authorised sources. Availability of information does not remove privacy, accuracy, marketing or source-use obligations.
Source controls
Sources should be assessed for lawful availability, relevant terms, business context and appropriate collection.
Controlled visibility
Selected information may be masked until a user spends a credit or receives authorised organisation access.
No raw database download
Users cannot download or scrape the complete underlying lead database.
Correction and quality
Individuals and users may report inaccurate, outdated or mismatched professional information.
Objection and suppression
Where applicable, Aerlinked may restrict, suppress, correct or remove a record after reviewing a valid request.
Business-purpose expectations
Users must use professional data only for genuine, lawful and relevant business purposes.
Professional information obtained from public sources remains subject to applicable privacy, direct-marketing, anti-spam, confidentiality and source restrictions. Users must honour objections and do-not-contact requests.
Where personal data may come from
Directly from you
Registration, CRM use, billing, support, referrals, consent and privacy requests.
Your organisation
Team invitations, domain verification, permissions, ownership and imported CRM content.
Public business sources
Business websites, directories, professional profiles, public registers and other lawful public sources.
Licensed or authorised providers
Data suppliers, verification providers, integrations and authorised contributors operating under applicable terms.
Automatically
Technical, session, usage, device, audit and security data generated through use of the platform.
Service providers
Payment status, message delivery, verification and integration events returned by authorised providers.
Why Aerlinked processes personal data
Provide the service
Create accounts, deliver lead search, process unlocks, manage CRM and support organisation collaboration.
Manage plans and billing
Process subscriptions, allocate credits, issue invoices, reconcile payments and handle refunds.
Protect users and systems
Authenticate users, detect misuse, prevent fraud, maintain logs and respond to incidents.
Support and grievances
Respond to enquiries, investigate lead quality, resolve disputes and fulfil privacy requests.
Improve Aerlinked
Measure reliability, diagnose errors, understand feature use and improve product workflows.
Communicate
Send service, security, billing and support messages, plus optional marketing where permitted.
Operate lead discovery
Organise, validate, display, mask and provide controlled access to relevant professional information.
Meet legal obligations
Maintain required records, respond to lawful requests and establish, exercise or defend legal claims.
Operate referrals
Track valid invitations, prevent abuse and allocate referral rewards or promotional benefits.
Legal bases depend on the applicable privacy framework
Aerlinked uses the legal ground appropriate to the purpose, jurisdiction, relationship and data involved.
| Ground | Examples of use | Important condition |
|---|---|---|
| Consent | Optional marketing, selected cookies, optional analytics or another purpose requiring affirmative choice. | Consent should be informed, specific and capable of withdrawal. |
| Contract or requested service | Account creation, subscriptions, CRM, support and requested platform features. | Processing must be reasonably necessary to perform or enter into the relevant service relationship. |
| Legitimate interests | Security, fraud prevention, service improvement, limited B2B operations and internal administration where GDPR applies. | Subject to necessity, balancing, expectations and applicable objection rights. |
| Legal obligation | Tax, accounting, lawful authority requests and mandatory records. | The obligation must be applicable to the relevant processing. |
| Certain legitimate uses or permitted processing | Processing allowed without consent in defined circumstances under applicable Indian law. | Used only where statutory conditions are met. |
| Legal claims and protection | Investigation, dispute resolution, fraud prevention and establishment, exercise or defence of claims. | Limited to what is necessary and appropriately protected. |
Essential functions are separated from optional tracking
Aerlinked may use cookies, local storage, pixels or similar technologies to provide security, remember settings, understand usage and support communications.
| Category | Purpose | Choice |
|---|---|---|
| Strictly necessary | Authentication, session security, load balancing, fraud prevention and requested service functions. | Required for the service and not disabled through the optional preference centre. |
| Functional | Remember interface, language, workspace and user-selected preferences. | Can be controlled where the feature is optional. |
| Analytics | Understand usage, performance, errors and feature engagement. | Used according to applicable consent and privacy requirements. |
| Marketing | Measure campaigns, manage communications and tailor optional offers. | Used only where permitted and selected. |
Who may receive or process personal data
Infrastructure providers
Hosting, storage, monitoring, email delivery, customer support and technical operations.
Payment and finance providers
Payment gateways, banks, accounting, tax and fraud-prevention services.
Authorised integrations
Applications connected by Aerlinked or by an authorised user within the configured permission scope.
Data and verification providers
Lawful lead-data, validation, enrichment, source and accuracy services operating under appropriate terms.
Your organisation
Authorised team members where shared access, ownership, organisation unlocks or collaboration is enabled.
Authorities and advisers
Courts, regulators, law enforcement, auditors and professional advisers where disclosure is lawful.
Business transactions
Appropriately protected disclosures in connection with financing, merger, acquisition or asset transfer.
At your direction
Recipients selected by you through exports, sharing, integrations or other authorised actions.
Public areas
Information you intentionally publish in a public feature, subject to the feature notice and your settings.
Where marketing or analytics providers are used, they should receive only the information reasonably required for the approved purpose and remain subject to applicable contractual and legal controls.
Personal data may be processed across borders
Aerlinked may operate from India and use providers in India or other countries. Where cross-border safeguards are legally required, Aerlinked aims to use an appropriate transfer mechanism and additional controls.
Adequacy or permitted destinations
Use recognised destinations or transfers allowed under the applicable legal framework.
Contractual safeguards
Use approved contractual clauses or equivalent processor and transfer protections where required.
Transfer assessment
Review destination risk, provider access, sensitivity and supplementary technical controls.
Data minimisation
Limit transferred data, control access and use encryption or pseudonymisation where appropriate.
Government restrictions
Review applicable restrictions, notifications or localisation obligations.
Ongoing review
Monitor providers, transfer mechanisms, legal developments and security controls.
We retain personal data only for a justified period
Retention depends on the purpose, account relationship, customer instructions, legal obligations, security needs, disputes and deletion workflows.
| Information | General approach | Deletion or review trigger |
|---|---|---|
| Account and organisation | During the relationship and for a limited period needed for recovery, security, disputes and legal records. | Verified account deletion, organisation closure and completion of lawful retention. |
| Lead-directory data | Reviewed according to source, accuracy, relevance, objection, suppression and business need. | Correction, source change, valid objection, removal request or expiry of the business need. |
| CRM content | Retained according to customer use, deletion settings, account status and backup lifecycle. | Customer deletion, account closure, contract termination or configured retention policy. |
| Billing and tax | Retained for applicable tax, accounting, payment and dispute periods. | Expiry of the applicable statutory and claims period. |
| Support and privacy requests | Retained through resolution and for a proportionate accountability or recurrence-prevention period. | Closure of the matter and expiry of the relevant retention need. |
| Security and audit logs | Retained for a defined period based on fraud, security, audit and legal requirements. | Expiry of the applicable period and absence of an investigation or legal hold. |
| Consent and suppression | Retained as needed to demonstrate choices and prevent unwanted re-contact or reintroduction. | When no longer needed for accountability, suppression or legal compliance. |
Deleted data may remain temporarily in restricted backups until the backup lifecycle completes. Deletion may be delayed where information is needed for security, fraud review, disputes, legal claims or statutory obligations.
Layered safeguards designed around risk
Appropriate encryption, masking, obfuscation, hashing or token-based protection.
Authentication, MFA, role permissions, least privilege and privileged-action controls.
Audit logs, security events, anomaly detection and investigation support.
Encrypted backups, restore processes, continuity controls and service recovery.
Processor due diligence, contractual safeguards and incident obligations.
Vulnerability management, periodic testing and effectiveness review.
Purpose-linked collection, restricted access, retention and secure deletion.
Detection, containment, assessment, notification, remediation and lessons learned.
Aerlinked uses reasonable safeguards, but no transmission or storage method can guarantee absolute security. Users must protect credentials, devices, exports and connected systems.
Privacy rights depend on the applicable law
Rights may be subject to identity verification, exemptions, customer-controller responsibilities, legal holds and lawful retention requirements.
Access or information
Request information about personal data processed and, where applicable, receive a copy.
Correction or completion
Ask Aerlinked to correct inaccurate, misleading or incomplete information.
Erasure or deletion
Request deletion where retention is no longer justified or required.
Restriction or suppression
Ask Aerlinked to restrict use, suppress a lead record or pause disputed processing where applicable.
Object or opt out
Object to applicable processing and opt out of direct marketing or optional communications.
Withdraw consent
Withdraw consent for future consent-based processing without affecting earlier lawful use.
Portability
Receive qualifying information in a structured, commonly used and machine-readable format where applicable.
Grievance or complaint
Raise a privacy grievance with Aerlinked and approach a competent authority where legally available.
Automated decision safeguards
Request applicable information or human review for qualifying solely automated decisions.
Nomination
Where Indian law applies, nominate another individual to exercise rights in the event of death or incapacity.
Customers remain responsible for data they place into CRM
Where an organisation determines why personal data is placed into Aerlinked CRM, that organisation must ensure it has an appropriate legal basis, provides required notices and respects individual rights.
Lawful collection
Do not upload or use personal data without appropriate authority or legal basis.
Data minimisation
Store only information reasonably needed for the professional relationship or workflow.
No unnecessary sensitive data
Avoid health, identity, payment credentials or other sensitive information in notes unless clearly authorised and protected.
Accuracy
Update ownership, contact details and status where errors could cause inappropriate outreach.
Retention
Delete or archive records when no longer needed, subject to lawful suppression or claims records.
Rights cooperation
Customers must assist with requests relating to data for which they are the controller or Data Fiduciary.
Risk signals and recommendations support human decisions
Aerlinked is not designed to make decisions about individuals based solely on automated processing that produce legal or similarly significant effects. Lead-quality indicators, duplicate signals, fraud alerts and recommendations are intended to support human review.
Aerlinked is designed for adult business users
Aerlinked is not intended for individuals under 18. We do not knowingly seek to create accounts for children or use children’s data for tracking, behavioural monitoring or targeted advertising. Contact Hello@aerlinked.com if you believe child data has been submitted.
How Aerlinked responds to a personal-data breach
Validate the incident, limit exposure and preserve evidence.
Identify affected data, people, systems, timing and likely consequences.
Provide legally required information to affected individuals, customers and authorities.
Reduce risk, prevent recurrence and document corrective measures.
Questions and privacy requests
Contact Aerlinked first so we can investigate, verify the request where appropriate and provide a tracked response.
Aerlinked Privacy & Grievance Team
For data access, correction, deletion, suppression, objections, consent withdrawal, lead-record concerns or another privacy question.
Depending on the applicable law, you may also have the right to complain to the Data Protection Board of India, an EU/EEA supervisory authority or another competent privacy regulator after or alongside the available Aerlinked process.
Changes to this Privacy Policy
Aerlinked may revise this policy to reflect product, vendor, legal or operational changes. Material changes may be communicated through the website, account notifications or email. The effective date and version will be updated above.
Privacy framework documents
Official legal texts and subsequent notifications prevail over this plain-language policy.
This design must be aligned with Aerlinked’s actual registered entity, address, processors, hosting locations, payment providers, analytics tools, lead-data sources, retention periods and operational workflows before it is published as a binding privacy policy.