Clear privacy information Version 1.0 Effective 12 July 2026

How Aerlinked uses and protects personal data.

This Privacy Policy explains what information we collect, where it comes from, why we process it, who may receive it, how long we retain it and how individuals can exercise privacy rights.

Applies to Aerlinked websites, accounts, lead search, CRM, billing, support and related services
Aerlinked Privacy Policy

Purpose first. Secure processing. Meaningful control.

TransparentUnderstand what data is used
Purpose-linkedProcessing connected to a defined need
ProtectedLayered security safeguards
ActionableAccessible privacy request routes
Hello@aerlinked.com

Questions, requests and grievances.

Controlled access

Raw lead data is not downloadable by users.

🛡
Layered safeguards

Access controls, encryption, logging and backups.

DPDP and GDPR

Regional rights and legal detail.

Scope Our role Data collected Lead directory Purposes Sharing Rights Contact
Scope

Where this Privacy Policy applies

This policy applies when you visit Aerlinked websites, create or use an account, search or unlock business leads, manage CRM records, purchase a plan, contact support, participate in referrals or otherwise interact with Aerlinked.

1.0 · 12 July 2026
This policy is the central privacy notice

Additional notices may apply to a specific form, feature, campaign or jurisdiction. The Aerlinked DPDP and GDPR centres provide more detailed regional information where those frameworks apply.

Privacy responsibility

Aerlinked may act in different privacy roles

The role depends on who determines why personal data is processed and the essential means used.

A

Aerlinked as controller or Data Fiduciary

Aerlinked generally determines the purposes of account registration, platform security, billing, support, service analytics, marketing preferences and its own lead-directory operations.

P

Aerlinked as processor

For certain customer-controlled CRM content, Aerlinked may process information on behalf of the customer organisation under its instructions and the applicable service agreement.

Production identity requirement

Before publication, this policy should identify Aerlinked’s registered legal entity, registered address and any formally appointed privacy representative or Data Protection Officer.

Data categories

Personal data we may collect and process

The information depends on the features you use, your organisation settings, your relationship with Aerlinked and applicable law.

CategoryExamplesTypical use
Account and identityName, business email, mobile number, login identifier, verification information and profile details.Registration, authentication, account administration and communication.
Organisation informationBusiness name, email domain, role, team membership, organisation settings and access permissions.Organisation grouping, collaboration, ownership and duplicate-protection controls.
Lead-search activitySearch filters, viewed records, unlock activity, credit usage, saved searches and organisation-sharing history.Providing lead search, managing credits, preventing repeat unlocks and improving relevance.
Professional lead dataName, professional role, employer, business email, business phone, website, location, industry and source information.Business lead discovery, quality review, correction, suppression and lawful B2B use.
CRM contentContacts, notes, deals, task details, follow-up history, ownership and communications metadata.Customer-controlled relationship and sales-workflow management.
Billing and taxPlan, payment status, billing address, tax information, invoice details and refund references.Subscription, payment, invoicing, accounting, taxation and dispute resolution.
Support and grievance dataTickets, messages, attachments, complaints, replies, evidence and request references.Support, data-quality review, rights handling, grievance redressal and service improvement.
Device and security dataIP address, browser, device, operating system, session, timestamps, request identifiers, logs and risk signals.Authentication, fraud prevention, monitoring, audit, incident response and reliability.
Consent and preferencesMarketing choices, cookie preferences, withdrawals, objections, suppression and consent records.Honouring choices and demonstrating how and when a preference changed.
Referral and campaign dataReferral code, inviter, invited business email, reward status and campaign engagement.Operating authorised referral, promotion and reward programmes.
Business lead directory

How professional and business contact data is handled

Aerlinked may provide professional and business information from lawful public, licensed, contributed or authorised sources. Availability of information does not remove privacy, accuracy, marketing or source-use obligations.

Src

Source controls

Sources should be assessed for lawful availability, relevant terms, business context and appropriate collection.

Min

Controlled visibility

Selected information may be masked until a user spends a credit or receives authorised organisation access.

No

No raw database download

Users cannot download or scrape the complete underlying lead database.

Fix

Correction and quality

Individuals and users may report inaccurate, outdated or mismatched professional information.

Obj

Objection and suppression

Where applicable, Aerlinked may restrict, suppress, correct or remove a record after reviewing a valid request.

B2B

Business-purpose expectations

Users must use professional data only for genuine, lawful and relevant business purposes.

Publicly available does not mean unrestricted

Professional information obtained from public sources remains subject to applicable privacy, direct-marketing, anti-spam, confidentiality and source restrictions. Users must honour objections and do-not-contact requests.

Sources

Where personal data may come from

You

Directly from you

Registration, CRM use, billing, support, referrals, consent and privacy requests.

Org

Your organisation

Team invitations, domain verification, permissions, ownership and imported CRM content.

Pub

Public business sources

Business websites, directories, professional profiles, public registers and other lawful public sources.

Lic

Licensed or authorised providers

Data suppliers, verification providers, integrations and authorised contributors operating under applicable terms.

Sys

Automatically

Technical, session, usage, device, audit and security data generated through use of the platform.

Pay

Service providers

Payment status, message delivery, verification and integration events returned by authorised providers.

Processing purposes

Why Aerlinked processes personal data

Provide the service

Create accounts, deliver lead search, process unlocks, manage CRM and support organisation collaboration.

Manage plans and billing

Process subscriptions, allocate credits, issue invoices, reconcile payments and handle refunds.

🛡

Protect users and systems

Authenticate users, detect misuse, prevent fraud, maintain logs and respond to incidents.

?

Support and grievances

Respond to enquiries, investigate lead quality, resolve disputes and fulfil privacy requests.

Improve Aerlinked

Measure reliability, diagnose errors, understand feature use and improve product workflows.

Communicate

Send service, security, billing and support messages, plus optional marketing where permitted.

B2B

Operate lead discovery

Organise, validate, display, mask and provide controlled access to relevant professional information.

Law

Meet legal obligations

Maintain required records, respond to lawful requests and establish, exercise or defend legal claims.

Ref

Operate referrals

Track valid invitations, prevent abuse and allocate referral rewards or promotional benefits.

Cookies and similar technologies

Essential functions are separated from optional tracking

Aerlinked may use cookies, local storage, pixels or similar technologies to provide security, remember settings, understand usage and support communications.

CategoryPurposeChoice
Strictly necessaryAuthentication, session security, load balancing, fraud prevention and requested service functions.Required for the service and not disabled through the optional preference centre.
FunctionalRemember interface, language, workspace and user-selected preferences.Can be controlled where the feature is optional.
AnalyticsUnderstand usage, performance, errors and feature engagement.Used according to applicable consent and privacy requirements.
MarketingMeasure campaigns, manage communications and tailor optional offers.Used only where permitted and selected.
Recipients and processors

Who may receive or process personal data

Cloud

Infrastructure providers

Hosting, storage, monitoring, email delivery, customer support and technical operations.

Payment and finance providers

Payment gateways, banks, accounting, tax and fraud-prevention services.

API

Authorised integrations

Applications connected by Aerlinked or by an authorised user within the configured permission scope.

Data

Data and verification providers

Lawful lead-data, validation, enrichment, source and accuracy services operating under appropriate terms.

Org

Your organisation

Authorised team members where shared access, ownership, organisation unlocks or collaboration is enabled.

Law

Authorities and advisers

Courts, regulators, law enforcement, auditors and professional advisers where disclosure is lawful.

M&A

Business transactions

Appropriately protected disclosures in connection with financing, merger, acquisition or asset transfer.

You

At your direction

Recipients selected by you through exports, sharing, integrations or other authorised actions.

Pub

Public areas

Information you intentionally publish in a public feature, subject to the feature notice and your settings.

Aerlinked does not sell user conversations to advertisers

Where marketing or analytics providers are used, they should receive only the information reasonably required for the approved purpose and remain subject to applicable contractual and legal controls.

International processing

Personal data may be processed across borders

Aerlinked may operate from India and use providers in India or other countries. Where cross-border safeguards are legally required, Aerlinked aims to use an appropriate transfer mechanism and additional controls.

Adeq

Adequacy or permitted destinations

Use recognised destinations or transfers allowed under the applicable legal framework.

SCC

Contractual safeguards

Use approved contractual clauses or equivalent processor and transfer protections where required.

Risk

Transfer assessment

Review destination risk, provider access, sensitivity and supplementary technical controls.

Min

Data minimisation

Limit transferred data, control access and use encryption or pseudonymisation where appropriate.

Gov

Government restrictions

Review applicable restrictions, notifications or localisation obligations.

Mon

Ongoing review

Monitor providers, transfer mechanisms, legal developments and security controls.

Retention and deletion

We retain personal data only for a justified period

Retention depends on the purpose, account relationship, customer instructions, legal obligations, security needs, disputes and deletion workflows.

InformationGeneral approachDeletion or review trigger
Account and organisationDuring the relationship and for a limited period needed for recovery, security, disputes and legal records.Verified account deletion, organisation closure and completion of lawful retention.
Lead-directory dataReviewed according to source, accuracy, relevance, objection, suppression and business need.Correction, source change, valid objection, removal request or expiry of the business need.
CRM contentRetained according to customer use, deletion settings, account status and backup lifecycle.Customer deletion, account closure, contract termination or configured retention policy.
Billing and taxRetained for applicable tax, accounting, payment and dispute periods.Expiry of the applicable statutory and claims period.
Support and privacy requestsRetained through resolution and for a proportionate accountability or recurrence-prevention period.Closure of the matter and expiry of the relevant retention need.
Security and audit logsRetained for a defined period based on fraud, security, audit and legal requirements.Expiry of the applicable period and absence of an investigation or legal hold.
Consent and suppressionRetained as needed to demonstrate choices and prevent unwanted re-contact or reintroduction.When no longer needed for accountability, suppression or legal compliance.
Backups and legal holds

Deleted data may remain temporarily in restricted backups until the backup lifecycle completes. Deletion may be delayed where information is needed for security, fraud review, disputes, legal claims or statutory obligations.

Security

Layered safeguards designed around risk

EEncryption and masking

Appropriate encryption, masking, obfuscation, hashing or token-based protection.

AAccess controls

Authentication, MFA, role permissions, least privilege and privileged-action controls.

LLogging and monitoring

Audit logs, security events, anomaly detection and investigation support.

BBackup and resilience

Encrypted backups, restore processes, continuity controls and service recovery.

VVendor controls

Processor due diligence, contractual safeguards and incident obligations.

TTesting and review

Vulnerability management, periodic testing and effectiveness review.

DData lifecycle controls

Purpose-linked collection, restricted access, retention and secure deletion.

RIncident response

Detection, containment, assessment, notification, remediation and lessons learned.

No system is completely risk-free

Aerlinked uses reasonable safeguards, but no transmission or storage method can guarantee absolute security. Users must protect credentials, devices, exports and connected systems.

Individual rights

Privacy rights depend on the applicable law

Rights may be subject to identity verification, exemptions, customer-controller responsibilities, legal holds and lawful retention requirements.

01

Access or information

Request information about personal data processed and, where applicable, receive a copy.

02

Correction or completion

Ask Aerlinked to correct inaccurate, misleading or incomplete information.

03

Erasure or deletion

Request deletion where retention is no longer justified or required.

04

Restriction or suppression

Ask Aerlinked to restrict use, suppress a lead record or pause disputed processing where applicable.

05

Object or opt out

Object to applicable processing and opt out of direct marketing or optional communications.

06

Withdraw consent

Withdraw consent for future consent-based processing without affecting earlier lawful use.

07

Portability

Receive qualifying information in a structured, commonly used and machine-readable format where applicable.

08

Grievance or complaint

Raise a privacy grievance with Aerlinked and approach a competent authority where legally available.

09

Automated decision safeguards

Request applicable information or human review for qualifying solely automated decisions.

10

Nomination

Where Indian law applies, nominate another individual to exercise rights in the event of death or incapacity.

Customer-controlled CRM content

Customers remain responsible for data they place into CRM

Where an organisation determines why personal data is placed into Aerlinked CRM, that organisation must ensure it has an appropriate legal basis, provides required notices and respects individual rights.

Law

Lawful collection

Do not upload or use personal data without appropriate authority or legal basis.

Min

Data minimisation

Store only information reasonably needed for the professional relationship or workflow.

No

No unnecessary sensitive data

Avoid health, identity, payment credentials or other sensitive information in notes unless clearly authorised and protected.

Acc

Accuracy

Update ownership, contact details and status where errors could cause inappropriate outreach.

Del

Retention

Delete or archive records when no longer needed, subject to lawful suppression or claims records.

Req

Rights cooperation

Customers must assist with requests relating to data for which they are the controller or Data Fiduciary.

Automated processing

Risk signals and recommendations support human decisions

No intended solely automated legal decisions

Aerlinked is not designed to make decisions about individuals based solely on automated processing that produce legal or similarly significant effects. Lead-quality indicators, duplicate signals, fraud alerts and recommendations are intended to support human review.

Children’s privacy

Aerlinked is designed for adult business users

Not directed to children

Aerlinked is not intended for individuals under 18. We do not knowingly seek to create accounts for children or use children’s data for tracking, behavioural monitoring or targeted advertising. Contact Hello@aerlinked.com if you believe child data has been submitted.

Incident response

How Aerlinked responds to a personal-data breach

1Detect and contain

Validate the incident, limit exposure and preserve evidence.

2Assess impact

Identify affected data, people, systems, timing and likely consequences.

3Notify where required

Provide legally required information to affected individuals, customers and authorities.

4Remediate and improve

Reduce risk, prevent recurrence and document corrective measures.

Contact and grievance redressal

Questions and privacy requests

Contact Aerlinked first so we can investigate, verify the request where appropriate and provide a tracked response.

Aerlinked Privacy & Grievance Team

For data access, correction, deletion, suppression, objections, consent withdrawal, lead-record concerns or another privacy question.

Hello@aerlinked.com Subject: Privacy Request Use your registered or verifiable email
Authority complaints

Depending on the applicable law, you may also have the right to complain to the Data Protection Board of India, an EU/EEA supervisory authority or another competent privacy regulator after or alongside the available Aerlinked process.

Policy updates

Changes to this Privacy Policy

We may update this policy

Aerlinked may revise this policy to reflect product, vendor, legal or operational changes. Material changes may be communicated through the website, account notifications or email. The effective date and version will be updated above.

Official references

Privacy framework documents

Official legal texts and subsequent notifications prevail over this plain-language policy.

Legal review before publication

This design must be aligned with Aerlinked’s actual registered entity, address, processors, hosting locations, payment providers, analytics tools, lead-data sources, retention periods and operational workflows before it is published as a binding privacy policy.

Frequently asked questions

Privacy answers in plain language

No. Aerlinked does not allow users to download, scrape or reconstruct the complete raw lead database. Access is provided through controlled search, preview and unlock workflows.
You may submit a correction, objection, suppression or erasure request. Aerlinked will verify the relevant record, source and applicable legal framework before responding.
Active account data may be deleted or deactivated after verification, but restricted backups, invoices, security logs, suppression records or legal-claims information may remain for a limited justified period.
The customer organisation generally determines why its CRM content is processed and remains responsible for legal basis, notices, accuracy and rights. Aerlinked may act as its processor for that content.
Yes. Optional marketing and editorial preferences should be managed separately from necessary account, billing, security and support communications.
Use the privacy request button on this page or email Hello@aerlinked.com with the subject “Privacy Request.” Include enough information to locate the relevant account or record, but do not send unnecessary identity documents.