GDPR / RGPD Compliance
Last updated: March 1, 2026
1. Our Commitment to GDPR Compliance
LinkedBrief is fully committed to complying with the General Data Protection Regulation (GDPR/RGPD) — Regulation (EU) 2016/679 of the European Parliament and Council. We take the protection of your personal data seriously and have implemented comprehensive measures to ensure compliance.
This document supplements our Privacy Policy and specifically addresses the rights and protections afforded to individuals under the GDPR.
2. Data Controller
LinkedBrief acts as the Data Controller for personal data collected through our Service. This means we determine the purposes and means of processing your personal data.
Data Controller: LinkedBrief SAS
Contact: dpo@linkedbrief.com
Data Protection Officer (DPO): Available at dpo@linkedbrief.com
3. Legal Basis for Processing
We process personal data under the following legal bases as defined in Article 6 of the GDPR:
- Consent (Art. 6(1)(a)): For marketing communications, cookies, and optional data processing. You can withdraw consent at any time.
- Contract Performance (Art. 6(1)(b)): Processing necessary to provide our Service — account management, sequence generation, lead management, and meeting booking.
- Legitimate Interest (Art. 6(1)(f)): For product improvement, fraud prevention, security, and basic analytics. We have conducted Legitimate Interest Assessments (LIAs) for these activities.
- Legal Obligation (Art. 6(1)(c)): For compliance with tax, accounting, and regulatory requirements.
4. Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights. We will respond to all requests within 30 days (extendable by 60 days for complex requests, with notification).
4.1 Right of Access (Article 15)
You have the right to obtain confirmation of whether we process your personal data and to receive a copy of that data in a commonly used electronic format.
4.2 Right to Rectification (Article 16)
You can request the correction of inaccurate personal data or the completion of incomplete data. You can also update most information directly in your account settings.
4.3 Right to Erasure — "Right to Be Forgotten" (Article 17)
You can request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when you object to processing. Certain data may be retained if required by law.
4.4 Right to Restriction of Processing (Article 18)
You can request that we limit the processing of your personal data in certain circumstances — for example, while we verify the accuracy of data you have contested.
4.5 Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format (e.g., JSON or CSV) and to transmit that data to another controller.
4.6 Right to Object (Article 21)
You can object to the processing of your personal data based on legitimate interest at any time. We will cease processing unless we demonstrate compelling legitimate grounds.
4.7 Right Not to Be Subject to Automated Decision-Making (Article 22)
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. Our AI-generated sequences are tools — all final decisions about sending messages remain with you.
5. Data Processing Activities
We maintain a Record of Processing Activities (ROPA) as required by Article 30. Key processing activities include:
- Account registration and authentication
- URL and document analysis for offer extraction
- AI-powered sequence generation
- Lead data storage and management
- Calendar integration for meeting booking
- Payment processing via Stripe
- Analytics and product improvement
- Customer support communications
6. Sub-Processors
We use the following categories of sub-processors to deliver the Service. All sub-processors are bound by Data Processing Agreements (DPAs) that ensure GDPR compliance:
- Cloud Infrastructure: Hosting, storage, and computing (EU and US data centers with SCCs)
- Payment Processing: Stripe (PCI DSS Level 1 certified)
- AI Processing: OpenAI (data not used for training per our agreement)
- Email Delivery: Transactional email services
- Analytics: Privacy-focused analytics tools
7. International Data Transfers
When personal data is transferred outside the EEA, we ensure adequate protection through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- EU-US Data Privacy Framework certification (where applicable)
- Supplementary security measures as recommended by the EDPB
8. Data Breach Notification
In accordance with Articles 33 and 34 of the GDPR, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach
- Notify affected individuals without undue delay if the breach is likely to result in a high risk to rights and freedoms
- Document all breaches, including facts, effects, and remedial actions taken
9. Data Protection Impact Assessments
We conduct Data Protection Impact Assessments (DPIAs) for processing activities that are likely to result in high risk to individuals, including our AI-powered sequence generation and lead management features.
10. Cookie Consent
In compliance with the ePrivacy Directive and GDPR, we obtain explicit consent before setting non-essential cookies. You can manage your cookie preferences at any time through our cookie banner or by contacting us.
11. Exercising Your Rights
To exercise any of your GDPR rights, you can:
- Email our DPO at dpo@linkedbrief.com
- Use the data management tools in your account settings
- Contact us via our contact page
We may need to verify your identity before processing your request. All requests are free of charge unless manifestly unfounded or excessive.
12. Supervisory Authority
If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.
The French supervisory authority is:
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
Website: www.cnil.fr
13. Updates
This GDPR policy is reviewed and updated regularly. Material changes will be communicated to you at least 30 days before they take effect. The "Last updated" date at the top of this page indicates the most recent revision.