Data Processing Agreement
This Data Processing Agreement ("DPA") is concluded pursuant to Art. 28(3) GDPR between the customer accepting it, referred to in the Terms of Service as the Customer and in this DPA as the "Controller", and Linnx Solutions UG (haftungsbeschränkt), Kollwitzstraße 76, 10435 Berlin, Germany, Amtsgericht Charlottenburg HRB 290197 B, the "Processor".
This DPA forms an integral part of the Terms of Service at linnx.ai/terms and is accepted electronically at account creation. This satisfies Art. 28(9) GDPR, which requires the contract to be in writing, including in electronic form, and does not require a signature. A countersigned copy is available on request to legal@linnx.ai.
"Customer Data" means personal data retrieved from the LinkedIn account the Controller connects to the Service and held in the Controller's Linnx account, together with the data the Controller adds within the Service. "Aggregated Data" has the meaning given in Clause 16 of the Terms of Service. Terms not defined here have the meaning given in the GDPR or in the Terms of Service.
1. Roles
1.1 The Controller determines the purposes and means of the processing of Customer Data. The Processor processes Customer Data solely on the documented instruction of the Controller.
1.2 The Controller is the controller in respect of all Customer Data, including personal data relating to its correspondents and connections.
1.3 The Processor is a controller, and this DPA does not apply, in respect of: account and authentication data of the Controller's own personnel, billing data, support correspondence, product usage data described in Section 7 of the Privacy Policy, and Aggregated Data created under Clause 3.6. That processing is governed by the Privacy Policy.
1.4 Where the Controller connects an artificial intelligence client of its own choosing (an "AI Client") through the interface implementing the Model Context Protocol (the "MCP Connector"), the Controller is the controller of the onward processing performed by that AI Client. The provider of that AI Client is not a subprocessor of the Processor. Clause 3.4 and Clause 7.7 apply.
2. Subject matter, nature and purpose
2.1 Subject matter. The provision of the Linnx service as described in the Terms of Service.
2.2 Duration. For the term of the Terms of Service and thereafter as provided in Clause 12.
2.3 Nature of the processing. Retrieval from the Controller's connected LinkedIn account through the Processor's access provider; storage; structuring; organisation; presentation to the Controller; transmission of Controller initiated actions to LinkedIn as set out in Clause 2.6; disclosure to an AI Client where the Controller connects one; anonymisation as set out in Clause 3.6; deletion.
2.4 Purpose. The provision of the Service to the Controller, and the creation of Aggregated Data on the Controller's instruction under Clause 3.6.
2.5 Automated processing. The Processor does not read the content of any message, connection request, post or comment in order to categorise, score, rank, prioritise, summarise, judge or otherwise assess it, its sender, or the Controller. This applies by any means, whether or not automated. It does not restrict the creation of Aggregated Data under Clause 3.6, from which no message, person or organisation can be identified.
The Processor takes no decision based solely on automated processing within the meaning of Art. 22 GDPR.
The Processor applies artificial intelligence and machine learning to Customer Data only as permitted by Clause 16.5 of the Terms of Service. Where a third party model is used, its provider is engaged as a subprocessor under Clause 7. Where the model is operated by the Processor within its own systems, no Customer Data is transmitted to any third party and no subprocessor is engaged. Subprocessors operate their own systems, which the Processor does not control, and may apply automated techniques within them to deliver, secure and maintain their services. Each is engaged under an agreement meeting Art. 28 GDPR which permits it to process Customer Data only on the Processor's behalf.
2.6 Operations taking effect on LinkedIn are limited to: sending a message in an existing chat; accepting a received connection invitation; declining a received connection invitation; withdrawing a sent connection invitation; and marking a chat as read, which occurs automatically when the Controller opens that chat in the Service. The first four occur only upon an explicit action taken by the Controller at that time. Where a chat is read by an AI Client through the MCP Connector, no read receipt is sent. No function available to an AI Client through the MCP Connector transmits anything to LinkedIn. All other operations take effect within the Service only.
2.7 Categories of data subject: the Controller and the natural person operating the account; the Controller's LinkedIn connections; persons who have sent or received messages to or from the Controller on LinkedIn; persons who have sent or received connection requests to or from the Controller; persons who have engaged with the Controller's posts.
2.8 Categories of personal data: name; professional headline; public LinkedIn profile link; profile picture; the Controller's own profile industry and location where available; message content and attachments including images, documents and voice notes; message metadata including timestamps, sender, recipient and read state; connection request content and status; post and comment text authored by the Controller; engagement metrics; archive and spam state; and data added by the Controller within the Service comprising categories, groups, favourites, notes, draft text and snooze times. Where LinkedIn or the access provider makes further categories available and the Processor begins to process them, the Privacy Policy is updated and the Controller is notified in accordance with Clause 13 of the Terms of Service.
2.9 Special categories of personal data are not intentionally processed. The Controller shall not use the Service to process data within Art. 9 or Art. 10 GDPR, except to the extent such data is incidentally contained in messages the Controller receives.
3. Instructions
3.1 The Processor processes Customer Data only on the documented instruction of the Controller, including as regards transfers to a third country, unless required to do otherwise by Union or Member State law. In such a case the Processor shall inform the Controller of that requirement before processing, unless the law prohibits it on important grounds of public interest.
3.2 The Terms of Service, this DPA, the Privacy Policy and the Controller's use of the functions of the Service together constitute the Controller's documented instructions.
3.3 The Processor shall inform the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
3.4 Where the Controller connects an AI Client, that act is the Controller's instruction to disclose Customer Data to it. The scope of that disclosure is set out in Clauses 6.2 to 6.5 of the Terms of Service, which the Controller accepts on creating an account.
3.5 Further instructions outside the functions of the Service require agreement in text form and the Processor may charge for their implementation.
3.6 Aggregated Data. The Controller instructs the Processor to create Aggregated Data from Customer Data. That instruction is subject to the following, which the Processor warrants:
(a) anonymisation is performed by the Processor within its own systems, by fixed rule based processing which produces the same result from the same input, and is irreversible within the meaning of Recital 26 GDPR;
(b) no artificial intelligence or machine learning is applied to Customer Data during the anonymisation itself;
(c) no Customer Data is transmitted to any third party for the purpose of creating Aggregated Data, other than as permitted by Clause 16.5 of the Terms of Service;
(d) Aggregated Data is derived only as permitted by Clause 16.2 of the Terms of Service, contains nothing listed in Clause 16.3 of the Terms of Service, and contains no special category of personal data within the meaning of Art. 9 GDPR.
This instruction does not permit any processing prohibited by Clause 2.5. Once created, Aggregated Data is not personal data, this DPA does not apply to it, and the Processor is not a processor in respect of it. Clause 16 of the Terms of Service governs its use.
4. Confidentiality
4.1 The Processor shall ensure that persons authorised to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4.2 Access to Customer Data is limited to those personnel who require it in order to perform the contract.
5. Security of processing
5.1 The Processor implements technical and organisational measures appropriate to the risk in accordance with Art. 32 GDPR, and reviews them on material change and at least annually. A current description of those measures is available to the Controller on request to privacy@linnx.ai.
5.2 The Processor may amend those measures provided the level of security is not reduced.
5.3 The Processor does not currently hold a third party security certification such as ISO 27001 or SOC 2, and makes no claim to hold one.
6. Personal data breach
6.1 The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data.
6.2 The notification shall describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact.
6.3 Where the information cannot be provided at once it may be provided in phases without undue further delay.
6.4 The Processor shall assist the Controller in fulfilling its obligations under Art. 33 and Art. 34 GDPR. Notification to a supervisory authority or to data subjects is the responsibility of the Controller.
7. Subprocessors
7.1 The Controller grants general written authorisation for the engagement of subprocessors, subject to this Clause.
7.2 The subprocessors engaged at the date of this DPA are listed in Annex 1 and at linnx.ai/subprocessors.
7.3 Each subprocessor is engaged under a written contract meeting the requirements of Art. 28 GDPR.
7.4 The Processor shall notify the Controller of any intended addition or replacement of a subprocessor, by electronic mail to the address registered on the account and by publication at linnx.ai/subprocessors, not less than thirty (30) days before that subprocessor begins processing Customer Data. Where a change is required urgently for security or legal reasons, notice is given as early as reasonably practicable.
7.5 The Controller may object on reasonable data protection grounds, in text form to legal@linnx.ai and stating those grounds, before the change takes effect. Where the Controller does not object before that date, the change is deemed accepted. An objection does not prevent the change from taking effect. Where the Controller objects and the parties cannot agree a resolution, the Controller may terminate the Terms of Service with effect from the date the change takes effect, and the Processor shall refund fees paid in respect of the unused remainder of the term.
7.6 The Processor remains fully liable to the Controller for the performance of each subprocessor's obligations.
7.7 The provider of an AI Client connected by the Controller under Clause 3.4 is not a subprocessor and is not subject to this Clause. Where the Processor engages that provider for its own purposes, it does so separately and not by reason of the Controller connecting that AI Client.
8. Data subject rights
8.1 Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, so far as possible, in fulfilling its obligation to respond to requests for the exercise of data subject rights under Chapter III GDPR.
8.2 Where a data subject addresses a request directly to the Processor, the Processor shall not respond on the merits and shall refer the request to the Controller without undue delay.
8.3 The Controller may delete all Customer Data by deleting the account, which deletes all associated records. Individual records are deleted on request to privacy@linnx.ai.
9. Assistance
9.1 The Processor shall assist the Controller in ensuring compliance with Art. 32 to Art. 36 GDPR, taking into account the nature of the processing and the information available to the Processor.
9.2 Assistance is provided by making available the description of measures referred to in Clause 5.1, the list of subprocessors, and this DPA. Assistance beyond that reasonably required may be charged at the Processor's then applicable rates.
10. Audit
10.1 The Processor shall make available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR.
10.2 The Processor discharges this obligation in the first instance by providing, on written request: the description of measures referred to in Clause 5.1, the list of subprocessors together with confirmation that Art. 28 compliant agreements are in place with each, and written responses to a reasonable security questionnaire.
10.3 Where that is not sufficient to demonstrate compliance, the Controller may conduct an audit, including an inspection, on thirty (30) days' written notice, not more than once in any twelve (12) month period, during ordinary business hours, subject to confidentiality undertakings and without unreasonable disruption to the Processor's operations. The Controller bears its own costs. A supervisory authority may audit without these restrictions.
11. International transfers
11.1 Where the Processor transfers Customer Data outside the European Economic Area, it shall ensure an appropriate safeguard under Chapter V GDPR.
11.2 The safeguard relied upon is the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Three (processor to processor), together with a transfer impact assessment and, where appropriate, supplementary measures.
11.3 Where a subprocessor is additionally certified under the EU-U.S. Data Privacy Framework, that certification is treated as a supplementary and not as the primary safeguard.
11.4 The transfer mechanism applicable to each subprocessor is stated in Annex 1.
12. Return and deletion
12.1 On termination of the Terms of Service, the Processor shall delete all Customer Data. At the choice of the Controller, the Processor shall first provide a copy of that data under Clause 12.3. Where the Controller makes no such request, deletion proceeds.
12.2 Deletion of live data occurs without undue delay following termination. Data held in encrypted backups is deleted on expiry of the backup cycle, during which it is not accessible for processing.
12.3 The Processor will provide an export of Customer Data on request to privacy@linnx.ai, at no charge and within one month of the request. A request may be made at any time while the account is active, and after termination for as long as the data has not yet been deleted under Clause 12.2.
12.4 The Processor may retain Customer Data to the extent required by Union or Member State law. Data so retained is restricted from further processing and is deleted on expiry of the applicable period.
12.5 Aggregated Data created under Clause 3.6 is not personal data. This Clause does not apply to it and it is unaffected by termination or by deletion of the Controller's Linnx account.
13. Liability and term
13.1 This DPA takes effect on acceptance and continues for so long as the Processor processes Customer Data on behalf of the Controller.
13.2 Liability between the parties is governed by Clause 12 of the Terms of Service. Liability towards data subjects under Art. 82 GDPR remains unaffected.
14. Precedence and final provisions
14.1 In the event of conflict, this DPA prevails over the Terms of Service in respect of the processing of personal data. In all other respects the Terms of Service prevail.
14.2 The Processor records the version of this DPA accepted by the Controller and the time of acceptance. The version accepted continues to govern until the Controller accepts a later version. Material amendments are notified in accordance with Clause 13 of the Terms of Service.
14.3 This DPA is governed by German law. The place of jurisdiction is Berlin.
14.4 Should any provision be invalid, the remainder is unaffected.
Annex 1: Subprocessors
The current list, including for each subprocessor its legal entity, purpose, location of processing and transfer mechanism, is maintained at linnx.ai/subprocessors and forms part of this DPA. Changes are notified in accordance with Clause 7.4.
Linnx Solutions UG (haftungsbeschränkt) Kollwitzstraße 76, 10435 Berlin, Germany legal@linnx.ai