Last updated: August 29, 2026
Our subprocessors
We do not sell personal data. We only share it with service providers that help us deliver the Platform, and only as far as needed. This page is the current overview of our sub-processors. For each one we list the purpose, where processing takes place, and the safeguard we rely on for any transfer outside the EEA — as set out in our Data Processing Agreement.
If we add or replace a sub-processor, we will let clients know in advance. You then have fourteen (14) days to object on reasonable grounds.
1. Supabase
Purpose: Database and hosting for the Platform (servers and database).
Processing location: Frankfurt, Germany (EEA)
Safeguard: Processing within the EEA. No transfer outside the EEA for the production database.
Data security and processing information:
2. Vercel
Purpose: Application hosting, compute, and edge delivery for the Platform.
Processing location: Primarily Frankfurt, Germany (fra1), with some platform operations in the United States.
Safeguard: EU processing where possible. Transfers outside the EEA under the EU-US Data Privacy Framework and/or Standard Contractual Clauses.
Data security and processing information:
3. Stripe
Purpose: Invoicing and payments. We receive payment statuses and invoice data; full card or bank details stay with Stripe.
Processing location: European Economic Area (Stripe Payments Europe) and the United States.
Safeguard: EU-US Data Privacy Framework and/or Standard Contractual Clauses.
Data security and processing information:
4. HubSpot
Purpose: CRM and marketing services (website forms, newsletters, and client communications).
Processing location: European Economic Area (including Frankfurt, Germany) and the United States.
Safeguard: EU-US Data Privacy Framework and/or Standard Contractual Clauses.
Data security and processing information:
5. Microsoft
Purpose: Communication and email services (Office 365).
Processing location: European Economic Area (including Amsterdam, Netherlands) and the United States.
Safeguard: EU-US Data Privacy Framework and/or Standard Contractual Clauses.
Data security and processing information:
6. GoLogin
Purpose: Secure browser environments for linked Channels (LinkedIn Live View and related outreach sessions).
Processing location: United States, with supporting infrastructure that may also process data in the EEA.
Safeguard: Standard Contractual Clauses, with additional measures where needed.
Data security and processing information:
7. Anthropic
Purpose: Linq AI via the business API (drafts, summaries, scores, enrichment). Data is used only to return the requested output — not to train their models.
Processing location: United States
Safeguard: EU-US Data Privacy Framework and/or Standard Contractual Clauses.
Data security and processing information:
8. OpenAI
Purpose: Linq AI via the business API (drafts, summaries, scores, enrichment). Data is used only to return the requested output — not to train their models.
Processing location: United States
Safeguard: EU-US Data Privacy Framework and/or Standard Contractual Clauses.
Data security and processing information:
9. Data enrichment providers
Purpose: Supplementing business contact and company data from public sources and license partners.
Processing location: EEA and, for some providers, the United States.
Safeguard: Adequacy decision (including the EU-US Data Privacy Framework) and/or Standard Contractual Clauses, plus extra measures where needed.
10. Channel automation partners
Purpose: Infrastructure for sending and receiving outreach via linked Channels, contracted under data processing agreements.
Processing location: EEA and, depending on the partner, other locations stated in their agreement with us.
Safeguard: Data processing agreements, plus an adequacy decision and/or Standard Contractual Clauses where data leaves the EEA.
Commitment to data protection
Each sub-processor is bound to the same or equivalent obligations as we are, including GDPR. Questions? Write to us at hello@linq.group.