01
Controller and contact channel
Linkses OÜ, company registration number 14547280, is the controller for data used to operate the Airbip website, evaluate invitations, manage accounts, contract services, bill customers, provide support and protect the platform.
Contact address: Avenida de España, 55, 37, Dos Hermanas, Sevilla, Spain. Privacy requests may be submitted through the contact form by identifying the request as a data-protection matter.
We may ask for proportionate information to verify identity before disclosing or changing personal data.
02
Controller and processor roles in cloud services
For account, billing, fraud-prevention and Airbip operational data, Linkses determines the purposes and means and therefore acts as controller.
When a customer uploads or generates personal data inside a hosted application for the customer’s own purposes, the customer will normally be the controller and Linkses may act as processor. That relationship, instructions, subject matter, duration, security assistance, deletion or return and subprocessor conditions should be documented in the applicable data-processing agreement.
The role depends on the actual processing activity, not only on the label used in a contract.
03
Categories of data we process
The data involved depends on the relationship and features used. We apply data minimisation and do not ask for special-category data through ordinary contact or invitation forms.
- Identity and contact data: name, organisation, language, email and information supplied in forms.
- Account and access data: user identifier, role, authentication events and security settings.
- Contract and billing data: selected services, order history, billing identity, address, tax context, payments and invoices.
- Support data: ticket messages, attachments, diagnostic details and actions taken.
- Technical data: IP address, timestamps, device or browser information, service health, security and audit events.
- Invitation and affiliate data: intended use, referral attribution and review status.
- Hosted customer data: content processed within a customer application under the customer’s instructions.
04
Purposes and legal bases
The applicable legal basis depends on the purpose. Consent is not used where processing is objectively necessary to perform a contract or meet a legal obligation.
| Purpose | Typical data | Legal basis |
| Answer enquiries and assess invitations | Contact details, organisation, intended use and message | Steps requested before a contract; legitimate interest in responding |
| Create and secure accounts | Identity, credentials, role, IP and access events | Contract performance; legitimate interest in preventing abuse |
| Activate and operate services | Order, configuration, domain and service telemetry | Contract performance |
| Billing, accounting and tax compliance | Billing identity, address, payment and invoice records | Contract performance; legal obligation |
| Provide support and investigate incidents | Tickets, diagnostics, logs and service history | Contract performance; legitimate interest in reliable operations |
| Protect rights and infrastructure | Security events, audit trails and abuse reports | Legitimate interest; legal claims; legal obligation where applicable |
| Send optional communications | Contact details and recorded preferences | Consent or another lawful basis notified at collection |
05
Sources and whether data is required
Most data comes directly from the person or organisation using Airbip. Other data may be generated by service operation, supplied by an authorised account administrator, obtained from a payment or infrastructure provider, or recorded through a referral link.
Fields marked as required are needed to answer a request, secure an account, issue an invoice or provide the selected service. Optional fields help us understand context. If necessary data is not supplied, the relevant request or service may not be possible.
06
Recipients and service providers
Access is limited to authorised personnel and providers that need data for infrastructure, communications, payment, accounting, security, support or legal compliance.
Providers acting as processors are subject to contractual confidentiality, security and data-protection obligations. A provider may act as an independent controller for its own regulated duties, such as payment or fraud controls; its own privacy information then applies.
Data may also be disclosed where required by law, a competent authority or the establishment, exercise or defence of legal claims.
07
International transfers
We prioritise processing within the European Economic Area where practical. Some technology providers or support operations may involve access from another country.
When personal data is transferred outside the EEA, we use an applicable lawful mechanism, such as an adequacy decision or approved standard contractual clauses, and supplementary measures where required. Information about the relevant safeguard may be requested through the contact form.
08
Retention criteria
We keep personal data only as long as needed for the purpose, service relationship, security and mandatory limitation, accounting or tax periods. Exact periods can differ by record and jurisdiction.
| Record | General criterion |
| Uncontracted enquiries and invitations | Until the request is resolved and for a limited follow-up or claims period |
| Account and service records | For the active relationship and the period needed for closure, portability, security and claims |
| Invoices and accounting records | For legally required accounting and tax periods |
| Support conversations | For service continuity and a proportionate claims or quality period |
| Security and access logs | For a limited period proportionate to detection, investigation and evidence needs |
| Hosted customer data | According to the service and processing agreement, including the agreed deletion or return process |
09
Data-protection rights
Subject to applicable conditions, a person may request access, rectification, erasure, restriction, portability or objection, and may withdraw consent without affecting processing already carried out.
A request should identify the relevant relationship or account and the right being exercised. We respond within the legally applicable period and may explain if an exemption or competing legal duty applies.
You may lodge a complaint with the competent data-protection authority. Where Linkses acts only as processor, a request concerning hosted data may need to be referred to or handled on the instructions of the customer acting as controller.
10
Security and personal-data incidents
We use technical and organisational measures appropriate to the service and risk, including access controls, separation, encrypted transport, logging, maintenance and recovery processes.
No system can eliminate all risk. Suspected incidents are assessed for containment, impact and notification duties. Where required, the relevant controller, authority or affected people will be informed under the applicable rules.
11
Automated decisions, children and sensitive data
Airbip does not use solely automated decisions that produce legal or similarly significant effects on ordinary website visitors or invitation applicants.
The service is intended for organisations and adults with legal capacity to contract. It is not directed to children. Do not submit health, biometric, political, religious or other sensitive information through general forms.
A customer deploying an application that will process children’s or special-category data must assess lawfulness and safeguards before using the service and communicate any specific requirements during onboarding.
12
Policy updates
We may update this policy to reflect changes in services, providers or applicable requirements. The review date identifies the current public version.
If a change materially affects an active service relationship, we will use a proportionate channel to communicate it where required.