effective on
Privacy Policy
Lire la version française de référence
In the event of a discrepancy, the French version prevails, subject to any mandatory rules applicable to the customer. The reference version is available at
/fr/legal/privacy.
Version 2.2 — In force from 13 September 2026
1. Who processes your data?
For the management of the website, accounts, subscriptions, security, support and product improvement, the controller is GOLDEN F, a French société par actions simplifiée unipersonnelle located at 21 avenue Pasteur, 92400 Courbevoie, France, RCS Nanterre 998 971 410.
Contact for any question or to exercise a right: contact@linkyflow.com.
Where LinkyFlow processes, on the instructions of a Business Customer, personal data coming from their Providers or concerning their own customers, employees, suppliers or users, GOLDEN F acts as a processor. The DPA available at /legal/dpa then applies to that processing.
2. Data concerned and sources
We may process the following categories:
2.1 Account data
Email address, name or pseudonym where provided, profile picture, sign-in method, account identifier, language, preferences, creation date and date of last activity. This data comes from you or from the authentication provider you choose.
2.2 Provider connection data
Connection name, chosen Provider, public identifiers, API keys, secrets, OAuth tokens, authorisations and connection status. Secrets are provided by you or transmitted by the Provider as part of an authorisation journey.
2.3 Queries, parameters and usage
Connector, resource, fields, filters, parameters, scheduled tasks, limits, counters, functions used, date, duration, technical result and status of requests.
2.4 Data coming from Providers
Depending on the Provider and your instruction, LinkyFlow may process balances, transactions, orders, products, customers, orders, payments, stock, history or other data accessible in your Provider account. Some of that data may concern natural persons.
This data is processed in order to answer your query and is transmitted to the interface you have chosen. The technical target is not to keep it in a business database after the answer, except where you expressly enable a function requiring retention, such as a setting, a task or an announced cache. Transient caches must be limited to twenty-four hours and logs must exclude business content, secrets and tokens. Any different retention must be stated at the time of the function concerned and added to this policy before it is enabled.
Data written into your Excel workbook, your system, an API or an MCP client then remains under your control and that of the recipients you have chosen.
2.5 Billing and tax data
Plan, subscription status and history, amounts, currency, invoices, credit notes, coupons, payment dates, incidents, name or company name, billing address, country, VAT number, VAT validation result and the elements needed to determine the place of taxation.
Full card details are collected by the payment provider. GOLDEN F receives only the information needed to follow the transaction, such as an identifier, the type or last digits of the means of payment, its status and its expiry date, according to what the provider returns.
2.6 Technical, security and support data
IP address, date and time, browser, device, system, application version, technical identifiers, authentication logs, errors, performance, fraud or abuse signals, and the content of requests sent to support.
2.7 Audience measurement and communication data
On the public website, with your consent given through the banner; in the signed-in application, on the acceptance of the Terms at account creation (section 6): pages or screens viewed, product events, originating campaign and measurement identifier. For communications: email address, message type, delivery, opens or clicks only where that tracking is lawfully enabled and described.
3. Mandatory data and consequences
The data marked as mandatory is necessary to create the account, secure access, connect a Provider or execute a payment. Without it, the corresponding function cannot be provided.
Optional profile data, additional connections and non-necessary trackers may be refused without preventing access to the essential functions, subject to the limits of the Plan.
4. Purposes and legal bases
| Purpose | Main data | Legal basis |
|---|---|---|
| Create the account, authenticate the user and provide the Service | account, connections, queries, usage, Provider data | performance of the contract or pre-contractual measures |
| Manage subscriptions, payments and invoices | account, billing, tax | performance of the contract and legal accounting and tax obligations |
| Secure the Service, prevent fraud, abuse and unauthorised access | account, IP, logs, security signals | GOLDEN F's legitimate interest in protecting the Service, its users and the Providers |
| Answer support and handle complaints | account, exchanges, diagnostics | performance of the contract and legitimate interest in resolving incidents and defending rights |
| Measure audience and improve the interface using non-necessary trackers | navigation and product events | consent given through the banner on the public website; acceptance of the Terms at account creation in the signed-in application, as part of the service provided to the account holder |
| Send the messages necessary for the account, security, payment or the Service | account and subscription | performance of the contract or legitimate interest depending on the message |
| Send commercial prospecting | email address and commercial relationship | consent where required, or legitimate interest in the cases permitted by law, with a simple objection at any time |
| Comply with the law and respond to competent authorities | data relevant to the request | legal obligation or the establishment and defence of legal claims |
We do not use Customer Data to train an artificial intelligence model. No password, secret, API key, token or Provider content may be transmitted to a generative AI. If a new AI function processes personal data, it must remain disabled until dedicated information, a legal basis, minimisation and the necessary safeguards are in place.
5. Recipients
The data is accessible only to authorised GOLDEN F personnel who need it for their duties, and to the technical subprocessors necessary for hosting, authentication, billing, sending emails, consented analytics, support and error monitoring.
The up-to-date list of those subprocessors, their purposes and places of processing is available at /legal/subprocessors.
When you connect a Provider, LinkyFlow exchanges data with that Provider according to your instructions. The Providers you choose, such as an exchange platform, a store or a payment service, are not subprocessors of GOLDEN F for the supply of their own service. Their own terms and policies apply.
When you use an external client, an AI agent or an MCP server chosen by you to receive data, that actor processes the data under your responsibility from the moment it is transmitted to it.
Finally, we may disclose data required by a legal obligation, a court decision or a valid request from a competent authority.
We do not sell your personal data and do not share it with data brokers or advertising networks for their own purposes.
6. Location and international transfers
The main components of the application and of the data are hosted on Amazon Web Services in the eu-central-1 region, in Frankfurt, subject to continued confirmation of the infrastructure and the backups.
The public website is delivered by Netlify. Some subprocessors, or their own subprocessors, may process data outside the European Economic Area. Where an international transfer is subject to the GDPR, it relies on an applicable adequacy decision, in particular the EU–US framework for the entity actually certified, or on the European Commission's standard contractual clauses accompanied, where necessary, by supplementary measures.
Per-provider information is available at /legal/subprocessors. A copy of the applicable safeguards may be requested at contact@linkyflow.com, subject to the protection of confidential information.
7. Retention periods
| Category | Target period |
|---|---|
| Account and preferences | for the life of the account, then deletion or anonymisation within 30 days of its closure, save data to be kept by law |
| Provider secrets and tokens | until the connection or the account is deleted; removal from the active database without undue delay and expiry of backups in their normal cycle, at the latest within 35 days |
| Provider data processed for an answer | the duration of the query; announced transient cache of 24 hours maximum; no retention in business logs |
| Saved queries, parameters and tasks | until deleted by the user or the account is closed, then 30 days maximum |
| Usage counters | six months after the close of the period concerned, unless needed as evidence for an invoice or a dispute |
| Security logs and diagnostics | 90 days, unless longer retention is necessary to analyse an incident or to meet a legal obligation |
| Consented audience measurement | 13 months maximum; tracker durations stated in the cookie policy |
| Tracker consent or refusal choices | six months, then a new choice |
| Support requests | three years after the last exchange, or for the duration of a dispute |
| Prospects | three years after the last contact from the prospect |
| Customers used for prospecting similar services | for the duration of the commercial relationship then three years, save prior objection |
| Invoices, credit notes and accounting records | ten years from the close of the financial year concerned |
| Contractual evidence and consents | the period necessary to prove the contract and for the applicable limitation periods; ten years for electronic contracts falling within the statutory archiving threshold |
8. Security
GOLDEN F applies measures appropriate to the risk, in particular TLS encryption in transit, encryption at rest, separate secret management, restricted access rights, logical isolation of accounts, security logging, removal of secrets from logs, protected backups, vulnerability management and incident procedures.
The Customer must protect their account, their email, their devices and their keys, use minimal authorisations, revoke unused keys and report an anomaly promptly.
No system offers absolute security. In the event of a personal data breach presenting a risk, GOLDEN F applies the notification obligations towards the authorities and the persons concerned under the conditions provided by law.
9. Your rights
Depending on the legal basis and your situation, you may request:
- access to your data and a copy;
- its rectification;
- its erasure;
- restriction of the processing;
- portability of the data you have provided where the right applies;
- objection to processing based on legitimate interest;
- withdrawal of your consent at any time for the future;
- an end to commercial prospecting at any time;
- directives concerning the fate of your data after your death under the conditions of French law.
Address your request to contact@linkyflow.com. We answer in principle within one month. That period may be extended by two months for a complex or numerous request; you are then informed. Proof of identity may be requested only where reasonable doubts exist.
You may also delete your connections and certain data from your account. Deleting a connection in LinkyFlow does not replace revoking the key or the authorisation with the Provider.
You may lodge a complaint with the French data protection authority: CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.
10. Automated decisions
GOLDEN F does not take, on the sole basis of automated processing, any decision producing legal effects or similarly significantly affecting a user.
Automatic Plan limits, security controls and abuse detection may temporarily restrict a function. The Customer may request a human review at contact@linkyflow.com.
11. Minors
LinkyFlow is not intended for persons under eighteen. If we learn that a minor has created an account, we take the appropriate measures to close it and delete the data that must not be kept.
12. Cookies and similar technologies
The policy available at /legal/cookie describes the cookies, local storage and scripts, and how to accept, refuse or withdraw a consent. It also explains why the public website carries a banner while the signed-in application does not, and how to object to the measurement performed there.
13. Changes
The date and the version appear at the top of this policy. A substantial change is brought to users' attention before it comes into force by an appropriate means, in particular in the application or by email. Previous versions are archived.
14. Contact
GOLDEN F — LinkyFlow 21 avenue Pasteur 92400 Courbevoie — France contact@linkyflow.com