Legal
Datenschutzerklärung
Stand: 25. Juli 2026
This Privacy Policy explains how WEBBYWOLF INNOVATIONS collects and uses personal data in connection with Linkova (linkova.club).
1. Controller
FIRST FLOOR, H.NO-1004/4, Navapur, Agashi Road,
Char Rasta, VIRAR WEST, Vasai Virar,
Palghar, Maharashtra, 401301, India
Email: [email protected]
Data protection contact: [email protected]
2. Who this policy covers
- Customers and users of the platform
- Website visitors
- Website operators and publisher contacts whose business contact details we process in order to arrange link placements (see section 6)
3. What we collect
3.1 Account and profile data
Name, business email, password (stored hashed), company name, country, language, workspace and project names, role.
3.2 Order data
Target URLs, anchor text, keywords, briefs, uploaded files, order status, published URLs, correspondence.
3.3 Payment data
Billing details and transaction records. Card details are entered directly with our payment providers and are never stored by us.
3.4 Communications
Emails and messages exchanged with us, including outreach threads and support requests.
3.5 Technical and usage data
IP address, browser and device type, pages viewed, timestamps, referring URL, log data, and cookie identifiers.
3.6 Publisher contact data
Business contact details (typically a generic or role-based email address such as info@ or editor@) obtained from publicly accessible pages of a website, or supplied to us by the publisher or an intermediary. See section 6.
We do not intentionally collect special category data and ask that you do not submit it.
4. Why we use it, and our legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and administering your account | Contract (6(1)(b)) |
| Processing and fulfilling orders | Contract (6(1)(b)) |
| Taking payment, invoicing, accounting | Contract (6(1)(b)); Legal obligation (6(1)(c)) |
| Customer support and service emails | Contract (6(1)(b)) |
| Contacting website operators to arrange placements | Legitimate interests (6(1)(f)) |
| Platform security, fraud prevention, abuse detection | Legitimate interests (6(1)(f)) |
| Service improvement and aggregate analytics | Legitimate interests (6(1)(f)) |
| Non-essential cookies and analytics | Consent (6(1)(a)) |
| Marketing emails to customers | Consent (6(1)(a)), or soft opt-in where permitted |
| Retaining records for tax, audit and legal claims | Legal obligation (6(1)(c)); Legitimate interests (6(1)(f)) |
Where we rely on legitimate interests, we have assessed that our interest in operating a link marketplace does not override your rights and freedoms. You may object at any time (section 9).
5. Automated processing and AI
5.1 We use artificial intelligence to assist with drafting outreach emails, suggesting order details, generating semantic search results, and classifying websites by topic. Content you submit and the text of outreach correspondence may be transmitted to our AI sub-processor for these purposes.
5.2 Outreach emails are prepared as drafts and reviewed by a human before sending. We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR.
5.3We use website metadata, categories and descriptive text to generate numerical representations ("embeddings") that power semantic search. These relate to websites, not to individuals.
6. Publisher and website operator data
To arrange link placements we process business contact details of website operators. We collect these from publicly accessible parts of a website (such as a contact or imprint page), from the operator directly, or via an intermediary marketplace.
- We process this data on the basis of legitimate interests for the purpose of business-to-business communication about a commercial collaboration.
- Where we obtain contact details other than from the individual, we provide the information required by Art. 14 GDPR in our first communication.
- We use these details only to contact the operator about placements, and we do not sell them.
- Any operator may object to further processing or request erasure by emailing [email protected], and we will action this and suppress further contact.
7. Recipients and sub-processors
We share personal data with service providers who process it on our behalf under contract. Categories include:
| Category | Purpose |
|---|---|
| Cloud hosting and database (Supabase / underlying cloud infrastructure) | Hosting the platform and storing data |
| Payment providers (including Polar) | Payment processing, invoicing, tax handling; may act as merchant of record |
| Transactional email provider (Mailgun) | Sending and receiving service and outreach email |
| AI provider (OpenAI) | Drafting assistance, classification, semantic search |
| SEO and website data providers (including DataForSEO) | Website metrics; queries relate to domains, not individuals |
| Analytics and error monitoring | Understanding usage and diagnosing faults |
| Professional advisers, accountants, auditors | Legal and financial compliance |
We may also disclose data where required by law, to enforce our Terms, or in connection with a merger, acquisition or reorganisation.
An up-to-date list of sub-processors is available on request from [email protected].
8. International transfers
We are established in India. Personal data of individuals in the European Economic Area and the United Kingdom is therefore transferred outside the EEA/UK, and our sub-processors may also process data in the United States and elsewhere.
India is not currently the subject of an EU adequacy decision. Where we transfer personal data from the EEA or UK, we rely on appropriate safeguards under Art. 46 GDPR, principally the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable), supported by a transfer impact assessment and technical measures including encryption in transit and at rest and access controls.
You may request a copy of the relevant safeguards by emailing [email protected].
9. Your rights
Where GDPR or UK GDPR applies, you have the right to:
- access your personal data and receive a copy;
- rectify inaccurate or incomplete data;
- erasedata ("right to be forgotten") where grounds apply;
- restrict processing in certain circumstances;
- data portability for data you provided, in a machine-readable format;
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent where processing is based on consent, without affecting prior lawful processing;
- not be subject to solely automated decisions with legal or similarly significant effect.
To exercise any right, email [email protected]. We will respond within one month, extendable by two further months for complex requests. We may need to verify your identity.
Complaints. You may lodge a complaint with your local supervisory authority. In Germany this is the data protection authority of your federal state; a list is available from the Federal Commissioner (BfDI). We would appreciate the chance to address your concern first.
Indian residents have rights under the Digital Personal Data Protection Act, 2023 as it comes into force, and may contact us at the same address.
10. Retention
| Data | Retention |
|---|---|
| Account data | For the life of the account, then up to 12 months after closure |
| Order and delivery records | 8 years from the end of the financial year, for tax and audit purposes |
| Invoices and payment records | As required by Indian and applicable EU tax law |
| Outreach correspondence | Up to 3 years after last contact |
| Publisher contact details | Until objection, or 3 years after last meaningful contact |
| Support tickets | 3 years |
| Server and security logs | Up to 12 months |
| Suppression list (do-not-contact) | Retained indefinitely, to honour your objection |
We delete or anonymise data once the applicable period expires and no legal claim requires its retention.
11. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and at rest, hashed passwords, row-level security on our database, least-privilege access controls, restricted administrative access, and logging. No system is completely secure; we cannot guarantee absolute security. We will notify affected individuals and the competent supervisory authority of a personal data breach where legally required.
12. Cookies
We use cookies and similar technologies:
- Strictly necessary — authentication, session management, security, load balancing. Set without consent as they are required for the service.
- Preference — language and display settings.
- Analytics — aggregate usage measurement. Set only with your consent.
Where required, we request consent through a cookie banner before setting non-essential cookies, and you can change or withdraw your choice at any time via the cookie settings link in the site footer. You can also block or delete cookies in your browser, though this may affect functionality.
13. Children
The Service is intended for businesses and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has provided data, contact us and we will delete it.
14. Changes to this policy
We may update this policy. The current version is always published at linkova.club with the date of last revision. Where changes are material, we will notify you by email or in-platform notice before they take effect.
15. Contact
FIRST FLOOR, H.NO-1004/4, Navapur, Agashi Road,
Char Rasta, VIRAR WEST, Vasai Virar,
Palghar, Maharashtra, 401301, India
Email: [email protected]