Legal

Privacy Policy

What personal data Linkvo handles, why, and the choices you have. It covers our customers, visitors to our website, and website owners and editors who may be contacted through Linkvo.

Last updated Oct 4, 2026

1. Who we are

Linkvo is operated by ITERO LTD, a private limited company registered in England and Wales under company number 16867644, with its registered office at 61 Bridge Street, Kington, Herefordshire, HR5 3DJ, United Kingdom (“we”, “us”).

For privacy questions or to exercise your rights, email [email protected].

2. Our role: controller and processor

Depending on the data, we act in one of two roles under the UK GDPR and the EU GDPR:

  • Controller for account, billing and usage data about our customers, for data about visitors to our website, and for our site intelligence database: public information about websites and the business contact details they publish.
  • Processor for the outreach data our customers upload to or create in Linkvo: their contact lists, campaigns, email content, replies and the contents of connected mailboxes. Our customer is the controller of that data and decides who to contact and why; we process it only on their instructions (see section 12).

If you received an email or contact-form message from someone using Linkvo, the sender is responsible for that message. You can still ask us to stop all Linkvo users from contacting you: see section 6.

3. Personal data we collect

Customers and their team members

  • Account data: name, email address, password (stored only as a hash), workspace name and role.
  • Billing data: billing name, address, VAT number and payment status. Card details are collected and stored by Stripe, not by us.
  • Mailbox connection data: email addresses, server settings and credentials or tokens for the mailboxes you connect. Credentials are encrypted at rest.
  • Usage and device data: IP address, browser, log-in times, actions in the app and error logs.
  • Communications: messages you send to our support team.

Website visitors

  • Technical data needed to deliver and secure the website, such as IP address, browser type and the pages requested, processed by our hosting and CDN providers. We do not use advertising or analytics cookies (see our Cookie Policy).
  • Inputs you enter into our free tools, such as domain names.

Website owners, editors and other business contacts (site intelligence)

  • Information about websites: domain, site name, topics, language, published contribution guidelines, contact-form addresses and public SEO metrics.
  • Business contact details published on or for the website, such as role addresses (for example editor@ or hello@), and, where publicly listed, a person’s name, job title and work email address.
  • Outreach signals across Linkvo: whether a site was recently contacted, whether it opted out, and aggregated, de-identified outcomes such as response rates and typical price ranges.

4. Where the data comes from

  • From you, when you sign up, connect a mailbox, upload contacts or contact us.
  • Automatically, when you use the Service or visit our website.
  • From publicly available sources, mainly the website itself (its contact, about and “write for us” pages) and public directories.
  • From data providers: DataForSEO (backlink and SEO metrics about domains) and email-finding and verification services such as Findymail and Hunter (published work email addresses).
  • From Stripe, for payment status and billing details.

5. Why we use it and our lawful bases

  • To provide the Service, run your account and send service emails such as verification and password reset (performance of a contract).
  • To bill you and keep accounting records (performance of a contract and legal obligation).
  • To keep the Service secure, prevent abuse and spam, and enforce our Acceptable Use Policy (legitimate interests).
  • To understand how the Service is used, fix problems and improve features, using aggregated data where possible (legitimate interests).
  • To tell customers about product updates and offers. You can opt out at any time; where the law requires consent, we ask for it first (legitimate interests or consent).
  • To build our site intelligence database so that our customers can find relevant websites and contact them about editorial collaborations such as guest posts, resource-page additions and broken-link fixes (legitimate interests).
  • To comply with legal obligations and respond to lawful requests (legal obligation).

When we rely on legitimate interests for site intelligence, we have balanced our interests and our customers’ against yours. We limit the data to business contact details that were published for people to get in touch, we do not collect sensitive data, we limit how often a website can be contacted across all Linkvo users, every message must carry an opt-out, and opting out applies across the whole platform.

6. If you run a website we have information about

We may hold your website’s details and published business contact information because it appears to accept guest posts, resources or other contributions. Our customers may use it to send you a pitch from their own mailbox.

You can stop this at any time:

  • Use our opt-out page to add your email address or your whole domain to our global suppression list. No Linkvo user will then be able to contact it through Linkvo.
  • Use the unsubscribe link in any email sent through Linkvo; it has the same effect for that address.
  • Email [email protected] to ask for access to, correction of or deletion of the data we hold about you. We keep only the minimum needed (the email address or domain) on the suppression list so that we can keep honouring your opt-out.

Opting out stops contact made through Linkvo. It cannot stop a sender from contacting you by other means; to reach them, reply to their message directly.

7. AI processing

We use large language models to draft emails, choose a pitch angle and classify replies. To do this we send the relevant context, such as public information about a website, a contact’s name and role, campaign details and the text of a reply, to model providers through OpenRouter.

We do not train our own models on your data, and we do not permit our AI providers to use the data we send them to train their models. AI output is used to assist our customers, who review it; we do not make decisions with legal or similarly significant effects about anyone based solely on automated processing.

8. Who we share it with

  • Service providers who process data for us, listed on our Subprocessors page.
  • Our customers: site intelligence (website information and published business contact details) is made available to them within the Service.
  • Professional advisers, such as lawyers and accountants, under confidentiality obligations.
  • Authorities, regulators or courts, where we are required by law or need to protect our rights or the safety of others.
  • A buyer or successor, if our business is sold or reorganised, subject to this policy.

We do not sell personal data, and we do not share it with advertisers.

9. International transfers

Our servers are located in the United States, and several of our providers are based in the United States or elsewhere outside the UK and EEA. When we transfer personal data outside the UK or EEA, we rely on an adequacy decision or the UK Extension to the EU–US Data Privacy Framework where the recipient is certified, or on appropriate safeguards such as the UK International Data Transfer Agreement or Addendum and the EU Standard Contractual Clauses. Contact us for more information about these safeguards.

10. How long we keep it

  • Account and workspace data: for as long as your account is active, then deleted within 30 days of account closure, except where we need to keep it longer to comply with the law or resolve disputes.
  • Outreach data we process for customers: until the customer deletes it, or within 30 days after their account closes.
  • Billing and tax records: 6 years, as required by UK law.
  • Security and application logs: up to 90 days.
  • Backups: deleted data may remain in encrypted backups for up to 14 days before being overwritten.
  • Site intelligence: for as long as the information remains relevant and publicly available; we review and refresh it regularly and delete it on valid request.
  • Suppression list entries: kept indefinitely, so that we can continue to honour opt-outs.

11. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit (TLS), encryption of mailbox credentials at rest, access controls limited to staff who need access, and monitoring for abuse. No system is completely secure; if we become aware of a personal data breach that affects you, we will notify you and the relevant authority where the law requires.

12. Data processing terms for customers

When we process personal data as your processor (outreach data), the following terms apply as part of our Terms of Service. We will:

  • process the data only on your documented instructions, which are given through your use of the Service, unless the law requires otherwise;
  • make sure that people authorised to process the data are bound by confidentiality;
  • apply the security measures described in section 11;
  • use only the subprocessors listed on our Subprocessors page, under written terms that protect the data at least as well as these terms, and update that page before adding a new one so that you can object;
  • help you respond to data subject requests and meet your obligations on security, breach notification and impact assessments, taking into account the nature of the processing;
  • notify you without undue delay after becoming aware of a personal data breach affecting your data;
  • delete or return the data when you close your account, subject to the retention periods above;
  • make available the information reasonably necessary to demonstrate compliance with these terms.

You are responsible for the lawfulness of the processing you instruct, including having a lawful basis for contacting each recipient and providing any notices required by law.

13. Your rights

Under the UK GDPR and the EU GDPR you have the right to access your personal data, have it corrected or deleted, restrict or object to its processing, and receive a copy of it in a portable format. You can object at any time to processing based on legitimate interests, and you have an absolute right to object to direct marketing. Where we rely on consent, you can withdraw it at any time.

To exercise your rights, email [email protected]. We will respond within one month and may need to verify your identity. If your request concerns outreach data that we process for one of our customers, we will pass it to that customer and help them respond.

You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk) or to the data protection authority where you live or work. We would appreciate the chance to address your concerns first.

14. Cookies

We use only strictly necessary cookies. See our Cookie Policy.

15. Children

The Service is for business use and is not directed at anyone under 18. We do not knowingly collect personal data from children.

16. Changes to this policy

We may update this policy from time to time. We will post the new version here with a new “last updated” date and, if the changes are significant, tell customers by email or in the app.

17. Contact

ITERO LTD, 61 Bridge Street, Kington, Herefordshire, HR5 3DJ, United Kingdom. Email: [email protected].

Questions about this document? Email [email protected].