Privacy Policy

Last updated: May 22, 2026

Data Controller
Eliasse Hamour (Entrepreneur Individuel)
SIRET: 937 788 172 00016 — VAT: FR02937788172
26 Rue de la Coopération, 93240 Stains, France
Privacy contact: [email protected]

1. Introduction

This Privacy Policy explains how Eliasse Hamour ("we," "us," or "our"), acting as data controller, collects, uses, discloses, and safeguards personal data when you use Linkfinder AI ("the Service"), a B2B contact data enrichment platform accessible at linkfinderai.com.

This Policy is issued in accordance with Regulation (EU) 2016/679 (the "GDPR"), the French Data Protection Act (Loi Informatique et Libertés), and other applicable data protection laws.

In short: We collect only what we need to operate the Service. We never sell personal data. We give data subjects — including individuals whose business information appears in our database — clear rights and a simple way to exercise them.

2. Personal Data We Collect

We collect personal data in three contexts: (a) when you create and use a User account; (b) when you make a payment; and (c) when we aggregate business contact information from publicly available sources for the database underlying the Service.

a) Account Data (Users of the Service)

Data TypePurposeLegal Basis (GDPR Art. 6)
Email address, nameAccount creation and authenticationPerformance of contract
Hashed password / OAuth tokenSecure loginPerformance of contract
Subscription and credit balanceService delivery and billingPerformance of contract
API requests, query logsService operation, abuse prevention, supportLegitimate interest
IP address, browser, device dataSecurity, fraud preventionLegitimate interest
Support communicationsCustomer supportLegitimate interest

b) Payment Data

Payments are processed by our authorized Merchant of Record ("MoR"), who acts as the seller of record and processes card or alternative payment data on our behalf. We do not store full card numbers on our systems. The MoR is an independent data controller for the payment transaction and operates under its own privacy policy.

Data TypePurposeLegal Basis
Billing name, email, billing address, VAT numberInvoicing and tax complianceLegal obligation
Last 4 digits of card, payment method typeSubscription management, dispute handlingPerformance of contract
Transaction historyAccounting, refunds, auditsLegal obligation

c) Business Contact Information in the Service Database

The Service maintains a database of business contact information aggregated from publicly available business data sources (company websites, public business directories, professional disclosures, official corporate registries, and similar public sources). This database may include the following data about individuals in a professional capacity:

  • First and last name (in a professional context)
  • Professional job title and employer
  • Business email address (work email)
  • Business phone number (work phone)
  • Public professional profile URL
  • City and country of employment

We do not knowingly collect or store: home addresses, personal phone numbers, personal email addresses, sensitive personal data (race, religion, health, sexual orientation, political opinions, etc.), or any data of children under 16.

Legal basis: Our processing of this business contact information relies on legitimate interest (GDPR Art. 6(1)(f)) — specifically, the legitimate interest of B2B users in identifying and contacting other professionals for legitimate business purposes. We have conducted a balancing test and provide a simple opt-out mechanism (see Section 6).

3. How We Use Personal Data

We use personal data only for the purposes for which it was collected, including:

  • Providing, operating, maintaining, and improving the Service;
  • Authenticating Users and managing accounts;
  • Processing subscriptions, payments, refunds, and credits;
  • Responding to support requests and User communications;
  • Sending essential service notifications (billing, security, important updates);
  • Preventing fraud, abuse, and unauthorized access;
  • Complying with legal, tax, and accounting obligations;
  • Conducting aggregated, anonymized analytics to improve the Service.

We do not:

  • Sell personal data to third parties;
  • Use personal data for behavioral advertising or ad targeting;
  • Share personal data with data brokers;
  • Use personal data for purposes incompatible with those listed above.

4. Sharing of Personal Data

We share personal data only with the following categories of recipients, all of whom are bound by contractual data protection obligations:

RecipientPurpose
Hosting and infrastructure providers (Cloudflare, Railway)Hosting the Service and serving requests
Merchant of Record (payment provider)Processing payments, invoicing, VAT collection
Analytics provider (PostHog, Plausible)Aggregated product analytics
Customer support toolsHandling support requests
Email delivery providersSending transactional emails
Competent authoritiesWhen required by law, court order, or legitimate legal process

In the event of a business transfer (merger, acquisition, asset sale), personal data may be transferred to the acquiring party, subject to equivalent privacy protections.

5. International Data Transfers

Some of our service providers are located outside the European Economic Area (EEA), including in the United States. Where data is transferred outside the EEA, we ensure adequate protection through one or more of the following mechanisms:

  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Transfers to countries covered by an adequacy decision from the European Commission;
  • Supplementary technical and organizational safeguards where appropriate.

You may request a copy of the safeguards in place by contacting [email protected].

6. Your Rights Under the GDPR

If you are located in the EEA, the United Kingdom, or Switzerland — including if your business contact information appears in our database — you have the following rights:

  • Right of access: Obtain confirmation of whether we process your personal data and a copy of that data.
  • Right to rectification: Have inaccurate or incomplete data corrected.
  • Right to erasure ("right to be forgotten"): Have your personal data deleted, subject to certain legal exceptions.
  • Right to restriction of processing: Request that we limit how we process your data.
  • Right to data portability: Receive your data in a structured, commonly used, machine-readable format.
  • Right to object: Object at any time to processing based on legitimate interest, including the inclusion of your business contact information in our database.
  • Right to withdraw consent: Where processing is based on consent, withdraw that consent at any time.
  • Right to lodge a complaint: Lodge a complaint with the French data protection authority (CNIL) or your local supervisory authority.
How to exercise your rights: Send a request to [email protected]. We respond within thirty (30) days. If your business contact information appears in our database and you wish to have it removed, simply email us — no proof of identity required for opt-out requests covering business contact data; we will remove the matching records within 30 days.

7. Data Retention

Data TypeRetention Period
Account dataFor the duration of your account, plus 30 days after deletion
Subscription and credit recordsFor the duration of the contract
Invoices and accounting records10 years (French Commercial Code, Art. L123-22)
API request logs12 months (security and operational purposes)
Support communications3 years
Business contact database entriesUntil opt-out request or until source data is no longer publicly available
Marketing communications (if applicable)Until opt-out, or 3 years from last interaction

8. Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction, including:

  • TLS/SSL encryption for all data in transit;
  • Encryption at rest for sensitive data;
  • Access controls and authentication on administrative systems;
  • Regular security reviews and dependency updates;
  • Hosting on infrastructure providers with industry-standard security certifications;
  • Restricted access to personal data on a need-to-know basis.

No system is perfectly secure. In the event of a personal data breach likely to result in a risk to data subjects' rights and freedoms, we will notify the CNIL within 72 hours and affected data subjects without undue delay, as required by GDPR Articles 33 and 34.

9. Cookies and Tracking

We use a minimal set of cookies and similar technologies for:

  • Strictly necessary: Session management, authentication, security, load balancing — these cannot be disabled.
  • Analytics: Privacy-friendly aggregated analytics (Plausible, PostHog) to understand how the Service is used and improve it.
  • Conversion tracking (with consent): Where you've consented, marketing pixels (Meta, Google) to measure the effectiveness of advertising campaigns.

You can manage cookie preferences through your browser settings. Disabling certain cookies may affect Service functionality.

10. Children

The Service is intended for business use and is not directed at individuals under sixteen (16) years of age. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without verified parental consent, we will delete that data promptly. If you believe a child has provided us with personal data, please contact [email protected].

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we do, we will:

  • Update the "Last Updated" date at the top of this page;
  • Notify active subscribers by email of any material changes at least thirty (30) days before they take effect;
  • Post the updated policy on this page.

Your continued use of the Service after the effective date of an updated Policy constitutes acceptance of the changes.

12. Contact Us

For any question, request, or complaint regarding this Privacy Policy or your personal data:

  • Email: [email protected]
  • Postal address: Eliasse Hamour, 26 Rue de la Coopération, 93240 Stains, France

You also have the right to lodge a complaint with the French data protection authority:

  • CNIL — Commission Nationale de l'Informatique et des Libertés
  • 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
  • www.cnil.fr

Questions about your data?

Email us at [email protected] — we respond within 30 days, and we make removal requests easy.