Privacy policy
Last updated: October 8, 2026
1. Data controller
Nova Corporation SNC, a general partnership under Swiss law (business ID CHE-207.947.982), Chemin des Alpes 6, 1418 Vuarrens, Switzerland. Contact: privacy@trylink.it.
This policy applies in accordance with the Swiss Federal Act on Data Protection (revised FADP, in force since September 1, 2023) and, insofar as people located in the European Union use the service, the General Data Protection Regulation (GDPR).
2. Data we process
Account data
- The ID, name and email of the connected LinkedIn account (provided by LinkedIn through OAuth/OpenID Connect);
- The LinkedIn access token (needed to publish on your behalf), stored encrypted on the server, never displayed or passed on to anyone;
- The language chosen for the website and the app.
Content
- Texts, visuals and context (business description, tone, themes) provided to generate posts;
- Posts generated, edited, published or rejected, and their status;
- Performance figures (reactions, comments) of posts, when you enter them.
Technical and browsing data
- IP address, browser type, pages visited, for security and basic audience measurement;
- Cookies: see the dedicated cookie policy.
3. Purposes
- Providing the service: generating, scheduling and publishing LinkedIn content;
- Making generated content more relevant (see the data collection policy for details of the strictly anonymised "shared structure library");
- Keeping the service secure and preventing abuse.
4. Legal basis
Processing is based on the performance of our contract with the user (providing the service), on our legitimate interest in keeping the service secure and improving it, and, for non-essential cookies, on the user's consent.
5. Who receives the data
The only external communications are those strictly needed for the service to work:
- LinkedIn / Microsoft Corporation (United States): for sign-in and publishing posts, through LinkedIn's official API;
- Mistral AI (France): provider of the AI model that writes your posts. The texts needed for generation (context, notes, conversation, posts to edit) are sent to it through its API, with Link'IT's key and under its terms. If a local model is offered to an account, these texts stay on our infrastructure;
- Neon Inc.: database hosting (servers located in the European Union);
- Stripe (Stripe Payments Europe Ltd. and its affiliates): processing payments and billing for subscriptions and credits. Card details are entered directly with Stripe; Link'IT only keeps the Stripe customer ID, the plan, the subscription status, the credits bought and the last 4 digits of the card shown on the Subscription page;
- Cloudflare, Inc.: secure routing of requests to our servers;
- Vercel Inc. (United States): hosting of the web interface, through which requests pass.
We never sell or rent personal data to third parties for advertising purposes.
6. International transfers
LinkedIn, Microsoft Corporation and Vercel Inc. are based in the United States. These transfers rely on the framework that applies to transfers to that country (in particular the Swiss extension of the EU-US Data Privacy Framework) or on the standard contractual clauses of the provider concerned. The database is hosted in the European Union, whose level of protection Switzerland recognises as adequate.
7. Retention
Data is kept for as long as the account is used. You can delete your account at any time from Settings: your pages, posts, notes and LinkedIn tokens are then erased immediately, unless the law requires them to be kept longer.
8. Your rights
Under the FADP and, where applicable, the GDPR, you have the right to access, correct, erase, restrict and object to the processing of your data, as well as the right to data portability. To exercise these rights, contact us at privacy@trylink.it. You also have the right to lodge a complaint with the competent supervisory authority, which in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC).
9. Security
Communications are encrypted (HTTPS), LinkedIn tokens are encrypted at rest, each account can only access its own data, and sessions can be revoked at any time by signing out. As no system is infallible, we cannot guarantee absolute security, but we apply reasonable measures suited to the scale of the service.
