General Data Protection Regulation (GDPR)
Last updated: 9 September 2026
What is GDPR
The General Data Protection Regulation protects the personal data and privacy of individuals for activity within the EU and EEA.
The GDPR harmonizes data privacy law across Europe so that people can understand how their information is used when they access or subscribe to a service. Regulation (EU) 2016/679 took effect on 25 May 2018 and replaced the earlier Data Protection Directive 95/46/EC. It also governs the transfer of personal data outside the EU. Any organization that processes the personal data of individuals in the EU must comply, wherever that organization is based. Under the GDPR, processing means any operation performed on personal data, including collecting, recording, using, transmitting and erasing it.
How We-Link handles your data
We-Link is a transit processor. You decide, We-Link does the acting, and the personal data involved in that action passes through us rather than living with us.
When you call the API, whether through an AI agent over MCP or your own program over REST, to search a profile, send a connection request, or deliver a message, the personal data in that request is processed to carry out the action and returned to you by webhook. We do not build or keep a database of the prospects you reach.
What we retain is limited and operational: request metadata and technical logs, so you can check the status of a call and reconcile your usage, kept for up to 3 months; and your account and connection details, including your We-Link API credentials and, for the LinkedIn account you connected, an encrypted session token and connection credentials, kept for as long as your account is active.
We are a processor for the prospect data that moves through the API. You, our customer, are the controller of that data, and you remain responsible for the lawful basis of your outreach. We act only on the instructions you send through the API, and only from an account you connected.
Data retention
We keep different kinds of data for different lengths of time:
- Prospect personal data that passes through the APITransient. It is processed to carry out your instruction and returned to you, not held as a standing database on our systems.
- Request metadata and technical logsKept for up to 3 months for monitoring, debugging, usage reconciliation and security, unless a specific security investigation requires holding them longer.
- Account and connection dataIncluding your We-Link API credentials and, for the connected LinkedIn account, an encrypted session token and connection credentials, kept for as long as your account is active. When you close your account we permanently delete it within 90 days, and we confirm the deletion in writing within 30 days of your request.
Where we process your data
We-Link processes data on servers in the United States. For customers in the EU, EEA, UK or Switzerland, these transfers are covered by the Standard Contractual Clauses incorporated into our Data Processing Agreement at we-link.ai/dpa. Our geo-matched connection proxies route the outbound action to LinkedIn from a location matched to your connected account; this is separate from where We-Link stores account and log data.
Your rights
You have the rights of access, rectification, erasure, restriction of processing, data portability and objection. Each right is described in full in our Privacy Policy at we-link.ai/privacy. To exercise any of these rights in respect of your own account data, contact us at [email protected].
Where a request concerns prospect data that we process on a customer's behalf, that customer is the controller. We will promptly route the request to the relevant customer and assist them in responding, rather than acting on the prospect data ourselves without the customer's instruction.
Our lawful bases
The lawful bases below apply to the account relationship data that We-Link controls, such as registration, billing and service communications. They do not cover your outreach to prospects; as the controller of that data, you are responsible for establishing your own lawful basis for contacting them.
- Performance of a contract. We process your registration, login and billing information because it is necessary to provide the We-Link service you have subscribed to.
- Legitimate interest. We rely on legitimate interest to send you service and product communications, to fight fraud, and to secure and improve the platform. A copy of our Legitimate Interests Assessment is available on request at [email protected].
- Consent. Where we send optional marketing communications, we rely on your consent, which you can withdraw at any time using the unsubscribe link in any email.
- Legal obligation. We process certain data where required by law, for example for tax and accounting purposes.
If we intend to use your account data for any new purpose, we will inform you before that processing begins.
Security
We maintain technical and organizational measures to protect your data, including encryption of data in transit, access controls with logged and verified connections to our infrastructure, and identity verification before we action sensitive account requests such as data deletion. The security measures that apply to customer data are described in our Data Processing Agreement at we-link.ai/dpa.
Data Processing Agreement
Under Article 28 of the GDPR, controllers must have a written data processing agreement in place with their processors. Our Data Processing Agreement, which incorporates the EU Standard Contractual Clauses, is available at we-link.ai/dpa. If you need a countersigned copy for your records, contact us at [email protected].
Data breaches
Should personal data that we control be lost, stolen or otherwise breached, and where this constitutes a high risk to your rights and freedoms, we will contact you without undue delay. We will explain the nature of the breach, the steps we are taking to deal with it, and give you the contact details of the person handling it.
Disclaimer
This GDPR Compliance page is provided as is and without warranty. In no event will We-Link or its affiliates have any liability whatsoever arising from or in connection with this document. You acknowledge and agree that you are solely responsible for complying with any and all laws and regulations in association with your use of We-Link, including without limitation laws and regulations related to data privacy.
Contact
Questions about this GDPR document should be sent to us at [email protected].