This page explains how Linkato supports GDPR compliance and sets out the terms of the Data Processing Agreement (DPA) that applies when we process personal data on the Customer’s behalf.
1. What the GDPR is
The General Data Protection Regulation (EU 2016/679) governs the processing of personal data of people in the EU/EEA, strengthening the rights of data subjects and the obligations of those who process data.
2. Roles: controller and processor
When you send campaigns through Linkato, you are the controller of your contacts’ data and Linkato acts as a processor, processing it under your documented instructions. For your account data, Linkato is the controller (see Privacy).
3. How we support your compliance
- Appropriate technical and organizational security measures.
- Tools to manage consent, unsubscribe and data-subject rights.
- Prompt notification of any data breach affecting us.
- Transparency about sub-processors and international transfers.
4. Compliance checklist for the Customer
- Identify a valid legal basis for each send (usually consent).
- Provide a clear privacy notice to your contacts.
- Collect and keep proof of consent.
- Honor access, rectification and erasure requests promptly.
- Enter into this DPA and, where needed, the Standard Contractual Clauses.
5. DPA — Subject matter and duration
The subject matter is the provision of the Linkato service; the duration matches the contract. Nature and purpose: sending, storing and processing the Customer’s communications and contacts.
6. DPA — Data categories and data subjects
- Data subjects: the contacts/subscribers in the Customer’s lists.
- Data categories: identifying and contact data, custom fields defined by the Customer, engagement data (opens, clicks).
- No special categories of data are processed unless the Customer instructs otherwise with an appropriate legal basis.
7. DPA — Obligations of the parties
Linkato processes data only on the Customer’s documented instructions, ensures confidentiality of authorized staff, applies appropriate security measures, and assists the Customer with data-subject and authority obligations. The Customer warrants the lawfulness of the data and instructions.
8. DPA — Sub-processors
The Customer authorizes the use of sub-processors. We keep an up-to-date list and will inform the Customer of material changes, allowing objection on reasonable grounds. The indicative list is set out in the Privacy Policy.
9. DPA — International transfers
Any transfers outside the EEA take place with appropriate safeguards (Standard Contractual Clauses or recognized frameworks). On request we provide information about the safeguards applied.
10. DPA — Audit, return and deletion
Upon reasonable request we make available the information needed to demonstrate compliance. At the end of the contract we delete or return the data processed on the Customer’s behalf, subject to legal retention obligations.
11. Contact
For the DPA or GDPR questions: privacy@linkato.ai — AMAZ ONLINE SRLS, Via Raffaello Sanzio 23, 62027 San Severino Marche (MC), Italy.