Privacy Policy

1. Scope and controller

This Policy explains how LongLink handles personal data when you visit our website, use our hosted platform, connect infrastructure, or contact us. The hosted platform is for users aged 18 or older. We do not knowingly collect children's data through the platform; contact us if you believe a child has provided it.

The controller is LongLink SAGL, UID CHE-150.642.313. Privacy enquiries and requests may be sent to info@longlink.ch.

"Service" means our website, hosted platform, and related support, including the SDK and runtime when connected to our platform. Separate service or data processing agreements also apply where relevant.

2. Our roles

We are the controller for account, organization, authentication, support, security, and other operational data needed to run our Service. This Policy primarily describes those activities.

Customers generally control the personal data they put in Solutions and connected databases or storage. When we operate the hosted Service for them, we generally process that Customer Content on their behalf.

If another organization operates LongLink, that operator is responsible for its own privacy practices. Customers are responsible for notices, lawful bases, retention, and user requests for personal data they process through their Solutions.

3. Personal data we process

Depending on how you use the Service, we may process the following categories of personal data:

  • Account and identity data: name, email address, optional avatar, account identifiers, roles, and sign-in information.
  • Authentication data: password hashes, signed session and email-verification tokens, password-reset tokens, and OAuth sign-in data. We do not store plaintext passwords.
  • Organization and access data: organization details, memberships, roles, invitations, infrastructure assignments, and audit records.
  • Solution and deployment data: names, images, versions, configuration, environment values, deployment status, errors, and runtime information needed to operate Solutions.
  • Connected infrastructure data: provider settings, endpoints, credentials, resource identifiers, usage information, and audit records for compute, databases, and storage.
  • Connection and log data: IP addresses, request and session details, timestamps, errors, security events, and operational or runtime logs.
  • Commercial data: billing contacts, invoices, payment status, and accounting records when we provide a paid service. We do not process full payment-card details in the platform; a payment or banking provider handles those if a separate payment flow is used.
  • Communications: messages, attachments, and contact details when you reach out to us for support, security reports, or other enquiries.
  • Customer Content: data processed by Solutions, connected databases, storage, and runtime services. We do not routinely inspect it, but authorized personnel may access it for support, security, abuse investigations, or legal requirements.

We receive data from you, organizations that invite or administer you, identity providers, connected infrastructure, and your use of the Service.

We do not sell personal data. We do not currently use third-party advertising trackers or analytics to build advertising profiles about visitors.

4. Why we process personal data

We process data to create accounts, manage organizations and access, operate Solutions and connected infrastructure, deliver account and service messages, protect the Service, diagnose problems, and improve reliability. This includes synchronizing organization users to Solution databases where needed for access. We also respond to enquiries, handle disputes, and meet legal obligations.

The Service automatically checks access and provisions or removes resources. These operational actions are not behavioral profiling. We do not use personal data for automated decisions that have legal or similarly significant effects. Contact us if an operational action appears incorrect and you want human review.

Where a legal basis is required, including under the EU or UK GDPR, we rely as appropriate on a contract, legal obligation, legitimate interests in operating and protecting the Service, or consent for optional uses. You may withdraw consent without affecting earlier processing.

5. Service providers and other recipients

We disclose only the data reasonably needed for the recipient's role:

  • Infrastructure providers and connected registries receive the configuration, secrets, and request data needed to host and operate Solutions.
  • Email providers receive contact details and message content to deliver invitations, account notices, and support messages.
  • Logging and monitoring providers receive operational data needed for reliability and security.
  • Payment, banking, or accounting providers receive billing data if you use a paid service or separate payment flow.
  • Advisers and authorities receive data where needed for legal, accounting, security, or regulatory purposes.
  • A prospective buyer or successor may receive data in a business transaction, subject to appropriate safeguards.

Some providers also act as independent controllers for their own legal and security purposes. Their privacy policies govern that processing.

6. International transfers

Personal data may be processed where we, our providers, or your connected infrastructure operate, including Switzerland, the European Economic Area, the United States, and other countries.

Where required, we use recognized adequacy decisions, contractual safeguards, or other lawful transfer mechanisms. Contact us for information about safeguards relevant to a particular transfer.

7. Cookies and similar storage

We use HTTP-only cookies for signed sign-in sessions, email registration, password resets, and OAuth sign-in. These are necessary for account access and security. A separate payment provider may set cookies if you visit its service.

During registration or password reset, your browser may briefly keep a verification token in session storage to complete the flow. Blocking or deleting these cookies or storage may interrupt sign-in or account setup.

We do not currently set advertising or cross-site tracking cookies. If that changes, we will update this Policy and provide any choices required by law.

8. Retention

We keep data for as long as needed to provide the Service or meet legal and security obligations:

  • account, membership, and invitation data are generally kept while the account or organization is active, then deleted or anonymized when no longer needed;
  • Solution, infrastructure, operation, and audit records are kept while needed to operate or secure the Service, and longer for investigations, disputes, or legal duties;
  • access, runtime, and security logs are generally kept for up to 12 months, longer when needed for an incident, dispute, or legal claim;
  • support and security communications are generally kept for up to three years after resolution;
  • invoices and accounting records, where applicable, are generally kept for 10 years under Swiss record-keeping requirements;
  • infrastructure credentials are kept while the related resource is configured, then deleted or rotated when no longer needed; and
  • Customer Content may be erased without a recovery period when a Solution, organization, or connected resource is deleted. Export data and keep independent backups.

Data may remain temporarily in protected backups or with providers subject to their own retention obligations. We delete, anonymize, or isolate it when no longer needed until backups expire.

9. Security and data incidents

We use safeguards appropriate to the risk, including access controls, password hashing, signed session cookies, transport encryption, resource isolation, secret management, and logging. No system is completely secure. You are responsible for securing your accounts, Solutions, and connected infrastructure.

We assess personal-data breaches and notify the Federal Data Protection and Information Commissioner (FDPIC) where a breach is likely to result in a high risk to a person's personality or fundamental rights. We notify affected individuals where required by law or where notification is necessary for their protection.

10. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, objection, or transfer of your personal data. You may request account closure and withdraw consent where we rely on it.

Send requests to info@longlink.ch. We may verify your identity before responding. We generally respond within 30 days. Access is normally free, subject to fees or exceptions permitted by law.

You may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) or another competent data-protection authority.

11. Changes to this Policy

We may update this Policy as the Service, providers, deployment model, or legal requirements change. We will post the revised Policy with a new update date. If a change materially affects how we use existing account data, we will provide reasonable advance notice through email or the Service where required.

12. Contact

LongLink SAGL, UID CHE-150.642.313.

Privacy enquiries and data-rights requests: info@longlink.ch. Security, technical, and account support: info@longlink.dev.