PRIVACY POLICY
Last updated 1 August 2026 · Version 2.4
This policy explains what personal data Linkforge ("we") collects through saaslinkbuildingservice.com, why, how long we keep it, and what rights you have over it. It is written to satisfy the UK GDPR, the EU GDPR (Regulation 2016/679) and, where applicable, the California Consumer Privacy Act.
1. Who is responsible
Linkforge is the data controller for information collected through this site. We are a productised SaaS link building service.
999 W Main StBoise, ID 83702, United States
+1 (986) 800 9412 999 W Main St
Boise, ID 83702, United States
+1 (986) 800 9412 999 W Main St
Boise, ID 83702, United States
+1 (986) 800 9412
To reach the person responsible for data protection, use the quote form and begin your message with "Privacy request". It is routed away from the commercial queue.
2. What we collect
| Category | Contents | Source |
|---|---|---|
| Enquiry data | Name, work email, company and domain, target page and keyword, package of interest, funding stage, free-text message | You, via the form |
| Anti-abuse data | IP address and browser user-agent recorded by the form processor at the moment of submission | Automatic, submission only |
| Correspondence | Emails, gap audits, quotes and notes exchanged afterwards | You and us |
Nothing else is collected. This site runs no analytics, sets no advertising or session cookies, embeds no third-party pixels and does no device fingerprinting. That is why you have not seen a cookie banner — there is nothing to consent to. The only outbound requests the page makes are for its own stylesheet and script, a web-font stylesheet, and the form endpoint at the moment you press send.
We also record limited technical information about every visit — pages, clicks, country, a truncated network address and whether the request came from a person or a crawler. Section 10 sets out exactly what, why, and for how long.
3. Why we use it
- To reply and produce the free gap audit and quote you asked for. Basis: your consent, plus steps taken at your request before entering a contract.
- To prevent automated abuse of the form. Basis: legitimate interest.
- To meet accounting and legal obligations where an engagement begins. Basis: legal obligation.
No profiling, no automated decision-making, no marketing list. Submitting the form subscribes you to nothing. If we do not end up working together, you will not hear from us again unless you write again.
4. Who processes it for us
- Form processor — receives the submission and relays it to our internal inbox; stores it transiently for delivery and spam filtering.
- Email provider — hosts the inbox receiving your enquiry and subsequent correspondence.
- Cloud storage and document tools — used to produce gap audits, quotes and client reporting sheets.
- Accounting software — only where an engagement begins, and only for legally required records.
Each is bound by a data-processing agreement and may not use your data for its own purposes. We never sell, rent, licence or trade personal data, and we never pass your details to other agencies, publishers, link vendors or lead brokers.
5. International transfers
Some processors run infrastructure outside the European Economic Area, principally in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.
6. How long we keep it
| Enquiries that do not become engagements | 24 months from last contact, then deleted |
|---|---|
| Enquiries we decline | 12 months, so the context survives if you write again |
| Client records | Term of engagement plus 7 years where tax law requires |
| Anti-abuse logs | 30 days |
7. Your rights
Wherever you are based we honour: access, rectification, erasure, restriction of processing, portability, objection to processing based on legitimate interest, and withdrawal of consent at any time without affecting processing already carried out.
Exercise any of them through the form. We respond within 30 days, usually much sooner, and never charge a fee. If you are unhappy with the outcome you may complain to your national supervisory authority.
8. Security
Served over HTTPS; submissions encrypted in transit. Internally, access to enquiry data is limited to the two founders and the researcher assigned to your account. Devices are encrypted at rest and shared tools require two-factor authentication. If a breach ever creates a risk to your rights, we notify you and the relevant authority within 72 hours of becoming aware of it.
9. Children
A business-to-business service; we do not knowingly collect data from anyone under 16. Tell us if you believe a minor has submitted data here and we will delete it.
10. Cookies and measurement
No cookies. This site sets no cookies at all — none for advertising, none for sessions, and none belonging to anyone but us. That is why you have not been asked to dismiss a banner.
One first-party identifier. Your browser stores a random string in this site's own local storage so we can tell a returning reader from a new one. It is not a cookie, it is not readable by any other website, it is never sold, shared or matched against anything, and clearing your browser data removes it. It carries no name, email or account.
What our own measurement records. We run no Google Analytics and no third-party trackers. Our own servers log, for each request:
- the page requested, the page you arrived from, and the time
- which links and buttons were clicked, including the telephone button, and how far down a page was read
- your country and the name of your internet provider or network
- your network address — stored truncated (for example
81.161.243.x) together with a one-way daily hash, so repeat visits can be recognised without us holding the full address - your browser's user-agent string, and whether the request came from a person or an automated crawler
Why. To see which pages and campaigns work, to keep the site available, and to separate genuine readers from the crawlers and scrapers that make up a large share of traffic. Legal basis: our legitimate interest in operating and improving the site (Article 6(1)(f) GDPR). We have limited what we collect specifically so that this basis holds — no cross-site tracking, no profiles, no advertising use, no data brokers.
How long. Raw request and interaction logs are deleted automatically after 180 days. Enquiries you send us are kept for as long as section 6 describes.
Opting out. If your browser sends a Global Privacy Control signal we record no interaction data at all. You can also block this site's scripts, or write to us using the contact details in section 1 and we will delete what relates to you.
11. Changes
Material changes are reflected in the version and date at the top. Where a change affects data you have already given us, we contact you before it takes effect.
← Back to the homepage