← Back to the homepage

PRIVACY POLICY

Last updated 1 August 2026 · Version 2.4

This policy explains what personal data Linkforge ("we") collects through saaslinkbuildingservice.com, why, how long we keep it, and what rights you have over it. It is written to satisfy the UK GDPR, the EU GDPR (Regulation 2016/679) and, where applicable, the California Consumer Privacy Act.

1. Who is responsible

Linkforge is the data controller for information collected through this site. We are a productised SaaS link building service.

To reach the person responsible for data protection, use the quote form and begin your message with "Privacy request". It is routed away from the commercial queue.

2. What we collect

CategoryContentsSource
Enquiry dataName, work email, company and domain, target page and keyword, package of interest, funding stage, free-text messageYou, via the form
Anti-abuse dataIP address and browser user-agent recorded by the form processor at the moment of submissionAutomatic, submission only
CorrespondenceEmails, gap audits, quotes and notes exchanged afterwardsYou and us

Nothing else is collected. This site runs no analytics, sets no advertising or session cookies, embeds no third-party pixels and does no device fingerprinting. That is why you have not seen a cookie banner — there is nothing to consent to. The only outbound requests the page makes are for its own stylesheet and script, a web-font stylesheet, and the form endpoint at the moment you press send.

We also record limited technical information about every visit — pages, clicks, country, a truncated network address and whether the request came from a person or a crawler. Section 10 sets out exactly what, why, and for how long.

3. Why we use it

No profiling, no automated decision-making, no marketing list. Submitting the form subscribes you to nothing. If we do not end up working together, you will not hear from us again unless you write again.

4. Who processes it for us

Each is bound by a data-processing agreement and may not use your data for its own purposes. We never sell, rent, licence or trade personal data, and we never pass your details to other agencies, publishers, link vendors or lead brokers.

5. International transfers

Some processors run infrastructure outside the European Economic Area, principally in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.

6. How long we keep it

Enquiries that do not become engagements24 months from last contact, then deleted
Enquiries we decline12 months, so the context survives if you write again
Client recordsTerm of engagement plus 7 years where tax law requires
Anti-abuse logs30 days

7. Your rights

Wherever you are based we honour: access, rectification, erasure, restriction of processing, portability, objection to processing based on legitimate interest, and withdrawal of consent at any time without affecting processing already carried out.

Exercise any of them through the form. We respond within 30 days, usually much sooner, and never charge a fee. If you are unhappy with the outcome you may complain to your national supervisory authority.

8. Security

Served over HTTPS; submissions encrypted in transit. Internally, access to enquiry data is limited to the two founders and the researcher assigned to your account. Devices are encrypted at rest and shared tools require two-factor authentication. If a breach ever creates a risk to your rights, we notify you and the relevant authority within 72 hours of becoming aware of it.

9. Children

A business-to-business service; we do not knowingly collect data from anyone under 16. Tell us if you believe a minor has submitted data here and we will delete it.

10. Cookies and measurement

No cookies. This site sets no cookies at all — none for advertising, none for sessions, and none belonging to anyone but us. That is why you have not been asked to dismiss a banner.

One first-party identifier. Your browser stores a random string in this site's own local storage so we can tell a returning reader from a new one. It is not a cookie, it is not readable by any other website, it is never sold, shared or matched against anything, and clearing your browser data removes it. It carries no name, email or account.

What our own measurement records. We run no Google Analytics and no third-party trackers. Our own servers log, for each request:

Why. To see which pages and campaigns work, to keep the site available, and to separate genuine readers from the crawlers and scrapers that make up a large share of traffic. Legal basis: our legitimate interest in operating and improving the site (Article 6(1)(f) GDPR). We have limited what we collect specifically so that this basis holds — no cross-site tracking, no profiles, no advertising use, no data brokers.

How long. Raw request and interaction logs are deleted automatically after 180 days. Enquiries you send us are kept for as long as section 6 describes.

Opting out. If your browser sends a Global Privacy Control signal we record no interaction data at all. You can also block this site's scripts, or write to us using the contact details in section 1 and we will delete what relates to you.

11. Changes

Material changes are reflected in the version and date at the top. Where a change affects data you have already given us, we contact you before it takes effect.

← Back to the homepage