Privacy Policy
Effective Date: October 18, 2024 Last Updated: September 2, 2026
This Privacy Policy explains how LinkyBot LLC, a California limited liability company ("LinkyBot," "we," "our," or "us"), collects, uses, shares, and protects personal information when you visit linkybot.ai, become a client, or interact with our services. LinkyBot is a platform-agnostic B2B go-to-market advisory and managed-services company. We help B2B teams build repeatable pipeline through go-to-market strategy, permitted prospect research, messaging, CRM workflow design, AI-assisted drafting and analysis, and outcome measurement (the "Services"). By using our website or the Services, you agree to the practices described in this policy.
1. Our Two Roles: Business and Service Provider
We handle personal information in two distinct capacities, and your rights depend on which category applies to you.
- As a business (controller). For information about our website visitors, prospective clients, and clients of LinkyBot itself, we decide how and why the data is used. This policy fully governs that data.
- As a service provider (processor). When we deliver the Services for a client, we handle data the client controls, such as records in the client's CRM, client-provided files, and research the client directs us to prepare. For that data, our client is the business (controller) and we act as a service provider under the California Consumer Privacy Act (CCPA) and as a processor under the EU General Data Protection Regulation (GDPR), where applicable. We handle client-controlled data only to deliver the Services and never for our own marketing purposes.
If a company that engaged us holds information about you, that company determined the purpose of the processing. Section 9 explains how to direct privacy requests about client-controlled data.
2. Where Information Comes From
We collect personal information directly from clients, prospective clients, website visitors, and people who communicate with us; from client-owned CRM systems, client-provided files, and client-authorized integrations; from our forms, communications, meetings, payment interactions, and service-usage records; from licensed business-data providers; and from public business sources such as company websites and government or business registries.
3. Information We Collect
3.1 Client and Prospective Client Information
- Identity and contact data: name, email address, phone number, company name, job title, and mailing address.
- Account data: engagement details, plan selection, service preferences, and approval decisions.
- Billing data: billing contact, billing address, and payment records processed by our payment processor. We do not store full card numbers on our systems.
- Communications: emails, form submissions, support requests, and call or meeting notes.
3.2 Client-Controlled Business Data
- CRM records the client controls, including business contact details, account and opportunity records, pipeline stages, and activity history.
- Campaign-planning data: target account and contact lists, qualification criteria, offers, messaging drafts, and sequence plans prepared for client review and approval.
- Outcome OS data: client-authorized CRM milestones and outcome measurements organized into a single reporting view.
3.3 Service-Usage, Analytics, and Security Data
- Service-usage records: deliverables produced, work performed, approvals recorded, and reporting activity.
- Website and analytics data: IP address, browser type, operating system, referring pages, pages viewed, and time on site.
- Security and access logs used to protect our systems and investigate incidents.
4. How We Use Information
We use personal information to:
- Deliver the Services, including strategy, research, messaging, and reporting work.
- Administer CRM workflows and integrations that clients authorize.
- Communicate with clients and prospective clients about the Services, including updates, reports, and support.
- Process payments and manage accounts, contracts, and subscriptions.
- Support AI-assisted drafting, research synthesis, and qualification analysis, with people making the judgment calls.
- Measure outcomes and improve the Services and our website through analytics.
- Protect our systems and detect, prevent, and address fraud, abuse, and security incidents.
- Send marketing communications about our own services, which you can opt out of at any time.
- Comply with legal obligations and enforce our agreements.
We do not use client or prospect data to train artificial intelligence models. Where we use AI tools to help deliver the Services, data is used only to perform the task at hand and is not retained by us for model training.
Legal Bases (EEA and UK Residents)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (delivering the Services to clients); legitimate interests (operating and improving the Services, business-to-business communications, and securing our systems); consent (where required, such as for certain cookies or marketing); and legal obligation (tax, accounting, and compliance records).
5. How We Share Information
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We share information only in the following circumstances.
5.1 Subprocessors and Service Providers
We use a small number of vetted providers to operate the Services. Each receives only the data needed for its function and is bound by contractual confidentiality and data protection obligations. Our current list of active subprocessors, including each provider's purpose and the general category of data involved, is published at linkybot.ai/subprocessors.
5.2 Legal Compliance
We may disclose information when required by law, subpoena, or court order, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others, or to investigate fraud.
5.3 Business Transfers
If LinkyBot LLC is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction. We will notify affected users of any such change and any choices they have regarding their data.
6. We Do Not Sell or Share Your Personal Information
LinkyBot does not sell personal information for monetary or other valuable consideration, and does not share personal information with third parties for cross-context behavioral advertising, as those terms are defined under California law. Because we do not sell or share personal information, no opt-out is required. If our practices ever change, we will update this policy, provide the required "Do Not Sell or Share My Personal Information" mechanism, and give at least thirty (30) days' notice as described in Section 13.
7. Data Retention
We retain personal information for the periods below. A retention period may be shortened by an approved deletion request or extended where a legal obligation requires it.
- Client, CRM, campaign-planning, prospect, and Outcome OS records: the duration of the client relationship plus ninety (90) days.
- Approved deliverables: the duration of the client relationship plus ninety (90) days.
- Temporary AI inputs and unapproved outputs: thirty (30) days.
- Website inquiries, support records, and ordinary business communications: twenty-four (24) months after the last substantive interaction.
- Security and access logs: twelve (12) months.
- Website analytics data: fourteen (14) months.
- Billing, tax, contracts, and accounting records: seven (7) years.
- Opt-out and suppression records: five (5) years.
- Backups: overwritten or deleted within thirty-five (35) days after the data is removed from active systems.
- Verified deletion requests: eligible data is removed from active systems within thirty (30) days.
- Legal holds: retained only until the applicable legal obligation ends.
8. Cookies and Analytics
Our website uses the following tracking technologies:
- GoHighLevel (LeadConnector) scripts that power our forms, scheduling, and site analytics.
You can also control cookies through your browser settings, including blocking or deleting them. Disabling cookies may limit some site functionality. We do not run third-party advertising pixels on our website.
Because some browsers' Global Privacy Control (GPC) and Do Not Track signals lack a common standard, and because we do not sell or share personal information, our site does not respond differently to those signals.
9. Data Security
We use commercially reasonable administrative, technical, and physical safeguards to protect personal information, including encryption in transit, access controls, least-privilege access, and vendor due diligence. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Breach Notification
If a security incident affects your personal information, we will notify affected clients and individuals without undue delay and in accordance with applicable breach notification laws, including California Civil Code section 1798.82. For client-controlled data we handle as a service provider, we will notify the affected client promptly so they can meet their own notification obligations.
10. Your Privacy Rights
Subject to applicable law, you may request to access, correct, or delete the personal information we hold about you, object to or restrict certain processing, and receive a copy of your data in a portable format. To exercise any right, email casey@linkybot.ai with the subject line "Privacy Request." We will verify your identity and respond within the time required by applicable law. We will not discriminate against you for exercising your rights.
10.1 California Residents
California residents have rights under the CCPA, as amended by the CPRA, including the rights to know, delete, and correct personal information, and the right to non-discrimination. As stated in Section 6, we do not sell or share personal information and do not use sensitive personal information for purposes requiring a right to limit. You may use an authorized agent to submit a request; we will require proof of authorization and verification of your identity.
10.2 Canadian Residents
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) for personal information of Canadian residents. You may request access to and correction of your personal information and may withdraw consent to its use, subject to legal and contractual restrictions. You may also challenge our compliance by contacting us, and you have the right to complain to the Office of the Privacy Commissioner of Canada.
10.3 Australian Residents
We handle personal information of Australian residents consistent with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). You may request access to and correction of your personal information. If you believe we have breached the APPs, you may complain to us and, if unresolved, to the Office of the Australian Information Commissioner (OAIC).
10.4 EEA and UK Residents
Although our Services are directed to clients in the United States, Canada, and Australia, individuals in the European Economic Area or United Kingdom whose data we handle have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local supervisory authority. Where we transfer EEA or UK personal data to the United States, we rely on appropriate safeguards such as Standard Contractual Clauses.
10.5 Requests About Client-Controlled Data
If your information is held by a client and we handle it on that client's behalf, we may refer your request to that client or handle it on their instructions, as required of a service provider. Either way, if you ask us to stop contacting you, we will add you to our suppression list and cease outreach to you across the Services.
11. International Data Transfers
We are based in the United States and process data on servers located in the United States. If you access the Services from Canada, Australia, or elsewhere, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction. We protect transferred data using the safeguards described in this policy and, where legally required, approved transfer mechanisms.
12. Children's Privacy
The Services are a business tool intended for users who are at least eighteen (18) years old, consistent with our Terms of Service. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a person under 18, we will delete it promptly.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice by email or through a prominent notice on our website at least thirty (30) days before the changes take effect, consistent with our Terms of Service. The "Last Updated" date at the top of this policy shows when it was most recently revised. Prior versions remain available in our archive for reference.
14. Contact Us
LinkyBot LLC 351 Paseo Nuevo, 2nd Floor, Santa Barbara, CA 93101 Email: casey@linkybot.ai (use subject line "Privacy Request" for rights requests) Phone: (805) 909-3347