1. Scope
This Privacy Policy explains how Lynka CRM ("Lynka", "we", "us" or "our") collects, uses, stores, discloses and otherwise processes personal data when you visit lynkacrm.com, create or use an account, join a workspace, connect an integration, communicate through Lynka, use Lead Generator, purchase a subscription, request an export or deletion, contact Support, or otherwise use the Services.
2. Who Is Responsible
For Lynka's own processing, "Lynka" means Anthony Akiki, trading as Lynka, an unincorporated business operated from WJH9+7CP, Beit El Chaar, Mount Lebanon, Lebanon. Questions and privacy requests may be sent to support@lynkacrm.com. Formal legal notices may also be sent to WJH9+7CP, Beit El Chaar, Mount Lebanon, Lebanon. When an organization controls a Lynka workspace and decides why personal data in that workspace is used, that organization is generally the controller and Lynka generally acts as its processor or service provider.
3. Controller and Processor Roles
Lynka generally acts as a controller for account registration, authentication, subscriptions and billing administration, website use, service security, support, legal compliance, operational communications and Lynka's own business operations. When a customer uses Lynka to store or manage its own leads, contacts, customers, suppliers, employees, emails, documents, transactions, tickets or other business records, the customer generally determines the purposes and means of that processing and Lynka processes the data on the customer's documented instructions. The Data Processing Agreement contains additional processor terms.
4. Personal Data We Process
Depending on the features used, Lynka may process names, business contact details, account and profile data, workspace membership and permissions, company and professional information, leads, contacts, companies, opportunities, activities, notes, quotes, invoices, products, suppliers, purchase orders, goods receipts, support tickets, accounting and transaction records entered into the service, communication content and metadata, subscription and payment metadata, files and documents, integration data, consent and communication preferences, device and browser information, session information, page paths, timestamps, security events, audit records and support communications.
5. Where Personal Data Comes From
We receive personal data directly from users and customers; from workspace owners, administrators and authorized users; from integrations chosen by users; from authentication, payment, email, infrastructure and analytics providers; automatically from use of our websites and Services; and, for Lead Generator, from public sources, search services, business-data providers or other third-party sources. Lynka may also create operational records such as audit logs, consent events, security events, attribution data, delivery events and usage records from activity in the Services.
6. Customer Workspace Data
Customers can enter, import, generate, upload or connect information relating to their own customers, prospects, contacts, suppliers, employees and other people or organizations ("Customer Data"). The customer is responsible for having the lawful basis, rights, notices and permissions required to use that data, responding to applicable privacy rights, honoring objections and opt-outs, and configuring appropriate access for workspace users. Lynka processes Customer Data to provide, secure, maintain and support the Services and as otherwise permitted by customer instructions, the Data Processing Agreement, applicable law and our agreements.
7. Lead Generator and Business Contact Information
Lead Generator can return business information obtained from public or third-party sources. Depending on availability, results may include a business name, category, location, address, website, telephone number, email address, rating, description, review information or related links. Results can be incomplete, outdated or inaccurate and not every result contains every field. Customers decide which results to save and use. Access to information through Lynka is not legal permission to contact a person or business. Customers remain independently responsible for privacy, direct-marketing, electronic-communications, telemarketing and anti-spam laws that apply to their outreach.
8. Sale, Sharing and Data-Broker Laws
Lynka does not sell Customer Data that a customer entrusts to Lynka solely for processing on that customer's behalf. Lead Generator is different: it may make business or professional contact information from public or third-party sources available to customers as part of the Services. Some jurisdictions use broad definitions of "sale", "sharing", "data broker" or similar regulated activity. Where a law applicable to Lynka legally classifies Lead Generator activity in that way, Lynka will provide the notices, registrations, opt-out, suppression, access, correction or deletion mechanisms required by that law. Requests concerning Lead Generator data may be sent to support@lynkacrm.com.
9. Google and Gmail Data
If you connect a Google account, Lynka uses Google's OAuth authorization process and requests the permissions shown during connection. Depending on the Gmail features you enable, Lynka may identify the connected account, read messages and related metadata, display and link Gmail activity with CRM records, and send email through the connected Gmail account. Lynka may store message and thread identifiers, sender and recipient information, subject lines, snippets, message bodies, labels, timestamps, synchronization state and access or refresh credentials needed to maintain the authorized integration. Google user data is used only to provide or support user-facing features you authorize and is handled in accordance with the Google API Services User Data Policy, including Limited Use requirements.
10. Payments and Subscription Data
Subscription payments may be processed by Paystack or another supported payment provider. Payment-card details submitted during checkout are processed by the payment provider under its own terms and privacy practices. Lynka may receive and store information needed to administer the subscription, such as account email, payment reference, subscription or invoice identifier, amount, currency, payment status, card brand and the last four digits of a card where provided by the processor. Lynka does not need full card numbers or card security codes for subscription processing and does not intentionally store those full credentials in its application database.
11. How We Use Personal Data
We use personal data to create and manage accounts and workspaces; authenticate users and enforce permissions; provide CRM, sales, agreements, inventory, accounting, marketing, reporting, support, email and communication features; operate Lead Generator; provide integrations chosen by users; generate documents and reports; administer subscriptions and billing; send operational messages and notifications; provide support; prevent fraud, spam, abuse and security threats; enforce plan limits and policies; maintain audit and activity records; diagnose errors and improve reliability; process exports, objections, corrections and deletion requests; comply with law; establish, exercise or defend legal claims; protect Lynka, users and third parties; and improve the Services using information we are legally permitted to process for that purpose.
12. Legal Bases Where Required
Where applicable law requires a legal basis, Lynka may rely on performance of a contract or steps requested before entering a contract; compliance with legal obligations; consent where consent is required; and legitimate interests such as providing and securing the Services, preventing abuse, supporting users, maintaining business records, improving reliability and operating the business, provided those interests are not overridden by applicable rights. Where Lynka acts solely as a processor, the customer is responsible for determining the legal basis for its processing.
13. Marketing, Email and Communication Preferences
Lynka may send operational communications relating to accounts, authentication, security, billing, service activity and transactions. Where Lynka sends marketing on its own behalf, it applies consent, legitimate-interest, opt-out or other requirements that apply. Customers using Lynka to contact their own recipients are responsible for the message, recipients, lawful basis, sender identification and legally required opt-out mechanism, and for honoring unsubscribe, objection, suppression, complaint and hard-bounce signals. Lynka may retain suppression information where necessary to prevent prohibited or unwanted sending.
14. Automation and AI-Assisted Processing
Lynka may provide rule-based, automated or AI-assisted features where enabled. Automated results can be affected by incomplete data, configuration errors, model limitations, service limits or third-party availability and may be inaccurate. Customers remain responsible for reviewing important business, legal, accounting, tax, employment, financial or other decisions. Where applicable law provides rights concerning solely automated decisions that produce legal or similarly significant effects, those rights remain available.
16. Service Providers and Subprocessors
Lynka uses service providers to operate parts of the Services. Current providers include Supabase for database, authentication and storage infrastructure; Vercel for web application and website hosting where deployed; Cloudflare R2 for external document storage where used; Resend for transactional and service email; Paystack for subscription payment processing where used; PostHog for analytics where the applicable consent and deployment configuration permit it; Sentry for application error and performance monitoring; n8n for automated workflow execution; and SerpApi for the currently released Lead Generator search workflow. Google is a user-selected integration provider when Gmail is connected. Apify is planned for a future Lead Generator V2 and is not represented as a current released provider until that version is enabled. The published Subprocessor List may be updated as the production stack changes.
17. Data Location and International Transfers
The primary Lynka Supabase project reviewed for this Policy is deployed in Supabase's eu-west-1 region, with the primary database, Auth service and Supabase Storage associated with that project hosted in that region. Other service providers, external storage, integrations, logs and edge processing may operate in other countries. Where data-protection law requires safeguards for a restricted international transfer, Lynka will use an applicable lawful transfer mechanism, such as an adequacy decision, approved contractual clauses or another legally permitted safeguard.
18. Data Retention
Lynka retains personal data for the period reasonably necessary for the purpose for which it is processed, customer instructions, contractual requirements, security and fraud prevention, legal claims and applicable legal obligations. Production retention differs by data type. Current lifecycle behavior includes a seven-day account-deletion grace period, a fourteen-day workspace-deletion grace period and seven-day retention of completed lifecycle export archives. Certain operational records are automatically pruned on shorter schedules. Billing, tax, legal-acceptance, consent, suppression, deletion-request, fraud, security and dispute records may be retained longer where reasonably necessary to prove a transaction or consent, comply with law, prevent abuse or establish, exercise or defend legal claims. See the Data Retention & Deletion Policy for additional detail.
19. Account Deletion
When an eligible user requests account deletion, Lynka currently schedules the request for seven days later, allowing the request to be cancelled during that grace period. A sole owner must first transfer ownership or delete the affected workspace. When the deletion worker completes the request, active memberships are revoked, directly personal profile fields are removed or replaced with a deleted-user marker, directly personal preference and integration records covered by the deletion workflow are removed, a stored profile avatar is removed where identifiable, and the Supabase Auth user is deleted. Business records that belong to a customer-controlled workspace may remain where the workspace itself has not been deleted, but the deleted user's profile is de-identified in the active CRM record. Legal, lifecycle, consent, billing, security and other records may remain where retention is reasonably necessary or legally permitted.
20. Workspace Deletion
A workspace owner can request workspace deletion. Lynka currently applies a fourteen-day grace period before permanent purge. At purge, the active deletion workflow removes workspace files from the relevant Lynka Supabase Storage locations, removes tracked Cloudflare R2 objects used for external document storage, and deletes the tenant's active database records through the workspace purge process. Users who belong to another workspace may remain as users of that other workspace. A workspace export can be requested separately before deletion. Completed lifecycle export archives are deleted after seven days.
21. Backups, Logs and Residual Copies
Deletion from active systems may not remove every residual copy at the exact same moment. Infrastructure providers may maintain protected backups, system logs, security records, caches or disaster-recovery data for provider-managed retention periods. Deleted information retained only in such systems is not used for ordinary customer-facing processing and is allowed to expire or is deleted under the applicable provider or Lynka retention process. The current Supabase project reviewed for this Policy is on Supabase's Free plan, which does not provide a contractual customer-facing daily-backup retention commitment comparable to paid-plan backup windows.
22. Data Exports
Lynka provides personal and workspace export workflows where available. Export requests can require authorization and workspace permissions. Completed export archives are currently retained in a private lifecycle-export storage bucket for seven days and are then removed by the retention worker. Customers are responsible for protecting files after download and for keeping any records they are legally required to retain.
23. Security
Lynka uses administrative, technical and organizational safeguards designed to protect personal data against unauthorized access, alteration, disclosure, loss and destruction. Current controls include authenticated access, Row Level Security and workspace isolation across many application tables, role and permission controls, private storage for protected files, logging and monitoring, and internal authenticated worker processes for sensitive lifecycle actions. No internet service can guarantee absolute security. Users are responsible for protecting credentials and devices, assigning appropriate permissions and promptly reporting suspected unauthorized access.
25. Privacy Rights
Depending on your location and applicable law, you may have rights to request access, a copy, correction, deletion, restriction, objection, portability, withdrawal of consent, objection to direct marketing, and opt-out of certain sale or sharing activities, and to complain to a privacy authority. Some rights are subject to legal exceptions and verification. If your data is in a customer-controlled workspace, that customer may be the controller responsible for the request and Lynka may direct the request to that customer or assist it in responding.
26. Privacy Request Timing
Lynka will respond to valid privacy requests within the period required by the law that applies to the request. Where the GDPR applies, information about action taken on a request is generally provided without undue delay and within one month, subject to lawful extensions for complex or numerous requests. A right to erasure does not require deletion of information that Lynka is legally entitled or required to retain.
27. Lead Generator Privacy Requests
If personal or professional information relating to you appears in Lead Generator, you may request access, correction, suppression, objection, opt-out or deletion through support@lynkacrm.com. Where Lynka controls the relevant processing, we will assess the request under applicable law. Where a Lynka customer has already saved the information and independently uses it in its own workspace, that customer may also be a controller responsible for its separate processing.
28. Children
Lynka is a business service and is not intended for children. A person creating a Lynka account must be at least 18 years old or the age of legal majority required to enter a binding business agreement in the applicable jurisdiction, unless an authorized organization has lawfully provided access under different arrangements.
29. Changes to This Policy
We may update this Privacy Policy when the Services, integrations, law or data practices change. The current version will show a revised last-updated date. Where a material change affects previously collected personal data and applicable law requires notice, consent or another choice, Lynka will provide the legally required process before applying the new use.
30. Contact and Complaints
Privacy questions, rights requests, legal notices and complaints may be sent to support@lynkacrm.com. We may request information reasonably necessary to verify identity, authority or the account involved. Depending on your jurisdiction, you may also have the right to complain to the competent privacy or data-protection authority.