Data subjects
Customer account users, team members, website contacts, publishers, journalists, outreach recipients, billing contacts, and people represented in customer-provided content.
Legal
Effective June 21, 2026. This Data Processing Addendum applies when AssetLed Linkbuilding processes personal data for a customer through the API, Blazor app, worker jobs, SDK, reporting, billing, and configured integrations.
Customer is the controller of customer-submitted personal data, prospect contact data, outreach recipient data, connected Google data, account user data, and reporting data. AssetLed is the processor when it handles that data to provide the configured service. AssetLed processes personal data only on documented customer instructions, including instructions expressed through product settings, API calls, worker jobs, and approved integrations.
Processing includes hosting account data, normalizing websites, analyzing linkable assets, enriching SEO metrics, ranking prospects, generating outreach drafts, sending customer-approved outreach through configured mailboxes, recording replies, maintaining suppressions, connecting Google Analytics and Google Search Console data, processing Stripe billing state, creating reports, tracking AI visibility, running compliance workflows, and performing trial-abuse prevention for self-serve signup and cancellation workflows.
Customer account users, team members, website contacts, publishers, journalists, outreach recipients, billing contacts, and people represented in customer-provided content.
Email addresses, names if supplied, roles, contact methods, domains, URLs, messages, replies, OAuth connection metadata, billing identifiers, usage logs, security records, and hashed and protected email, IP, website, domain, Stripe customer, Stripe subscription, and payment-fingerprint data used for trial-abuse prevention.
For the term of the customer account and any additional period needed for legal compliance, security, billing, dispute resolution, backups, and suppression-list integrity.
Subprocessors are used only when the corresponding feature, deployment environment, or integration is configured. Categories include cloud hosting and infrastructure, SQL Server hosting, email delivery and mailbox providers, Stripe for billing, Google for authorized Analytics and Search Console data, Anthropic and configured AI answer engines for analysis and drafting, DataForSEO for enrichment, logging and monitoring providers, and source-code or CI infrastructure used to operate the service.
Mailgun for product and site transactional or marketing email delivery is a product-email subprocessor. The customer-configured or admin-configured outreach mailbox providers remain separate from Mailgun and process outreach messages, replies, and deliverability metadata only when outreach workflows are configured.
See the dedicated subprocessors page for purpose, data-category, transfer-note, and usage details.
AssetLed remains responsible for subprocessors it appoints and requires them to protect personal data according to materially similar confidentiality and security obligations.
AssetLed provides account export, account deletion, unsubscribe, suppression, and public data deletion workflows. If a deletion request cannot be completed through the authenticated product, use the data deletion request page or send it to [email protected]. AssetLed will provide reasonable assistance for verified access, deletion, correction, restriction, objection, portability, and regulatory requests related to data processed on behalf of the customer.
Personnel and service providers with access to personal data must protect it as confidential. AssetLed will notify affected customers without undue delay after confirming a personal-data breach involving customer personal data and will provide available information needed for legally required notices. Reasonable security questions may be sent through the security contact page.
Where personal data is transferred internationally, the parties will use a legally recognized transfer mechanism, including the Standard Contractual Clauses where applicable. If a transfer mechanism changes or is invalidated, the parties will work in good faith to apply a replacement mechanism required by applicable law.
On account termination or verified customer request, AssetLed will delete or return personal data through the available compliance workflows, including data-deletion, unless retention is required for law, security, billing, audit, dispute resolution, backup integrity, or suppression-list integrity. Aggregated or de-identified data that cannot reasonably identify a person or customer account may be retained for service operation and security improvement.