Privacy policy

This policy explains what personal data IntentBridges collects through LINC, both the LINC app and the joinlinc.com website, how we use it, who we share it with, and the choices you have. LINC is a service for businesses, so most of what it holds is business information. The personal data in it is mostly about the people who use LINC for a publisher or a channel partner, and the people named as a publisher's contact.

1. Who we are

LINC is operated by IntentBridges Pte. Ltd. (UEN 202445703M), a company incorporated in Singapore. In this policy, “IntentBridges,” “we” and “us” mean that company. We decide how and why personal data in LINC is used, and we are responsible for it under Singapore's Personal Data Protection Act 2012 (PDPA).

IntentBridges is an Enrollment Partner of the RSL Collective. Publishers, which are businesses that own websites, use LINC to enroll their websites with the RSL Collective, which licenses their content to AI companies, and to receive what the RSL Collective allocates to them. Channel partners can manage publishers' accounts in LINC for them.

You can contact our Data Protection Officer about this policy or your personal data using the details in section 16.

2. Who this policy covers

This policy covers personal data about:

It does not cover how the RSL Collective, AI companies or a channel partner handle data outside LINC. Their own policies apply to that.

3. What we collect

Registering interest on joinlinc.com

When you register interest on joinlinc.com, we collect your organization or publisher name, your first and last name, your work email, your website or domains, your country or market, anything you choose to tell us, and that you agreed to the Publisher Registration Terms. We use these details to assess fit, reply to you and contact you about licensing opportunities, as those terms describe. The form sends them to our customer relationship management service, Zoho CRM (section 7).

Your account

When you sign in, we receive your email address. LINC has no passwords: you sign in with Google, or with a sign-in link we email you.

If you continue with Google, Google also tells us your name and that your email address is verified. Google also sends your Google account ID and a link to your profile picture. LINC does not use the picture. If you register a publisher, the name you give there replaces the name from Google.

Our authentication provider, Supabase, keeps your sign-in identity: your email address, when it was confirmed, what Google sent, and your sessions.

Your organization

We record which organization you belong to (a publisher, a channel partner or LINC) and your role in it.

Publisher and contact details

When a publisher registers, we collect its company name and main website, and the name and email address of the person registering. When a channel partner invites a publisher, the partner gives us the same details for the publisher and its contact person. Where given, we also keep the publisher's country and the contact person's job title. A channel partner that gives us someone's details must be entitled to do so and must tell them about this policy.

Invitations

When a channel partner or our staff invite someone, we keep the invited email address, the details the inviter entered (such as a publisher's name, website, contact name and service fee), who sent the invitation and when, and when it was accepted or canceled. An invitation expires after 30 days.

We store an invitation's secret code only as a hash, which cannot be turned back into the code. The code itself is part of the invitation link, so it is in the invitation email and in our hosting provider's request logs, and it is shown once to the person who sent the invitation. We hold it with the queued email only until the email is sent. If you open an invitation link while signed out, a cookie holds the code for up to an hour (section 12).

Websites and the checks we run

For each website a publisher adds, we keep its address, the licensing terms set for it in LINC, its state, who added it and when, and the results the RSL Collective returns for it.

LINC's checker reads each website's public robots.txt file and the RSL license file it points to or, when there is none, /rsl.xml and /license.xml. It does this when a website is added, when someone selects Check now, and once a day for every website LINC may send to the RSL Collective, including websites of publishers that have not yet acknowledged LINC's authorization. It identifies itself with a User-Agent that starts with LINC-Checker. We keep what each check found (whether it passed, and the values it saw), when it ran and who ran it, but not the files themselves. LINC does not crawl a website's pages or content.

Acknowledgement records

When a member of a publisher selects Acknowledge, to give LINC's authorization or to confirm the publisher's rights to its websites, we record:

Bank account details

We keep the account holder, bank name, account number or IBAN, and SWIFT/BIC code a publisher gives for its payments, with who saved them and when. When a publisher replaces its bank account, we keep the old one, marked as replaced. If an account is in a person's name, for example a sole trader's, these details are personal data.

Settlement and payment information

The RSL Collective sends us settlement and payment files. They show what it allocated to each publisher, by licensee (the AI companies it licenses) and licensing pool, and what it paid us. From them we record each publisher's allocations, fees, payments, corrections and statements, and our bank references. This is business information, but it is personal data where a publisher is an individual.

Activity history

Each publisher's account has an activity history: what happened (for example, a website added, rights confirmed, terms saved, a check, a service fee change, the bank account updated, or a result from the RSL Collective), when, and who did it, by name or, for someone with no name in LINC, by email address. When a channel partner's user acts, the partner's name is shown with theirs, and when our staff act, LINC's name is. Bank details never appear in the activity history.

Emails we send

We keep a copy of each email LINC queues: the recipient's address, the subject and text, when it was sent, and any delivery error. LINC emails the addresses that members of an organization sign in with, or the address an invitation was sent to. Emails never contain bank details. Sign-in link emails are sent by our authentication provider, Supabase, and LINC keeps no copy of them.

Technical data

Our hosting provider logs requests to LINC, including IP addresses, browser details and the pages requested, along with error messages from our servers. Our authentication provider logs sign-ins, including IP addresses. Our database keeps an audit log of privileged actions, such as each sign-in, changes to our staff's access, registrations, checks and emails sent, with the time, the user and a short detail such as an email address or a website. LINC uses only the cookies described in section 12.

The joinlinc.com website uses Cloudflare Web Analytics, which counts page visits without cookies and without identifying you. The website does not set cookies.

4. How we use it

We use personal data to:

We do not sell personal data, use it for advertising, or send marketing emails. The LINC app has no analytics or advertising trackers; the website's analytics are described in section 3.

Under the PDPA, we collect, use and disclose personal data with consent, or without it where the PDPA allows. In practice:

If the EU or UK General Data Protection Regulation (GDPR) applies to you, our legal bases are: performance of a contract where you are a party to it, for example as a sole trader (Article 6(1)(b)); otherwise our legitimate interest, and your organization's, in providing LINC to the organization you work for, together with the legitimate interests above (Article 6(1)(f)); legal obligation (Article 6(1)(c)); and consent where we ask for it (Article 6(1)(a)).

You need to give us your email address to use LINC. A publisher must give its company name, main website and contact details to register and enroll websites, and a publisher we pay directly must give its bank details to be paid; without them we cannot provide the service. LINC's automated checks decide whether a website is sent to the RSL Collective, based on the files the website publishes, not on any assessment of you. You can ask us to review a result.

6. Who can see your data in LINC

Inside LINC, what each person sees depends on their organization, and our database enforces it.

The IP address recorded with a rights acknowledgement is shown to the publisher's members and our staff, in the record they can download. The IP address recorded with LINC's authorization is not shown to anyone in LINC. On LINC's screens, bank account numbers are shown masked to their last four digits, except to the channel partner that pays the publisher, which sees the current account in full. Our staff who make transfers can read full bank details in our database.

7. Who we share it with

The RSL Collective

To enroll websites, we send the RSL Collective a file every night with one line for each eligible website: the publisher's LINC id, its main website, the website's hostname, and the ids and dates of the publisher's acknowledgements. The file contains no names, email addresses, IP addresses or bank details. A website's address can identify a person if the website belongs to an individual.

The RSL Collective sends back its results for each website, and the settlement and payment information described in section 3.

Channel partners

A publisher's channel partner sees the data described in section 6. For a publisher with a channel partner, we pay the partner, and the partner pays the publisher.

Service providers

These providers handle data for us, to provide LINC:

Banks

Banks process the transfers: the RSL Collective's payments to us, and our payments to publishers and channel partners.

Authorities and legal claims

We disclose personal data to courts, regulators, law enforcement or other authorities when the law requires it, and where needed to establish or defend legal claims.

Professional advisers

Our lawyers, auditors and accountants, who must keep it confidential, where they need it to advise us or audit our accounts.

Business transfers

If IntentBridges or LINC is merged, acquired or sold, we may disclose personal data to the other party, as the PDPA allows, and it may continue to use it as this policy describes.

We do not sell personal data, and we share it only as this section describes.

8. International transfers

IntentBridges is based in Singapore. Our database is hosted by Supabase in Singapore. Some recipients store or process data in other countries: Supabase, Vercel, Cloudflare, Google and Resend are based in the United States and operate worldwide; Zoho CRM on zoho.com stores data in the United States; the RSL Collective is based in the United States; channel partners may be in other countries, for example Japan; and banks process transfers in the countries where they and the recipient's bank operate.

When we transfer personal data out of Singapore, we take the steps the PDPA requires so that the recipient protects it to a standard comparable to the PDPA. For our service providers, that is their data processing terms. Transfers to the RSL Collective, channel partners and banks are made where they are necessary to provide LINC to you or your organization, for example to enroll your websites, to let your channel partner manage your account and pay you, or to make a bank transfer, as the PDPA allows.

If the GDPR applies to you, transfers to our service providers are covered by the European Commission's standard contractual clauses in their terms, or by an adequacy decision such as the EU-US Data Privacy Framework where a provider is certified under it. You can ask us for details of these safeguards.

9. How long we keep it

We keep personal data only as long as we need it for the purposes in section 4, or as long as the law requires.

LINC does not yet delete or anonymize personal data on a fixed schedule, and some of it cannot yet be deleted at all: a person who has acted in LINC, or a publisher that has acknowledged LINC's authorization, stays in it. Until that changes, we keep this data protected as section 10 describes. When we set periods after which we delete it, we will update this policy.

10. How we protect it

No system is perfectly secure. If a data breach is likely to result in significant harm to the people affected, or affects 500 or more people, we will notify the Personal Data Protection Commission within 3 calendar days of assessing that it must be notified. If it is likely to result in significant harm to you, we will also notify you, unless the PDPA does not require it, for example because we have taken action that makes significant harm unlikely, or a law enforcement agency or the Commission tells us not to.

11. Your rights

Under the PDPA, you can:

You can also ask us to delete your personal data. The PDPA does not give a general right to deletion, but we will tell you what we can delete or anonymize, and why we must keep the rest. We cannot delete records we must keep (section 9), and LINC does not yet offer account deletion in the app.

If the GDPR or a similar law applies to you, you may also have the right to have your personal data erased, to restrict its processing, to object to processing based on legitimate interests, and to receive data you gave us in a portable format, in each case as that law provides.

To make a request, contact us (section 16). We may need to confirm who you are. We will respond to an access or correction request within 30 days; if we cannot, we will tell you within that time when we will. Correcting your data is free. We may charge a reasonable fee for an access request to cover our costs; if we do, we will tell you the amount before we proceed. When we correct your data, we also send the correction to any organization we disclosed it to in the past year that needs it, such as your channel partner. Where the GDPR applies, we respond within one month, which we may extend by up to two more months for complex requests.

If you are not satisfied with our response, you can complain to Singapore's Personal Data Protection Commission (PDPC) at pdpc.gov.sg, or to the data protection authority where you live.

12. Cookies

LINC uses only the cookies it needs to sign you in and keep it secure. It sets no analytics, advertising or third-party cookies, and stores nothing else in your browser, except as listed here.

Scripts on the page cannot read LINC's sign-in and invitation cookies. Because LINC needs these cookies to work, we do not ask for consent to them. You can block or delete cookies in your browser, but then you cannot sign in.

Every page loads its fonts from Google Fonts. That is a request from your browser to Google (section 7), not a cookie LINC sets.

13. Google user data

If you continue with Google, LINC asks Google, through our authentication provider Supabase, only for the openid, email and profile permissions. Google then gives us your Google account ID, your name, your email address and whether it is verified, and a link to your profile picture. LINC does not access your Gmail, contacts, calendar, files or any other Google data.

How we use it. We use your email address to sign you in, to decide which organization and invitations are yours, and to email you about LINC. We use your name to identify you in LINC: it is shown with what you do in your organization's activity history and acknowledgement records, which the people in section 6 can see, unless you give a different name when you register a publisher. We use your Google account ID only to link your Google sign-in to your LINC account. We do not use your profile picture.

How we store and share it. Supabase stores this data in our database, protected as section 10 describes. We share it only as section 6 and section 7 describe: inside LINC with the people who can see your name, and outside LINC with the service providers that run it, or where the law requires. We do not send it to the RSL Collective. We do not sell it, use it for advertising, or use it to develop, improve or train AI or machine-learning models.

How long we keep it. As section 9 describes; your name stays on acknowledgement records you gave for as long as they are kept. You can remove LINC's access to your Google account at any time at myaccount.google.com/permissions; Google then asks for your permission again the next time you continue with Google. Removing access does not delete what LINC already holds; to ask us to delete it, contact us (section 16).

LINC's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

14. Children

LINC is a service for businesses and the people who work for them. It is not meant for anyone under 18, and we do not knowingly collect personal data from children.

15. Changes to this policy

We may update this policy. When we do, we will change the date at the top of this page. If a change is significant, we will email the members of each organization before it takes effect.

16. Contact us

For questions, requests or complaints about this policy or your personal data, contact our Data Protection Officer: