Privacy Statement
1. Controller
Link6 GmbH, Hofstrasse 43, 6300 Zug, Switzerland ("Link6", "we") is the controller for personal data processed in connection with the Link6 platform (the "Service"). Contact: info@link6.ai.
2. Roles: controller vs. processor
For account, billing, usage, and security data, Link6 acts as controller. For content our business customers and their users store in the Service ("Customer Data" — tasks, notes, files, messages, meeting recordings), Link6 acts as processor on the customer organization's behalf; the organization is the controller of that content. A data processing agreement is available to business customers on request.
3. Data we process
Account data: email address, display name, hashed credentials (managed by our authentication provider), MFA status, locale, timezone, role and permissions within an organization, Terms-of-Use acceptance record (version and timestamp).
Customer Data: content submitted by users — tasks, projects, comments, uploaded files, knowledge-base documents, emails routed into the Service, voice recordings and their transcripts, and prompts submitted to AI features.
Usage and security data: authentication events, audit and lifecycle logs, IP address and technical metadata as needed for security (e.g. bot protection), error logs, AI usage/credit consumption.
Payment data: when purchasing credit packs or a subscription, payment is handled by our payment provider (Mollie); Link6 receives payment status, customer and mandate references and the amount, never full card details.
4. Purposes and legal bases
We process data to provide and secure the Service (performance of contract; Swiss revDSG and, where applicable, GDPR Art. 6(1)(b)); to prevent abuse and ensure security, including bot protection and audit logging (legitimate interest, Art. 6(1)(f)); to comply with legal obligations (Art. 6(1)(c)); and, for optional communications, with consent (Art. 6(1)(a)). We do not sell personal data and do not use Customer Data for advertising.
5. AI features
AI-assisted features send the relevant prompt and context to a machine-learning model for inference. Model routing follows a residency hierarchy — Swiss region first, then EU, then global — depending on the model selected and the organization's configuration. Providers currently in use: AWS Bedrock (primary inference region Zurich, Switzerland; some models in other regions), Anthropic, Mistral (EU), and Google (AI Studio / Vertex). Voice transcription runs on Link6's own infrastructure in Switzerland and is not sent to third-party AI providers.
6. Hosting and sub-processors
Primary hosting is in Switzerland: the database, authentication, and file storage run on Supabase (Zurich region); self-hosted email and processing infrastructure runs on Infomaniak (Switzerland). Frontend delivery and bot protection are provided by Cloudflare. Payments are processed by Mollie (Netherlands). A current sub-processor list with roles and locations is available on request.
7. International transfers
Data is primarily processed in Switzerland and the EU/EEA (adequacy applies in both directions). Where a selected AI model or service processes data outside Switzerland/EEA (e.g. global model regions, US-based providers), transfers are protected by Standard Contractual Clauses or an equivalent recognised transfer mechanism. Organizations can restrict AI processing to Swiss/EU residency through model selection.
8. Retention
Account and Customer Data are retained for the duration of the contract and deleted after termination per the Terms of Use export window, subject to backup cycles and statutory retention duties. Audit and lifecycle logs are retained for 12 months for security and accountability, unless the organization configures a different retention period in the Service. Payment records are retained per Swiss commercial-law retention (10 years).
9. Security
Measures include: row-level security isolating each organization's data at the database layer; role- and clearance-based access control; TOTP multi-factor authentication; encrypted transport (TLS) and encrypted storage; audit logging of privileged changes; bot protection on authentication; and least-privilege service credentials. No method is 100% secure; we notify affected customers and authorities of breaches as legally required.
10. Monitoring
We do not proactively monitor or scan Customer Data for content violations, except where and to the extent required by applicable law or a binding order of a competent authority (see Terms of Use §4.3). AI-feature inputs are subject to the usage policies of the underlying model providers.
11. Cookies and local storage
The Service uses strictly necessary storage only: session tokens in browser local storage (authentication) and Cloudflare Turnstile's technical cookies for bot protection. No advertising or cross-site tracking cookies are used.
12. Your rights
Under the revDSG and, where applicable, the GDPR, you may request access, correction, deletion, restriction, portability, and object to processing based on legitimate interest; where processing is based on consent, you may withdraw it. Requests: info@link6.ai. For Customer Data controlled by your organization, we may redirect your request to your organization's administrator. You may complain to the Swiss FDPIC or, in the EU, to your supervisory authority.
13. Changes
Each published revision carries a version identifier. Material changes will be notified in line with Terms of Use §14.
Effective date: 2026-09-13.