Privacy Policy
Laatst bijgewerkt / Last updated: 10 september 2026
Dit privacybeleid beschrijft welke persoonsgegevens Linkqon verwerkt, hoe wij die verzamelen, voor welk doel, hoe lang wij ze bewaren, hoe wij ze beveiligen, met wie wij ze delen, en hoe u uw rechten kunt uitoefenen — inclusief het intrekken van toegang en het verzoeken om verwijdering.
Dit beleid geldt voor:
Linkqon B.V.
Aanslagsweg 18
7622 LD Borne
Nederland
KvK: 42068355
E-mail: info@linkqon.nl
Linkqon B.V. is verwerkingsverantwoordelijke voor de persoonsgegevens die wij verwerken voor onze eigen bedrijfsvoering (website, account, facturatie, beveiliging en support).
Wij hebben geen functionaris gegevensbescherming (FG) aangesteld. Privacyvragen en -verzoeken kunt u sturen naar info@linkqon.nl.
Voor gegevens in de systemen die u koppelt (bijvoorbeeld relaties, contactpersonen of offertes in uw CRM of boekhouding) bent u of uw organisatie verwerkingsverantwoordelijke. Linkqon is dan verwerker: wij verwerken die gegevens alleen in opdracht van u, om de door u ingeschakelde koppeling uit te voeren.
Wij gebruiken koppelingsgegevens niet voor eigen marketing, profilering of verkoop aan derden.
Gegevens. De velden die u zelf invult in het contactformulier (onder meer bedrijfsnaam, KvK-nummer, contactpersoon, e-mailadres, telefoonnummer, interesse en eventuele opmerkingen) en de inhoud van e-mail aan info@linkqon.nl.
Hoe verzameld. Via het contactformulier op linkqon.nl (doorgestuurd naar ons CRM) of via e-mail.
Doel. Reageren op vragen, offertes en andere verzoeken.
Grondslag. Uitvoering van (pre)contractuele stappen (art. 6 lid 1 onder b AVG) en/of gerechtvaardigd belang om te kunnen reageren (art. 6 lid 1 onder f AVG).
Bewaartermijn. Zolang nodig voor de afhandeling van uw vraag, daarna tot maximaal twee jaar na het laatste contact, tenzij een overeenkomst tot stand komt. In dat geval vallen de gegevens onder de klantdossiers.
Gegevens. Organisatienaam; een technisch kenmerk van de omgeving waarmee u inlogt; versleutelde toegangstokens en refresh-tokens; tokenverloop; sessiegegevens. Wij slaan geen apart gebruikersprofiel met wachtwoord op.
Hoe verzameld. Wanneer u inlogt via Cirqll (OAuth 2.0) en die koppeling autoriseert.
Doel. U toegang geven tot de Dienst, uw organisatie herkennen en de sessie in stand houden.
Grondslag. Voor zover u zelf partij bent bij de overeenkomst: uitvoering van de overeenkomst (art. 6 lid 1 onder b AVG). Voor gebruikers die namens een organisatie toegang hebben tot de Dienst: ons gerechtvaardigd belang en dat van onze klant om geautoriseerde gebruikers veilige toegang tot de Dienst te bieden (art. 6 lid 1 onder f AVG).
Bewaartermijn. Zolang u de Dienst gebruikt. Na ontkoppeling of verwijdering van het account verwijderen wij deze gegevens, behalve wat wij fiscaal of juridisch moeten bewaren (zie 2.4).
U heeft geen Linkqon-wachtwoord. Toegang tot de app loopt via uw Cirqll-account.
De Dienst synchrooniseert gegevens tussen de systemen die u zelf inschakelt. Welke entiteiten dat zijn, hangt af van de koppeling (bijvoorbeeld relaties of klanten, contactpersonen, offertes of kansen, taken, of formulierinzendingen).
Gegevens die tussen systemen worden uitgewisseld. Afhankelijk van de koppeling onder meer namen, e-mailadressen, telefoonnummers, KvK-nummers, adresgegevens, functies, offertenummers en bedragen, en de overige velden die nodig zijn om die entiteit in het andere systeem aan te maken of bij te werken.
Gegevens die wij daarvoor op onze servers bewaren.
Hoe verzameld.
Doel. De door u gekozen gegevens synchroon houden tussen de systemen die u koppelt, volgens de regels die u in de Dienst zet. Wij gebruiken deze gegevens niet voor andere doeleinden, voor verkoop aan derden of voor advertentiedoeleinden.
Rol en grondslag. Voor de persoonsgegevens in uw gekoppelde systemen bent u of uw organisatie verwerkingsverantwoordelijke en bepaalt u de toepasselijke AVG-grondslag. Linkqon verwerkt deze persoonsgegevens als verwerker uitsluitend namens u en op uw instructie, om de door u ingeschakelde koppeling uit te voeren. De dienstverlening van Linkqon aan uw organisatie vindt plaats op basis van de overeenkomst met Linkqon. De machtiging in het gekoppelde systeem geeft Linkqon de technische autorisatie om namens u gegevens op te vragen en te wijzigen. Wij ontvangen geen onversleutelde wachtwoorden.
Bewaartermijn.
Wij vragen aan een gekoppeld systeem alleen de gegevens die nodig zijn voor de door u ingeschakelde koppeling.
Gegevens. Klant-ID bij onze betaaldienstverlener; type betaalmiddel en laatste vier cijfers; abonnementsstatus, prijsgegevens en looptijd. Kaart- of iDEAL-gegevens worden door Stripe verwerkt; wij slaan geen volledig kaartnummer op.
Hoe verzameld. Via Stripe wanneer u een koppeling betaalt.
Doel. Abonnement uitvoeren, factureren, btw afdragen en fraude- of sterke-klantauthenticatie afhandelen.
Grondslag. Uitvoering van de overeenkomst (art. 6 lid 1 onder b AVG) en wettelijke fiscale plicht (art. 6 lid 1 onder c AVG).
Bewaartermijn. Factuur- en betalingsgegevens: zeven jaar na het boekjaar (fiscale bewaarplicht). Overige betalingskoppelgegevens tot einde klantrelatie, plus diezelfde termijn waar de wet dat eist.
Gegevens. Tijdstip, type koppeling, HTTP-methode, URL, statuscode, duur; bij fouten (een deel van) de response. Geheimhoudingsplichtige waarden zoals tokens worden in applicatielogs weggelaten. Een IP-adres kan in serverlogs van onze hoster voorkomen.
Hoe verzameld. Automatisch bij verkeer tussen Linkqon, de door u gekoppelde systemen en onze betaaldienstverlener.
Doel. Storingen oplossen, beveiliging, misbruik tegengaan en de Dienst in stand houden.
Grondslag. Gerechtvaardigd belang (art. 6 lid 1 onder f AVG): een betrouwbare en veilige dienst.
Bewaartermijn. Applicatie-API-logs: maximaal zeven dagen. Serverlogs van de hoster volgens diens beheer, niet langer dan nodig voor beveiliging en storingen.
Wij nemen geen geautomatiseerde besluiten met rechtsgevolg en doen geen profilering in de zin van artikel 22 AVG.
Wij verkopen geen persoonsgegevens. Wij delen gegevens alleen als dat nodig is voor de Dienst, een wettelijke plicht, of met uw opdracht.
Broncodebeheer (bijvoorbeeld GitLab) ontvangt geen klantdata uit uw gekoppelde systemen.
Het aanbod van koppelingen kan groeien. Zodra u een extra systeem inschakelt, verwerken wij de daarvoor nodige gegevens volgens dezelfde uitgangspunten. Dit beleid passen wij aan als dat materieel iets verandert.
De Dienst en de database draaien in Nederland.
Stripe is een internationale betaaldienst. Betalingsgegevens kunnen buiten de EER worden verwerkt, onder meer in de Verenigde Staten. Stripe hanteert hiervoor passende waarborgen, zoals het EU-VS Data Privacy Framework en/of standaardcontractbepalingen. Zie stripe.com/privacy.
Een door u gekoppeld systeem kan binnen of buiten de EER zijn gevestigd. Als u een systeem buiten de EER koppelt, kan daarbij sprake zijn van doorgifte van persoonsgegevens naar een derde land. U bent als verwerkingsverantwoordelijke verantwoordelijk voor de keuze van het gekoppelde systeem en voor de toepasselijke waarborgen voor die doorgifte. Linkqon verwerkt en verzendt deze gegevens overeenkomstig uw instructies. Op de verwerking door de leverancier van het gekoppelde systeem is daarnaast diens eigen privacybeleid van toepassing.
Wij treffen passende technische en organisatorische maatregelen, waaronder:
Een koppeling betekent dat gegevens via onze servers van het ene systeem naar het andere gaan. Dat is transportversleuteling (TLS), geen end-to-end-versleuteling waarbij Linkqon de inhoud nooit kan zien.
app.linkqon.nl plaatst functionele cookies die nodig zijn voor de sessie (ingelogd blijven) en beveiliging (onder meer CSRF). Zonder deze cookies werkt de Dienst niet. Wij plaatsen in de app geen tracking- of advertisingcookies.
linkqon.nl gebruikt wat nodig is voor het contactformulier. Als wij later analytics- of marketingcookies toevoegen, vermelden wij dat hier en vragen wij waar nodig toestemming.
U heeft onder de AVG het recht op inzage, rectificatie, verwijdering, beperking, dataportabiliteit, en bezwaar tegen verwerking op gerechtvaardigd belang. Waar verwerking op toestemming berust, mag u die toestemming intrekken zonder dat eerdere rechtmatige verwerking ongedaan wordt.
Stuur verzoeken naar info@linkqon.nl. Wij reageren in beginsel binnen één maand en sturen bij een verwijderingsverzoek een bevestiging. Wij kunnen om extra gegevens vragen om vast te stellen dat het verzoek van u of een gemachtigde van uw organisatie komt. Heeft uw verzoek betrekking op persoonsgegevens die Linkqon uitsluitend namens een klant verwerkt via een koppeling? Dan is die klant de verwerkingsverantwoordelijke. Wij verwijzen het verzoek waar nodig naar die organisatie of ondersteunen haar bij de afhandeling. Gegevens in een gekoppeld systeem past u vaak het snelst in dat systeem zelf aan; Linkqon is daar verwerker.
Intrekken betekent dat die koppeling niet meer werkt. Gegevens die al in een gekoppeld systeem staan, blijven daar totdat u ze in dat systeem verwijdert.
Als u er met ons niet uitkomt, kunt u een klacht indienen bij de Autoriteit Persoonsgegevens: https://www.autoriteitpersoonsgegevens.nl.
De Dienst is bedoeld voor zakelijk gebruik en niet gericht op kinderen onder de 16 jaar.
Bij materiële wijzigingen passen wij dit beleid aan en wijzigen wij de datum bovenaan. De actuele versie staat op https://linkqon.nl/privacy.html en, zodra ingebouwd, in de app. Bij het inschakelen of betalen van een koppeling kunnen wij u vragen kennis te nemen van de dan geldende verklaring.
Heeft u vragen over dit privacybeleid of over de verwerking van uw gegevens? Neem dan contact met ons op:
Disclaimer - This Privacy Policy is an English translation of the original Dutch document (Privacybeleid). It is provided for informational purposes only. The Dutch version is the sole official text and shall prevail in all matters of interpretation, legal validity, or dispute resolution.
This privacy policy describes which personal data Linkqon processes, how we collect it, for what purpose, how long we retain it, how we secure it, with whom we share it, and how you can exercise your rights — including withdrawing access and requesting deletion.
This policy applies to:
Linkqon B.V.
Aanslagsweg 18
7622 LD Borne
The Netherlands
Chamber of Commerce (KvK): 42068355
Email: info@linkqon.nl
Linkqon B.V. is the controller for the personal data we process for our own operations (website, account, billing, security and support).
We have not appointed a data protection officer. Privacy questions and requests can be sent to info@linkqon.nl.
For data in the systems you connect (for example contacts or quotes in your CRM or accounting software), you or your organisation are the controller. Linkqon is then a processor: we process that data only on your instructions, to run the connection you enabled.
We do not use connection data for our own marketing, profiling or sale to third parties.
Data. The fields you enter in the contact form (including company name, Chamber of Commerce number, contact person, email address, phone number, interest and any remarks) and the contents of email to info@linkqon.nl.
How collected. Via the contact form on linkqon.nl (forwarded to our CRM) or by email.
Purpose. To respond to questions, quotes and other requests.
Legal basis. Taking steps prior to a contract (GDPR art. 6(1)(b)) and/or legitimate interest in being able to reply (art. 6(1)(f)).
Retention. For as long as needed to handle your enquiry, then up to two years after last contact, unless a contract is concluded. In that case the data forms part of the customer file.
Data. Organisation name; a technical identifier of the environment you sign in with; encrypted access tokens and refresh tokens; token expiry; session data. We do not store a separate user profile with a password.
How collected. When you sign in via Cirqll (OAuth 2.0) and authorise that connection.
Purpose. To give you access to the Service, recognise your organisation and keep the session active.
Legal basis. Where you yourself are a party to the contract: performance of the contract (GDPR art. 6(1)(b)). For users who have access to the Service on behalf of an organisation: our legitimate interest and that of our customer in providing authorised users with secure access to the Service (art. 6(1)(f)).
Retention. For as long as you use the Service. After disconnecting or deleting the account we delete this data, except what we must keep for tax or legal reasons (see 2.4).
You do not have a Linkqon password. Access to the app is through your Cirqll account.
The Service synchronises data between the systems you enable. Which entities that covers depends on the connection (for example accounts or customers, contacts, quotes or opportunities, tasks, or form submissions).
Data exchanged between systems. Depending on the connection, among other things names, email addresses, phone numbers, Chamber of Commerce numbers, addresses, job titles, quote numbers and amounts, and the other fields needed to create or update that entity in the other system.
Data we store on our servers for that purpose.
How collected.
Purpose. To keep the data you selected in sync between the systems you connect, according to the rules you set in the Service. We do not use this data for other purposes, for sale to third parties or for advertising purposes.
Role and legal basis. For the personal data in your connected systems, you or your organisation are the controller and you determine the applicable GDPR legal basis. Linkqon processes this personal data as processor solely on your behalf and on your instructions, to run the connection you enabled. Linkqon’s provision of services to your organisation takes place on the basis of the contract with Linkqon. The grant in the connected system gives Linkqon the technical authorisation to retrieve and change data on your behalf. We do not receive unencrypted passwords.
Retention.
We only request from a connected system the data needed for the connection you enabled.
Data. Customer ID at our payment provider; payment method type and last four digits; subscription status, price data and term. Card or iDEAL details are processed by Stripe; we do not store a full card number.
How collected. Via Stripe when you pay for a connection.
Purpose. To run the subscription, invoice, charge VAT and handle fraud or strong customer authentication.
Legal basis. Performance of the contract (GDPR art. 6(1)(b)) and a legal tax obligation (art. 6(1)(c)).
Retention. Invoice and payment data: seven years after the financial year (Dutch tax retention duty). Other payment linkage data until the end of the customer relationship, plus the same period where the law requires it.
Data. Timestamp, connection type, HTTP method, URL, status code, duration; on errors (part of) the response. Secrets such as tokens are omitted from application logs. An IP address may appear in our hoster’s server logs.
How collected. Automatically with traffic between Linkqon, the systems you connect and our payment provider.
Purpose. To resolve incidents, security, prevent abuse and keep the Service running.
Legal basis. Legitimate interest (GDPR art. 6(1)(f)): a reliable and secure service.
Retention. Application API logs: a maximum of seven days. Server logs of the hoster according to their operations, no longer than needed for security and incidents.
We do not take automated decisions with legal effect and we do not profile in the sense of GDPR article 22.
We do not sell personal data. We share data only if that is necessary for the Service, a legal duty, or on your instruction.
Source-code hosting (for example GitLab) does not receive customer data from your connected systems.
The range of connections may grow. When you enable an additional system, we process the data needed for it under the same principles. We will update this policy if that changes anything material.
The Service and the database run in the Netherlands.
Stripe is an international payment provider. Payment data may be processed outside the EEA, including in the United States. Stripe uses appropriate safeguards such as the EU-US Data Privacy Framework and/or standard contractual clauses. See stripe.com/privacy.
A system you connect may be established inside or outside the EEA. If you connect a system outside the EEA, that may involve a transfer of personal data to a third country. As controller, you are responsible for the choice of the connected system and for the applicable safeguards for that transfer. Linkqon processes and transmits this data in accordance with your instructions. The processing by the vendor of the connected system is additionally subject to that vendor’s own privacy policy.
We implement appropriate technical and organisational measures, including:
A connection means data travels via our servers from one system to another. That is transport encryption (TLS), not end-to-end encryption where Linkqon can never see the contents.
app.linkqon.nl sets functional cookies required for the session (staying signed in) and security (including CSRF). Without these cookies the Service does not work. We do not place tracking or advertising cookies in the app.
linkqon.nl uses what is needed for the contact form. If we later add analytics or marketing cookies, we will state that here and ask for consent where required.
Under the GDPR you have the right of access, rectification, erasure, restriction, data portability, and to object to processing based on legitimate interest. Where processing is based on consent, you may withdraw that consent without affecting prior lawful processing.
Send requests to info@linkqon.nl. We will respond within one month in principle and, for a deletion request, send a confirmation. We may ask for additional information to verify that the request comes from you or an authorised representative of your organisation. Does your request relate to personal data that Linkqon processes solely on behalf of a customer via a connection? Then that customer is the controller. We refer the request where necessary to that organisation or support it in handling. Data in a connected system is often fastest to change in that system itself; Linkqon is the processor there.
Withdrawing means that connection no longer works. Data already in a connected system remains there until you delete it in that system.
If we cannot resolve the matter, you may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): https://www.autoriteitpersoonsgegevens.nl.
The Service is intended for business use and is not directed at children under 16.
If we make material changes we will update this policy and the date at the top. The current version is at https://linkqon.nl/privacy.html and, once built in, in the app. When you enable or pay for a connection we may ask you to take note of the policy then in force.
If you have questions about this privacy policy or about the processing of your data, please contact us: