Privacy Policy

Effective date: To be set before commercial launch
Last updated: To be set before commercial launch

1. Who we are

linXera is published by the entity identified in the Legal Notices page. Until that entity (a French SAS) is incorporated, the service is in pre-launch draft and not yet open to paying customers. Commercial transactions, when they begin, will be handled by Paddle.com Market Limited as Merchant of Record.

Data controller (responsable de traitement): the publisher identified in the Legal Notices page. The controller's registered name and address will be published there before commercial launch.

Data controller contact: privacy@linxera.io

2. What data we collect

Account data

  • Email address (required for account creation)
  • Password (hashed, never stored in plain text)
  • Name (if provided)

Subscription data

  • Subscription status and history
  • Payment information (processed by Paddle, we do not store credit card details)
  • Invoices and transaction records (via Paddle)

Licence data

  • Licence key
  • Activation status
  • Licence verification requests (timestamp, IP address, software version)

Analytics data

  • Page views and navigation patterns on linxera.io, captured by a privacy-friendly cookieless analytics tool. No session recording, no autocapture, no persistent visitor identifiers.

Error reporting (website and customer portal)

  • Frontend and backend errors raised by linxera.io and the customer portal are captured for debugging. Reports may include browser/OS version, page URL, and stack traces.
  • We strip IP addresses, cookies and authentication headers from every event, and we do not intentionally include personal data. Session replay is disabled.
  • Crash reports from the desktop add-in are handled separately. See section 4: Crash reports from the desktop add-in.

3. What we do NOT collect

  • Your project files: linXera runs on your desktop. Your .mpp files are never uploaded, read, or transmitted to our servers.
  • Your project data: task names, dates, dependencies, resources. None of this leaves your machine.
  • Credit card numbers: payment is handled entirely by Paddle.

4. Crash reports from the desktop add-in

The linXera add-in for Microsoft Project includes an automatic crash-reporting feature so we can detect and fix technical incidents quickly. The feature is enabled by default and you can turn it off at any time (see How to disable it below). When you first launch the add-in, a one-time disclosure dialog informs you of this and offers a single-click opt-out.

What is transmitted

When the add-in crashes and crash reporting is enabled, the following data is sent:

  • The technical stack trace and panic message of the crash
  • The operating system version
  • The version of the linXera add-in
  • The Build ID of the native runtime (used to resolve debug symbols)
  • Technical session identifiers (random values, not tied to your account)

What is never transmitted

The crash-reporting channel is constrained to the data above. It never includes:

  • The contents of your .mpp project files
  • Task names, resource names, project names, or any project data
  • File paths from your machine
  • Your email address, account identifier, or any personal data
  • Your IP address. IP address storage is disabled at the project level on our error-monitoring provider

A server-side scrubber additionally filters the fields email, path, mpp, task_name, and project_path as a defence-in-depth measure against accidental inclusion.

Where the data is stored

Crash reports are received and stored by our error-monitoring sub-processor in the European Union (Frankfurt region). The data does not leave the EU/EEA at rest.

How long we keep it

Crash reports are retained for up to 90 days, then automatically deleted (consistent with section 7 below).

Legal basis (GDPR)

We rely on the legitimate interest of ensuring the stability and security of a paid software product (GDPR article 6(1)(f)). Crash data is technical and minimised by design: it carries no project content and no direct identifier. You retain the right to object at any time by disabling crash reporting (see below). Exercising this right has no impact on your subscription or licence.

How to disable it

  • At first launch: click Disable now in the disclosure dialog that appears the first time you open the add-in inside Microsoft Project.
  • At any time afterwards: in Microsoft Project, open linXera ribbon → Help → About, then toggle off Send anonymous crash reports to linXera.

The change takes effect immediately. No restart of Microsoft Project is required. Once disabled, the add-in continues to log crashes locally (so you can share them on demand if you contact support), but nothing is transmitted to our servers.

Sub-processor

Crash reports are processed by Functional Software, Inc. dba Sentry, acting as our processor on the EU-Frankfurt region under a Data Processing Agreement. See section 6 below for the full sub-processor framework.

5. Why we collect data

DataPurposeLegal basis (GDPR)
Email, passwordAccount management, authenticationContract performance
Subscription dataLicence activation, billingContract performance
Licence verificationEnsuring valid licenceLegitimate interest
AnalyticsImproving the website and serviceLegitimate interest
Error reports (web and customer portal)Identifying and fixing bugsLegitimate interest
Crash reports (desktop add-in)Detecting and fixing technical incidentsLegitimate interest (see section 4)

6. Categories of recipients (sub-processors)

We rely on a small number of trusted sub-processors to operate the Service. They process personal data only on our instructions and under a Data Processing Agreement.

CategoryRoleData shared
Hosting & infrastructureServing the website, API and databaseAccount data, licence data, access logs
Payment & invoicingPaddle.com Market Limited acts as Merchant of Record. Collects payments, manages VAT and issues invoicesEmail, payment info
Website analyticsCookieless visitor analyticsAnonymised page views
Error monitoring (web)Capturing frontend and backend errors for debuggingBrowser/OS, page URL, stack traces (no PII)
Crash monitoring (desktop add-in)Receiving automatic crash reports from the linXera add-in, hosted in the EU (Frankfurt). See section 4.Stack trace, OS version, add-in version, Build ID, technical session identifiers (no project data, no PII, IP not stored)
Transactional emailSending account, billing and support emailsEmail address

A current list of named sub-processors is available on request at privacy@linxera.io.

International data transfers

Several of our processors are headquartered outside the EU/EEA (United States, United Kingdom). Where personal data leaves the EU/EEA, transfers are based on:

  • the European Commission's Standard Contractual Clauses (SCCs) for transfers to all our US-based processors;
  • the EU-US Data Privacy Framework (DPF), where the processor is certified under the framework;
  • adequacy decisions where applicable (for example, the United Kingdom).

Where a provider offers EU host regions, we select them so that the data stays within the EU/EEA at rest.

7. Data retention

  • Account data: Retained while your account is active. Deleted within 30 days of an account deletion request.
  • Subscription data: Retained for the duration required by tax and accounting regulations (typically 10 years for invoices).
  • Analytics data: Anonymised. Retained for up to 12 months.
  • Error reports and crash reports (web and desktop add-in): Retained for up to 90 days.

8. Your rights (GDPR)

If you are in the European Economic Area, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data (“right to be forgotten”)
  • Export your data in a portable format
  • Object to processing based on legitimate interest
  • Restrict processing in certain circumstances

To exercise any of these rights, contact privacy@linxera.io. We will respond within 30 days.

9. Cookies and similar technologies

linxera.io uses only strictly necessary cookies — to maintain your authenticated session in the customer dashboard and to enforce the pre-launch access gate during the beta period. We do not use advertising or third-party tracking cookies, and analytics is cookieless. As a result, no consent banner is required.

10. Changes to this policy

We may update this Privacy Policy. Changes take effect when published on this page. For material changes, we will notify you by email.

11. Contact

For privacy-related questions: privacy@linxera.io

Privacy Policy | linXera