Privacy Policy
Effective date: To be set before commercial launch
Last updated: To be set before commercial launch
1. Who we are
linXera is an editorial site: it publishes articles about project planning and sends a newsletter to the people who ask for it. The publisher is identified in the Legal Notices page.
Data controller (responsable de traitement): the publisher identified in the Legal Notices page.
Data controller contact: support@linxera.io
2. What this policy covers
This policy describes what the site does today. Where an activity has not begun, this policy is silent about it rather than describing it in advance. If linXera later sells a product, this page is amended before that happens, and the processing it introduces is described here at that time.
3. The newsletter and the waitlist
This is the only processing in which you give us personal data directly, and it happens only if you choose to. Nothing below applies to a visitor who simply reads an article.
What we record when you subscribe
- Your email address. We cannot send you a newsletter without it.
- What you subscribed to (the newsletter, the waitlist, or access to a downloadable resource), and the date and time you did so.
- The exact wording you agreed to, stored as a snapshot alongside your consent, together with the page you subscribed from and your language preference.
- Your IP address and browser user-agent string, recorded at the moment you consent.
- The date you withdraw, if you do, and any delivery failure or spam complaint reported back to us by our email provider.
Why the IP address, specifically
The GDPR requires us to be able to demonstrate that you consented (article 7(1)), not merely to assert it. The IP address and user-agent, recorded with the wording you saw and the moment you saw it, are what make that demonstration possible if you or a regulator ever ask. They are stored unmodified for that reason: a hashed or truncated address cannot answer the question it exists to answer.
This data is never used to profile you, to infer your location, or to target anything at you. It is not readable from your browser, and it is not shared.
Why we may do this (legal basis)
Your consent (GDPR article 6(1)(a)) for sending you the newsletter, and our legal obligation to keep proof of that consent (article 7(1)) for the record described above.
How long we keep it
Your email address and preferences are kept for as long as you stay subscribed. When you withdraw, we stop sending immediately.
The record proving you consented is kept for as long as we may need to demonstrate that the consent was validly obtained, which outlives your time on the list, since the question can be asked after you have left. We do not delete it when you withdraw, because deleting it would destroy the only evidence that we were entitled to write to you in the first place. If you ask us to erase your data entirely, see section 7.
How to withdraw
Every newsletter contains an unsubscribe link that works in one click, without signing in and without explaining yourself. You can also write to support@linxera.io. Withdrawing is as easy as subscribing was, and costs you nothing else.
4. What we record when you simply read
Analytics
- Page views and navigation patterns on linxera.io, captured by a privacy-friendly cookieless analytics tool. No session recording, no autocapture, no persistent visitor identifiers, and nothing that identifies you personally.
Error monitoring
- Errors raised by the website are captured so we can fix them. Reports may include browser/OS version, page URL, and stack traces.
- We strip IP addresses, cookies and authentication headers from every event, and we do not intentionally include personal data. Session replay is disabled.
5. Why we collect data
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Email address and preferences | Sending the newsletter you asked for | Consent |
| Consent record (wording, timestamp, IP, user-agent) | Demonstrating that consent was validly obtained | Legal obligation (article 7(1)) |
| Analytics | Understanding which articles are read | Legitimate interest |
| Error reports | Identifying and fixing bugs | Legitimate interest |
6. Crash reports from the desktop add-in
This section describes a desktop add-in for Microsoft Project that is not yet on sale. It is kept here because a version already installed on some machines links directly to this section. If you have not installed that add-in, nothing in this section applies to you.
The linXera add-in for Microsoft Project includes an automatic crash-reporting feature so we can detect and fix technical incidents quickly. The feature is enabled by default and you can turn it off at any time (see How to disable it below). When you first launch the add-in, a one-time disclosure dialog informs you of this and offers a single-click opt-out.
What is transmitted
When the add-in crashes and crash reporting is enabled, the following data is sent:
- The technical stack trace and panic message of the crash
- The operating system version
- The version of the linXera add-in
- The Build ID of the native runtime (used to resolve debug symbols)
- Technical session identifiers (random values, not tied to any account)
What is never transmitted
The crash-reporting channel is constrained to the data above. It never includes:
- The contents of your
.mppproject files - Task names, resource names, project names, or any project data
- File paths from your machine
- Your email address or any personal data
- Your IP address. IP address storage is disabled at the project level on our error-monitoring provider
A server-side scrubber additionally filters the fields email, path, mpp, task_name, and project_path as a defence-in-depth measure against accidental inclusion.
Where the data is stored, and for how long
Crash reports are received and stored by our error-monitoring sub-processor in the European Union (Frankfurt region). The data does not leave the EU/EEA at rest. Reports are retained for up to 90 days, then automatically deleted.
Legal basis (GDPR)
We rely on the legitimate interest of ensuring the stability and security of the software (GDPR article 6(1)(f)). Crash data is technical and minimised by design: it carries no project content and no direct identifier. You retain the right to object at any time by disabling crash reporting.
How to disable it
- At first launch: click Disable now in the disclosure dialog that appears the first time you open the add-in inside Microsoft Project.
- At any time afterwards: in Microsoft Project, open linXera ribbon → Help → About, then toggle off Send anonymous crash reports to linXera.
The change takes effect immediately. No restart of Microsoft Project is required. Once disabled, the add-in continues to log crashes locally (so you can share them on demand if you contact us), but nothing is transmitted to our servers.
7. Your rights (GDPR)
If you are in the European Economic Area, you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data (“right to be forgotten”)
- Export your data in a portable format
- Withdraw your consent at any time, without giving a reason
- Object to processing based on legitimate interest
- Restrict processing in certain circumstances
To exercise any of these rights, write to support@linxera.io. We will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. In France, that is the CNIL.
8. Who else processes this data (sub-processors)
We rely on a small number of trusted sub-processors to operate the site. They process personal data only on our instructions and under a Data Processing Agreement.
| Category | Role | Data shared |
|---|---|---|
| Hosting & infrastructure | Serving the website and its database | Subscriber data, consent records, access logs |
| Website analytics | Cookieless visitor analytics | Anonymised page views |
| Error monitoring | Capturing website errors for debugging | Browser/OS, page URL, stack traces (no personal data) |
| Email delivery | Sending the newsletter and confirmation emails | Email address |
A current list of named sub-processors is available on request at support@linxera.io.
International data transfers
Some of our processors are headquartered outside the EU/EEA (United States, United Kingdom). Where personal data leaves the EU/EEA, transfers are based on:
- the European Commission's Standard Contractual Clauses (SCCs) for transfers to all our US-based processors;
- the EU-US Data Privacy Framework (DPF), where the processor is certified under the framework;
- adequacy decisions where applicable (for example, the United Kingdom).
Where a provider offers EU host regions, we select them so that the data stays within the EU/EEA at rest.
9. Cookies and similar technologies
linxera.io uses only strictly necessary cookies, and our analytics is cookieless. We do not use advertising or third-party tracking cookies. As a result, no consent banner is required.
10. Changes to this policy
We may update this Privacy Policy. Changes take effect when published on this page. For material changes affecting subscribers, we will notify you by email.
11. Contact
For any privacy-related question: support@linxera.io