This page explains how We-Connect Systems LLC ("We-Connect") approaches the General Data Protection Regulation. We-Connect is the data controller for account data and the data processor for the prospect data you process through the platform, as set out in our Privacy Policy and Data Processing Agreement.
What is GDPR?
The General Data Protection Regulation is designed to protect the personal data and privacy of individuals in the European Union. It harmonizes data privacy laws across Europe so people can feel confident about how their information is used. The GDPR took effect on 25 May 2018, replacing the earlier Data Protection Directive 95/46/EC, and it also governs the transfer of personal data outside the EU. Under the GDPR, "processing" means any operation performed on personal data, such as collecting, recording, storing, using, transmitting, or erasing it.
Who must comply?
The GDPR can apply to any business that offers goods or services to, or monitors the behavior of, individuals in the EU, even if the business has no physical presence there. To comply, a business needs to understand what personal data it processes and put appropriate technical and organizational measures in place to protect it.
Your rights
You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection, and the right to lodge a complaint with a supervisory authority. Each right is described in full in Section 5 of our Privacy Policy. To exercise any of these rights, contact us at privacy@we-connect.io; we will verify your identity before actioning the request.
Our commitments
We permanently delete your data within 90 days after you cancel your account. When you request deletion, we verify your identity and provide written confirmation of the deletion within 30 days.
Our lawful bases for processing
We rely on the following lawful bases under Article 6 of the GDPR:
- Performance of a contract. We process your account data, such as registration, login, and billing information, because it is necessary to provide the We-Connect service you have subscribed to.
- Legitimate interest. Where our customers use the platform to contact business prospects, the lawful basis is legitimate interest: business-to-business outreach using professional information that individuals have made publicly available on LinkedIn. We also rely on legitimate interest to send our customers service and product communications, to fight fraud, and to secure and improve the platform. A copy of our Legitimate Interests Assessment is available on request at privacy@we-connect.io.
- Consent. Where we send optional marketing communications, we rely on your consent, which you can withdraw at any time using the unsubscribe link in any email.
- Legal obligation. We process certain data where required by law, for example for tax and accounting purposes.
If we intend to use your data for any new purpose, we will inform you before that processing begins.
Security
We have implemented technical and organizational measures to protect your data, including logged and verified connections to our infrastructure and identity verification before actioning sensitive account requests such as data deletion. The security measures that apply to customer data are described in our Data Processing Agreement.
Data Processing Agreement
Under Article 28 of the GDPR, controllers must have a written data processing agreement in place with their processors. Our Data Processing Agreement, which incorporates the EU Standard Contractual Clauses, is available at we-connect.io/dpa. If you need a countersigned copy for your records, contact us at privacy@we-connect.io.
Log retention
We keep technical logs for monitoring, debugging, and security purposes. Logs are deleted within 3 months of their collection date, unless a specific security investigation requires retaining them longer.
Data breaches
If personal data we control is lost, stolen, or otherwise breached in a way that presents a high risk to your rights and freedoms, we will contact you without undue delay, explain the nature of the breach and the steps we are taking, and give you a point of contact for more information. Our processor breach-notification obligations to customers are set out in the Data Processing Agreement.
Pseudonymisation of personal data
Where personal data does not need to remain in its original form, we pseudonymise it: identifying attributes are removed or replaced so the data can no longer be linked to a specific person without additional information kept separately.
Disclaimer
This GDPR page is provided for information only and does not form part of any contract. You are responsible for complying with the laws and regulations that apply to your own use of We-Connect, including data-privacy laws.
Contact
Data-subject requests should be sent to privacy@we-connect.io. Formal data-protection matters may be directed to our data protection contact at dpo@we-connect.io.
Back to top

