Skip to Content
Linard

Linard Privacy Policy

Last updated: 22 September 2026

This policy explains how Linard handles personal data, across the marketing site at linard.ai and the application at app.linard.ai.

1. Who is responsible

Linard is operated by Linard AG, Oberburg 14, 8158 Regensberg, Switzerland.1

Correspondence relating to this policy, including any data-subject request, should be sent to privacy@linard.ai.

2. Two different relationships, and which one applies to you

Linard is used in two ways, and the data protection roles differ between them. Which sections of this policy apply depends on how you came to use Linard.

2.1 Where you signed up directly

If you registered yourself using an invitation code, Linard is the controller of your personal data. This policy applies to you in full, and Linard decides the purposes and means of the processing described here.

2.2 Where your employer or another organization provides Linard to you

If you use Linard because an organization made it available to you, that organization is the controller and Linard acts as its processor. Linard processes your personal data on that organization's documented instructions, under a data processing agreement.

In that case:

  • Your relationship on data protection is with that organization, and its own privacy notice governs
  • Requests to access, correct or delete your data should go to that organization, which Linard will support
  • The purposes of the processing are set by that organization, not by Linard

One thing the organization cannot decide. Linard is designed so that conversation transcripts, individual feedback and the profile information you add are visible only to you. They are not shared with managers, with human resources, or with anyone else in the organization, and the product provides no way to do so. An organization may receive information about how the application is used, including at individual level, for example how much time a person has spent practicing. It does not receive transcripts, feedback, analysis or profile information.

Sections 5, 6, 7, 8 and 11 of this policy, covering how information is used, sub-processors, transfers, retention and security, describe how Linard handles data in both cases and remain relevant. The rest describes Linard acting as controller.

Where a data processing agreement conflicts with this policy, the agreement governs.

3. What is collected

Account data

Name and email address. Where sign-in with Google or Microsoft is used, the basic profile information those providers return to confirm identity; Linard does not receive the password. Where email and password sign-in is used, an encrypted (hashed) version of the password, never stored in readable form. Any access code or invitation used to join.

Conversation data

When a conversation runs:

  • Microphone audio and video are captured by the browser and streamed in real time to conduct the conversation. They are used to produce the transcript and to generate the counterpart's replies.
  • A transcript of the conversation is recorded and stored.
  • What you enter before the conversation. The scenario you select and any briefing or preparation notes you write to set up the situation.
  • The feedback Linard produces. The analysis of the conversation and the suggestions shown in the debrief afterwards.
  • Session details. Which scenario and counterpart were used, when the session took place and how long it lasted.

Raw audio and video are not stored. They are processed only to conduct the live conversation and are not retained afterwards.

Voice and image are never used to identify a person. They are processed to conduct the conversation, not for biometric identification, and no voiceprints or facial templates are created or retained.

Profile information

You may add information about yourself to your profile, for example the results of a strengths assessment, so that Linard can suggest exercises that suit you. Adding it is optional, and you can change or remove it at any time.

Where you upload a document to add this information, such as an assessment report, it is processed only to extract the relevant results and is then discarded. The document itself is not stored and is not sent to an external AI service.

Technical and usage data

IP address, browser and device type, pages or screens viewed, and similar log data, collected automatically to keep the service running and secure.

Correspondence

If you email Linard, submit comments or suggestions through the product, or take part in a user interview, a record of that exchange is kept.

4. Why it is collected, and the legal basis

This section applies where Linard is the controller. Where an organization provides Linard to you, that organization determines the purposes and the legal basis.

PurposeLegal basis
To provide the service: create the account, run conversations, store sessions, show feedbackPerformance of the agreement with the user
To run, secure, debug and improve the applicationLegitimate interests in operating and developing the service
To stay in contact about the serviceLegitimate interests, and consent where required
To meet legal, accounting and regulatory obligationsLegal obligation

Where consent is the basis, it may be withdrawn at any time by email. Withdrawal does not affect anything done beforehand.

5. How information is used

Personal data is used only to provide and improve Linard and to stay in contact with users about it.

Linard does not, and will not:

  • Sell personal data
  • Share personal data with other businesses for their own marketing, sales or research
  • Make conversations, transcripts or feedback visible to other users

On what the analysis does. Linard evaluates how a conversation was conducted: structure, argumentation, handling of objections and similar aspects of professional communication. It does not assess personality, emotional state, or characteristics unrelated to the conversation, and it does not infer them from voice or image.

On profile information. Information you add to your profile is used to recommend exercises suited to you.

Where Linard acts as controller, it treats this analysis as high-risk profiling under the revised Federal Act on Data Protection and applies the stricter requirements, even though the classification is arguable. Where an organization provides Linard to you, the classification is that organization's to make.

On improving Linard. Session data may be reviewed to debug problems and improve the scenarios and the quality of the analysis. Where Linard acts as a processor, this happens only within the instructions given by the controller.

On anonymized and aggregated data. Linard may create anonymized and aggregated data that can no longer be linked to any individual. Because data in that form is no longer personal data, it may be used to improve current and future products, to build benchmarks and for research, including after personal data has been deleted. Personal data itself is never sold.

On AI model providers. Linard's agreements with its model providers prohibit training on data processed for Linard.

6. Sub-processors

Linard relies on a small number of providers to operate the application. They act on instruction, under data processing terms, and may use the data only to provide their service.

FunctionJurisdictionData handlingTransfer basis
Application and data storageEUPersistent, encryptedAdequate jurisdiction
ObservabilityEUPersistent metrics and logsAdequate jurisdiction
Avatar renderingNorway (EEA)Transient, not storedAdequate jurisdiction
Voice, reasoning and analysis modelsUnited StatesTransient, not stored. No training on the dataEU Standard Contractual Clauses with Swiss adaptation
Call setupUnited StatesTransient, not storedSwiss-US Data Privacy Framework, with EU Standard Contractual Clauses as fallback
AuthenticationUnited StatesIdentity confirmation onlySwiss-US Data Privacy Framework or Standard Contractual Clauses
Internal productivity toolsEU and United StatesCorrespondence and documentsAdequacy or Standard Contractual Clauses

The full list of named sub-processors with their jurisdictions is available on request to privacy@linard.ai, and forms part of the data processing agreement for organizational customers.

Personal data may also be disclosed where the law requires it, or where strictly necessary to protect legal rights.

7. International data transfers

Linard is a Swiss company and operates under the revised Federal Act on Data Protection (revFADP). The revFADP permits processing outside Switzerland where adequate protection exists, either because the jurisdiction appears on the Federal Council's adequacy list, or because contractual safeguards apply. Linard uses both routes, as set out in the table above.

Linard prefers to keep data in Switzerland or the EU wherever possible. Conversation transcripts and the analysis derived from them are stored in the EU. Providers in the United States are used for transient processing during a live conversation and do not retain that data afterwards.

8. How long it is kept

Session history is part of what makes Linard useful, so account and session data is kept for as long as the account is active.

Users may ask for their data to be deleted at any time by emailing privacy@linard.ai, and it will be removed, subject to limited legal exceptions. When an account is closed, its data is deleted or anonymized within a reasonable period afterwards.

Raw audio and video are not stored.

Where Linard acts as a processor, retention is determined by the controller and set out in the data processing agreement.

9. Your rights

Under the revised Federal Act on Data Protection, the GDPR where it applies, and equivalent laws, you have the right to access, correct, delete, restrict or object to the processing of your personal data, to port it to another service, and to withdraw consent where it is the basis for processing.

Where Linard is the controller, email privacy@linard.ai. Requests are answered within one month.

Where an organization provides Linard to you, address your request to that organization as controller. Linard will support them in responding.

If you believe personal data is being mishandled, you may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch, or, where the GDPR applies, your local supervisory authority. A chance to put things right first would be appreciated.

10. Automated decisions

Linard produces feedback and analysis. It does not make automated decisions that have legal effects or similarly significant effects on a person.

Where an organization provides Linard to you, Linard's design keeps individual analysis with the user rather than with management, so that employment decisions are not based on it. How that is applied is set out in the agreement with that organization.

11. Security

Linard's practices are aligned with ISO 27001, the international standard for information security management, which is a common framework for meeting the data security obligations under Swiss data protection law. Alignment covers access control, encryption in transit and at rest, secure development, logging and incident response, and vendor and sub-processor risk management.

Linard is not yet certified. As a young company, certification is a step ahead of us rather than behind.

No system is perfectly secure. If a breach affecting personal data comes to light, affected individuals and the relevant authority will be notified where the law requires, and where Linard acts as a processor, the controller will be informed without undue delay.

12. Cookies

The Linard sites use a small number of cookies and similar technologies that are essential for the service to work, for example to keep a user signed in. No third-party advertising or cross-site tracking cookies are used. Analytics, where used, are cookieless. If non-essential cookies are added in future, this policy will be updated and consent obtained where required.

13. Children

Linard is a professional tool and is not directed at children. Data is not knowingly collected from anyone under the age of 18.

14. Changes to this policy

This policy may be updated from time to time. The "Last updated" date shows the most recent version. Material changes, including changes to how data is used or to the categories of sub-processors, will be flagged and, where appropriate, communicated directly.

Footnotes

  1. Note on incorporation. Linard AG is in the process of being incorporated. Until entry in the commercial register is complete, the application is operated jointly by Flurin Schmid, Manu Drijvers and Samuel Burri, all domiciled in Switzerland. On incorporation, Linard AG succeeds them and becomes responsible for the personal data described in this policy. This note will be removed once incorporation is complete. ↩