Skip to Content
Linard

Security

Our position

Learning new communication techniques requires a safe space to practice. Linard is designed to offer that space, where your practice conversations are private to you.

Two aspects are worth separating. What Linard does is what the product guarantees by design. How Linard is used is what the client decides. We share recommendations, but ultimately this remains a client decision.

This page is an overview. The privacy policy and the terms of use are the binding documents.

Swiss data protection applies

Linard is a Swiss company and operates as such under the revised Federal Act on Data Protection (revFADP). In a client relationship the client takes the role of controller and Linard that of processor, governed by a data processing agreement (DPA). The revFADP permits processing and storage of data outside Switzerland where adequate protection is in place, either because the jurisdiction is on the Federal Council's adequacy list or because contractual safeguards apply. We use that possibility. Where the data actually resides is set out in section 4.

Profiling. The revFADP defines profiling as the automated evaluation of personal aspects and names performance at work explicitly. Linard's analysis falls under that definition. Within profiling, the law marks out a stricter category: high-risk profiling, where linking data permits an assessment of essential aspects of a person's personality. Linard's analysis describes how one conversation was conducted, not what kind of person conducted it. Linard is not intended for personnel decisions.

Biometric data. Voice and image are processed to conduct the conversation. They are never used to identify a person.

Security practices. ISO 27001 is the international standard for managing information security, and the common way to meet the technical and organizational measures the revFADP requires. Our practices are aligned with ISO 27001. We encrypt data in transit and at rest, follow secure development practices, maintain logging and incident response, and perform vendor risk management. We are not yet certified.

What is stored, and who sees it

RetentionNoteAccess
UserOr­ga­ni­za­tion
Audio and videoNot retainedDuring the sessionNot accessible
TranscriptRetainedAccessibleNot accessible
AnalysisRetainedAccessibleNot accessible
AggregatesRetainedAccessibleAccessible
Note

Linard staff do not read transcripts or analyses in the course of normal operations. Access is limited to named individuals, requires a specific reason such as investigating a fault a user has reported, and is logged. We do not look at session content to evaluate or report on how anyone performed.

For product improvement we analyze conversation data automatically and in aggregate. No person reads individual sessions for this purpose, and nothing is attributed to an individual.

Retention

Retained
Kept until someone deletes it. Users can delete their own sessions at any time; clients can request deletion of all their data.
Not retained
Data is not stored and cannot be retrieved.

Access

Accessible
Visible in the product, for as long as the account exists.
During the session
Seen and heard while the conversation runs, never afterwards.
Not accessible
Never shown in the product.

Where the data lives

We store data in the EU. Only transcripts of conversations, conversation analysis, training progress and aggregations thereof are stored. Audio and video are processed during a conversation but not retained.

What it doesWhere it runsBasisRetention
Application and data storageEUAdequacyRetained
Logging and monitoringEUAdequacyRetained
Voice and reasoning modelUSContractual safeguardsTransient
Analysis modelUSContractual safeguardsTransient
Avatar modelNorwayAdequacyTransient
Call setupUSContractual safeguardsTransient

Basis

Adequacy
The Federal Council recognizes this country as providing adequate data protection. No further safeguards are required.
Contractual safeguards
Transfers rest on standard contractual clauses adapted for Switzerland, or on the Swiss-US Data Privacy Framework where the provider is certified.

Retention

Retained
Data is kept here. See previous section.
Transient
Data passes through these services, making a conversation possible, but nothing stays behind.

We name classes of provider here rather than individual companies. The named list, with each provider's jurisdiction, forms part of the data processing agreement.

Authentication. Sign-in runs through the client's own identity provider, or users can create a profile with a username and password. Passwords are stored as hashes in the same database as the rest of the application data. No conversation data reaches identity providers.

AI usage

Mistakes. Linard makes use of AI models, and AI makes mistakes. A counterpart may say something a real client would not. An analysis may misread a turn or miss one. We test extensively but a residual risk remains. In a rehearsal this is tolerable: nothing said here reaches a client, and nothing rests on a single session being right.

Training. Our agreements with the model providers prohibit training on the data we process through them.

Human in the loop. The analysis goes to the person who spoke. It is not an input to personnel decisions. See “Profiling” above.

AI inventories. Some sectors require firms to maintain an inventory of the AI systems they use. Linard belongs in such an inventory, and we supply what is needed to enter it: what the system does, what data it processes, where it runs and how it is tested.

Recommendations

Everything above describes how Linard is built. How it is deployed is the client's decision, and the client is the controller. In this section we share our recommendations.

Voluntary use. People who are required to practice will produce sessions rather than progress. Voluntary use is also the cleanest position under the Ordinance to the Employment Act, which prohibits systems intended to monitor employee behavior. Linard is not such a system and should not be introduced as one.

Do not use it for performance reviews. Linard is built for the person who spoke, not for their appraisal. Under the revFADP data may only be used for the purpose stated when it was collected, so tying it to reviews later is not merely against our advice.

Inform the team. Informing employees about what is collected and why is the controller's duty. It also builds trust in your organization: people who do not know where their session data goes may assume the worst. As this page shows, we are glad to supply what you need to inform your team.

Confidential information. Linard can be used with generic situations, or with the details of a real upcoming meeting. The second brings client information into a session. Decide deliberately what may be shared and what may not, and make that decision before rollout rather than leaving it to individual users. We support either way of working.

Documents and contact

Binding documents. This page is an overview. What holds legally is the privacy policy and the terms of use.

On request. With a data processing agreement we are happy to provide the named list of sub-processors with their jurisdictions, and a more detailed architecture overview. Clients often need this for their own risk assessment or AI inventory.

Get in touch. Reach us at privacy@linard.ai with questions about data handling, or report a security issue to support@linard.ai.