Your Data Rights Under GDPR
At PrepLinx, we are committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR).
Last updated: January 16, 2026
What is GDPR?
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that applies to organizations processing personal data of individuals in the European Union (EU) and European Economic Area (EEA). It gives you greater control over your personal data and how it is used.
Data Controller
PrepLinx LLC is the data controller responsible for your personal data. This means we determine the purposes and means of processing your personal data.
PrepLinx LLC
Email: hello@preplinx.com
Legal Basis for Processing
We process your personal data based on the following legal grounds:
Your Rights Under GDPR
Right to Access
You have the right to request a copy of the personal data we hold about you. You can view most of your data directly in your account settings.
Right to Rectification
You have the right to request that we correct any inaccurate personal data or complete any incomplete data we hold about you.
Right to Erasure
You have the right to request that we delete your personal data. You can delete your account at any time from your account settings.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data under certain circumstances.
Right to Object
You have the right to object to the processing of your personal data for direct marketing or based on legitimate interests.
Data Retention Periods
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
| Data Type | Retention Period | Purpose |
|---|---|---|
| Account Information | Until account deletion | Providing the service |
| Interview Sessions | Until account deletion or 2 years | Progress tracking & feedback |
| Analytics Data | 12 months | Service improvement |
| Consent Records | 3 years after consent withdrawal | Legal compliance |
| Support Inquiries | 2 years after resolution | Service quality |
International Data Transfers
Your data may be transferred to and processed in countries outside the EU/EEA. When we transfer data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, to protect your data in accordance with GDPR requirements.
Third-Party Data Processors
We work with trusted third-party service providers who process data on our behalf. All processors are bound by Data Processing Agreements (DPAs) that ensure GDPR compliance:
- Supabase: Database and authentication services
- PostHog: Analytics (only with your consent)
- Google: Authentication via Google Sign-In
- Deepgram: Speech-to-text processing
- OpenAI / AI Providers: AI-powered interview feedback
How to Exercise Your Rights
You can exercise your GDPR rights in the following ways:
We will respond to your request within 30 days as required by GDPR.
Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU member state of your residence, place of work, or where the alleged violation occurred. We encourage you to contact us first so we can address your concerns directly.
Related Policies
For more detailed information, please review our other policies: