Privacy Policy

Last updated: 28 August 2026

1. Who we are

The Link is a practice management platform operated by Victoriam Sales Limited (company number 13606514), a company registered in England and Wales. Our registered office is at Merlin House, Brunel Road, Theale, England, RG7 4AB.

For privacy enquiries, contact us at enquiry@usethelink.com.

2. What data we collect

We collect and process the following categories of personal data:

  • Account information — name, email address, job title, and company name when you or your firm create an account.
  • Contact details — phone numbers and postal addresses stored as part of client records managed by your firm.
  • Communications — messages, emails, and notes sent or received through the platform.
  • Documents and files — files uploaded to or generated within the platform, including signed documents.
  • Photographs of documents — images of receipts, invoices, bank statements and similar paperwork, captured with your device camera or uploaded from your device. These images are sent to automated extraction services that read the information off them — see section 4.
  • Audio recordings — voice notes recorded in messages, dictated text, and, where your firm has enabled call recording, recordings of telephone calls. Recordings are transcribed automatically — see section 4.
  • Diagnostics and crash reports — when the app encounters an error we collect the technical detail of the failure, including a stack trace, device model, operating system version and app version. Each report carries a hashed user identifier so we can tell whether one person hit the same fault repeatedly. The hash is not reversible into your name or email address by the diagnostics provider.
  • Device information — device type, operating system, and push notification tokens when you use our mobile app.
  • Usage data — pages visited, features used, and timestamps for the purpose of providing and improving the service.

3. How we use your data

We process personal data for the following purposes:

  • Providing and operating the platform, including messaging, task management, and project tracking.
  • Sending push notifications, emails, and SMS messages triggered by platform activity.
  • Authenticating users, including biometric login on mobile devices.
  • Generating documents, reports, and approval workflows.
  • Maintaining the security and integrity of the platform.
  • Improving the platform based on aggregated usage patterns.
  • Reading data automatically from photographs and documents you upload — for example pulling the date, amount and supplier off a receipt, or the transaction lines off a bank statement — so the information does not have to be typed in by hand.
  • Transcribing voice notes, dictation and recorded calls into text.
  • Diagnosing crashes and errors so we can fix them.

Our legal bases for processing under UK GDPR are: performance of a contract (providing the service), legitimate interests (security, improvement), and consent (where applicable, e.g. push notifications, and access to your camera and microphone, which the app asks for at the point of use and which you can withdraw in your device settings at any time).

Automated processing. The extraction and transcription described above are automated, but they do not make decisions about you. Their output is presented to a person at your firm, who reviews and corrects it before it is used. There is no automated decision-making producing legal or similarly significant effects within the meaning of Article 22 of the UK GDPR.

4. Third-party services

We use the following third-party services to operate the platform. Data shared with each is limited to what is necessary for the specific function:

  • Neon — database hosting (EU/UK region).
  • Cloudflare — content delivery, file storage (R2), and DDoS protection.
  • SendGrid — transactional email delivery.
  • Firebase Cloud Messaging — push notifications to Android devices.
  • Apple Push Notification service — push notifications to iOS devices.
  • Railway — application hosting.
  • Anthropic, OpenAI and Google — automated extraction of information from uploaded documents and photographs, and transcription of voice notes and recorded calls. Content is sent for processing and the result is returned to the platform. We use these services on terms that do not permit your content to be used to train their models.
  • Sentry — crash and error diagnostics. Reports carry a hashed user identifier as described in section 2.

We do not sell, rent, or trade your personal data to any third party.

5. Data retention

We retain your personal data for as long as your account or your firm's account is active, and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce agreements.

Push notification tokens and device identifiers are removed automatically when they expire or when you uninstall the app.

6. Data security

All data transmitted between your device and our servers is encrypted using TLS (HTTPS). Data at rest is encrypted within our database and storage infrastructure. We use session-based authentication for staff users and token-based authentication for the client portal, with optional biometric verification on mobile devices.

7. Your rights

Under UK GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — request correction of inaccurate data.
  • Erasure — request deletion of your personal data where there is no compelling reason to continue processing.
  • Restriction — request that we limit processing of your data in certain circumstances.
  • Portability — request your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.

To exercise any of these rights, email enquiry@usethelink.com. We will respond within 30 days.

8. Cookies and local storage

The Link uses session cookies to keep you logged in. We use local storage and the Capacitor Preferences API on mobile devices to store your session and notification preferences. We do not use third-party tracking cookies or advertising cookies.

9. Children's privacy

The Link is a business application intended for use by professionals aged 18 and over. We do not knowingly collect personal data from children.

10. Changes to this policy

We may update this privacy policy from time to time. Material changes will be communicated through the platform or via email. The “last updated” date at the top of this page reflects when the policy was last revised.

11. Contact and complaints

If you have questions or concerns about this policy or our data practices, contact us at enquiry@usethelink.com.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).