Privacy Policy
Accepted and effective as of 07.07.2026.
This Privacy Policy governs the collection, processing, and storage of personal data by BMF DIGITAL SRL, a limited liability company organized and existing under the laws of Romania, hereinafter referred to as “LinksPulse”, “we”, “us”, “the Platform”, or “the Administrator”, on the one hand, and the Users (including both Advertisers and independent media partners) of the internet pages and services located on the website https://linkspulse.com/, hereinafter referred to as “User”, “Data Subject”, or “you” as the case may be.
I. General Provisions & Legal Basis
In the course of operating the marketplace, platform diagnostic modules, and client interfaces, the Site collects, handles, and processes specific information relating to its Users, including data qualifying as personal data under applicable frameworks.
All personal data operations are executed strictly in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, hereinafter referred to as "GDPR"), as well as Romanian Law no. 190/2018.
User data is collected primarily via voluntary submission during the account registration workflow, support desk interactions, checkout configurations, or automatically through tracking cookies.
In addition to explicit profile forms, the platform collects environmental telemetry including:
- The User’s internet protocol (IP) address;
- Web browser types, version counts, and operating system attributes;
- HTTP referral source pathways directing traffic onto the Site.
Clear context indicators are provided at data collection points to explain the transactional or contractual necessity of processing.
Technical metadata collected by the interface is utilized for statistical analysis, system security audits, automated database load management, and infrastructure monitoring.
The Administrator reserves the right to introduce timely amendments to this Privacy Policy to reflect processing adjustments or shifting regulatory landscapes. Users will be notified via email or dashboard alert regarding material revisions.
II. Controller Identity & Data Categories
The Controller (Administrator) of your personal data is BMF DIGITAL SRL, a limited liability company organized under the laws of Romania, having its registered office in Romania.
The Administrator collects personal data directly from natural persons creating user profiles, or from authorized corporate representatives establishing entity workspaces on the platform.
Data processing categories managed via our system architecture include:
- Identity Information: First name, last name, and localized corporate profile roles;
- Contact Channels: Verified email address and commercial telephone lines;
- Company Metadata: Legal corporate names, EU VAT registration identifiers, and office registration addresses;
- Financial References: Invoicing addresses, deposit transaction logs, and internal Credit ledger allocations.
III. Purposes & Legal Grounding for Processing
The processing of personal data is executed under the following legal frameworks outlined in Article 6(1) of the GDPR:
- Contract Performance (Art. 6(1)(b) GDPR): To establish accounts, render access to the link-building marketplace, process link placement orders, track replacement warranties, and handle internal live support desk communications.
- Legal Obligation (Art. 6(1)(c) GDPR): To fulfill fiscal compliance, corporate bookkeeping requirements, anti-fraud checks, and mandatory invoicing obligations under Romanian tax law.
- Consent (Art. 6(1)(a) GDPR): To transmit opt-in direct marketing materials, feature highlights, marketplace inventory alerts, or educational newsletters. Consent can be revoked at any time via account toggle preferences.
- Legitimate Interest (Art. 6(1)(f) GDPR): To protect our platform infrastructure against web-scraping bots, coordinate internal platform performance analytics, prevent payment chargebacks, and maintain legal defense positions during corporate disputes.
IV. Data Receivers & Transfer Privileges
Where necessary to execute campaigns or maintain business continuity, specific data elements may be shared with authorized third-party providers bound by professional data processing agreements (DPAs):
- Cloud hosting, server infrastructure networks, and CDN managers;
- Secure, integrated third-party payment gateways and banking networks;
- Automated analytics utilities (e.g., DataForSEO integration modules used to pull search metrics);
- Professional legal counselors, internal accountants, and corporate audit specialists.
V. Comprehensive Data Subject Rights
Under the GDPR framework, you possess the following actionable rights regarding your personal data:
- Right of Access (Art. 15 GDPR): The right to obtain verification of active data processing and request clear copies of your profile metrics along with processing contexts.
- Right to Rectification (Art. 16 GDPR): The right to request immediate updates or corrections to out-of-date or improperly formatted identity details.
- Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): The right to demand account purging where data is no longer necessary for original transaction performance, subject to statutory tax retention constraints.
- Right to Restriction (Art. 18 GDPR): The right to halt data processing tracks while verification disputes regarding accuracy or processing legality are actively reviewed.
- Right to Data Portability (Art. 20 GDPR): The right to receive your personal profile metrics in a structured, machine-readable format to transfer to external system ecosystems.
- Right to Object (Art. 21 GDPR): The right to object to processing tracks leveraging legitimate interests, including an absolute right to halt direct marketing or newsletter outreach profiles.
- Right to Lodge a Complaint: The right to log formal complaints regarding data mismanagement before the national supervisory authority:
The National Supervisory Authority for Personal Data Processing (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, post code 010336, Bucharest, Romania.
Official Portal: https://www.dataprotection.ro/
To exercise any of your statutory data rights, you can contact our privacy officer directly at support@linkspulse.com.
VI. Cookies & Tracking Mechanisms
LinksPulse utilizes session parameters and browser-stored tokens to track logged-in states, remember marketplace filter choices, and secure financial transactions.
- Session Tokens (Session Storage): Temporary, isolated application elements that vanish the second your browser window closes or your session times out.
- Persistent Tokens (Local Storage): Local data keys used to retain necessary system states (such as active support chat strings or persistent login preferences).
You can alter, block, or completely clear cookie profiles inside your personal browser settings panel. Note that stripping required platform session keys may impair order execution pathways or checkout modules.
VII. Retention Bounds
- Personal data profiles are retained exclusively for the lifespan of your active user account space.
- Following account closure requests, core corporate billing records, financial transaction logs, and issued VAT invoices will remain securely archived for the periods mandated by Romanian fiscal and accounting legislation.
- General telemetry logs and statistical optimization variables are purged after a rolling period of 2 years.
VIII. Third-Party Architectures & APIs
The Platform hooks into external cloud systems (such as Google Analytics, cloud security suites, and DataForSEO modules) to deliver link metrics and traffic analytics.
LinksPulse maintains clear validation standards to ensure that its integrated infrastructure partners employ data security controls aligned with modern EU standards.
Our platform handles sensitive card entries via fully PCI-DSS-compliant merchant gateways. The raw credentials never touch or sit on our internal database tables.
IX. Liability Limitations & Security Forces
LinksPulse employs strict cryptographic tokenizations, Row-Level Security (RLS) tables, database isolation policies, and SSL/TLS communication layers to guard user profiles from unauthorized access trails.
The Administrator holds no accountability over the individual privacy rules or data tracking setups deployed on independent external publisher domains listed inside the marketplace grid.
Users are highly encouraged to maintain password security hygiene (employing complex combinations and rotating keys) to safeguard their client portals.