Back to Home

Privacy Policy

Last updated: 01-June-2026

Version 1.1

1. Introduction

This Privacy Policy explains how RatioX Labs DWC-LLC, trading as Linkist ("Linkist", "we", "our", or "us"), collects, uses, stores, shares, transfers, and protects personal data when you use the Linkist website, mobile application, NFC card services, digital profile pages, QR code sharing, Personal Relationship Manager (PRM) features, AI-enabled relationship tools, contact import features, subscriptions, customer support, and related services.

Linkist is designed to help users create and share digital profiles, manage professional relationships, remember important contact context, use NFC and QR-based sharing, and use optional AI-powered tools to organize and improve relationship management.

We are committed to protecting personal data in accordance with applicable UAE data protection laws, including Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, and other applicable privacy, consumer protection, electronic communications, and cybersecurity requirements.

This Privacy Policy should be read together with our Terms of Service.

2. Data Controller

For the purposes of applicable data protection laws, the data controller responsible for your personal data is:

RatioX Labs DWC-LLC

Dubai South Business Park, Building A3, 3rd Floor

Dubai South, Dubai, United Arab Emirates

Email: privacy@linkist.ai

Where Linkist processes contact data imported by a user from their own device, that user may also be responsible for ensuring that the import and use of such contact data is lawful.

3. Data Protection Officer and Privacy Contact

Linkist has designated a privacy contact responsible for handling privacy requests, data subject rights, and privacy governance.

Privacy contact: privacy@linkist.ai

Data Protection Officer contact: dpo@linkist.ai

Users may contact us using the above details for privacy questions, rights requests, complaints, data deletion, consent withdrawal, or concerns about imported contact data.

4. Personal Data We Collect

We collect personal data depending on how you use Linkist.

4.1 Account and identity data

This may include:

  • Full name
  • Display name or nickname
  • Email address
  • Phone number
  • Passwordless login information, OTP verification records, or authentication tokens
  • Account ID
  • Language, country, and account preferences
  • Age confirmation or eligibility confirmation

4.2 Profile and professional data

This may include:

  • Job title
  • Company name
  • Department or role
  • Professional biography
  • Profile photograph
  • Company logo
  • Website links
  • LinkedIn profile URL
  • Other professional or social profile links that you choose to add
  • Digital profile content displayed through your Linkist profile, QR code, NFC card, or profile URL

4.3 Contact and relationship data

This may include:

  • Contacts you create manually
  • Notes about where and how you met a person
  • Follow-up reminders
  • Relationship tags or categories
  • Interaction history
  • User-generated notes
  • Connection context
  • Contact groups, teams, or communities
  • Relationship status, priority, or relationship health indicators

4.4 Imported contact data

If you choose to import contacts from your device, address book, email account, or another permitted source, we may process information such as:

  • Contact names
  • Email addresses
  • Phone numbers
  • Company names
  • Job titles
  • Contact notes or other fields, only where imported and necessary for the selected feature

Contact import is optional. You should not import contact information unless you have the right, consent, authority, or legitimate reason to do so.

4.5 NFC card, QR, order, and fulfilment data

This may include:

  • NFC card configuration details
  • Name, role, phone, email, logo, or profile details printed or encoded for card use
  • Shipping and delivery address
  • Billing address
  • Order number
  • Product selection
  • Delivery tracking information
  • Customer service communications
  • Product feedback

4.6 Payment and subscription data

Payments are processed by third-party payment providers such as Stripe. We do not store full card numbers.

We may process:

  • Subscription plan
  • Invoice details
  • Payment status
  • Stripe customer ID, payment session ID, or subscription ID
  • Transaction references
  • Tax or accounting records

4.7 Technical and device data

This may include:

  • IP address
  • Browser type
  • Device type
  • Operating system
  • App version
  • Device identifiers
  • Push notification tokens
  • Login records
  • Security logs
  • Crash logs
  • Diagnostic information
  • Website and app usage data

4.8 Location data

Linkist may request access to approximate or precise location only for specific features, such as recording or verifying where a professional connection was made. Location access is optional unless required for that specific feature.

We will request separate permission before collecting precise location data. We do not use location data for advertising or unrelated profiling unless we obtain separate consent.

4.9 Cookies and similar technologies

We use cookies, pixels, SDKs, local storage, and similar technologies for essential functionality, security, analytics, preferences, and, where consented, marketing.

4.10 AI-generated and profiling data

If you use optional AI-enabled features, we may generate:

  • Contact enrichment summaries
  • Relationship reminders
  • ICP or relevance scores
  • Smart Signals
  • Suggested introductions
  • Suggested follow-up actions
  • Contact priority indicators
  • Network insights
  • Profile or relationship summaries

AI outputs are assistive and may be incomplete or inaccurate. They should not be treated as legal, financial, employment, credit, medical, or other professional advice.

5. How We Collect Personal Data

We collect personal data:

  • Directly from you when you create an account, profile, order, or support request
  • When you use Linkist features, including QR, NFC, PRM, contact management, AI tools, and reminders
  • When you import or sync contacts
  • When another user shares, imports, tags, or records your contact details in Linkist
  • From payment, shipping, analytics, communication, and customer support providers
  • From public or professional sources where AI enrichment is enabled and lawful
  • Automatically through cookies, app logs, device data, and security monitoring

6. How We Use Personal Data

We use personal data for the following purposes:

6.1 Providing the service

We use data to:

  • Create and manage user accounts
  • Host digital profiles
  • Enable NFC and QR profile sharing
  • Process NFC card orders
  • Configure cards and digital profiles
  • Provide PRM contact management features
  • Match ICP or provide relevance scores
  • Generate Smart Signals
  • Suggest contact introductions
  • Enable reminders, notes, groups, and connection history
  • Provide subscriptions and paid services
  • Provide customer support

6.2 Payments, billing, and order fulfilment

We use data to:

  • Process payments
  • Manage subscriptions
  • Issue invoices
  • Process refunds or replacements if applicable
  • Ship NFC cards or other products
  • Maintain tax and accounting records

6.3 AI-enabled features

Where enabled, we use data to:

  • Organize and summarize contact information
  • Generate relationship context
  • Suggest follow-ups
  • Score or prioritize contacts
  • Generate Smart Signals
  • Suggest introductions
  • Improve professional relationship management

AI-enabled features may involve automated processing or profiling. Users may disable optional AI features or object to automated profiling through Privacy Settings or by contacting us.

6.4 Contact import and matching

Where enabled, we use imported contact data to:

  • Help users manage their contact list
  • Detect existing Linkist users
  • Organize contacts
  • Suggest follow-ups
  • Support PRM features
  • Prevent duplicate entries
  • Invite and add contacts to user's Linkist address book

We do not sell imported contact data. We do not use imported non-user contact data for marketing unless the individual has independently opted in.

6.5 Security and fraud prevention

We use data to:

  • Verify accounts
  • Prevent fraud, misuse, spam, phishing, and unauthorized access
  • Maintain audit logs
  • Protect the integrity of our service
  • Investigate suspicious activity

6.6 Analytics and service improvement

Where permitted, we use data to:

  • Understand feature usage
  • Improve website and app performance
  • Fix bugs
  • Improve product design
  • Measure service reliability

Analytics cookies or tracking technologies that are not strictly necessary will be used only where consent is required and obtained.

6.7 Communications

We use data to send:

  • Account notices
  • OTP and verification messages
  • Order confirmations
  • Shipping updates
  • Subscription notices
  • Security alerts
  • Support responses
  • Policy update notices
  • Marketing communications, only where consented or otherwise lawful

7. Legal Basis for Processing

We process personal data only where we have a lawful basis.

Processing activityLegal basis
Account registration and loginContractual necessity
Digital profile hostingContractual necessity
NFC card order fulfilmentContractual necessity
Payment processing and subscriptionsContractual necessity and legal obligation
Tax and accounting recordsLegal obligation
Customer supportContractual necessity and legitimate interests
Security monitoring and fraud preventionLegitimate interests and legal obligation
Essential cookiesContractual necessity and legitimate interests
Analytics cookiesConsent, where required
Marketing emails, SMS, WhatsApp, or promotional push notificationsExplicit consent
Push notifications for non-essential purposesConsent
Contact importConsent and/or legitimate interests, depending on feature and context
AI enrichment, Smart Signals, and automated profilingExplicit consent, unless another lawful basis applies and is documented
Geolocation captureExplicit consent
Service improvementLegitimate interests, where not overridden by user rights
Legal claims, dispute handling, and complianceLegal obligation and legitimate interests

Where we rely on legitimate interests, we assess whether our interests are overridden by your rights, freedoms, or reasonable expectations.

8. Consent

We request separate consent for optional or higher-risk processing. Consent is not bundled with the Terms of Service.

Separate consent may be requested for:

  • Acceptance of Terms of Service
  • Acknowledgement of this Privacy Policy
  • Marketing communications
  • Analytics cookies
  • Push notifications
  • Device contact import
  • Geolocation capture
  • AI enablement for Contact enrichment, Smart Signals, ICP and Smart Introductions

Consent records may include user ID, consent type, consent version, timestamp, device or app context, and the consent mechanism used.

You may withdraw consent at any time through Privacy Settings or by contacting privacy@linkist.ai. Withdrawal of consent does not affect processing completed before withdrawal.

9. AI Features, Profiling, and Automated Processing

Linkist may provide optional AI-enabled tools that assist with relationship management. These features may analyze profile data, contact details, notes, connection history, interaction context, and professional information to produce suggestions, summaries, scores, or reminders.

AI features may include:

  • Contact enrichment
  • ICP matching
  • Relationship scoring
  • Network scoring
  • Smart Signals
  • Smart Introductions
  • Suggested follow-ups
  • Profile or contact summaries

We do not use AI features to make legally binding decisions about users. AI outputs are assistive only. Users are responsible for reviewing outputs before relying on them.

Users may disable optional AI features or object to automated profiling through Privacy Settings or by contacting privacy@linkist.ai.

We do not knowingly use AI profiling on minors.

10. Contact Import and Third-Party Contact Data

Contact import is optional.

If you import contacts into Linkist, you confirm that you have the right, authority, consent, or legitimate reason to provide those contacts for your own personal or professional contact management purposes.

We process imported contact data only to provide selected Linkist features, such as contact organization, matching, reminders, relationship management, and AI-enabled features where separately enabled.

We apply data minimisation to imported contacts and aim to retain only what is necessary for the selected feature.

Individuals whose information has been imported into Linkist may request access, correction, objection, restriction, or deletion by contacting privacy@linkist.ai.

We do not sell imported contacts. We do not send marketing communications to imported contacts unless they independently opt in.

11. Location Data

Some Linkist features may use location to record or verify where a professional connection occurred. Location information may also be helpful when attending an event or conference to connect with like-minded contacts for business purposes.

We will request permission before collecting precise location data. You may refuse location access, but some location-based features may not work.

Where possible, we use the minimum level of location detail necessary. We do not use location data for advertising or unrelated profiling without separate consent.

12. Cookies and Tracking Technologies

We use the following types of cookies and similar technologies:

12.1 Essential cookies

These are required for login, security, checkout, fraud prevention, user preferences, and core service operation. They cannot be disabled through our cookie banner.

12.2 Analytics cookies

These help us understand website and app usage, diagnose issues, and improve our services. We use analytics cookies only where permitted by law and, where required, with consent.

12.3 Marketing cookies

These may be used to measure campaigns or provide relevant content. We use marketing cookies only with consent where required.

You can manage cookie preferences through our cookie banner, Privacy Settings, or browser settings.

13. Marketing Communications

We send marketing communications only where we have consent or another lawful basis.

Marketing may include product updates, promotional offers, early access announcements, event messages, or founder-member communications.

You may opt out at any time by using the unsubscribe link, changing Privacy Settings, or contacting privacy@linkist.ai.

Transactional messages, such as OTPs, order confirmations, payment notices, security alerts, service updates, and subscription plan related updates, are not marketing and may still be sent where necessary.

14. Sharing Personal Data

We do not sell personal data.

We may share personal data with trusted service providers and partners where necessary to operate Linkist, including:

  • Hosting and infrastructure providers
  • Database and backend service providers
  • Payment processors, including Stripe
  • Email and transactional messaging providers used to send OTPs
  • Shipping and fulfilment providers
  • Customer support providers
  • Analytics providers
  • Security, monitoring, and fraud prevention providers
  • AI and large language model providers, where AI features are enabled
  • Professional advisers, including lawyers, auditors, accountants, and compliance advisers
  • Regulators, courts, law enforcement, or government authorities where required by law

All processors are expected to process personal data only under our instructions and subject to appropriate confidentiality, security, and data processing terms.

15. International Data Transfers

Some of our service providers may be located outside the United Arab Emirates. Personal data may be transferred to countries where our hosting, payment, communication, analytics, AI, support, or other service providers operate.

Where required, we use appropriate safeguards, which may include:

  • Data Processing Agreements
  • Standard contractual clauses or equivalent transfer terms
  • Contractual confidentiality commitments
  • Encryption in transit and at rest
  • Access controls
  • Vendor security assessments
  • Data minimisation

16. Data Security

We use technical and organisational measures designed to protect personal data, including:

  • Encryption in transit
  • Encryption at rest where appropriate
  • Access controls and role-based permissions
  • Secure authentication
  • OTP expiry and secure token handling
  • Audit logging
  • Security monitoring
  • Restricted administrative access
  • Vendor security review
  • Vulnerability assessment and penetration testing where appropriate
  • Staff awareness and confidentiality obligations

No system is completely secure. Users are responsible for keeping their account access, email, devices, and login methods secure.

17. Data Retention

We retain personal data only for as long as necessary for the purpose for which it was collected, unless a longer period is required for legal, accounting, tax, dispute, security, or legitimate business purposes.

Data categoryRetention period
Account and profile dataDuration of account plus up to 30 days after deletion, unless longer retention is legally required
NFC card and order records5 to 7 years, depending on tax, accounting, commercial, and dispute requirements
Payment and invoice recordsMinimum period required by UAE tax and accounting rules
Consent recordsAccount duration plus up to 7 years for legal defence and compliance records
Imported non-user contact dataRetained only as necessary for the selected feature, then deleted or anonymised according to our retention schedule
AI enrichment outputsUp to 6 months or until account deletion, unless refreshed, deleted, or legally retained
Authentication tokens and OTPsShort expiry after issuance or use, with limited security logs retained as needed
Security and audit logsUsually up to 12 months, unless needed for investigation or legal defence
Technical troubleshooting logsUsually up to 90 days, unless needed for security, debugging, or legal purposes

When retention is no longer necessary, we delete, anonymise, or securely archive personal data.

18. Your Privacy Rights

Subject to applicable law, you may have the following rights:

  • Right to access your personal data
  • Right to correct inaccurate or incomplete data
  • Right to request deletion of personal data
  • Right to restrict or suspend certain processing
  • Right to request data portability in a machine-readable format
  • Right to object to processing based on legitimate interests
  • Right to object to direct marketing
  • Right to object to automated profiling
  • Right to withdraw consent
  • Right to receive information about international transfers
  • Right to complain to a competent data protection authority, including the UAE Data Office where applicable

To exercise your rights, contact privacy@linkist.ai or use the Privacy Settings available in your account.

We may need to verify your identity before responding. We aim to respond within 30 days unless a different period applies under law or the request is complex.

19. Account Deletion

Users may request account deletion through the app, website, or by contacting privacy@linkist.ai.

After account deletion, we will delete or anonymise account data unless retention is required for:

  • Tax and accounting obligations
  • Fraud prevention
  • Security investigations
  • Dispute resolution
  • Legal claims
  • Compliance records
  • Enforcement of our Terms

Some data may remain in backup systems for a limited period before deletion through ordinary backup cycles.

20. Children and Minors

Linkist is intended only for users aged 18 or above.

We do not knowingly allow users under 18 to create accounts. We do not knowingly collect personal data from minors or conduct AI profiling of minors.

If we become aware that we have collected personal data from a person under 18 without valid authorisation, we will delete it or take other appropriate action.

21. Data Breach Notification

If a personal data breach occurs, we will assess the nature and impact of the breach and take appropriate steps to contain, investigate, and remediate it.

Where required by applicable law, we will notify the competent authority and affected individuals. Notification may include the nature of the breach, categories of data affected, likely consequences, and steps taken or proposed to address the breach.

22. Third-Party Links and Services

Linkist profiles may include links to third-party websites, social media pages, messaging services, payment providers, or other external services. We are not responsible for the privacy practices, content, security, or accuracy of third-party services.

Users should review the privacy policies of third-party services before using them.

23. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If changes are material, we may notify users by email, in-app notice, website notice, or another appropriate method.

The updated Privacy Policy will apply from the effective date stated above. Continued use of Linkist after the effective date means you acknowledge the updated policy.

24. Contact Us

For privacy questions, complaints, or rights requests, contact:

RatioX Labs DWC-LLC

Dubai South Business Park, Building A3, 3rd Floor

Dubai South, Dubai, United Arab Emirates

Email: privacy@linkist.ai

Support: support@linkist.ai