Privacy policy
What EasyData holds, why it is allowed to, how long it keeps it, and how anyone - customer or not - gets themselves out of it.
Effective 20 September 2026 Terms of service
On this page
EasyData is the data enrichment API at easydata.win, together with the console and the documentation site that go with it. In this document "we", "us" and "EasyData" mean the operator of that service, reachable at [email protected], and "the service" means the API, the console and this site together.
The short version: we hold as little about a customer as running an API allows, we sell personal data to nobody, and the professional records we return are read from pages LinkedIn publishes to the open web. If you are a person rather than a customer and would rather not be in it, one email to [email protected] takes you out and keeps you out.
Who this policy is about #
Two different sets of people are described below, and which one you are changes what follows. Customers are the businesses that hold an account and call the API, and the people at those businesses who sign in. The others are the professionals and companies whose public LinkedIn information a customer asked us to look up. We hold very different things about the two, for different reasons, and the rights sections say what each can ask for.
What we hold about customers #
- Account and organisation: the name, work email address and organisation name given when the account was created, a hash of the password - never the password itself - and the sign-in sessions that follow from it.
- API keys: stored as a hash. We show you a prefix so you can tell keys apart; nobody here can read one back, which is why a lost key is replaced rather than recovered.
- What you send: the identifiers you submit - profile URLs, company URLs, post URNs, a pasted Sales Navigator search URL - and the batches they belong to.
- What we returned: the records the API produced for those batches, kept so that the results cursor can be read again.
- Delivery settings: webhook URLs, their signing secrets, and the log of what we sent where and what came back.
- Usage: one row per unit of work - operation, timestamp, credits charged, request id. It is what the usage endpoint answers from and what an invoice is built from.
- Correspondence: what you write to sales or support, and our replies.
- Technical logs: IP address, user agent, request path, status and timing, written by the API and by the web server in front of it.
There is no advertising and no analytics anywhere on this site or in the console. No trackers, no pixels, no third-party script loaded to watch you read.
What we process about people in the results #
When a customer asks for a profile, a company, a post or a search, the record we return is the professional information the source page publishes:
- Identity: name, public profile identifier, member URN, a profile URL and the URL of the profile photo.
- Professional description: headline, About text, stated location, skills, current and past positions, education, certifications, languages, and badges such as premium or open to work.
- Public counts: followers and connections, as LinkedIn itself reports them.
- Day and month of birth, where the member chose to publish it. LinkedIn never returns a year and neither do we.
- Public activity: posts, comments and reactions attributed to a profile, and the posts they were made on.
- Companies: what a company page shows - description, industry, size, locations, website.
We do not return email addresses, phone numbers, private messages, connection lists or anything behind a login. We do not seek out special-category data - health, beliefs, political opinion, trade union membership, sexual orientation - and where a member has written such a thing into their own public About text it arrives as text in a field that did not ask for it.
Where it comes from #
From LinkedIn pages that are public, read the way a browser reads them. Nothing is bought from a data broker and nothing is merged in from a second source, which is also why a record can be out of date: it is what the page said at the moment it was read. Correct the profile and the next lookup follows it.
LinkedIn and Sales Navigator are trademarks of LinkedIn Corporation. EasyData is not affiliated with, endorsed by or sponsored by LinkedIn or Microsoft.
Why we are allowed to hold it #
| What | Why | Legal basis |
|---|---|---|
| Your account and the API | We cannot provide the thing you signed up for without it | Performance of a contract |
| Usage and credit records | Billing, and answering "what did we spend it on" | Contract, plus a legal obligation to keep accounting records |
| Security and abuse logs | Keeping keys and the worker fleet from being abused | Legitimate interests |
| Professional data in results | Providing a business directory service over information already published | Legitimate interests, weighed against the interests of the person - see the opt-out below |
| Product email you asked for | Telling you what changed before it changes | Consent, withdrawn from the link in the mail |
The fourth row is the one that carries the product, and it is the one with a balancing test behind it: the data is professional rather than private, the person published it in order to be found, the use is business to business, and the balance tips back the moment somebody objects - which is what the opt-out below is. Note also that once a record is in a customer's hands they are its controller: what they then do with it runs on their own basis, not ours.
Who else sees it #
- The hosting provider whose servers run the database and the API.
- The mail provider that delivers transactional email - verification links, alerts, invoices.
- Professional advisers, such as accountants and lawyers, where they need it to do their job.
- A public authority, where we are legally required to hand something over. We ask for the request in writing, and we tell the customer unless we are forbidden to.
That is the entire list. We do not sell personal data, we do not share it for advertising, and there is no third party we pass a customer's results to.
How long we keep it #
| What | How long |
|---|---|
| Account, organisation and API keys | While the account exists, and 30 days after you ask us to close it |
| Batch inputs and results | While the account exists, or until you ask us to delete a batch |
| Usage and credit records | Kept as accounting records for as long as the law where we are established requires |
| Webhook delivery log | 14 days after the delivery finished |
| Sent email log | 30 days. A delivery that failed is kept, because it is the only record that somebody did not get their mail |
| Server and access logs | Rotated on a short cycle, and read for nothing but security and debugging |
There is no self-serve delete button yet. Write to [email protected], we do it by hand and we confirm in writing - slower to describe, no slower to happen.
Your rights as a customer #
If you are in the EU, the UK, or anywhere with equivalent law, you can ask for a copy of what we hold about you, have it corrected or deleted, restrict or object to what we do with it, and have it handed over in a portable form. Write to [email protected] and we answer within 30 days. You can also complain to your local supervisory authority, and we would rather you told us first so we can fix it.
If your own profile turned up in a result #
You need no account and no reason. Email [email protected] with the URL of your LinkedIn profile. We delete the records we hold for it and add it to a suppression list, so a later lookup by any customer returns nothing rather than quietly refilling it, and we confirm when that is done.
We will ask you to show the profile is yours - a message from the address on it, or a temporary line in the About section - and nothing else. What we cannot do is reach into a copy a customer already downloaded. Those we can only forward your request to, which we will do if you ask us.
Security #
- Passwords are hashed with a modern password hash, and API keys are stored hashed rather than in the clear.
- Everything is served over TLS. The API does not answer on plain HTTP.
- Webhook deliveries are signed, so a receiver can tell one of ours from a forgery.
- Access to the production database is limited to the people who operate it.
If something goes wrong in a way that puts personal data at risk, we tell the affected customers and, where the law requires it, the supervisory authority - within 72 hours of knowing.
Cookies #
This documentation site sets no cookies at all. It stores one value in your browser, remembering whether you chose the light or the dark theme, and that value never leaves your device. The console sets a session cookie when you sign in, which is what keeps you signed in, and a CSRF token that stops another site acting as you. Both are strictly necessary. There is no analytics or advertising cookie to consent to, which is why there is no cookie banner.
Children #
The service is sold to businesses. It is not directed at anyone under 18, and we do not knowingly hold an account for one.
Changes #
If we change this policy we change the date at the top. If the change matters - a new purpose, a new recipient, a narrower right - we email account holders before it takes effect rather than after.
Contact #
Anything in this document, including a request to see, correct or delete what we hold: [email protected]. Commercial questions go to [email protected].