Privacy
Privacy policy for Link11 Arc
For the Link11 Arc app, the website arc.l11next.com and support by email.
In short: The Arc app has no user accounts, no advertising and no analytics or tracking tools. Link11 receives no usage data from the app. The app exchanges data only with your organisation's Arc hub, and only as far as the connection requires. Link11 does not sell data from Arc, does not use it for its own purposes and does not disclose it to third parties. This website sets no cookies and loads no third-party content.
1. Controller
Link11 GmbHLindleystraße 12
60314 Frankfurt am Main
Germany
Phone: +49 69 264929777
Email: info@link11.com
Questions about Link11 Arc: support@l11next.com
2. Data protection officer
Hopp + Flaig PartG mbBDatenschutzbeauftragter
Neue Weinsteige 69/71
70180 Stuttgart
Germany
Email: flaig@hopp-flaig.de
3. Website arc.l11next.com
Visiting the website
When you open the website, the server processes technically necessary data: IP address, time, requested address, referrer and browser identification. The purpose is to deliver the pages and to operate them securely and reliably, including defence against attacks. The legal basis is our legitimate interest in this (Art. 6(1)(f) GDPR). Logs are kept only as long as these purposes require.
No cookies, no third-party content
The website sets no cookies, stores nothing in your browser and loads no fonts, scripts or other content from third parties. There is no tracking.
Hosting
Colopoint GmbH (web&co), Lindleystraße 12, 60314 Frankfurt am Main, Germany, operates the website and the support mailbox for us as a processor (Art. 28 GDPR). The servers are located at Hetzner Online GmbH in a data centre in Germany; encrypted backups are kept in a Hetzner data centre in Finland (EU).
4. The Link11 Arc app
Enrollment
During enrollment the app creates a WireGuard key pair on your device. The private key is kept in the operating system's protected storage (the keychain on iOS, iPadOS and macOS, the Android Keystore, DPAPI encryption on Windows) and never leaves the device. The app sends the public key and the one-time enrollment code from the link or QR code to your organisation's hub. The hub responds with the tunnel configuration, such as the tunnel address, networks and DNS settings.
Connection and policy
While Arc is connected, an encrypted tunnel to the hub exists and the app regularly fetches the current policy. For technical reasons the hub receives: your device's public IP address and port, the public key and the device name assigned by your organisation, the times of connection set-up and policy requests, the amount of data transferred, and the platform, app version and operating system version.
Traffic in the tunnel
Your organisation's policy decides which traffic uses the tunnel: only traffic to its internal networks, or all traffic. This traffic reaches your organisation's network through the hub. The app itself neither analyses nor stores its content.
Who is responsible for connection data
Your organisation, usually your employer, is responsible for processing in the hub and in its network. It decides which data the hub logs and for how long. Where Link11 operates the hub for your organisation, we act as its processor and follow its instructions. Your organisation's privacy notice applies in addition; requests about this data are best addressed to your organisation.
Our commitment
Link11 does not sell data from Arc, does not use it for any purpose of its own and does not disclose it to third parties. Where we operate the hub for your organisation, we process connection data solely to provide the connection to your organisation.
Diagnostics
The app keeps a local diagnostics log of limited size with connection events, the networks and DNS settings applied, and errors. Private keys, enrollment codes and certificate contents are never logged. The log leaves your device only when you share it yourself through “Export diagnostics”; you choose the recipient.
Crash reports
The app sends no crash reports of its own. Should a future version offer this, it will stay switched off until your organisation or you switch it on, and we will update this policy beforehand. If you have agreed in your device settings to share analytics with app developers, Apple or Google provide us with crash and stability statistics that do not directly identify you. The legal basis is our legitimate interest in a stable app (Art. 6(1)(f) GDPR).
Permissions
- VPN configuration (iOS, iPadOS, macOS, Android): to set up the tunnel.
- Camera: only to scan the QR code; images are neither stored nor transmitted.
- Notifications (optional): for connection status messages.
- Windows: a background service with administrator rights sets up the network adapter, routes and DNS.
- Root certificate (Windows and macOS, optional): Arc installs your organisation's root certificate only with your consent.
Managed devices
On devices your organisation manages (MDM or EMM), it can install, preconfigure and remove Arc. Link11 receives no data from your organisation's device management.
App stores
When you download the app from the App Store, Google Play or the Microsoft Store, Apple, Google or Microsoft process data under their own responsibility; their privacy notices apply.
5. Support by email
When you write to support@l11next.com, we process your email address, your name, the content of your message and attachments such as a diagnostics file in order to answer your request. The legal basis is Art. 6(1)(b) GDPR where the request concerns a contract, otherwise our legitimate interest in answering it (Art. 6(1)(f) GDPR). We pass your request on to your organisation only with your consent. We delete the data once the request is settled, unless statutory retention obligations apply, for example for commercial correspondence.
6. Recipients and transfers to third countries
The recipients are the processors named above: Colopoint GmbH (web&co) for the website and the support mailbox, with Hetzner Online GmbH as data centre operator. We do not transfer personal data to countries outside the EU or EEA. For the app stores, the respective provider's notices apply.
7. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You may object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest (Art. 21). You may withdraw any consent at any time with effect for the future (Art. 7(3)).
You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example with the authority responsible for us: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Wilhelmstraße 7, 65185 Wiesbaden, Germany.
8. No automated decisions
We make no automated decisions within the meaning of Art. 22 GDPR and create no profiles.
9. Changes
We update this policy when the app, the website or the legal situation changes. The version published here applies.