Effective 14 August 2026. Applies to CommonLynk ("CommonLynk", "we", "us"), operated by Common Ground Solutions (CGS), a limited liability company established under Egyptian Law No. 159 of 1981, New Maadi, Cairo, Egypt.
1. About this policy
This policy explains how CommonLynk handles personal data when you visit our website, create an account, and use the CommonLynk platform. We are committed to protecting personal data and to handling it in line with major data protection frameworks, including the EU General Data Protection Regulation (GDPR), and the data protection laws applicable to your use of the platform.
CommonLynk is a multi-tenant platform that organisations (NGOs, civil-society and similar bodies — "Organisations") use to manage their programmes, beneficiaries, forms and reporting.
2. Our two roles
- As a controller: for data about our direct customers and website visitors — account holders, billing contacts, and people who contact us — we decide why and how that data is processed. This policy governs that processing.
- As a processor: for the data an Organisation enters about the individuals, households and establishments it records and serves on the platform (each, a "Beneficiary") and about its operations, the Organisation is the controller and CommonLynk acts only as a processor on the Organisation's documented instructions. That processing is governed by our Data Processing Agreement, and questions about that data should go to the relevant Organisation.
3. Personal data we collect (as controller)
- Account & identity: name, work email, organisation, role, language and regional preferences.
- Authentication: password (hashed), one-time sign-in codes, and security/login metadata.
- Billing: billing name, address, tax ID, subscription, invoices, and payment references. We do not store full card numbers — card payments are handled by our payment provider; bank-transfer references and proof you upload are stored to reconcile payment.
- Usage & technical: IP address (used, among other things, to show the right currency and language), device/browser data, and log data.
- Communications: messages you send us and email-delivery metadata.
- Diagnostic & support data: when the platform encounters an error, or when you report a problem or make a suggestion, we record technical information about what happened — the page address, the technical error details, your browser and operating system, your language, the time, your account and organisation, and a record of the actions taken immediately beforehand (the type of action and the name of the control used — never the content you typed or the records you were viewing). If you choose to attach a screenshot or a file to a report, we store it too. Section 6 explains how this data is handled, including our controls on screenshots.
4. Why we use it and our legal bases
We process the above to: provide and secure the service; authenticate you; process subscriptions, payments and invoices; provide support; diagnose, fix and prevent faults in the platform (Section 6); send service and transactional emails; and comply with legal obligations. Depending on the applicable law, our legal bases include performance of a contract, legitimate interests, consent, and compliance with legal obligations. Where consent is the basis, you may withdraw it at any time. Our legitimate interest in diagnostic data is keeping the platform working correctly and secure; we limit what is collected to what serves that purpose.
5. Sub-processors and sharing
We use vetted third parties to run the service — for example email delivery, payment processing, cloud hosting/backups. They process data only on our instructions and under appropriate safeguards. A current list of sub-processors — naming each provider, what it processes, and where — is set out in the Sub-processors (current list) section at the end of this policy. We give at least 30 days' advance notice before adding or replacing a sub-processor, so that Organisations can object on reasonable data-protection grounds. We do not sell personal data.
5A. Connecting your own storage (Google Drive, Dropbox, OneDrive or S3)
An Organisation may optionally connect its own cloud storage so that CommonLynk delivers a copy of the Organisation's encrypted backup packages there (see the Data Processing Agreement Section 4A(8)). When you connect such an account, CommonLynk uses app-folder-scoped access only: the connection can only ever read and write the backup files CommonLynk itself creates in its own dedicated folder — it can never see, read, or access any of your other files in that account.
Google API Limited Use. Where you connect Google Drive, CommonLynk's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, CommonLynk does not use Google user data to serve advertising; does not sell it or transfer it to data brokers or information resellers; does not use it for creditworthiness or lending purposes; and does not use it to train, create or improve any generalised artificial-intelligence or machine-learning model. Humans do not read this data except with your affirmative consent, where necessary for security or to comply with law, or in aggregated/anonymised form for internal operations. The equivalent app-folder limitation applies to Dropbox (App Folder) and OneDrive (Microsoft Graph Files.ReadWrite.AppFolder).
6. Diagnostic data and fault reports
When something goes wrong on the platform, or you report a problem, we record diagnostic data so we can understand and fix the fault: the technical error details, the page address, the browser and operating system, the interface language, timestamps, who was signed in and in which workspace, and a trail of the actions immediately before the fault — limited to the type of action and the name of the control used, never what was typed or the contents of any record. You may also choose to attach a screenshot or a file.
Reports are read by people. Our support staff receive one internal summary each day listing the reports that arrived, so a person reads every one. That summary travels by email and never carries a screenshot or an uploaded file — it carries a link that opens the report inside the platform, so the protections below still apply, including the log of who opened it.
Screenshots deserve a specific word. A screenshot of a page in the platform can contain personal data about the people an Organisation serves. So: screenshots are only ever captured when a person chooses to attach one; the person sees a preview and can black out any part of it, or discard it, before sending; they are stored in protected storage that the public web cannot reach; only authorised support staff can open one, and every time one is opened it is recorded in our audit log; and they are retained and deleted in accordance with the Data Retention Policy.
7. International transfers
The platform may process data in more than one country. Where personal data is transferred across borders, we apply the safeguards required by applicable law (which may include the regulator authorisations, contractual safeguards such as Standard Contractual Clauses, or in-region hosting that the relevant jurisdiction requires). Organisations should review the Data Processing Agreement for details relevant to their beneficiary data.
8. Retention
We keep personal data only as long as needed for the purposes above and as required by law. Account and tenant data follow the lifecycle in our Data Retention Policy (active → grace → dormant → deletion).
9. Your rights
Subject to applicable law, you may have the right to access, correct, delete, restrict or object to processing, withdraw consent, and request portability of your personal data, and to lodge a complaint with your data protection authority. To exercise these for data we hold as controller, contact our Data Protection Officer, Yasmine Ossama — dpo@commonlynk.com. For data an Organisation holds about you as a Beneficiary, contact that Organisation (we will assist them as processor).
10. Security
We use technical and organisational measures appropriate to the risk — including encryption in transit (HTTPS), access controls, tenant isolation, authenticated access to uploaded files, and regular backups. No system is perfectly secure, but we work to protect your data and to notify the right parties promptly if a breach occurs.
11. Children
The platform is intended for use by Organisations and their staff, not for direct use by children. Where an Organisation records data about children as Beneficiaries, the Organisation is the controller and is responsible for the heightened consent and protection that applicable law requires; CommonLynk supports this as processor.
12. Changes & contact
We may update this policy; the "last updated" date will change and material updates will be notified. Questions or requests: our Data Protection Officer, Yasmine Ossama — dpo@commonlynk.com / Common Ground Solutions (CGS), a limited liability company established under Egyptian Law No. 159 of 1981, New Maadi, Cairo, Egypt.
Sub-processors (current list)
What this page is
A sub-processor is a third-party company that processes personal data on CommonLynk's behalf in order to deliver the service. This page names every one of them, says what each processes and where, so that an Organisation using CommonLynk can satisfy its own accountability and donor due-diligence obligations.
Notice of change. We give Organisations at least 30 days' advance notice before adding or replacing a sub-processor. An Organisation may object on reasonable data-protection grounds; the process is in the DPA Section 5. To receive change notices, contact our Data Protection Officer, Yasmine Ossama — dpo@commonlynk.com.
Last reviewed: 18 August 2026.
Current sub-processors
Brevo
- Purpose: Outbound transactional email — account, billing, support and notification messages
- Personal data processed: Recipient name and email address, message subject and body, delivery metadata
- Processing location: EU
- Status: Active
Paymob
- Purpose: Card payment processing
- Personal data processed: Billing name, contact details, payment identifiers. CommonLynk never receives or stores card numbers — these are entered on the provider's own hosted page
- Processing location: Egypt
- Status: Configured — not yet processing live cardholder data; activated when the first live payment is taken
Contabo GmbH
- Purpose: Server infrastructure hosting (VPS running the platform and its databases, including the first tenant workspace) and access-controlled off-site backup storage
- Personal data processed: All platform data — at rest, in processing, and within full backups
- Processing location: Germany (EU)
- Status: Active
Hosting expansion. As CommonLynk grows, additional workspaces may be hosted with other providers or in other countries. Each such provider will be named on this list and Organisations given advance notice before it is added, per the DPA Section 5.
Not sub-processors
Listed so that the absence is deliberate rather than an oversight — due-diligence reviewers ask about these:
GeoNames
- Why it is not a sub-processor: CommonLynk retrieves public administrative-division reference data from it. No personal data is sent.
Public exchange-rate source
- Why it is not a sub-processor: Rates are fetched; nothing is sent.
IP-to-country lookup (local database)
- Why it is not a sub-processor: Visitor country (for currency/language) is read from a local database; no IP address is sent to any third party.
Contabo GmbH's own hardware maintenance
- Why it is not a sub-processor: Covered by the hosting agreement above, not a separate engagement.
Controller-connected escrow storage (Google Drive / Dropbox / OneDrive / S3)
- Why it is not a sub-processor: When an Organisation connects its own storage to receive backup copies, that account is the Organisation's own facility, not a CommonLynk sub-processor. CommonLynk uses app-folder-scoped access and can touch only the backup files it creates. See DPA Section 4A(8).
What we require of every sub-processor
Per DPA Section 5, each sub-processor is bound by a written agreement imposing data-protection obligations at least as protective as those CommonLynk owes its Organisations, and CommonLynk remains fully liable for their performance.