Linear
Last Reviewed: 17 Jun 2026
At a Glance
Linear explicitly claims independent controller status over account and usage data and uses it to optimise and develop its own platform — going beyond processing on the customer's instructions. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.
Company & Product Details
HQ
United States
Products
Project Management & Issue Tracking
Product description
Project management and issue tracking platform for software development teams.
What data is being processed?
Customer Account Data (names, contact information, billing information), Customer Usage Data (activity logs, source/destination of communications, performance data), Personal Data provided by Customer including name, location, email address, date of birth, physical address, unique identifiers such as passwords
Document Details
Date of DPA
31 May 2025
Additional date information
The DPA is dated May 31, 2025, signed by Tuomas Artman (Co-Founder) and explicitly stated as "Signed: May 31, 2025" at the top of the document. No clause number — date appears in the document header and Exhibit B signature block.
What jurisdictions are covered?
The DPA explicitly covers: EU GDPR (Regulation (EU) 2016/679), UK GDPR (EU GDPR as retained in UK law via the European Union (Withdrawal) Act 2018), UK Data Protection Act 2018, Privacy and Electronic Communications (EC Directive) Regulations 2003, California Consumer Privacy Act (CCPA), and the Swiss Federal Act on Data Protection. (clause 1.7)
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
United States, European Union, Global Linear's primary processing operations take place in the United States (clause 5.1). Exhibit B lists 32 authorised sub-processors across infrastructure, AI, analytics and support functions. Cloud/infrastructure sub-processors: Google LLC (US, EU), Amazon Web Services (US, EU), Cloudflare (Global), PlanetScale (US, EU), Modal Labs (US, EU). Monitoring: Datadog (US), Functional Software Inc./Sentry (US). AI sub-processors: Anthropic PBC (US, EU), OpenAI OpCo (US, EU), Cohere Inc (US, EU), Fireworks AI (US), turbopuffer Inc (US, EU), Braintrust Data (US). Analytics/product: Retool (US), PostHog (US), Hex Technologies (US). Customer support/CRM: Intercom (US), Pylon Labs (US), HubSpot (US), Enterpret (US). Business/sales: Stripe (US), Slack (US), Snowflake (US), Fivetran (US), Hevo Data (US), Postmark (US), Pocus (US), Outreach Corporation (US), Gong.io (US), Common Room (US), Loops (US), Clay Labs (US). Customer cannot select data location. Elasticsearch BV no longer listed as an authorised sub-processor in the current DPA. (Exhibit B)
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Encryption of data at rest (database-level encryption managed by Google Cloud Platform) and in transit (HTTPS/SSL for all data outside Linear's private network). Sensitive authentication information encrypted at the logical database level. Multi-tenant application with logical separation between customer instances. Daily database backups using Google Cloud SQL with annual restore testing. Access Control Policy with formally documented roles/permissions, strong passwords via password manager, SSO/2FA where available, encrypted connections to production systems. Detailed event logging with automated alerts. SOC2 Type II certification achieved (report available at trustcenter.linear.app). Vanta used to automate control monitoring. Background checks and NDAs for all employees. Annual security training and policy acknowledgement required. Physical security training for all employees; screen lock required when unattended. Data minimisation and limited retention policies. Subprocessor security assessments reviewed annually. (Exhibit C)
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Linear shall notify Customer of a Personal Data Breach "without undue delay" and take steps it deems necessary and reasonable to remediate the breach. Linear will also provide reasonable cooperation and assistance to help Customer comply with its GDPR obligations regarding notification to supervisory authorities and affected Data Subjects, again "without undue delay." No specific hour timeframe is stated beyond "without undue delay." Breach notification obligations do not apply if the breach results from Customer's own actions or omissions. (clauses 7.6–7.8)
What happens to the data on termination?
Following completion of Services, at Customer's choice, Linear shall return or delete Customer's Personal Data. If return or destruction is impracticable or prohibited by applicable law, Linear will block the data from further processing and continue to protect it. Certification of deletion (as referenced in EU SCCs clause 8.1(d)/8.5 and UK SCCs clause 12(1)) is provided only upon Customer's request. No specific retention period post-termination is stated beyond what is required by law. (clause 2.4)