Linear

Last Reviewed: 17 Jun 2026

Data Use Review

At a Glance

Linear explicitly claims independent controller status over account and usage data and uses it to optimise and develop its own platform — going beyond processing on the customer's instructions. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.

Company & Product Details

HQ

United States

Products

Project Management & Issue Tracking

Product description

Project management and issue tracking platform for software development teams.

What data is being processed?

Customer Account Data (names, contact information, billing information), Customer Usage Data (activity logs, source/destination of communications, performance data), Personal Data provided by Customer including name, location, email address, date of birth, physical address, unique identifiers such as passwords

Document Details

Date of DPA

31 May 2025

Additional date information

The DPA is dated May 31, 2025, signed by Tuomas Artman (Co-Founder) and explicitly stated as "Signed: May 31, 2025" at the top of the document. No clause number — date appears in the document header and Exhibit B signature block.

What jurisdictions are covered?

The DPA explicitly covers: EU GDPR (Regulation (EU) 2016/679), UK GDPR (EU GDPR as retained in UK law via the European Union (Withdrawal) Act 2018), UK Data Protection Act 2018, Privacy and Electronic Communications (EC Directive) Regulations 2003, California Consumer Privacy Act (CCPA), and the Swiss Federal Act on Data Protection. (clause 1.7)

Is the DPA incorporated into service or customer agreements?

Yes
The DPA is expressed as a supplement to the Terms of Service (the "Agreement") entered into between Customer and Linear Orbit, Inc. By executing the Agreement, Customer also enters into this DPA. In the event of conflict, the order of precedence is: (1) applicable Standard Contractual Clauses; (2) this DPA; (3) the Agreement; (4) any other written agreement between the parties. Any claims under the DPA are subject to the limitations set forth in the Agreement. (clause 9 / preamble)

Location & Transfers

Where is data held or processed?

United States, European Union, Global Linear's primary processing operations take place in the United States (clause 5.1). Exhibit B lists 32 authorised sub-processors across infrastructure, AI, analytics and support functions. Cloud/infrastructure sub-processors: Google LLC (US, EU), Amazon Web Services (US, EU), Cloudflare (Global), PlanetScale (US, EU), Modal Labs (US, EU). Monitoring: Datadog (US), Functional Software Inc./Sentry (US). AI sub-processors: Anthropic PBC (US, EU), OpenAI OpCo (US, EU), Cohere Inc (US, EU), Fireworks AI (US), turbopuffer Inc (US, EU), Braintrust Data (US). Analytics/product: Retool (US), PostHog (US), Hex Technologies (US). Customer support/CRM: Intercom (US), Pylon Labs (US), HubSpot (US), Enterpret (US). Business/sales: Stripe (US), Slack (US), Snowflake (US), Fivetran (US), Hevo Data (US), Postmark (US), Pocus (US), Outreach Corporation (US), Gong.io (US), Common Room (US), Loops (US), Clay Labs (US). Customer cannot select data location. Elasticsearch BV no longer listed as an authorised sub-processor in the current DPA. (Exhibit B)

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
The DPA incorporates EU SCCs (Commission Decision 2021/914, dated 4 June 2021) covering all four modules: Module 1 (Controller-to-Controller) when Linear acts as controller under section 8; Module 2 (Controller-to-Processor) when Customer is controller and Linear is processor; Module 3 (Processor-to-Sub-Processor) when Customer is a processor; Module 4 (Processor-to-Controller) for Customer Usage Data. Governed by Irish law; disputes before Irish courts (clause 5.2–5.3). For ex-UK transfers, UK Controller-to-Processor SCCs and UK Controller-to-Controller SCCs are incorporated, with modifications to substitute UK GDPR and UK DPA 2018 references. The UK Addendum (ICO International Data Transfer Addendum) is defined in the DPA but the specific incorporation mechanism is via the UK SCCs provisions directly rather than the standalone UK Addendum document. Provision for transition to New UK SCCs if current ones are superseded (clause 5.4). Supplementary measures for government agency requests are included (clause 5.5). (clauses 1.8, 1.12, 5.2–5.5)

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Encryption of data at rest (database-level encryption managed by Google Cloud Platform) and in transit (HTTPS/SSL for all data outside Linear's private network). Sensitive authentication information encrypted at the logical database level. Multi-tenant application with logical separation between customer instances. Daily database backups using Google Cloud SQL with annual restore testing. Access Control Policy with formally documented roles/permissions, strong passwords via password manager, SSO/2FA where available, encrypted connections to production systems. Detailed event logging with automated alerts. SOC2 Type II certification achieved (report available at trustcenter.linear.app). Vanta used to automate control monitoring. Background checks and NDAs for all employees. Annual security training and policy acknowledgement required. Physical security training for all employees; screen lock required when unattended. Data minimisation and limited retention policies. Subprocessor security assessments reviewed annually. (Exhibit C)

Non Processor Data Use

Does the company process data solely as a processor?

No
Section 8 explicitly establishes that Linear is an independent controller (not a joint controller with Customer) for Customer Account Data and Customer Usage Data. Linear processes these categories as controller for: managing the customer relationship; core business operations (accounting, audits, tax, compliance); monitoring, investigating and preventing fraud and security incidents; identity verification; legal/regulatory obligations; and service optimisation. All other Customer Personal Data (i.e. data Customer provides or collects through its use of the Services) is processed by Linear as processor under Customer's instructions per Section 2. (clause 8)

Subprocessing

General authorization

General
By executing the DPA, Customer provides general written authorisation for Linear to engage sub-processors listed in Exhibit B and any additional third parties as needed for the Services (clause 3.1). Linear must provide at least 15 days' prior notice before enabling a new sub-processor to access Personal Data, by updating the Exhibit B list and notifying Customer by email (clause 3.2). Customer has 10 days from receipt of notice to object in writing on reasonable data protection grounds (clause 3.2). If Linear cannot provide a commercially reasonable alternative to an objected sub-processor, Customer may discontinue the affected Service but remains liable for fees owed (clause 3.3). Failure to object within the 10-day window deems the third party an Authorised Sub-Processor (clause 3.4). (clauses 3.1–3.4)

Do all the DPA terms flow down to sub-processors?

Yes
Linear is required to enter into a written agreement with each Authorised Sub-Processor imposing data protection obligations comparable to those in the DPA. If a sub-processor fails to meet those obligations, Linear remains liable to the Customer (clause 3.5). Linear also reviews sub-processor security assessments annually (Exhibit C). (clause 3.5)

Is data only processed on the instruction of the controller?

Yes
Linear shall not process Personal Data (i) for purposes other than those in the Agreement and/or Exhibit A, (ii) inconsistently with the DPA or documented instructions, or (iii) in violation of Data Protection Laws. Customer's instructions are embedded in the Agreement, Exhibit A, and any other documented instructions provided by Customer. Linear must inform Customer if it receives a legal requirement to process contrary to instructions (unless prohibited by law). (clause 2.2)

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Upon receipt of a Data Subject Request (access, rectification, erasure, portability, restriction/cessation of processing, withdrawal of consent, or objection to automated decision-making), Linear will notify Customer and advise the Data Subject to submit their request to Customer. Linear will apply appropriate technical and organisational measures to assist Customer in responding to such requests, where Customer is unable to respond without assistance and where Linear is able to do so in accordance with applicable law. Customer is responsible for costs of such assistance (clause 6.1–6.2). (clauses 6.1–6.2)

Does the contract include staff confidentiality clauses?

Yes
All Linear employees are required to sign a non-disclosure agreement before gaining access to Linear information. Background checks are conducted on all new employees. Employees must complete security training and acknowledge Linear security policies (including the Information Security Roles and Responsibilities Policy) prior to joining. (Exhibit C — Measures for ensuring accountability)

Are there audit rights for the data?

Structured
Audit rights exist but are structured/limited. Customer has the right to review, audit and copy Linear's compliance records at Linear's offices during regular business hours with reasonable notice (clause 7.3). For more detailed audits: Linear may first satisfy the right by providing copies of certifications or compliance reports (e.g. SOC2 Type II). Only if reports are not reasonably sufficient under Data Protection Laws may Customer conduct (via an independent third-party representative) a physical audit of Linear's data security infrastructure. Physical audits are subject to: (a) reasonable prior written notice; (b) conducted during business hours only, no more than once per calendar year; (c) restricted to data relevant to Customer; (d) Customer bears all costs including reimbursement of Linear's time. (clauses 7.3–7.4)

Is there assistance with DPIA requests?

Yes
Linear will provide reasonable cooperation and assistance for Customer to conduct Data Protection Impact Assessments (DPIAs), including where Customer does not otherwise have access to relevant information, at Customer's cost (clause 7.1). Linear will also provide reasonable cooperation and assistance for Customer's engagement with any Supervisory Authority where required by GDPR, again at Customer's cost (clause 7.2). (clauses 7.1–7.2)

How much notice is provided for data breaches?

Linear shall notify Customer of a Personal Data Breach "without undue delay" and take steps it deems necessary and reasonable to remediate the breach. Linear will also provide reasonable cooperation and assistance to help Customer comply with its GDPR obligations regarding notification to supervisory authorities and affected Data Subjects, again "without undue delay." No specific hour timeframe is stated beyond "without undue delay." Breach notification obligations do not apply if the breach results from Customer's own actions or omissions. (clauses 7.6–7.8)

What happens to the data on termination?

Following completion of Services, at Customer's choice, Linear shall return or delete Customer's Personal Data. If return or destruction is impracticable or prohibited by applicable law, Linear will block the data from further processing and continue to protect it. Certification of deletion (as referenced in EU SCCs clause 8.1(d)/8.5 and UK SCCs clause 12(1)) is provided only upon Customer's request. No specific retention period post-termination is stated beyond what is required by law. (clause 2.4)