Privacy Policy

At Leasup, the protection of your personal data is a priority.

When you use the website leasup.com (hereinafter the ‘Site’), we may collect personal data concerning you.

The purpose of this policy is to inform you of the manner in which we process such data in accordance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the ‘GDPR’).

Who is the data controller?

The data controller is LEASUP, a Société par actions simplifiée (simplified joint-stock company), registered with the Paris Trade and Companies Register (RCS) under number 891 183 931, whose registered office is located at 11 bis rue de Milan 75009 Paris (hereinafter ‘We’ or ‘Us’).

What data do we collect?

Personal data means any data that makes it possible to identify an individual, either directly or by cross-referencing with other data.

If you choose to ‘Contact’ us via the ‘Contact’ form available on our website, we collect your name, your contact details, your company name, the size of your property portfolio and details of your contact request.

When you subscribe to our Newsletter, we process the contact details you provide to us as well as other analytical data derived from features built into the newsletter itself, such as whether or not the relevant email has been opened. You may unsubscribe from the Newsletter at any time by using the link included in the email or by contacting us.

Mandatory data are indicated when you provide us with your data. They are marked with an asterisk and are necessary in order to provide you with our services.

If you decide to use our software, we will collect personal data in order to provide you with our services. The data processed depend on the services you choose to use. We collect data falling within the following categories:

  • Identification data: in particular surname or company name, title, address, telephone number, email address;
  • For online payments: we use a PCI-DSS certified provider. The PCI-DSS standard is an international security standard intended to guarantee the confidentiality and integrity of cardholder data, and thereby to secure card data during transactions. We do not under any circumstances have access to your credit card details or IBAN in the context of this processing;
  • Data relating to professional life: in particular your position within the company, the company name and your business email address;
  • Login data: in particular your login email and your password.
On what legal bases, for what purposes and for how long do we retain your personal data?
Purposes
Legal bases
Retention periods
Building a customer and prospect database
Our legitimate interest in developing and promoting our business
For customers: the data are retained for the entire duration of the business relationship and are deleted upon expiry of a period of 3 years from the end of the business relationship.
‍
In addition, the data are archived for evidential purposes for a period of 5 years from the end of the business relationship.
Sending newsletters, solicitations and promotional messages
Our legitimate interest in developing and promoting our business
The data are retained for 3 years from your last contact.
Responding to your requests for information
Our legitimate interest in responding to your requests
The data are retained for the time necessary to process your request for information and are deleted once the request for information has been processed.
Who are the recipients of your data?

The following will have access to your personal data:

  1. Our company’s staff;
  2. Our sub-processors: hosting provider, traffic data analytics solution, transactional email solution, CRM tool, meeting scheduling solution and the online payment solution (for software users);
  3. Our partners;
  4. Where applicable: public and private bodies, exclusively in order to comply with our legal obligations.
Is your data likely to be transferred outside the European Union?

Your data are retained and stored for the entire duration of the processing on the servers of OVH, located within the European Union.

In connection with the tools we use (see the section on recipients concerning our sub-processors), your data may be transferred outside the European Union. The transfer of your data in this context is secured by means of the following instruments:

  • Either the data are transferred to a country that has been deemed to offer an adequate level of protection by a decision of the European Commission;
  • Or we have entered into a specific contract with our sub-processors governing transfers of your data outside the European Union, on the basis of the standard contractual clauses between a controller and a processor approved by the European Commission;
  • Or we rely on the appropriate safeguards provided for by the applicable regulations.
What are your rights over your data?

You have the following rights with regard to your personal data:

  • Right to information: this is precisely why we have drawn up this policy. This right is provided for by Articles 13 and 14 of the GDPR.
  • Right of access: you have the right to access all of your personal data at any time, pursuant to Article 15 of the GDPR.
  • Right to rectification: you have the right to rectify your inaccurate, incomplete or outdated personal data at any time in accordance with Article 16 of the GDPR
  • Right to restriction: you have the right to obtain restriction of the processing of your personal data in certain cases defined in Article 18 of the GDPR.
  • Right to erasure: you have the right to require that your personal data be erased and to prohibit any future collection thereof on the grounds set out in Article 17 of the GDPR
  • Right to lodge a complaint with a competent supervisory authority (in France, the CNIL), if you consider that the processing of your personal data constitutes an infringement of the applicable legislation. (Article 77 of the GDPR)
  • Right to set out instructions concerning the retention, erasure and communication of your personal data after your death, in accordance with Article 40-1 of the French Data Protection Act (loi Informatique et Libertés).
  • Right to withdraw your consent at any time: for purposes based on consent, Article 7 of the GDPR provides that you may withdraw your consent at any time. Such withdrawal shall not affect the lawfulness of processing carried out prior to the withdrawal.
  • Right to data portability: under certain conditions specified in Article 20 of the GDPR, you have the right to receive the personal data you have provided to us in a standard machine-readable format and to require that they be transferred to the recipient of your choice.
  • Right to object: pursuant to Article 21 of the GDPR, you have the right to object to the processing of your personal data. Please note, however, that we may continue to process such data notwithstanding your objection, on legitimate grounds or for the establishment or defence of legal claims.

You may exercise these rights by writing to us at the contact details below. We may, on that occasion, ask you to provide additional information or documents to verify your identity.

Personal data contact point

Contact email: support@leasup.com
‍
Contact address: Leasup, 11 bis rue de Milan 75009

Amendments

We may amend this policy at any time, in particular in order to comply with any regulatory, case-law, editorial or technical developments. Such amendments shall apply from the effective date of the amended version. You are therefore invited to consult the latest version of this policy regularly. Nevertheless, we will inform you of any significant change to this privacy policy.

Effective date: 13/10/2021