1. Definition and nature of personal data
When using our website www.leanpay.io, you may be asked to provide certain personal data in order to use the services offered by LeanPay.
The term “Personal Data” refers to any information that directly or indirectly identifies a natural person. This includes, among others: surname, first name, postal address, email address, telephone number, browsing data on the website, type of subscription selected, and any other information you choose to provide to us.
2. Purpose
The purpose of this Privacy Policy is to inform you about our practices regarding the collection of personal data. The collection and processing of personal data are carried out in accordance with Act 78-17 of 6 January 1978 "Loi informatique et libertés", and with Regulation (EU) 2016/679 of 27 April 2016, commonly known as the General Data Protection Regulation (GDPR).
3. Entity responsible
The entity in charge of collecting your personal data LeanPay SAS, a simplified joint-stock company registered with the Lille Trade and Companies Register under RCS number 884 733 098, with its registered office located at 65 Avenue Becquart, 59130 Lambersart, France.
4. Collection of personal data
LeanPay may collect your personal data based on the rules defined by the GDPR. We collect your personal data during your browsing on the website on the basis of LeanPay’s legitimate interest. In this context, your data is collected in order to better respond to your requests for information about our services. We ask for your consent regarding the use of cookies and the analytical tools mentioned in Article 10. We collect your data as part of a contract if you are a customer of LeanPay.
Your personal data is collected for one of the following purposes:
- To personalize our responses to information requests;
- To manage your access to the services from the website;
- To create a list of our customers, users and prospects;
- To send our newsletters and promotional communications;
- To establish statistics on our sales and visits to our website;
- To effectively manage payment issues and any other service-related issues;
- To comply with our legal obligations;
- In the case of using the services, to ensure the continuity of the services, in particular the follow-up of invoices and communication with debtors.
When collecting your personal data, we inform you whether providing such data is mandatory or optional. Mandatory data is essential for the proper functioning of the services. Optional data may be submitted at your discretion.
If you do not wish to receive this information, you may express your refusal at the time the database is created.
5. Access to personal data
The individuals who have access to your personal data are the following:
- LeanPay employees and executives, in particular the teams responsible for data management;
- LeanPay’s auditors and other advisors, subject to confidentiality obligations;
- Other entities authorised to access your personal data, such as public and judicial authorities, in accordance with applicable laws.
6. Personal data transfer
Except for the individuals and entities mentioned in Article 5, LeanPay undertakes not to transfer, sell, lease or disclose your personal data to any third party.
7. Data retention period
7.1. For data related to customers and prospects
Your personal data will only be retained for the duration of the informational or commercial relationship between you and LeanPay. However, data relating to a contract or the establishment of rights, and data that must be retained to comply with legal obligations, will be kept for the period required by applicable law. Regarding commercial prospecting activities targeting customers, LeanPay reserves the right to store data for a period of three years following the end of the commercial relationship. Personal data of individuals who are not LeanPay customers may be kept for three years from the date of collection or the last contact initiated by the prospect. After this three-year period, LeanPay reserves the right to contact the individual to determine whether they wish to continue receiving commercial offers.
7.2. For bank details:
Banking data refers to all information related to bank transactions from bank accounts you have chosen to connect to LeanPay as part of the use of the services. This includes the bank name, account name, transaction date, transaction amount, and transaction description. This banking information is stored by LeanPay to ensure the proper functioning of the services, for a period of thirteen months from the date the transaction appeared in LeanPay. This information can be used as support data in the event of a dispute.
7.3. For individuals who do not wish to be contacted for commercial purposes:
LeanPay retains only the information indicating that these individuals have opted out of commercial communications, for a period of three years from the date the objection was recorded.
7.4. For cookies management:
Cookies are stored for a period of 13 months, in accordance with Article 10.
8. Security
LeanPay is committed to implementing all technical and organisational measures to protect the security, integrity, inalterability and confidentiality of your personal data.
9. Storage
As part of the use of the services, personal data is stored for the entire duration of the commercial relationship on servers belonging to Amazon Web Services and OVH, both of which are exclusively located in France.
10. Cookies
Cookies are text files, most often encrypted and stored in your browser. They are created when you load a specific website: this site sends information to the browser which then stores it as a text file. During the next visits to this same website, your browser sends the text file back to the website's servers. Several types of cookies exist, each having different purposes:
10.1. Technical cookies
- Technical cookies are used while browsing the website to measure activity and enable certain functionalities. For instance, a technical cookie may store a visitor’s response to a form or their language and interface preferences, when these choices are possible. As part of the services, a technical cookie is used to save the user's session and allow them, within 15 days, to return to the customer interface without having to re-enter their username and password on the authentication page.
We therefore use technical cookies on the website and within the customer interface when providing our services.
10.2. "Social media" cookies
- "Social media" cookies may be created by social networks to allow website developers to share content from their site directly onto the relevant social network. These cookies are used by social networks to track users' browsing activity from the website.
We do not use “social media” cookies.
10.3. Advertising Cookies
- Advertising cookies may be generated by the website a user is browsing, as well as by third parties using the website to display sponsored content or other elements. These cookies may be used in particular for marketing purposes, i.e. to trigger communication campaigns based on users’ browsing behaviour.
We do not use advertising cookies.
We use the following analytical tools: Google Analytics, FullStory, MixPanel, Posthog, Storylane.
These tools generate a cookie that allows us to track the number of visits to the website, the number of pages viewed and browsing behavior when you are on the site or using the services. The sole purpose of analyzing this data is to improve your experience on the website and when using the services.
Your IP address is collected to determine the location from which the connection is made. This cookie is created in your browser. You may choose to accept or refuse it. Please note that you can always oppose the creation of cookies in your browser settings. However, refusing these cookies may affect the optimal functioning of the website.
11. Access to your personal data
In accordance with Act 78-17 of 6 January 1978 "Loi informatique et libertés", and with the General Data Protection Regulation (GDPR), you have the right to access, modify, and delete your personal data when you are a LeanPay customer. You can contact us for this purpose using the following methods:
- Postal address: LeanPay SAS, 65 Avenue Becquart, 59130 Lambersart, France
- Email address: contact@leanpay.fr
Please note that personal data is only collected to serve LeanPay’s legitimate purpose, as described in Article 4. You may object to the use of your data at any time. LeanPay reserves the right to use this data in the context of defending its rights before the relevant courts.
12. Data management in the event of death
You may provide LeanPay with instructions regarding the management, storage, communication and deletion of your personal data in the event of death. These instructions must include all of your personal data and must be registered using a certified digital tool recognised by the CNIL (Commission Nationale de l'Informatique et de Libertés). By sharing these instructions, you consent to their storage, transmission and implementation as specified in the document. You may also designate a person to ensure these instructions are properly applied after your death. This person will be authorised to consult your instructions and request that they be followed. If no one is designated, your heirs will be authorised to access the instructions and ensure their implementation. You may modify or delete your instructions at any time by contacting us using the methods outlined above.
13. Availability of your personal data
You have the right to access the personal data you have provided to us, which includes the data you deliberately shared at the time of your registration and the data generated during your use of the services. This right may be exercised at any time and free of charge. It can be exercised when the account is closed through the customer interface, in order to retrieve and retain your personal data. We will respect your right by sending you all your personal data in a structured format that can be automatically read using current technologies and in a commonly accepted format.
14. File a complaint with a supervisory authority
You may submit a complaint to the supervisory authority competent in your territory, the CNIL (Commission Nationale Informatique et Libertés) in France, if you consider that the methods of collecting and using your personal data described in this document infringe your rights under applicable laws. This request may be made in parallel with another appeal to an administrative or judicial authority.
15. Limitation
You may restrict the collection and use of your personal data in the following cases:
- If, during the registration period, you realise that the personal data provided is inaccurate;
- If the collection and processing of personal data is unlawful and you prefer to restrict its use rather than request its deletion;
- If we no longer need to process your personal data but you would like us to retain it in order to exercise your rights;
- If, during the registration period, you have expressed your wish to object to the collection and use of your personal data.
16. Changes
LeanPay reserves the right to amend all or part of its Privacy Policy. Any changes will apply from the date of publication of the updated Privacy Policy. By continuing to use the website after such changes have been published, you acknowledge and accept the new Privacy Policy. If you do not agree to the new terms, you must stop using the website and services.