Skip to main content

Privacy Policy

Last updated: 9 July 2026

Clairly is a rental trust and payment-reliability platform for France and the EU. This policy explains what data we process, why, and the rights you have.

1. Who we are

The data controller is Clairly, a SAS with share capital of 100 euros, Lyon RCS 952 573 053, registered office 11 rue Émile Zola, 69002 Lyon.

  • Privacy contact: privacy@clairly.co
  • Data Protection Officer (DPO): dpo@clairly.co

2. What Clairly is not

Clairly is not a guarantee, an insurance product, a replacement for the rental dossier, a full dossier verification service, a legal authority, a public-sector decision tool, a blacklist, a debt collection product, a surveillance product, or a credit score.

The Clairly Signal is a summary indicator of payment reliability, presented within the Clairly Report. It is not a rating, a judgment, or a decision. It must not be used, on its own, to decide whether to grant or refuse a tenancy (see section 10).

3. What data we process

CategoryExamples
Identity and contactname, email, phone, preferred language
Tenancy relationshiptenant–property link, declared rent, relevant lease
Payment historymonthly status and per-entry verification level
Bank data (open banking)transactions from selected accounts, processed transiently to identify rent payments
Dispute evidencesupporting documents submitted in a dispute
Billingplan, subscription and purchase payment history
Security and auditaccess logs, IP addresses, consent ledger, hashed share tokens

Bank transactions unrelated to rent are neither retained nor analysed. Clairly does not analyse spending habits, overall financial health, or any behaviour unrelated to rent.

5. Open banking

  • Bank connections run through Powens, an account information service provider (AISP) authorised under PSD2 and supervised by the ACPR, after a Clairly consent screen that is separate from account signup and bank authentication.
  • You choose which account(s) are covered. Clairly looks for rental transactions only.
  • Boost can import up to 36 months of eligible past rent payment history.
  • Under PSD2, bank consent must be renewed every 180 days.
  • Raw transaction data is retained only temporarily, to convert identified rent payments into structured entries.
  • Landlord-side monitoring reads only the landlord’s own account and matches the declared rent amount; non-matching transactions are not retained.

6. Who can see what

  • Landlords and agencies see only the authorised shared report view: monthly payment statuses, the summary signal, history length, per-entry verification level, and dispute flags.
  • They cannot see unshared tenancies, bank account details, unrelated transactions, or identity/supporting documents (unless separately and explicitly shared through another valid flow).
  • Every share is a deliberate tenant action — never public, never automatic. Share links expire after 30 days unless re-authorised.
  • Access is revocable at any time; revocation removes the report from the third party’s dashboard and blocks future access through Clairly.

7. Recipients and processors

Clairly uses the following processors under GDPR Art. 28 agreements:

ProcessorRoleLocation / transfer
ClerkAccount authenticationUSA — SCC / DPF
Supabase (AWS, EU region)Database and storageEuropean Union
Powens (Powens SAS, ACPR-supervised AISP, CIB 16948)Open banking (account aggregation)European Union
StripeSubscription and purchase paymentsUSA — SCC / DPF
MailerSendTransactional email deliveryUSA — SCC / DPF
Google AnalyticsSite audience measurementUSA — SCC / DPF
VercelSite hostingUSA — SCC / DPF
Support & monitoring providersCustomer support and error monitoringEU / USA

Where data is transferred outside the EU/EEA, Clairly relies on an adequacy decision, Standard Contractual Clauses (SCC), or the EU–US Data Privacy Framework (DPF) where the provider is certified. No data is sold, and no data is passed to third parties for marketing.

8. Retention

  • Account data, structured payment history, and records needed for the Clairly Report are kept for the life of the account, then archived for up to 10 years for evidence, dispute handling, defence of our rights, audit, and accounting and legal obligations.
  • Raw open banking transactions are processed transiently and deleted once rent payments are converted into structured entries. Transactions unrelated to rent are not retained.
  • After account deletion, Clairly keeps a pseudonymised marker (e.g. a hash of the email address) to prevent fraud — in particular delete-and-recreate cycling intended to erase a payment history. This marker alone cannot reconstruct your profile.
  • Billing data is kept 10 years under accounting obligations.

9. Your rights

You can exercise the following rights via privacy@clairly.co:

  • Access and copy of your data; export of your Clairly Report and payment history.
  • Rectification; the dispute flow also lets you challenge an inaccurate payment record with evidence.
  • Erasure, subject to lawfully grounded retention.
  • Restriction of processing and objection under GDPR conditions.
  • Portability of data you provided.
  • Withdrawal of consent at any time (sharing, open banking).
  • Post-mortem directives about your data (Art. 85 French Data Protection Act).
  • Complaint to the CNIL: www.cnil.fr.

We respond within one month, extendable under GDPR Art. 12(3).

10. Clairly Signal, profiling, and decisions

The Clairly Signal is computed from the structured payment history described above. It may inform the assessment of a rental application, but:

  • it is one element of information among others, not a decision;
  • the landlord or agency must not base a letting decision on this signal alone and must consider other supporting materials (employment situation, income, guarantor, complete dossier);
  • no decision producing legal effects or significantly affecting you is based solely on automated processing — the decision to rent rests with the landlord or agency, who are human;
  • any disputed record remains clearly flagged until resolved, through a dispute flow with human review, and is not counted in the Clairly Signal while the dispute is open;
  • every dispute resolves to a definite outcome: Amended (the record is corrected) or Confirmed (the record stands).

11. Security

Encryption at rest with our providers, role-scoped access controls, share tokens stored as hashes, access logging, and a consent ledger. In the event of a data breach, the CNIL is notified within 72 hours where legally required, and affected individuals are informed under GDPR Art. 34.

12. Minors

The service is for adults (18+) and is not directed at minors.

13. Changes

Any material change to this policy will be notified with an effective date shown at the top of this page.