Privacy Policy
Last updated: 9 July 2026
Clairly is a rental trust and payment-reliability platform for France and the EU. This policy explains what data we process, why, and the rights you have.
1. Who we are
The data controller is Clairly, a SAS with share capital of 100 euros, Lyon RCS 952 573 053, registered office 11 rue Émile Zola, 69002 Lyon.
- Privacy contact: privacy@clairly.co
- Data Protection Officer (DPO): dpo@clairly.co
2. What Clairly is not
Clairly is not a guarantee, an insurance product, a replacement for the rental dossier, a full dossier verification service, a legal authority, a public-sector decision tool, a blacklist, a debt collection product, a surveillance product, or a credit score.
The Clairly Signal is a summary indicator of payment reliability, presented within the Clairly Report. It is not a rating, a judgment, or a decision. It must not be used, on its own, to decide whether to grant or refuse a tenancy (see section 10).
3. What data we process
| Category | Examples |
|---|---|
| Identity and contact | name, email, phone, preferred language |
| Tenancy relationship | tenant–property link, declared rent, relevant lease |
| Payment history | monthly status and per-entry verification level |
| Bank data (open banking) | transactions from selected accounts, processed transiently to identify rent payments |
| Dispute evidence | supporting documents submitted in a dispute |
| Billing | plan, subscription and purchase payment history |
| Security and audit | access logs, IP addresses, consent ledger, hashed share tokens |
Bank transactions unrelated to rent are neither retained nor analysed. Clairly does not analyse spending habits, overall financial health, or any behaviour unrelated to rent.
4. Why, and on what legal basis
Each purpose rests on its own lawful basis — no single basis covers all processing.
| Purpose | Lawful basis |
|---|---|
| Tenant-controlled sharing of the Clairly Report | Consent (Art. 6(1)(a)) |
| Open banking connection (rent verification, Boost import) | Consent, collected separately before each connection |
| Retroactive attachment of pre-consent history (landlord monitoring) | Tenant consent |
| Account creation, delivery and management of the Service | Performance of a contract (Art. 6(1)(b)) |
| Security, fraud prevention, account integrity | Legitimate interest (Art. 6(1)(f)) |
| Accounting and billing obligations | Legal obligation (Art. 6(1)(c)) |
Consent can be withdrawn at any time, without justification; withdrawal does not affect the lawfulness of prior processing. Data is processed for rental payment reliability only — not for credit scoring, unrelated profiling, spending analysis, or marketing reuse.
5. Open banking
- Bank connections run through Powens, an account information service provider (AISP) authorised under PSD2 and supervised by the ACPR, after a Clairly consent screen that is separate from account signup and bank authentication.
- You choose which account(s) are covered. Clairly looks for rental transactions only.
- Boost can import up to 36 months of eligible past rent payment history.
- Under PSD2, bank consent must be renewed every 180 days.
- Raw transaction data is retained only temporarily, to convert identified rent payments into structured entries.
- Landlord-side monitoring reads only the landlord’s own account and matches the declared rent amount; non-matching transactions are not retained.
6. Who can see what
- Landlords and agencies see only the authorised shared report view: monthly payment statuses, the summary signal, history length, per-entry verification level, and dispute flags.
- They cannot see unshared tenancies, bank account details, unrelated transactions, or identity/supporting documents (unless separately and explicitly shared through another valid flow).
- Every share is a deliberate tenant action — never public, never automatic. Share links expire after 30 days unless re-authorised.
- Access is revocable at any time; revocation removes the report from the third party’s dashboard and blocks future access through Clairly.
7. Recipients and processors
Clairly uses the following processors under GDPR Art. 28 agreements:
| Processor | Role | Location / transfer |
|---|---|---|
| Clerk | Account authentication | USA — SCC / DPF |
| Supabase (AWS, EU region) | Database and storage | European Union |
| Powens (Powens SAS, ACPR-supervised AISP, CIB 16948) | Open banking (account aggregation) | European Union |
| Stripe | Subscription and purchase payments | USA — SCC / DPF |
| MailerSend | Transactional email delivery | USA — SCC / DPF |
| Google Analytics | Site audience measurement | USA — SCC / DPF |
| Vercel | Site hosting | USA — SCC / DPF |
| Support & monitoring providers | Customer support and error monitoring | EU / USA |
Where data is transferred outside the EU/EEA, Clairly relies on an adequacy decision, Standard Contractual Clauses (SCC), or the EU–US Data Privacy Framework (DPF) where the provider is certified. No data is sold, and no data is passed to third parties for marketing.
8. Retention
- Account data, structured payment history, and records needed for the Clairly Report are kept for the life of the account, then archived for up to 10 years for evidence, dispute handling, defence of our rights, audit, and accounting and legal obligations.
- Raw open banking transactions are processed transiently and deleted once rent payments are converted into structured entries. Transactions unrelated to rent are not retained.
- After account deletion, Clairly keeps a pseudonymised marker (e.g. a hash of the email address) to prevent fraud — in particular delete-and-recreate cycling intended to erase a payment history. This marker alone cannot reconstruct your profile.
- Billing data is kept 10 years under accounting obligations.
9. Your rights
You can exercise the following rights via privacy@clairly.co:
- Access and copy of your data; export of your Clairly Report and payment history.
- Rectification; the dispute flow also lets you challenge an inaccurate payment record with evidence.
- Erasure, subject to lawfully grounded retention.
- Restriction of processing and objection under GDPR conditions.
- Portability of data you provided.
- Withdrawal of consent at any time (sharing, open banking).
- Post-mortem directives about your data (Art. 85 French Data Protection Act).
- Complaint to the CNIL: www.cnil.fr.
We respond within one month, extendable under GDPR Art. 12(3).
10. Clairly Signal, profiling, and decisions
The Clairly Signal is computed from the structured payment history described above. It may inform the assessment of a rental application, but:
- it is one element of information among others, not a decision;
- the landlord or agency must not base a letting decision on this signal alone and must consider other supporting materials (employment situation, income, guarantor, complete dossier);
- no decision producing legal effects or significantly affecting you is based solely on automated processing — the decision to rent rests with the landlord or agency, who are human;
- any disputed record remains clearly flagged until resolved, through a dispute flow with human review, and is not counted in the Clairly Signal while the dispute is open;
- every dispute resolves to a definite outcome: Amended (the record is corrected) or Confirmed (the record stands).
11. Security
Encryption at rest with our providers, role-scoped access controls, share tokens stored as hashes, access logging, and a consent ledger. In the event of a data breach, the CNIL is notified within 72 hours where legally required, and affected individuals are informed under GDPR Art. 34.
12. Minors
The service is for adults (18+) and is not directed at minors.
13. Changes
Any material change to this policy will be notified with an effective date shown at the top of this page.