Data protection & Security
Last updated: July 2, 2026
Version identifier : data-protection-security-2026-07-03
Effective since July 03, 2026
Technical fingerprint :Show SHA-256
90333eb3a040bcd86e6484b55723b26ddfbee0357596cf309d88e33f1874d0acProtecting personal data and securing information are a priority for Homellya.
The platform is designed and operated in compliance with the General Data Protection Regulation (GDPR — EU 2016/679) and applies privacy by design and privacy by default principles.
1. Scope
This page describes the commitments, measures and practices implemented by Homellya in terms of:
- Personal data protection
- Information system security
- Respect of users’ rights
It applies to all platform users (owners, tenants, organization representatives, administrators).
2. Core GDPR principles
Homellya is committed to the following principles:
- Lawfulness, fairness and transparency
- Specified and legitimate purposes
- Data minimization
- Accuracy and data updates
- Limited retention periods
- Integrity, confidentiality and security
3. Personal data processed
Depending on how the platform is used, Homellya may process in particular:
- Identification data: first name, last name, email address, phone number
- Property-related data: addresses, floor areas, equipment
- Contractual data: leases, rents, due dates, associated documents
- User-related data: roles, permissions, organization
- Technical data: access logs, IP addresses, security events
Data is never resold or used for advertising purposes.
4. Purposes of processing
Data processing is exclusively intended for:
- Property and rental management
- User account and organization management
- Performance of contracts and legal obligations
- Secure communication between authorized users
- Continuous improvement, maintenance and security of the platform
5. Rights of data subjects
In accordance with the GDPR, each user has the following rights:
- Right of access to their data
- Right to rectification
- Right to erasure, within legal limits
- Right to restrict processing
- Right to data portability
- Right to object when applicable
Exercising your rights: any request can be sent to: contact@homellya.com
We will respond within the statutory time limits.
6. Data security and technical infrastructure
Homellya implements appropriate technical and organizational measures to ensure a level of security appropriate to the risks.
Application security
- Application built with the Django framework
- Granular access management by roles and permissions
- Strict data separation by organization (multi-tenant)
- Protection against common vulnerabilities (OWASP)
Authentication and access
- Passwords stored in encrypted form (secure hashing)
- Data access limited to authorized users
- Logging of access and sensitive actions
Data and infrastructure
- PostgreSQL database
- Containerized services via Docker
- Isolated environments (development / production)
- Regular and secure backups
Hosting
Platform data is hosted on infrastructure provided by OVHcloud, located in France within the European Union. Access to the infrastructure is strictly controlled and limited to authorized personnel.
These measures aim to prevent any loss, alteration, disclosure or unauthorized access to data.
7. Processors and service providers
Homellya may use technical service providers acting as processors under the GDPR, in particular for:
- Hosting
- Transactional email delivery
- Payment, billing and subscription management, in particular through Stripe.
- File storage
Each provider is contractually required to comply with:
- Data confidentiality
- High security standards
- The obligations laid down by the GDPR
8. Data transfers outside the EU
No transfer of personal data outside the European Union, nor access from a third country, is carried out without appropriate safeguards in line with the GDPR, including standard contractual clauses where necessary.
9. Documentation and accountability
Homellya applies the accountability principle and maintains:
- A record of processing activities
- Security documentation
- Internal data protection procedures
These elements may be presented to the competent supervisory authority upon request.
10. Data protection contact
Homellya has not appointed a DPO. A data protection contact nevertheless follows GDPR matters and user requests. Contact: contact@homellya.com
11. Supervisory authority
If you believe, after contacting us, that your rights are not being respected, you may lodge a complaint with the competent supervisory authority, in particular the CNIL (French Data Protection Authority).
12. Commitment
Homellya is committed to processing personal data responsibly, securely and in compliance with the GDPR, with a focus on transparency, security and continuous improvement.
Version history
Review previously published versions of this legal document.
- View this version
Version identifier : data-protection-security-2026-07-03
Effective since July 03, 2026
Technical fingerprint :Show SHA-256
90333eb3a040bcd86e6484b55723b26ddfbee0357596cf309d88e33f1874d0ac