Data protection & Security

Last updated: July 2, 2026

Version identifier : data-protection-security-2026-07-03

Effective since July 03, 2026

Technical fingerprint :Show SHA-25690333eb3a040bcd86e6484b55723b26ddfbee0357596cf309d88e33f1874d0ac

Protecting personal data and securing information are a priority for Homellya.

The platform is designed and operated in compliance with the General Data Protection Regulation (GDPR — EU 2016/679) and applies privacy by design and privacy by default principles.

1. Scope

This page describes the commitments, measures and practices implemented by Homellya in terms of:

  • Personal data protection
  • Information system security
  • Respect of users’ rights

It applies to all platform users (owners, tenants, organization representatives, administrators).

2. Core GDPR principles

Homellya is committed to the following principles:

  • Lawfulness, fairness and transparency
  • Specified and legitimate purposes
  • Data minimization
  • Accuracy and data updates
  • Limited retention periods
  • Integrity, confidentiality and security

3. Personal data processed

Depending on how the platform is used, Homellya may process in particular:

  • Identification data: first name, last name, email address, phone number
  • Property-related data: addresses, floor areas, equipment
  • Contractual data: leases, rents, due dates, associated documents
  • User-related data: roles, permissions, organization
  • Technical data: access logs, IP addresses, security events

Data is never resold or used for advertising purposes.

4. Purposes of processing

Data processing is exclusively intended for:

  • Property and rental management
  • User account and organization management
  • Performance of contracts and legal obligations
  • Secure communication between authorized users
  • Continuous improvement, maintenance and security of the platform

5. Rights of data subjects

In accordance with the GDPR, each user has the following rights:

  • Right of access to their data
  • Right to rectification
  • Right to erasure, within legal limits
  • Right to restrict processing
  • Right to data portability
  • Right to object when applicable

Exercising your rights: any request can be sent to: contact@homellya.com

We will respond within the statutory time limits.

6. Data security and technical infrastructure

Homellya implements appropriate technical and organizational measures to ensure a level of security appropriate to the risks.

Application security

  • Application built with the Django framework
  • Granular access management by roles and permissions
  • Strict data separation by organization (multi-tenant)
  • Protection against common vulnerabilities (OWASP)

Authentication and access

  • Passwords stored in encrypted form (secure hashing)
  • Data access limited to authorized users
  • Logging of access and sensitive actions

Data and infrastructure

  • PostgreSQL database
  • Containerized services via Docker
  • Isolated environments (development / production)
  • Regular and secure backups

Hosting

Platform data is hosted on infrastructure provided by OVHcloud, located in France within the European Union. Access to the infrastructure is strictly controlled and limited to authorized personnel.

These measures aim to prevent any loss, alteration, disclosure or unauthorized access to data.

7. Processors and service providers

Homellya may use technical service providers acting as processors under the GDPR, in particular for:

  • Hosting
  • Transactional email delivery
  • Payment, billing and subscription management, in particular through Stripe.
  • File storage

Each provider is contractually required to comply with:

  • Data confidentiality
  • High security standards
  • The obligations laid down by the GDPR

8. Data transfers outside the EU

No transfer of personal data outside the European Union, nor access from a third country, is carried out without appropriate safeguards in line with the GDPR, including standard contractual clauses where necessary.

9. Documentation and accountability

Homellya applies the accountability principle and maintains:

  • A record of processing activities
  • Security documentation
  • Internal data protection procedures

These elements may be presented to the competent supervisory authority upon request.

10. Data protection contact

Homellya has not appointed a DPO. A data protection contact nevertheless follows GDPR matters and user requests. Contact: contact@homellya.com

11. Supervisory authority

If you believe, after contacting us, that your rights are not being respected, you may lodge a complaint with the competent supervisory authority, in particular the CNIL (French Data Protection Authority).

12. Commitment

Homellya is committed to processing personal data responsibly, securely and in compliance with the GDPR, with a focus on transparency, security and continuous improvement.

Version history

Review previously published versions of this legal document.

  • View this version

    Version identifier : data-protection-security-2026-07-03

    Effective since July 03, 2026

    Technical fingerprint :Show SHA-25690333eb3a040bcd86e6484b55723b26ddfbee0357596cf309d88e33f1874d0ac