Privacy policy
This privacy policy explains how Homellya collects, uses and protects your personal data when you use our website and property management platform.
Version identifier : privacy-2026-07-03
Effective since July 03, 2026
Technical fingerprint :Show SHA-256
2e67d0f98b255e1b710ea8ee6732f6b6c5e13454ac0c209b7ec323a59d2ced501. Data controller
The data controller is: Melocha Web SASU, 9 place Jacques Marette, 75015 Paris, France. You can contact us at: contact@homellya.com.
1.1. Data Protection Officer (DPO)
Homellya has not appointed a DPO. For any questions about your personal data, you can contact us at contact@homellya.com.
2. Data collected
2.1. Data provided by the user
We collect the data you provide directly, in particular when creating your account or using the platform: first name, last name, email address, information relating to your properties and rentals, and billing data where applicable.
2.2. Data collected automatically
When you browse Homellya, certain data is collected automatically: IP address, connection information, browser type and version, pages viewed, visit duration, as well as cookies and technical or analytics trackers. Non-essential cookies, in particular analytics and audience measurement cookies, are only placed with your consent, collected via our cookie consent banner.
2.3. Data sources
- Data you provide directly through forms, account creation or use of the service.
- Technical data generated automatically when you browse or use the platform.
- Where applicable, certain data may be transmitted by partners strictly necessary for the provision of the Service, in particular payment and billing service providers such as Stripe, acting as data processors within the meaning of the GDPR.
3. Purposes of processing
- Provide access to the platform and its features (management of properties, tenants, rents and documents).
- Manage your user account and authentication.
- Provide customer support, handle requests and communicate with you.
- Improve the quality of our services, measure audience and produce statistics, where you have given your consent.
- Comply with our legal, tax and accounting obligations.
4. Legal bases
- Performance of a contract: when processing is necessary to provide the Homellya platform and related services.
- Homellya’s legitimate interests: to secure the platform, prevent fraud and improve our services.
- Compliance with legal obligations: in particular for billing, accounting or dispute management.
- Your consent: for certain optional processing activities, in particular the placement of non-essential cookies (analytics and audience measurement cookies) and marketing communications where required.
5. Recipients of the data
Your data may be shared with service providers strictly necessary for the operation of the service, acting as processors under the GDPR:
- The hosting provider of the platform (for example OVH) for server hosting and maintenance.
- Payment and billing service providers such as Stripe, for the purpose of processing payments, managing subscriptions and issuing invoices.
- Analytics, support or communication tools used for user assistance and service improvement.
- Photon (Komoot) geocoding service, used to provide address suggestions while typing. Requests may include the searched address and technical metadata (for example an IP address) required to operate the service.
- OpenStreetMap (map tiles rendered via Leaflet), used to display a map preview after an address is selected. Loading tiles may trigger technical exchanges with OpenStreetMap servers (for example IP address, user-agent and, depending on your browser, potential third-party cookies).
6. Data retention period
Your data is kept for as long as necessary for the purposes for which it was collected. Your account and associated data are retained for as long as you use the platform. If your account or an organization is deleted, data is deleted or anonymized within a reasonable timeframe, unless legal retention obligations apply. Some billing data may be retained by payment service providers acting as processors for the applicable legal retention periods.
By way of example, we apply the following retention periods:
- Active account data: for the duration of the account’s use, then deleted/anonymized after a deletion request.
- Billing data: up to 10 years (accounting and tax obligations).
- Deleted organization data: deleted/anonymized within a reasonable timeframe, subject to legal obligations.
7. Your rights
In accordance with the General Data Protection Regulation (GDPR), you have the following rights: right of access, rectification, erasure, restriction of processing, objection and data portability. You can exercise these rights by contacting us at: contact@homellya.com. You also have the right to lodge a complaint with the French Data Protection Authority (CNIL): www.cnil.fr.
8. Data security
Homellya implements appropriate technical and organizational measures to protect your data against loss, unauthorized access, disclosure or alteration: encrypted communications (HTTPS), passwords stored in encrypted form, regular backups, internal access control.
9. Data transfers outside the European Union
Where service providers located outside the European Union are involved or may access data from a third country (including Stripe, Google or Microsoft), Homellya ensures that appropriate safeguards are in place, such as standard contractual clauses adopted by the European Commission.
10. Automated decisions
Unless otherwise stated, Homellya does not carry out automated decision-making producing legal or similarly significant effects within the meaning of the GDPR.
11. Changes to this privacy policy
This privacy policy may be updated to reflect legal, technical, functional or organizational developments at Homellya.
In the event of a significant change concerning the processing of your personal data, Homellya will inform you by an appropriate means, including by email or by notification in your user area.
The applicable version is the one indicated at the top of this page. Previously published versions can be viewed in the version history.
Version history
Review previously published versions of this legal document.
- View this version
Version identifier : privacy-2026-07-03
Effective since July 03, 2026
Technical fingerprint :Show SHA-256
2e67d0f98b255e1b710ea8ee6732f6b6c5e13454ac0c209b7ec323a59d2ced50