Privacy Policy
Last updated: September 28, 2026
Introduction
Cleemo protects personal data in accordance with the General Data Protection Regulation (GDPR) and applicable French law. This policy explains the collection, use, storage and sharing of personal data through cleemo.com and the Cleemo applications.
Data Controller
CLEEMO, SAS, 2 rue du Malsaucy, 90300 Sermamagny, France, is the controller for account administration and operation of the service. For tenant, applicant and other agency records, the landlord or agency determines the purposes of processing and Cleemo processes data on its instructions. Privacy contact: igor@cleemo.com.
Data We Collect
We collect the following categories of personal data: (1) Account data: name, email address, phone number, professional details; (2) Property data: property addresses, unit descriptions, lease terms, rent amounts; (3) Tenant and contact data: names, contact details, identification documents where legally required; (4) Financial data: rent payment history, bank account details for direct debit (processed via certified payment providers); (5) Usage data: log files, IP addresses, browser type, pages visited, actions performed on the platform; (6) Communications: messages exchanged through the platform between landlords, tenants, and service providers.
Purposes of Data Processing
We process your personal data for the following purposes: (1) Providing and managing the Cleemo platform and its features; (2) Managing user accounts, authentication, and access control; (3) Facilitating lease management, rent tracking, and document storage; (4) Processing rent payments and financial transactions; (5) Sending notifications, reminders, and alerts related to your properties and tenancies; (6) Providing customer support and responding to inquiries; (7) Improving our platform through analytics and user feedback; (8) Complying with legal and regulatory obligations applicable to property management in France.
Legal Basis for Processing
We process your personal data on the following legal bases under Article 6 of the GDPR: (1) Performance of a contract (Art. 6(1)(b)): processing necessary to provide the Cleemo service you have subscribed to; (2) Legal obligation (Art. 6(1)(c)): processing required to comply with applicable laws, including accounting, tax, and property law obligations; (3) Legitimate interests (Art. 6(1)(f)): processing for platform security, fraud prevention, and service improvement, where your interests do not override ours; (4) Consent (Art. 6(1)(a)): processing for marketing communications and optional analytics, which you may withdraw at any time.
Data Sharing and Third Parties
Cleemo does not sell personal data. On the demo.cleemo.com page only, and with the consent you give on that page, the advertising measurement events described in Tracking and Usage Statistics (page viewed, demo requested, demo booked) are shared with OpenAI. Demo bookings and their WhatsApp follow-up are handled by Evo Agent (app.evo-agent.ai), our booking tool acting as a processor. Technical recipients include Lamdera (application hosting), Cloudflare R2 (file storage), OpenAI (assistant conversations, drafting, document classification and extraction), Mistral AI (document OCR), Stripe (payments), Resend (transactional email), and the other providers used for features you activate. When the agency uses Hermes through Telegram, its messages and assistant replies pass through Telegram. Authorized workspace members receive data according to their access rights. The Google and AI supplement below explains the specific data sent to each AI provider. Data may also be disclosed where legally required or as part of a business transfer with applicable safeguards.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy, or as required by law. Specifically: account data is retained for the duration of your subscription and for 3 years thereafter for legal purposes; lease and financial records are retained for 10 years as required by French accounting law; communications and support records are retained for 3 years; usage logs are retained for 12 months. When data is no longer needed, it is securely deleted or anonymised. You may request early deletion of your data subject to our legal retention obligations.
Data Security
Cleemo uses TLS for data in transit, access controls by workspace and role, hashed passwords, protected credentials, backups and technical logs. Lamdera hosts the application in Germany, and production Cloudflare R2 document storage uses the EU jurisdiction restriction. Some external service providers may process data outside the EEA as explained below. No system provides absolute security. Personal-data incidents are handled under applicable GDPR notification requirements.
Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data: (1) Right of access (Art. 15): obtain a copy of the personal data we hold about you; (2) Right to rectification (Art. 16): request correction of inaccurate or incomplete data; (3) Right to erasure (Art. 17): request deletion of your data where there is no lawful basis for retention; (4) Right to restriction of processing (Art. 18): request that we limit how we use your data; (5) Right to data portability (Art. 20): receive your data in a structured, machine-readable format; (6) Right to object (Art. 21): object to processing based on legitimate interests; (7) Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing. To exercise these rights, contact us at igor@cleemo.com. We will respond within 30 days. You also have the right to lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés) at www.cnil.fr.
Tracking and Usage Statistics
Cleemo uses its own usage statistics system to improve the platform: anonymous HTTP requests, without third-party cookies, covering event categories, page paths and an anonymous session identifier. This measurement is only activated after your consent, collected through the banner shown on your first visit; you can change your choice at any time through Tracking preferences in the footer. On the demo.cleemo.com page only, and with the separate consent you give on that page, Cleemo uses the OpenAI advertising measurement pixel: OpenAI receives the page view, the demo request and the demo booking, the page URL and technical request information (including IP address and browser). From demo.cleemo.com, the pixel sets two cookies on the cleemo.com domain: __oppref (ad click identifier, 30 days) and __obref (random browser reference, 365 days). That page has no input field of its own: the booking form is served in a separate frame by our booking tool, which the pixel cannot read. Our events contain no contact details and no property or tenant data, and each one requests exclusion from future individual ad personalization. No pixel is loaded before consent, and it is never loaded on other pages of the site or in the iOS and Android apps. You can refuse or withdraw that consent through the page’s “Ad measurement” button, without affecting the booking; withdrawal deletes both cookies. Essential authentication cookies remain necessary.
International Data Transfers
The application backend is hosted by Lamdera in Germany. Both production Cloudflare R2 buckets, for main files and private documents, use the European Union jurisdiction restriction (eu). Other providers, including OpenAI, Google, Stripe, Apple and Telegram, may process data or provide access from outside the EEA for the features described in this policy. International transfers are subject to the applicable safeguards under Chapter V of the GDPR. Information about a specific transfer and its safeguards can be requested at igor@cleemo.com.
Children's Privacy
The Cleemo platform is intended for use by adults (aged 18 and over) and is not directed at children. We do not knowingly collect or process personal data from children under the age of 16. If you believe that we have inadvertently collected data relating to a child, please contact us immediately at igor@cleemo.com and we will promptly delete such data.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make significant changes, we will notify you by email and/or by displaying a prominent notice within the platform at least 30 days before the changes take effect. The updated policy will indicate the date of the last revision at the top of the page. We encourage you to review this Privacy Policy periodically. Your continued use of the platform after the effective date of any changes constitutes your acceptance of the updated policy.
Contact Us / Data Protection Officer
For any questions, requests, or complaints relating to this Privacy Policy or the processing of your personal data, please contact us: By email: igor@cleemo.com — By post: Cleemo SAS, 2 rue du Malsaucy, 90300 Sermamagny, France. We are committed to resolving all privacy-related inquiries within 30 days of receipt. If you are not satisfied with our response, you have the right to file a complaint with the French data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL): Website: www.cnil.fr — Phone: +33 (0)1 53 73 22 22 — Post: CNIL, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.
Optional Google Calendar connection
Cleemo’s calendar works without Google. If an administrator connects Google Calendar, Cleemo receives the authorized account identity (email address and Google identifier), the list of accessible calendars and access roles, and then events and availability from the selected calendar. Synchronized data includes event identifiers, non-private titles, dates, times, time zones and statuses. Event descriptions and attendees are not imported; private or confidential event titles are hidden.
Calendar data is used to select the agency calendar, display appointments and check availability. After user confirmation and an explicit choice to add a Google copy, Cleemo creates the appointment in that calendar. Where Google grants write access, users can update or cancel synchronized appointments and edit or delete imported Google events from Cleemo. Existing Cleemo appointments are not exported automatically, and this integration does not send attendee invitations.
Events from the selected calendar are visible to authorized agency members. Access and refresh tokens remain on Cleemo’s backend and are not sent to the browser or other agencies. The synchronization itself exchanges data with Google and does not invoke an AI model. The separate Hermes and Gmail document-import features described below can process Google data with AI.
The mirror is refreshed for a window of 7 past days and 60 upcoming days; if synchronization fails, the last successful copy is retained. ‘Disconnect from Cleemo’ removes this connection’s tokens and mirror from active state. Appointments created in Cleemo and their synchronization references remain in the agency history under this policy’s retention periods; disconnecting does not delete events at Google. You can also revoke authorization through your Google account’s third-party connections, or request deletion of retained data at igor@cleemo.com, subject to applicable obligations. Backups follow the general retention periods and are not guaranteed to be erased immediately.
Manage my Google account’s third-party connections
Cleemo’s use and transfer of raw, aggregated or derived information received from Google Workspace APIs adheres to the Google Workspace API User Data and Developer Policy, including its Limited Use requirements. This data is not sold, used for advertising, or used to create, train or improve generalized AI or machine-learning models. Human access is limited to the cases permitted by that policy, including explicit user consent, security purposes and legal obligations.
Google Workspace API User Data and Developer Policy
Google data and artificial intelligence
Hermes is an optional agency assistant with a Google authorization separate from calendar synchronization. Gmail messages and Calendar events requested by an authorized user, tool results and conversation context are processed by OpenAI through Codex; replies are delivered through Telegram when that channel is used. Gmail document import sends subjects, senders, short email excerpts and attachment metadata to OpenAI for relevance scoring. Selected PDFs or images are sent to Mistral AI for OCR, and the extracted text is processed by OpenAI for classification and structured extraction. Imported files are stored in Cloudflare R2; retained OCR text can be used later in user-requested document searches by the assistant, subject to workspace access rights.
The default OpenAI connection uses ChatGPT Pro through Cleemo’s self-hosted Codex gateway or directly from Hermes. The account’s model-training setting is disabled. Mistral is used only through its hosted OCR API, on the Free plan, with API training sharing and Labs disabled. These controls exclude new interactions from generalized model training; they are not a Zero Data Retention guarantee. Structured document analysis disables web search and external tools. Hermes does not automatically route web tools through anonymous free-tier providers. Cleemo does not submit Google content as model-training feedback or fine-tuning data. Disconnecting Google stops future authorized access; imported documents and assistant history remain subject to this policy’s retention and deletion provisions. Requests can be sent to igor@cleemo.com.
Hermes transcribes voice messages locally using NVIDIA Parakeet TDT 0.6B v3. This local inference does not transmit audio or Google data to NVIDIA or use it to train NVIDIA models. The resulting text may then be sent to OpenAI as assistant context. The OpenAI and Mistral services themselves are hosted services, not offline inference.
Optional ChatGPT connector
Cleemo works without ChatGPT. If you connect your Cleemo account to ChatGPT, the Cleemo app for ChatGPT can read what your account can read in Cleemo: workspaces, properties, units, leases, rents and payments, contacts and tenants, applications, mandates, sales follow-up, documents and, if you are a member of an agency, the data of that agency your role gives you access to. At your request it can also create, change, send or delete what your account can create, change, send or delete in Cleemo: ChatGPT shows you each change and waits for your confirmation before sending it to Cleemo. Some operations remain reserved to the Cleemo app itself: deleting the account, anything about authentication (password, sign-in email, linking third-party accounts), issuing or revoking access tokens, and platform administration. Technical credentials (tokens, passwords, keys) are masked before anything is sent to ChatGPT. Connections made before 28 September 2026 stay read-only until you renew them.
This data is used for one purpose: answering the questions you ask in ChatGPT and carrying out the changes you request and confirm there. For each request, ChatGPT sends Cleemo the read or the change it needs, and only that information is sent. Cleemo does not receive the content of your conversations with ChatGPT, only the requests addressed to it.
Cleemo's answers are sent to OpenAI (OpenAI Ireland Ltd / OpenAI, L.L.C.), which displays them in your conversation and processes them under its own terms and privacy policy, and according to the settings of your ChatGPT account. The connector is hosted by Cloudflare, Inc.; the service that prepares the requests is hosted by Hetzner Online GmbH, in Germany. Both pass requests and answers along without keeping them.
The connector stores no data from your portfolio. It keeps, at Cloudflare, the email address of the connected account and the Cleemo access token, encrypted: with the access token given to ChatGPT, for one hour; and with the renewal token, for 90 days, a period that starts again at each renewal. A connection request that was not completed is erased after 15 minutes. On Cleemo's side, the access token stays valid until it is revoked.
You can withdraw this access at any time: in Cleemo, under Settings, in the list of active access, where the connection appears under the name “ChatGPT (MCP)”; or in ChatGPT, by disconnecting the Cleemo app. Revoking in Cleemo takes effect immediately. What was already displayed in your conversations remains subject to OpenAI's retention rules.