Personal Data
The Leasys Group has implemented a personal data management policy designed to ensure processing complies with applicable regulations:
- European Regulation No. 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation or GDPR).
- Applicable local laws on the protection of personal data.
This notice describes our rules for protecting information relating to our prospects, customers, our customers' employees, partners, our partners' employees, students or independent candidates, and visitors to our websites.
PROTECTION AND MANAGEMENT OF PERSONAL DATA
1. DATA PROCESSING RESPONSIBILITY
Ø LEASYS France is responsible for processing personal data provided in the context of:
- A request for information,
- A quote,
- An online order (depending on the country),
- The day-to-day management of your contracts and services,
- Submitting an application for an internship or job offer.
Ø LEASYS France disclaims all liability in the event of disclosure of information to third parties outside the strict framework of using its web spaces or those of its partners. It is therefore your responsibility to take all necessary precautions to ensure that you avoid any errors or destructive elements such as viruses.
2. APPROPRIATE, RELEVANT, AND LIMITED DATA COLLECTION
To establish and maintain our relationship, we will collect the following data directly from you:
- Identification: surname, first name, nationality, signature (or signature authorization), intra-community VAT number, etc.
- Contact: postal address, email, telephone number, etc.
- Personal: marital status, number of children, household composition, etc.
- Professional: education, studies, employer, job title, etc.
- Economic and Financial: bank details, IBAN, creditworthiness, tax identification number, tax status, country of residence, etc.
- Browsing data on our websites or applications: cookies, IP address, connection and browsing data, etc.
- Your habits and preferences through the use of our products and services or your interactions with us.
- To verify that you are authorized to drive, we may ask for your driver's license. • Where permitted by local law, we may use a provider specializing in facial recognition technology to identify you in certain cases, such as for electronic signatures. As this is considered sensitive data, your consent will be required by this provider if you select this type of authentication. Their data protection policy will be available on their website (https://www.docusign.com/privacy).
• We may also collect data about other individuals indirectly because they have a connection to you (some will be informed by us, others will need to be informed by you):
- Guarantors or sureties;
- Heirs and beneficiaries in the event of death;
- For legal entities: legal representatives and authorized persons, beneficial owners, and shareholders;
- Employees or drivers (not signatories to the lease agreement)
We may also collect some of the technical and/or operational data from the vehicle we lease to you ("long-term lease") for our use or yours, including mileage, accident reports, geolocation (this feature can be deactivated), and maintenance. This data is used for the following purposes: contract execution, vehicle management and maintenance, claims prevention and analysis, and responding to requests from the relevant judicial or administrative authorities.
3. PROCESSING AND PURPOSES
Our data processing is lawful, fair, and transparent. The associated purposes are specific, explicit, and legitimate. The list below is not exhaustive and may change depending on legal requirements or our industry.
Ø Based on the contractual agreement (prospect) or during the performance of the contractual relationship (customer)
- When reviewing your long-term lease (LLD) application/renewal, automated processing may be carried out by our banking intermediary or any other intermediary used for this purpose (scoring or pre-scoring). One of these processes uses an artificial intelligence tool that may request your prior consent to run.
These are decision-making aids: human intervention is planned in the final decision-making process.
You have the right to obtain an explanation of the decision and to contest it by requesting a review.
- You can subscribe to additional services or certain standalone services (without a long-term lease agreement).
- All operations related to managing our relationship, from pre-contractual agreement to vehicle return.
- Management of amicable and legal debt recovery and, more generally, any necessary legal or extrajudicial action related to the execution of the lease agreement.
Ø Based on legal and regulatory obligations
We use some of your data to fulfill certain legal obligations, either independently or in conjunction with our banking intermediary:
- Prevention and combating of money laundering and terrorist financing. We must comply with regulations regarding international sanctions and embargoes. This requires us to identify you and verify your identity within the framework of the lease agreement and at each renewal.
- Leasys and/or its financial intermediaries/partners may consult regulatory files when reviewing your long-term lease application.
- In accordance with our legal obligations, we are also required to inform certain organizations in the event of a significant payment incident (e.g., the Bank of France or the FIP).
- In certain cases, strictly governed by law, we may be required to disclose certain information to respond to an official request from a competent judicial, criminal, tax, or administrative authority.
Ø Based on our legitimate interest (balanced with the protection of your interests and rights, and taking into account your prior consent according to the country and your status as a natural or legal person):
- We use some of your personal data to manage our customer relationship:
o Improving the quality of our products or services
o Conducting satisfaction or opinion surveys (customer, prospect, etc.), both internally and externally (https://fr.legal.trustpilot.com/for-reviewers/end-user-privacy-terms). • Improving the training of our advisors (through telephone monitoring or recording of your conversations), tracking your routine or specific requests, and improving our processes.
• Preparing reports, studies, statistics, and audits to monitor our business and our obligations to our shareholders.
- We also use your data to improve:
- The management, prevention, and detection of internal fraud.
- Risk and compliance management.
- We may share certain information with trusted third parties (banks and financial institutions) and during the sale of receivables or securitization transactions (Securitization involves transforming illiquid assets, such as receivables, into financial securities that are easily traded on the markets).
• Based on your consent (or that of your employees/drivers), which you can withdraw at any time (opt-in or opt-out depending on the country and your status as an individual/legal entity):
- We may conduct electronic marketing communications (email and SMS).
- We may send you offers for products or services from our company, the shareholders of our group's holding company (Leasys SAS), namely: Crédit Agricole Consumer Finance SA (trading as "Crédit Agricole Personal Finance & Mobility") and Stellantis NV, or from some of our partners.
- We may also invite you to participate in contests or promotional offers.
• Based on our legitimate interest and your consent:
- Call center management (providing a telephone service to our customers for management purposes and the performance of the contract)
- Websites and cookies (certain information is collected using cookies that allow you to have a smoother experience and improve your browsing experience, combat fraud, and analyze the performance of our websites and services);
- Profiling (settings to allow us to better understand your profile and interests, in particular to personalize your experience when using our websites and services, as well as to tailor marketing and remarketing activities to your needs and interests).
Ø Based on the protection of your vital interests:
We may use your information to contact you if there are urgent safety or product recall notices to communicate to you (for example, in conjunction with a manufacturer recall, which may also request your contact information on this basis) or if we reasonably believe that processing your information will prevent or reduce any potential harm to you. It is in your vital interests that we use your privacy information in this way.
4. DATA RETENTION PERIODS
Ø We do not retain your personal data longer than necessary for the purposes for which it was obtained, unless we are legally obligated to retain it for a longer period or are authorized to do so if there is a legal need to do so.
Ø Information provided on the website https://www.clickar.com/ is retained for a period of three (3) to six (6) months, depending on the process used by the client/prospect/candidate.
Ø Information provided on the website https://areaclienti.leasys.com/MyLeasys/login.jsp is retained for a period of three (3) to five (5) years, depending on the data.
Ø Data collected during a quote request that does not result in a signed contract is retained for six (6) months.
• Personal data of a prospective client that may be used for marketing purposes is retained for three (3) years for business clients.
• Certain data collected under a signed lease agreement is retained for ten (10) years to ensure compliance with accounting obligations. This period may be extended until all legal remedies have been exhausted in the event of a dispute.
5. THIRD PARTIES INVOLVED IN PROCESSING
In some cases, Leasys shares your personal data with third parties who are independent or jointly appointed "data processors." Only the data strictly necessary for these third parties to perform their tasks will be shared. Leasys France may share data with:
Ø other divisions within Leasys S.p.A. and its subsidiaries (including Leasys France), as well as with the group's holding company "Leasys SAS," its shareholders, Crédit Agricole Personal Finance SA (Crédit Agricole Personal Finance & Mobility), Stellantis NV, and certain of their respective entities/brands, when necessary for the performance of a contract with you or for the pursuit of legitimate business interests (consent, contract, and legitimate interest);
Ø dealers or intermediaries from their distribution network or ours (consent, contract, and legitimate interest);
• If we suspect a violation of third-party rights, punishable offenses, or abuse, we may provide personal data to third parties with a legitimate interest in doing so, to supervisory authorities, or to investigative bodies (legal obligation, protection of your vital interests and those of another natural person);
• With parties who assist Leasys France in providing its services and are not data processors. For example, accountants and legal advisors (legal obligation, legitimate interest);
• With our Data Processors: external entities to whom we delegate certain processing activities. For example, security system providers, accounting and other consultants, data hosting providers, banks, insurance companies, etc. We have signed agreements with each of our Data Processors to ensure that your data is processed with appropriate safeguards and only according to our instructions (contract, legitimate interest);
• with parties that assist Leasys France in deploying marketing activities: monitoring our service quality or partnerships, or for sales prospecting purposes (where applicable, your prior consent will have been obtained, legitimate interest);
• with system administrators: our employees or those of the Data Processors to whom we have delegated the management of our IT systems and who are therefore able to access, modify, suspend, or limit the processing of your Data. These individuals have been selected, appropriately trained, and their activities are monitored by systems that they cannot modify, as required by the provisions of our competent supervisory authority (contract, legitimate interest);
• with so-called "subcontractors" (for example, hosting providers, software suppliers, outsourced customer service, or parties that organize or carry out actions and research for Leasys France). Leasys France is required to enter into a subcontracting agreement.
6. TRANSFER OF DATA OUTSIDE THE EUROPEAN ECONOMIC AREA
Ø Your data will not be transferred to a third country or international organization, except in exceptional and strictly necessary circumstances.
Ø If necessary, for technical or operational reasons, the same data may be processed in countries located outside the European Union, provided that there is an adequacy decision from the European Commission (List regularly updated by the supervisory authorities and available on their websites).
Ø In the absence of such a decision, any transfer of personal data to third countries will only be possible if adequate contractual or legal certainty guarantees, including the standard contractual clauses adopted by the European Commission ((EU) 2021/914), are provided by the data controllers and processors concerned.
7. LINKS TO THIRD-PARTY WEBSITES
Third-party websites, accessible via hyperlinks or references, are the sole responsibility of those third parties. The Company disclaims all liability regarding the request for or provision of personal data to third-party websites.
We advise you to consult the privacy policy of the relevant third party for information on how they handle personal data.
8. MARKETING, PROFILING, AND COOKIES
Ø Leasys uses cookies (small text files that are placed on your computer and stored for a maximum of thirteen (13) months). Our cookie policy is available in the website footer.
The minimum (technically necessary) data is used to ensure the proper functioning of the website and to identify fraudulent or repeated login attempts in order to protect the login system against misuse.
Ø Our website uses Google Analytics 4, a web analytics service provided by Google Inc. ("Google"). Google Analytics 4 uses cookies to help analyze website usage. The information generated by a cookie about your use of the website is transmitted to and stored by Google (https://support.google.com/analytics/answer/12017362?sjid=15918576281740044030-EU).
Subject to your consent, we use this information to:
- Maintain an up-to-date record of how you use the website;
- Compile reports on website activity for Leasys France;
- Offer other services related to website activity and internet usage.
You can refuse the use of cookies on your first visit (or each time you visit in private browsing mode) or modify your consent in the "Manage my settings" section of our cookie policy.
9. INTERACTION WITH SOCIAL MEDIA
Ø Customer Support via Social Media
- You can also contact us through our social media channels. For example, if you send us or post a message on our social media pages, we may use the information in your message or post to contact you regarding your question/request. To provide you with the requested assistance, we may ask you to provide additional information via direct or private message, such as details about the problem, your name, email address, vehicle identification number (VIN), phone number, location (city/country), and/or the make, model, and year of your vehicle. The information you provide will not be used for direct marketing purposes; market research aimed at improving services and products will only be conducted using aggregated (anonymous) data.
- Please note that you must not include sensitive data (such as information about racial or ethnic origin, political opinions, religious or philosophical beliefs, or health) in your message. When you post a message in the public area of a social network, anyone can read it.
Ø Links to social networks
Our websites may include links to social networks.
- To protect your personal data when you visit our website, we do not use social plugins. Instead, HTML links are integrated into the website, which allows for easy sharing on social networks. The integration of such a link prevents a direct connection to the various social network servers when a page on our website is opened. By clicking on one of the buttons, a window opens in the browser and directs the user to the website of the relevant social network where (after logging in) they can, for example, use the "Like" or "Share" button.
- For more information on the purpose and scope of data processing and the subsequent use of your personal data by social networks and their websites, as well as your rights and the available settings to protect your privacy, please refer to the data protection policies of each social network.
YouTube: https://www.google.de/intl/de/policies/privacy/
LinkedIn: https://www.linkedin.com/legal/privacy-policy
10. EXERCISING YOUR RIGHTS
In accordance with applicable regulations, you may exercise certain rights with our services, within the limits permitted by law:
Rights | Description | Article RGPD |
Information and access* | You can obtain information regarding the processing of your personal data, as well as a copy of it. Nous vous fournirons les renseignements sur les finalités des traitements, les catégories de données traitées, les destinataires, leur période de conservation, vos droits de rectification, de suppression ou de restriction des données consultées, le cas échéant. | 13 & 15 |
Rectification | You can have your data corrected when it is incorrect, outdated, or incomplete. | 16 |
Erasure (right to be forgotten) | You can request the deletion of your data. | 17 |
Limitation of treatment | You can request the limitation of a treatment. | 18 |
Portability | You can request the portability of your data to another data controller. This copy must be in a structured and machine-readable format. | 20 |
Opposition | You have the right to object to processing (profiling, for example) for reasons relating to your particular situation. | 21 |
Review of your consents | You can review your consents at any time, including when this review is automated in our processes. | 7 |
* In accordance with local regulations concerning the fight against money laundering and terrorist financing, we are prohibited from giving you direct access to your personal data processed for this purpose. In this case, you must exercise your right of access with the French Data Protection Authority (CNIL), which will then contact us.
To exercise any of the rights described above, you may, at any time, without providing a reason and free of charge, send your request to the following email address: dpo-france@leasys.com. You will be asked to confirm your identity by providing certain information or a copy of official documents.
You also have the right to lodge a complaint with the CNIL: 3, place de Fontenoy – TFSA 80715 – 75334 PARIS CEDEX 07; www.cnil.fr or to avail yourself of the remedies provided by applicable law.
11. PROTECTION
We have implemented appropriate technical and organizational measures to protect your personal data from unauthorized or unlawful processing, and from loss, destruction, damage, alteration, or disclosure.
Our information system security policy is available upon request.
12. CHANGES TO THIS PRIVACY POLICY
We reserve the right to unilaterally modify or supplement this privacy policy. We advise you to consult our privacy policy regularly.
This privacy policy was last updated in September 2025.
13. CONTACTING LEASYS FRANCE
For questions or comments regarding this privacy policy or the processing of personal data, you can contact us by mail:
Leasys France
Attn: Data Protection Officer
43 Rue Jean Pierre Timbaud
CS 30183
78300 POISSY
or by email: dpo-france@leasys.com