PERSONAL DATA NOTICE

 

Leasys Group has put in place a policy for the management of personal data to ensure that it is processed in accordance with the applicable regulations:

-       European Regulation No 2016/679 of 27 April 2016 on the protection of individuals regarding the processing of personal data and the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation or GDPR hereafter).

-       All data privacy law and regulation implemented at country level.

This privacy policy explains our practices in relation to the personal data of customers, users and visitors of our website.

 

PERSONAL DATA PROTECTION AND MANAGEMENT

 

1.    TREATMENT RESPONSIBILITY 

Ø Leasys Mobility is responsible for the processing of personal data communicated in connection with the use of the website or the Customer Area. 

Ø LEASYS Mobility disclaims all liability for the disclosure of information to third parties and outside the strict framework of the use of its web spaces or those of its partners. It is therefore your responsibility to take all necessary precautions to ensure that you avoid any errors or elements of a destructive nature such as viruses.

 

2.    ADEQUATE, RELEVANT AND LIMITED DATA COLLECTION

Ø       To establish and maintain our relationship, we will collect your data directly from you:

-       Identification: name, first name, nationality, signature (or delegation of signature), civil identification number, VAT number.

-       Contact: postal address, email, telephone.

-       Personal: marital status, number of children, household composition.

-       Professionals: training, studies, employer, job.

-       Economic and Financial: bank details, IBAN, solvency, tax identification, tax status, country of residence.

-       From browsing our sites or applications: cookies, IP address, login and navigation data.

-       Your habits and preferences using our products and services or your contacts with us.

-       To verify that you are well-qualified to drive, we can ask for your driver's license. 

Ø       When authorized by local law, we may call upon a provider with expertise in facial recognition technologies to identify you in certain cases, such as electronic signature. As part of sensitive data, your consent will be required by this provider if you select this type of authentication. Its data protection charter will be available on its website.

Ø       We can also collect data about other people indirectly because they are related to you (some will be informed by us, others will have to be informed by you) such as, in case of legal persons, data from legal representatives and authorized persons, beneficial owners and shareholders.

 

3.    TREATMENTS AND FINALITIES

Ø Our treatments are lawful, fair and transparent. The associated purposes are defined, explicit and legitimate. The list below is not exhaustive and may change as a result of changes in legislation or our business line.

- Evaluation and Identification of the Customer for the purposes of the Sales Contract,

- sales and management of the contractual relationship with car dealers and merchants (B2B and, when applicable, B2C),

- Auctions (B2B),

- Management of the contractual relationship with retail trade (B2C and B2B), 

- Pick-up Services

Ø Based on compliance with legal obligations

- Defleeting

Ø Based on compliance with legal obligations and Legitimate Interest

- Compliance with legal obligations, namely in terms of corruption, money laundering and sanctions and embargoes

Ø Based on consent

- Commercial purposes, such as sending advertising communications, marketing, newsletters and/or holding events

 

 

4.    DEADLINE FOR CONSERVATION

Ø       The data will be retained for the period of time required by law or for as long as is necessary to fulfil the purposes for which they were collected. In situations where the data are required to demonstrate compliance with legal obligations, they may be retained until the expiry of the applicable statutory limitation period.The information provided on the website is kept for a period of three (3) months for a information request and 10 years for brokers which create their profiles and buy some cars.

The data collected under the purchase and sale agreement entered into with the customer is kept for ten (10) years from the contract ending for good accounting and fiscal. This time limit may be extended until the remedies are exhausted in the case of a dispute.

 

 

5.    THIRD PARTIES INVOLVED IN THE TREATMENT

In some cases, Leasys communicates your personal data to third parties who are independent or attached "data managers". Only data that is strictly necessary to fulfill the tasks of such third parties will be transmitted. Leasys can share data with:

Ø       other divisions within Leasys S.p.A. and its shareholders, Crédit Agricole Personal Finance & Mobility and its shareholders, Stellantis NV and its shareholders, for the performance of a contract with you or for justified commercial interests (consent, contract and legitimate interest);

Ø       dealers or intermediaries from their brand/distribution network or from our broker (consent, contract and legitimate interest);

Ø        if we suspect a violation of third parties’ rights, punishable acts or abuse, we may provide personal data to third parties who have a legitimate interest in this, to supervisory authorities or administrative or judicial authorities (legal obligation, protection of your vital interests and those of another natural person);

Ø       parties that assist Leasys in the course of its service and are not subcontractors. For example, accountants and legal advisers, banks, insurance companies and car manufacturers (legal obligation, legitimate interest);

Ø       parties that assist Leasys in the deployment of marketing activities: monitoring of our quality of service or partnerships or for commercial purposes (your consent will have been required beforehand, legitimate interest);

Ø       system administrators: our employees or those of Data Processors to whom we have delegated the management of our computer systems and who are therefore able to access, modify, suspend or limit the processing of your Data. These subjects have been selected, adequately trained and their activities are followed by systems which they cannot modify, as provided for by the provisions of our Competent Control Authority (contract, legitimate interest);

Ø       our Data Processors: 

-       external subjects to which we delegate certain treatment activities, as, for example, maintenance workshops, credit and vehicle external collections and recovery companies; towing companies, etc. We have signed agreements with each of our Data Processors to ensure that your data is processed with appropriate safeguards and only according to our instructions (contract);

-       so-called “service providers” (e.g. security system providers, data hosting providers, software providers, or parties that organize or execute actions and research for Leasys). Based on a legitimate interest and, whenever applicable, a contract is also signed with those service providers. (legitimate interest; contract, whenever applicable)

 

6.    DATA TRANSFER OUTSIDE THE EUROPEAN ECONOMIC SPACE

Ø       Your data will not be transferred to a third country or an international organization, except in exceptional and strictly necessary cases.

Ø       If necessary, for technical or operational reasons, the same data may be processed in countries outside the European Union, provided that there is a decision by the European Commission on the adequacy of the data (List regularly updated by the supervisory authorities and available on their websites).

Ø       In the absence of this, any transfer of personal data to third countries will only be possible if adequate contractual or legal certainty, including standard contractual clauses adopted by the European Commission ((EU) 2021/914), are provided by the holders and the officials concerned.

 

7.    LINKS TO THIRD PARTY WEBSITES

Third-party websites, which are accessible through hyperlinks or a reference, are the responsibility of these third parties. Leasys assumes no responsibility for the request or supply of personal data to third party websites.

We advise you to consult the privacy statement of the third party concerned for information on how the third party manages the personal data.

 

8.    MARKETING, PROFILING AND COOKIES

Leasys Mobility may collect data through cookies (small text files that are placed on your computer and stored up) to improve the user's browsing experience. Our cookie policy is available on the website. 

The purpose of the minimum data (technically necessary) is to enable the site to function properly and to identify fraudulent or repeated attempts at connection in order to protect the connection system from misuse.

Ø       Our website uses Google Analytics 4, a web analysis service offered by Google Inc. ("Google"). Google Analytics 4 uses cookies to help analyze the use of the website. Information generated by a cookie about the use of the website is transferred to Google and recorded by Google (https://support.google.com/analytics/answer/12017362?sjid=15918576281740044030-EU)

Ø Subject to your consent, we use this information to:

o  Maintain the way you use the website;

o  Prepare reports on the activity of the website for Leasys;

o  Offer other services related to the activity of the website and the use of the Internet.

For more details you can consult our Cookies Policy available at Clickar Business

Ø You can refuse to use cookies on your first login (or every private login) or change your consent in the "Manage my settings" tab available in our cookie policy.

 

9.    INTERACTION WITH SOCIAL NETWORKS

Ø       Customer support via social media

o  You can also contact us via our social media channels. For example, if you send us or post a message on our social media pages, we may use the information contained in your message or publication to contact you about the question/request issued. In order to provide you with the assistance requested, we may ask you to provide, by direct or private message, additional information such as details of the problem, your name, e-mail address, your phone, location (city/country) plate, identification number (VIN) and/or the vehicle's brand, model and year. The information you provide to us will not be used for direct marketing purposes; market studies to improve services and products will only be carried out on the basis of aggregated (anonymous) data.

o  Please note that you should not transmit sensitive data (such as information on racial or ethnic origin, political opinions, religious or philosophical beliefs, or health) in your message. When you post a message about the public space of a social network, everyone can read it.

Ø        

10. EXERCISE YOUR RIGHTS

In accordance with the regulations in force you may exercise certain rights with our services, within the limits permitted by the regulations:

Rights

Description

GDPR Article

Information and access*

You can obtain information about the processing of your personal data, as well as a copy of it. 

We will provide you with information on the purposes of the processing, the categories of data processed, the recipients, their retention period, your rights to correct, delete or restrict the data consulted, if applicable.

13 & 15

Rectification

You can have your data corrected when it is incorrect or more up-to-date or incomplete.

16

Erasure (right to be forgotten)

You can request the deletion of your data.

17

Processing Limit

You can request a treatment limitation.

18

Portability

You can request portability of your data to another processor. This copy must be in a structured format and usable by a machine.

20

Opposition

You can oppose to a treatment (for example profiling) for reasons related to your particular situation.

21

Review of your consent

You can review your consent at any time, without compromising the lawfulness of the processing up to that moment.

7

* Where applicable by local regulation, the anti-money laundering and anti-terrorist financing regulations which prohibit us from giving you direct access to your personal data processed for this purpose. In this case, you must exercise your right of access to the local Authority which will ask us.

 

Ø       For any exercise of the rights set out above, you may at any time, without reason or charge, send your request to the following email below indicated. You will be asked to confirm your identity by providing certain information or a copy of official documents.

Ø       You also have the right to file a complaint with the Comissão Nacional de Proteção de Dados or to avail yourself of the remedies provided by the applicable law.

 

11. PROTECTION

We have taken appropriate technical and organizational measures to protect your personal data from unauthorized or illegitimate processing, and from loss, destruction, degradation, modification or publication.

Our information system security policy can be provided upon request.

 

12. AMENDMENT TO THIS PRIVACY DECLARATION

Ø       We reserve the right to unilaterally amend or supplement this Privacy Statement. We advise you to check our privacy statement regularly.

Ø       This Privacy Statement was last updated on October4, 2025.

 

13. CONTACT WITH LEASYS

For questions or comments about this Privacy Statement or the processing of personal data, you can contact us by mail: ptprivacidade@leasys.com