Draft, published while company registration details are being finalised. Anything in [square brackets] is a placeholder to be filled in.
Data Processing & Sub-processors
The short version
Inside your workspace, the data is yours and we act only on your instructions. Each customer gets a separate database, access is role-based, and posted journals cannot be altered. The sub-processors we use are listed below.
Roles
For data inside your Leascape workspace, you are the data fiduciary (controller) and we are the data processor. We process that data only to provide the service, on your documented instructions, and for no purpose of our own. For account, billing and website data we act as controller — see the Privacy Policy.
This page describes the processing. Customers who need a signed data processing agreement can request one at hello@leascape.com.
Subject matter, duration and scope
- Subject matter — provision of the Leascape lease accounting service.
- Duration — the term of your subscription, plus the deletion period described on the Account & Data Deletion page.
- Categories of data subject — your employees and contractors who use the service, and individuals named in your lease records (for example landlord or lessee contacts).
- Categories of personal data — names, work contact details, user roles and activity records; and any personal data your lease documentation happens to contain.
- Special category data — none is required by the service; please do not put any into it.
Our commitments
- Process personal data only on your documented instructions, including for transfers, unless the law requires otherwise — in which case we tell you, where we may.
- Ensure the people who handle it are bound by confidentiality.
- Apply the security measures below.
- Assist you, as far as we reasonably can, with requests from individuals and with your own obligations on security, breach notification and impact assessments.
- Delete or return the data at the end of the service, as described in the deletion page.
- Engage sub-processors only as set out below.
Security measures
- Separation by customer — every customer's records are in a separate physical database, not a shared table filtered by an identifier.
- Encrypted credentials — the connection details for those databases are stored encrypted.
- Encryption in transit — TLS for all traffic to the application and its API; encryption at rest is provided by our hosting provider.
- Access control — role-based permissions per module and action, and modules can be switched off entirely for a customer. Our own staff access production data only when needed to run or support the service.
- Auditability — leases are versioned, approvals are recorded, and posted journal entries are immutable, so changes can be reconstructed.
- Backups — taken regularly and retained for [BACKUP RETENTION].
Sub-processors
We use these providers to deliver the service. Each is bound by contract to protect the data:
| Provider | Purpose | Location |
|---|---|---|
| [HOSTING PROVIDER] | Application and database hosting | [HOSTING REGION] |
| Zoho Mail (Zoho Corporation) | Transactional, support and grievance email for leascape.com | India |
| Cloudflare | Hosting and delivery of the leascape.com website; its edge logs include visitor IP addresses | Global edge network |
| [PAYMENT GATEWAY] | Subscription payments and invoicing | India |
We give customers at least [SUBPROCESSOR NOTICE DAYS] days' notice by email before adding or replacing a sub-processor, so you can object.
International transfers
Under the Digital Personal Data Protection Act, 2023, personal data may be transferred outside India to any country the Central Government has not restricted by notification under section 16. We monitor that list and will relocate data if a country we use is restricted. Where the GDPR applies to a customer in the EU or UK, we additionally put a lawful transfer mechanism in place, such as the European Commission's standard contractual clauses. The safeguards described above apply wherever the data sits. Tell us before you subscribe if your data must remain in a particular country and we will confirm whether we can meet that.
Security incidents
If we become aware of a breach of security affecting your personal data, we notify you without undue delay and in any case within [BREACH NOTICE HOURS] of becoming aware. Where the Digital Personal Data Protection Act, 2023 applies, section 8(6) also requires intimation to the Data Protection Board of India and to each affected individual, in the form and within the time the Act and its rules prescribe; we make those notifications and tell you when we have. The notice describes what happened, the data affected as far as we know it, the likely consequences and the steps we are taking, and we keep you updated as we learn more.
Information and audits
On reasonable written request, and no more than once a year unless an incident or a regulator requires otherwise, we provide the information needed to show we meet these commitments. Audits are arranged in advance, under confidentiality, and must not disrupt the service or affect other customers.
Return and deletion
At the end of the service we delete your workspace data as described on the Account & Data Deletion page. Until the deletion date you can export your records yourself from the reports section, in Excel.
Contact
[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Email hello@leascape.com.