Privacy Policy
Last updated: October 2026
1. What we collect
Account details (name, email), company and property records you create, tenant and lease information you enter, documents you upload (including lease documents and, where you use the feature, tenant identification documents), payment records, and technical logs needed to operate the service.
2. How we use it
Solely to provide the BERLYMA service: managing your portfolio, processing rent payments, sending notifications you and your tenants expect, generating documents, and keeping the platform secure. We do not sell your data.
3. Data isolation
Every company’s data is isolated with database-level row security. Users can only access data for companies where they hold an active membership, and tenants can only see their own leases, payments and documents.
4. Payments
Payments are processed by Stripe. Card numbers and bank credentials go directly to Stripe and are never stored on BERLYMA servers. We store only payment metadata (amounts, dates, status) needed for your records.
5. Documents & identification
Uploaded documents are stored in access-controlled storage and served only to authorized members of the owning company and, where intended, the tenant concerned. AI-assisted document features (such as ID scanning or lease reading) process files transiently to extract the requested information and do not use your documents to train models.
6. Third-party services (sub-processors)
We rely on carefully chosen processors to run the Service: Supabase (database, authentication, storage), Stripe (payments), DocuSign (e-signatures), Resend (email delivery) and OpenAI (optional AI document features). Each receives only the data required for its function and is bound by contractual data-protection obligations.
6a. Electronic signatures via DocuSign
When a landlord or property manager sends a lease or other document for e-signature, BERLYMA transmits the document and the signers’ names and email addresses to DocuSign, Inc., which processes them as our sub-processor. Envelopes are sent from a DocuSign account operated by BERLYMA (the sending account) rather than from your own DocuSign account. Consequently, authorised BERLYMA platform administrators are technically able to access envelopes across all customer companies within that account; such access is restricted to operating, supporting and securing the Service, is protected by multi-factor authentication, and is never used to review your documents’ contents for any other purpose. Landlords and property managers see only their own envelopes inside BERLYMA. To limit the data held by DocuSign, every envelope is labelled with your company identifier, and once an envelope is completed (or voided/declined) and the executed PDF and Certificate of Completion have been archived to your company’s storage in BERLYMA, we instruct DocuSign to purge its copy of the documents; DocuSign performs the deletion after its fixed 14-day purge period and retains only envelope metadata (status, timestamps, signer emails) for audit purposes. During signing, DocuSign also collects signer IP addresses and timestamps, which appear in the Certificate of Completion. DocuSign’s own handling of this data is described in its privacy notice at docusign.com/privacy.
7. Cookies & consent
We use essential cookies to keep you signed in and secure the session. On our public website, non-essential first-party analytics only run after you accept them via our consent banner — you can accept, decline, or choose per-category under “Manage preferences”, and change your choice at any time using the button below. Essential cookies always work. We do not use third-party advertising trackers.
8. First-party analytics & IP addresses
To understand how our website and app are used, keep the service secure and prevent abuse, we operate our own first-party analytics (no third-party ad networks). For each visit we may record the page visited, referrer, approximate location, device/browser type and the visitor’s IP address. IP addresses are personal data. On our public site we process this only with your consent (see the banner above); for signed-in in-app activity we rely on our legitimate interest in operating and securing the Service, and the activity is associated with your account so administrators can support you. Analytics records are retained for a limited period and then purged. You can contact us to request access to, or deletion of, this data.
9. Retention & deletion
Your data is retained while your account is active. You may delete records within the app, and you may request full account deletion or a data export by contacting your administrator or support.
10. Security
All traffic is encrypted in transit (TLS). Access to production data is restricted, and role-based permissions govern what every user can see and do within a company.
11. Changes
We may update this policy as the Service evolves. Material changes will be reflected on this page with an updated date.