Privacy Policy for the Levo Eigentumer Platform

Effective date: March 3, 2026

This privacy policy applies to the Levo Eigentumer Platform, meaning the owner/operator dashboard used to manage projects, customer data, billing, payouts, and support requests.

1. Controller

The controller for the processing of personal data under the GDPR is:

Levo GmbH
Buecklestrasse 3
78467 Konstanz
Germany
Email: contact@levo.gmbh

2. What data we process

Depending on how you use the Levo Eigentumer Platform, we may process the following categories of personal data:

  • Account data: name, email address, phone number, language preference, and information needed for login and account security.
  • Billing and payment data: payment method details, invoice information, payment status, and bank details where needed for payments or payouts.
  • Payout data: information required for payouts and identity or business verification in connection with Stripe.
  • Project and property data: project name, status, addresses, units, installation data, and overall project figures.
  • Customer data within your projects: names, contact details, billing addresses, contract status, move-in and move-out dates, and related invoices.
  • Support data: name, email address, subject line, message, and optional attachments when you use the contact form.
  • Notification data: messages and status updates shown within the platform.
  • Preference data: selected language, display preferences, and the last project you used.

We only process personal data where necessary. In particular, we process data for the following purposes:

  • Providing the dashboard, login, access control, and session management.
  • Managing your account and handling changes to profile data, email, password, and language settings.
  • Displaying and managing projects, structures, units, customer relationships, contract links, documents, and invoices.
  • Processing payments, storing payment methods, managing payouts, and running Stripe Connect onboarding.
  • Handling support and contact requests.
  • IT security, abuse prevention, troubleshooting, service stability, and technical improvement.
  • Meeting legal retention and compliance obligations.

The main legal bases are:

  • Article 6(1)(b) GDPR where processing is necessary to perform a contract or take steps prior to entering into a contract.
  • Article 6(1)(c) GDPR where processing is required to comply with legal obligations, including accounting, tax, or regulatory obligations.
  • Article 6(1)(f) GDPR based on our legitimate interests in operating a secure, stable, and economically viable dashboard, providing support, and preventing misuse.

4. Payments and Stripe

We use Stripe for payment and payout related functions. The Levo Eigentumer Platform uses Stripe-hosted payment components and Stripe Connect embedded components.

This means in particular:

  • Payment details such as card data are generally entered directly into input components provided by Stripe.
  • As part of operating our own system, we usually do not receive full card details; instead, we receive technical references and masked payment information (for example brand, type, last four digits, and expiry month/year).
  • For payouts and Connect onboarding, Stripe may require additional information, including bank data and identity, tax, or business information. Stripe processes that information to support regulatory checks, verification, and payouts.

This processing is necessary for contract performance and for financial/compliance obligations. You can find more information about Stripe's own processing at https://stripe.com/privacy.

5. Support and contact form

If you contact us through the contact form, we process your request, including any attachments, in order to review and respond to your enquiry.

Attachments are processed only to the extent you provide them. Please do not send sensitive information through the contact form unless it is strictly necessary for your request.

6. Error monitoring and technical security

The Levo Eigentumer Platform uses a technical service provider for error and stability monitoring. This may involve processing information needed to detect, analyse, and fix technical issues.

This processing is based on our legitimate interest in operating a secure and stable service.

Important: based on the current code reviewed for this draft, no advertising or marketing trackers were identified in the Levo Eigentumer Platform. This does not affect technical error monitoring.

7. Cookies and technically necessary storage

The Levo Eigentumer Platform uses technically necessary cookies and similar storage technologies so you can stay securely signed in, keep your preferences, and use the platform smoothly.

These technologies are not used for advertising.

8. Recipients and categories of recipients

We only share personal data where necessary for the purposes described above. Recipients may include:

  • authorised Levo personnel;
  • hosting, infrastructure, and storage providers;
  • email and communications providers for support and system messages;
  • Stripe as payment and payout processor;
  • technical service providers for hosting, security, communications, and error monitoring;
  • public authorities or other bodies where disclosure is legally required.

We do not disclose personal data for advertising or list-broker purposes.

9. International transfers

Some service providers, especially in the areas of payments, infrastructure, support, or error monitoring, may process data outside the EU/EEA or permit access from outside the EU/EEA. Where this happens, we take steps to ensure an adequate level of protection, for example through adequacy decisions or appropriate safeguards such as standard contractual clauses.

10. Retention periods

We store personal data only for as long as necessary for the relevant purpose or where statutory retention obligations apply.

In particular:

  • We generally store account data for the duration of the contractual or user relationship.
  • We store support requests for as long as needed to resolve the issue and afterwards where necessary for evidentiary, warranty, or organisational purposes.
  • We retain invoice and billing related data in line with statutory retention obligations.
  • We retain security and error logs only for as long as required for security, analysis, and evidentiary purposes.
  • Browser-side cookies and preference storage can be removed by you at any time through your browser settings.

11. Your rights

Subject to the applicable legal requirements, you have the right to:

  • request access to the personal data we hold about you;
  • request correction of inaccurate data;
  • request deletion or restriction of processing;
  • object to processing;
  • receive your data in a portable format;
  • withdraw consent at any time with future effect where processing is based on consent;
  • lodge a complaint with a data protection supervisory authority.

To exercise your rights, you can contact us at contact@levo.gmbh.

12. Data security

We implement appropriate technical and organisational measures to protect your data against loss, misuse, unauthorised access, unauthorised disclosure, or unlawful alteration. This includes access controls, secure login processes, and the use of specialised payment providers for sensitive payment data.

13. No automated decision-making

Based on the functionality currently reviewed in the Levo Eigentumer Platform, we do not carry out automated decision-making, including profiling, within the meaning of Article 22 GDPR that produces legal effects concerning you or similarly significantly affects you.

14. Changes to this privacy policy

We may update this privacy policy with future effect if technical, legal, or organisational conditions change. You should therefore review the current version regularly.