Legal

    Data Processing & Role Definition Statement

    GDPR: B2B & B2B2C Context

    1. Purpose of this Statement

    This Data Processing & Role Definition Statement (the Statement) defines the roles, responsibilities and legal positioning of Leniqo and its Partners with respect to the processing of personal data in connection with the Leniqo platform.

    This Statement is intended to:

    • clearly allocate data protection roles;
    • prevent misclassification of responsibilities;
    • support regulatory, banking and compliance reviews;
    • operate as an interpretative framework alongside Leniqo's Service Policy, Privacy Notices and AML / Financial Integrity Policy.

    This Statement is non-promotional and non-contractual in nature and is provided solely for legal and compliance clarification purposes.

    2. Scope of Application

    This Statement applies to:

    • all Partners using the Leniqo platform;
    • all personal data processed in connection with deposit-free rentals, bookings, excess handling, trust assessment and recovery activities;
    • both B2B and B2B2C processing contexts.

    This Statement does not replace or amend any contractual agreements.

    3. Core Principle: Independent Controllers

    As a fundamental principle, Leniqo and each Partner act as independent data controllers within the meaning of Article 4(7) GDPR.

    Nothing in this Statement creates joint controllership within the meaning of Article 26 GDPR.

    Each party independently determines the purposes and means of processing for the personal data under its control.

    4. Role of Leniqo as Data Controller

    Leniqo acts as an independent data controller for personal data processed for the following purposes:

    • operation and administration of the Leniqo platform;
    • trust, risk and behavioural assessment;
    • fraud prevention and misuse detection;
    • excess, dispute and recovery handling;
    • legal protection, enforcement and audit;
    • internal compliance and integrity monitoring.

    Leniqo determines autonomously:

    • which data is processed;
    • how data is evaluated;
    • how long data is retained;
    • with whom data is shared where legally permitted.

    5. Role of the Partner as Data Controller

    Each Partner acts as an independent data controller for personal data processed in connection with:

    • renter onboarding and acceptance;
    • identity verification and KYC (where applicable);
    • rental contract formation and execution;
    • customer communication;
    • statutory, regulatory and consumer law obligations.

    Partners remain solely responsible for:

    • establishing a lawful basis for processing;
    • providing required privacy notices to renters;
    • obtaining consent where required;
    • ensuring data accuracy and minimisation.

    6. Limited Technical Processing by Leniqo

    Only where strictly necessary for technical platform operation, Leniqo may process personal data in a limited technical capacity, such as:

    • hosting and storage of platform data;
    • technical transmission of booking-related information;
    • system maintenance and security.

    Such processing:

    • is purely technical in nature;
    • does not involve compliance, KYC or legal decision-making;
    • does not constitute delegated or outsourced compliance functions.

    7. No Transfer of Compliance Obligations

    Nothing in this Statement, the platform services, or any related documentation transfers, replaces or limits any GDPR, AML, KYC or customer due diligence obligations of the Partner.

    Each Partner remains fully and solely responsible for compliance with all applicable data protection, AML and regulatory requirements arising from its own activities, licensing status and jurisdiction.

    Leniqo does not perform compliance functions on behalf of Partners.

    9. Indemnification

    The Partner shall indemnify and hold harmless Leniqo from and against any claims, fines, penalties, damages, costs or losses arising from:

    • unlawful disclosure of personal data by the Partner;
    • failure to obtain required consent;
    • inaccurate, incomplete or misleading data provided by the Partner;
    • breaches of applicable data protection laws attributable to the Partner.

    This indemnity applies regardless of whether claims are brought by data subjects, authorities or third parties.

    10. International Data Transfers

    Where personal data is transferred outside the European Economic Area, Leniqo ensures appropriate safeguards in accordance with applicable data protection laws, including standard contractual clauses or equivalent mechanisms.

    Personal data is never sold or commercially exploited.

    11. Data Security & Retention

    Leniqo applies appropriate technical and organisational measures to protect personal data against unauthorised access, loss or misuse.

    Personal data is retained only for as long as necessary to:

    • fulfil platform purposes;
    • comply with legal obligations;
    • protect legal interests.

    12. Governing Law & Interpretation

    This Statement is governed by Irish law.

    In case of ambiguity, this Statement shall be interpreted consistently with Leniqo's Master Legal Positioning Statement.

    Leniqo Limited

    Company Number: 802949

    The Black Church, St. Mary's Place
    Dublin 7, Ireland (D07 P4AX)