Back to home

GDPR Compliance

Last updated: December 19, 2025

We protect personal data and comply with GDPR (General Data Protection Regulation). This page explains our approach to data protection and how you can use your rights.

Our Approach to Data Protection

We built iLea Business with privacy in mind. We process your data in a way that's: • lawful, fair, and transparent • limited to clear and legitimate purposes • accurate and kept up to date • stored only as long as necessary • protected against unauthorized access or misuse

Lawful Basis for Processing

We process data under these legal bases: • Contract Performance (Art. 6(1)(b)): Processing necessary to provide the iLea Business platform and requested services. • Legitimate Interest (Art. 6(1)(f)): Processing required to operate, secure, and improve the platform, and prevent misuse. • Legal Obligation (Art. 6(1)(c)): Processing required to comply with applicable laws and regulations. • Consent (Art. 6(1)(a)): Processing based on your consent, where required. Consent can be withdrawn at any time.

Your Rights Under GDPR

Under GDPR, you can: • Access (Art. 15) – obtain confirmation and a copy of your personal data • Rectification (Art. 16) – correct inaccurate or incomplete data • Erasure (Art. 17) – request deletion of your data • Restriction (Art. 18) – limit processing in certain cases • Data Portability (Art. 20) – receive your data in a machine-readable format • Object (Art. 21) – object to processing based on legitimate interest • Withdraw Consent – withdraw consent at any time without affecting prior processing

How to use your rights

To use any of your GDPR rights: 1. Email us at mark.malko@ileaapp.com 2. Include your name, email address, and a clear description of your request 3. We may request verification to confirm your identity 4. We will respond within 30 days (this may be extended where permitted by law) There is no fee for using your rights, unless requests are excessive or repetitive.

Data Security

We protect your data with security measures appropriate to our scale and stage: • encrypted data transmission (TLS/SSL) • access controls and authentication • internal access limitation based on role • monitoring and basic security practices No system is 100% secure, but we continuously work to protect your data.

International Data Transfers

Your data may be processed or stored outside the European Economic Area (EEA). When that happens, we use safeguards required by GDPR.

Data Breach Handling

If a data breach happens, we'll: • assess the scope and impact • take reasonable steps to mitigate risks • notify relevant authorities and affected individuals where required by law

Records of Processing

We maintain internal records of personal data processing activities in accordance with Article 30 GDPR, appropriate to the size and nature of our operations.

Right to Lodge a Complaint

If you think we violated your data protection rights, you can file a complaint with your local data protection authority. Please contact us first so we can address your concerns directly.

Contact

For GDPR questions or to use your rights: Email: mark.malko@ileaapp.com iLea is early-stage. We'll complete formal company registration as we grow.