Privacy Policy

Effective Date: February 13, 2026 — Version 1.0

1. INTRODUCTION

This Privacy Policy explains how LAZO GROUP ("Penry", "We", "Us", "Our") collects, uses, stores, and protects your personal data when you use our Service. Data Controller: • Legal entity: LAZO GROUP • SIRET: 983 329 442 00013 • Address: 3 rue Lamartine, 91320 Wissous, France • Email: privacy@penry.fr Applicable Laws: • EU General Data Protection Regulation (GDPR) • French Data Protection Act (Loi Informatique et Libertés) • French Consumer Code (Code de la consommation)

2. DATA WE COLLECT

2.1 Account Information What we collect: • Email address (required) • Full name (required) • Password (encrypted with bcrypt, we cannot see your password) • Company name / Business name (optional) • SIRET number (optional) • Phone number (optional) • Profile photo (optional) Legal basis: Contract performance (necessary to provide Service) 2.2 Financial Information What we collect (that YOU enter): • Income records (amounts, dates, sources, descriptions) • Expense records (amounts, dates, categories, descriptions, receipts) • Client information (names, addresses, emails, phone numbers) • Tenant information (names, addresses, emails, phone numbers) • Property details (addresses, ownership info, rental terms) • Invoice data (items, prices, payment terms) • Bank account names and last 4 digits (NOT full account numbers) • Financial entity details (LMNP properties, business entities, SCI, etc.) What we DO NOT collect: • Full bank account numbers • Banking passwords or credentials • Credit card numbers (handled by Stripe, we never see them) • Social security numbers • Sensitive personal data (health, religion, political views, etc.) 2.3 Bank Synchronization Data (Via Bridge API) If you enable bank sync: What Bridge API accesses (NOT us directly): • Bank account balances • Transaction history • Transaction descriptions, amounts, dates • Account holder names What we receive from Bridge: • Transaction data (anonymized sensitive details) • Account balances • Last 4 digits of account numbers • Account nicknames What we DO NOT receive: Your banking credentials (password, security codes), full account numbers, or sensitive banking authentication data. Legal basis: Your explicit consent (you authorize connection) Third-party processor: Bridge API (EU-based, GDPR-compliant) 2.4 Payment Information Processed by Stripe (we do NOT see or store): • Credit/debit card numbers • Card expiration dates • CVV codes • Billing addresses What we receive from Stripe: Last 4 digits of card, card brand, payment success/failure status, subscription status. 2.5 AI-Generated Content Data When you use AI document generation: What we send to Anthropic Claude API: • Your document generation requests • Context data (anonymized where possible) • Template preferences What we DO NOT send: Unrelated personal data, data from other users, unnecessary sensitive information. You acknowledge: AI providers may use your inputs for model improvement. We anonymize data where possible, but cannot guarantee complete anonymization. 2.6 Usage Data What we collect automatically: • Pages viewed in the Service • Features used • IP address (anonymized after 90 days) • Device type (desktop, mobile, tablet) • Browser type and version • Operating system • Date and time of access Legal basis: Legitimate interest (service improvement, security, analytics) 2.7 Cookies and Tracking Essential Cookies (always active): • Session management (keep you logged in) • Authentication (verify your identity) • Security (prevent fraud, CSRF protection) • Load balancing (distribute traffic) Analytics Cookies (require your consent): Usage statistics, feature usage tracking, user journey analysis. We do NOT use: Advertising cookies, cross-site tracking, third-party ad networks.

3. HOW WE USE YOUR DATA

3.1 Primary Purposes (Contract Performance) We use your data to: • Provide the Service features you use • Create and manage your account • Process your subscription payments • Generate invoices, receipts, quotes, and documents • Synchronize bank transactions (if enabled) • Export tax forms and financial reports • Provide customer support • Send transactional emails (account, billing, security) 3.2 Service Improvement (Legitimate Interest) We use anonymized/aggregated data to: • Analyze usage patterns • Improve features and user experience • Identify and fix bugs • Develop new features We do NOT: Sell your data to third parties, use your data for advertising, or share identifiable data for marketing. 3.3 Communication Transactional emails (cannot opt out): Account confirmation, password reset, payment receipts, subscription renewal notices, security alerts, critical service updates. Marketing emails (can opt out): Product updates, tips and tutorials, special offers, company news. You can unsubscribe from marketing emails by clicking "Unsubscribe" in any marketing email or via Account Settings.

4. DATA SHARING AND TRANSFERS

4.1 Third-Party Service Providers We share data with processors to provide the Service: • Stripe — Payment processing (EU/US, GDPR-compliant, DPA, EU-US DPF) • Bridge API — Bank synchronization (EU, GDPR-compliant, DPA) • Anthropic — AI document generation (US, EU-US DPF, SCC, DPA) • Cloud Hosting — Infrastructure (EU, GDPR-compliant, DPA) Data Processing Agreements (DPA): We have DPAs in place with all processors, ensuring GDPR compliance. 4.2 International Data Transfers Some processors are located outside the EU. For US-based processors (Anthropic, Stripe), we ensure adequate protection through EU-US Data Privacy Framework certification and Standard Contractual Clauses (SCC). Your data is primarily stored in EU data centers (France/Germany). 4.3 Legal Disclosures We may disclose your data if legally required: • Court order or subpoena • French tax authority (DGFIP) request • URSSAF or other regulatory inquiry • Law enforcement investigation (with valid legal basis) • To protect our legal rights or safety 4.4 No Selling of Data WE DO NOT: Sell your personal data to anyone, share your data with advertisers, provide your data to data brokers, or use your data for unrelated commercial purposes.

5. DATA RETENTION

5.1 Active Accounts While your account is active, we retain all your data to provide the Service. No automatic deletion. You control your data (can delete anytime). 5.2 Canceled Accounts After you cancel: • Grace period: 90 days (data retained for possible reactivation) • After 90 days: All personal data permanently deleted • Exceptions: Anonymized analytics, legal/tax records (as required by law), fraud prevention records 5.3 Legal Requirements French law may require us to retain: • Accounting records: 10 years • Tax documents: 6 years • Customer contracts: 5 years after end • Payment records: As required by tax law

6. YOUR RIGHTS (GDPR)

6.1 Right of Access (Article 15) You can request confirmation of what data we hold about you, a copy of your personal data, and information about how we use your data. How to exercise: Email privacy@penry.fr with subject "Data Access Request" Timeline: We respond within 30 days 6.2 Right to Rectification (Article 16) You can correct inaccurate data or complete incomplete data. How to exercise: Update directly in Account Settings OR email privacy@penry.fr 6.3 Right to Erasure / "Right to Be Forgotten" (Article 17) You can request deletion if: • Data no longer necessary for original purpose • You withdraw consent (for consent-based processing) • You object to processing (and no overriding legitimate grounds) • Data processed unlawfully Exceptions: We cannot delete if required for legal compliance (tax records, accounting), legal claims or defense, or public interest. 6.4 Right to Data Portability (Article 20) You can receive your data in structured, machine-readable format (CSV, JSON) and request transmission to another service (where technically feasible). How to exercise: Export data in Account Settings → Export Data 6.5 Right to Restrict Processing (Article 18) You can restrict processing if: • Accuracy of data is contested (during verification) • Processing is unlawful (but you don't want deletion) • We no longer need data, but you need it for legal claims • You objected to processing (pending verification) 6.6 Right to Object (Article 21) You can object to processing based on legitimate interest, direct marketing (always). For marketing: Click "Unsubscribe" or Account Settings → Email Preferences 6.7 Right to Withdraw Consent (Article 7) For processing based on consent (bank synchronization, analytics cookies, marketing communications, AI feature usage), you can withdraw consent anytime via Account Settings → Privacy Settings. 6.8 Right to Lodge Complaint If you believe we violated GDPR, you can complain to: French Supervisory Authority (CNIL): • Website: https://www.cnil.fr • Address: 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 • Phone: +33 1 53 73 22 22 We encourage contacting us first: privacy@penry.fr

7. DATA SECURITY

7.1 Security Measures We implement industry-standard security: Encryption: • TLS 1.3 for data in transit (HTTPS) • AES-256 for data at rest (database encryption) • Bcrypt for password hashing (one-way, irreversible) Access Controls: • Role-based access (employees have minimum necessary access) • Multi-factor authentication for admin access • Regular access reviews Infrastructure Security: • EU-based cloud hosting with SOC 2 compliance • Firewalls and intrusion detection • Regular security audits • DDoS protection • Regular encrypted backups 7.2 Limitations WE CANNOT GUARANTEE: Absolute security (no system is 100% secure), prevention of all unauthorized access, protection against all cyber threats, or zero risk of data breaches. 7.3 Data Breach Response If we discover a data breach: • Within 72 hours: Notify CNIL (French data protection authority) • If high risk to you: Notify you directly via email • Investigate cause and implement additional safeguards

8. CHILDREN'S PRIVACY

The Service is NOT intended for children under 18. We do not knowingly collect data from children under 18, market to children, or allow children to create accounts. If we discover a user is under 18, we will immediately delete their account and data. If you're a parent/guardian and believe your child created an account, contact us immediately: privacy@penry.fr

9. AUTOMATED DECISION-MAKING AND PROFILING

9.1 Limited Automated Processing We use automation for: • Expense categorization suggestions (AI-assisted) • Transaction categorization (based on merchant names) • Fraud detection (flagging suspicious activity) Important: • You can always override automated categorization • You review and approve all AI suggestions • No automated decision has legal or similarly significant effect on you • You have the final say on all categorization 9.2 No Profiling We do NOT create profiles about you for marketing, use your data to predict your behavior, make automated decisions that significantly affect you, or sell your profile to third parties.

10. CHANGES TO THIS PRIVACY POLICY

We may update this policy for new features, changes in laws, or improved practices. For significant changes: 30-day advance notice via email, prominent notice in Service, updated "Last Updated" date. If you disagree with changes, you can cancel your account before the effective date or exercise your data deletion rights.

11. CONTACT INFORMATION

Privacy Questions: • Email: privacy@penry.fr • Response time: Within 7 business days (GDPR requests within 30 days) Company Information: • Legal entity: LAZO GROUP • SIRET: 983 329 442 00013 • Address: 3 rue Lamartine, 91320 Wissous, France • Email: contact@penry.fr • Website: https://penry.fr Supervisory Authority — CNIL (Commission Nationale de l'Informatique et des Libertés): • Website: https://www.cnil.fr • Address: 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France • Phone: +33 1 53 73 22 22 BY USING PENRY, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY.

LAZO GROUP — 3 rue Lamartine, 91320 Wissous, France — SIRET: 983 329 442 00013