Skip to content
Leasdesk
ProductPlans
Sign inStart free
ProductPlansSign in

Language

Privacy Policy

Last updated: September 25, 2026

Controlling language: English. Translations (e.g. Spanish, Portuguese) may be provided for convenience; if there is a conflict, the English version controls, except where mandatory local law requires otherwise.

Related documents: Terms of Service | Cookie Policy

1. Who we are and how to contact us

This Privacy Policy explains how PixelPleno LTDA (“Leasdesk”, “we”, “us”) collects, uses, shares, and protects personal data when you visit our websites, create an account, or use our applications and related services (the “Service”).

The Service is designed for condominium / property operations customers in markets including the United States, Canada, Brazil, Mexico, Chile, Colombia, and the euro area countries, and may be accessible from other places.

Privacy contact: privacy@leasdesk.com
Legal entity: PixelPleno LTDA, CNPJ 62.416.625/0001-96, São Paulo, Brazil
Data Protection Officer / privacy lead: Privacy and Data Protection Team.

If you are in Brazil, you may also contact us to exercise LGPD rights at the same email. Supervisory authority: Agência Nacional de Proteção de Dados (ANPD), where applicable.

2. Scope — whose data, whose rules

This Policy covers personal data we process as:

(A) Controller — when we decide purposes and means (for example account registration with us, our billing relationship, Business verification, our marketing site, and our own security logs); and

(B) Processor — when we process data on behalf of a customer Organization for condominium operations inside the Service (for example residents linked to units, tickets, bookings, maintenance, in-product invoices and expense shares). In that case, the Organization is the controller; their privacy notices and instructions also apply. Residents and staff should usually contact their Organization first for that data.

This Policy does not cover third-party websites or services that we do not control (including Stripe’s own processing as described in Stripe’s policies), except to explain that we use them.

3. Roles on the platform (transparency)

Role Typical relationship to data
Organization (condo manager or management company / administradora) Controller of condo operations data it enters or generates
Managers / Staff Users authorized by the Organization
Residents (Owner/Tenant linked to a unit) Data subjects whose data the Organization may enter; not paid seats
Vendors Usually records only (not Service accounts by default)
Leasdesk Controller for account/billing/verification/security/marketing as below; processor for Organization ops data
Leasdesk admin staff Separate admin app; may open a read-only, thirty-minute, audited support session as a customer user (“View as”) to resolve a support case, never a write

Whether the customer is an association or an administradora, the platform role split is the same. Country-specific labels may appear in local notices.

4. Personal data we collect

Depending on how you use the Service, we may process:

4.1 Account and profile

Email address; password or credential identifiers and 2FA status; name; phone; language preference (e.g. en / es / pt / fr); account role and Organization membership.

4.2 Organization and billing identity

Organization name; tax id; billing and legal address; plan; payment method tokens via Stripe (we do not store full card numbers); invoices and payment status for fees you pay us.

4.3 Business verification

Company documents and optional identity documents uploaded for Business (or similar) verification. Treat these as sensitive; submit only what we request.

4.4 Condominium structure and operations (usually Organization as controller)

Buildings, units, amenities, parking, assets, bylaws metadata; tickets (including comments); bookings; maintenance schedules; resident linkages to units (Owner/Tenant and stay information as entered by the Organization).

4.5 Money records inside the product (usually Organization as controller)

Issued invoices, recorded payments, expense shares, and bank-statement CSV lines the Organization imports. There is no live bank feed. Residents do not pay Leasdesk through the Service for condo fees unless we later enable that under updated terms and this Policy.

4.6 Files and photos

Uploads associated with tickets or other features. Product rule (not customer-configurable): photos are public within the product contexts where they are shown; all other uploads are private. Do not upload photos you are unwilling to have displayed as public in those contexts.

4.7 Technical and usage data

IP address; device and browser type; approximate location derived from IP; timestamps; log data, including a record of each sign-in (account, IP address and time); cookies and similar technologies (see Cookie Policy); referral URLs; feature usage events; Microsoft Clarity session recordings on the marketing site, only when you accept analytics cookies.

4.8 Communications

Support messages; email receipts we send (in the recipient’s language where configured); survey or feedback content if you provide it.

4.9 Sources

Data you or your Organization submit; data created by use of the Service; payment processors (Stripe); security and fraud tools we enable; publicly available sources only if we use them for verification or abuse prevention and disclose that use where required.

We do not require you to provide more data than needed for the purposes below; if you withhold required account or billing data, you may not be able to use parts of the Service.

5. Purposes and legal bases

We process personal data for the purposes below. Legal bases vary by country. Where GDPR-style or LGPD bases apply, we rely on:

Purpose Examples Typical bases (summary)
Provide the Service Accounts, roles, hosting Customer Content, syncing features Contract; LGPD contract performance
Bill and collect fees Stripe charges, invoices, dunning Contract; legal obligation (tax/accounting where applicable)
Business verification / abuse prevention Review uploads; block fraud or sanctions risk Legitimate interests; legal obligation; contract; consent where required for ID docs
Secure the Service Logs, sign-in records, rate limits, incident response Legitimate interests; legal obligation (for sign-in records, Brazil’s Marco Civil da Internet, Law 12.965/2014, art. 15)
Support Respond to tickets Contract; legitimate interests
Improve the Service Aggregated / de-identified analytics; debugging Legitimate interests; consent for analytics cookies
Analytics on the marketing site and the app Google Analytics 4 on both (in the app, only the kind of page, never its identifiers, searches or names) and Microsoft Clarity on the marketing site, only after you accept analytics cookies (see Cookie Policy) Consent
Comply with law Respond to lawful requests; retain required records Legal obligation
Corporate events Merger or sale (see Section 7.4) Legitimate interests; contract

Legitimate interests (where used) include securing the Service, preventing fraud, improving reliability, and running a B2B SaaS business. You may object where local law allows (see Section 11).

We do not use Organization condo-ops data to train public generative AI models for unrelated commercial products. If that ever changes, we will update this Policy and obtain any required consent or contract terms first.

6. When we act as processor

For personal data in condominium operations that the Organization enters or generates, Leasdesk processes under the Organization’s instructions and our Terms / any DPA. We will:

  • process only to provide the Service and as instructed (including this Policy and the Terms);
  • require confidentiality from personnel with access;
  • use subprocessors as described in Section 7.1, with appropriate contracts;
  • assist with data-subject requests as reasonably needed, channeling resident requests to the Organization when appropriate;
  • help with security and breach notifications as required by law and contract;
  • delete or return data on termination per product behavior and the Terms (noting anonymize/lock vs hard-erase rules below), unless law requires retention.

Organizations are responsible for having a lawful basis to enter resident and staff data, for their own privacy notices, and for configuring access correctly.

7. How we share personal data

We share personal data only as needed for the purposes above:

7.1 Service providers (processors / operators)

  • Stripe — payment processing; Leasdesk merchant account registered in Brazil.
  • Google Analytics 4 — usage measurement on the marketing site and the app, only after you accept analytics cookies; in the app, it receives only the kind of page you are on (its address pattern), never the page’s identifiers, searches, names or links; data processed by Google.
  • Microsoft Clarity — session recordings, heatmaps and usage measurement on the marketing site only, after you accept analytics cookies; it does not run in the app; data processed by Microsoft.
  • Hosting / infrastructure — Microsoft Azure, West US 3 region (Arizona, United States): application servers, database, file storage and logs.
  • Content delivery and security — Cloudflare, on its global network: delivery of the websites, the application’s pages and the requests to our API, DNS, short-lived request logs, and the Turnstile security check on the application’s sign-in, registration and password-recovery forms.
  • Email / transactional messaging — Azure Communication Services (Microsoft), data location United States.
  • Business email — Microsoft 365, for the messages you send to our addresses.
  • Customer support tooling — In App.
  • Professional advisors (lawyers, accountants) under confidentiality.

7.2 Within your Organization

Managers and Staff see data according to roles the Organization assigns. Public photos are visible in the product contexts described above.

7.3 Legal and safety

We may disclose data if we believe in good faith it is required by law, regulation, legal process, or governmental request; to protect rights, safety, and security of Leasdesk, our users, or the public; or to detect and prevent fraud or security incidents.

7.4 Business transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate confidentiality and continued protection consistent with this Policy (or notice of changes).

7.5 With your direction

We may share data when you or the Organization ask us to (for example export or integration you enable).

We do not sell personal data. We do not share personal data for cross-context behavioral advertising as a “sale”/“sharing” under CCPA/CPRA-style laws, unless we update this Policy and offer required opt-outs. If our practices change, we will provide notice and choice as required.

8. International transfers

Personal data may be processed in Brazil and in other countries where we or our providers operate (including where hosting is located — USA). Our websites, the application’s pages and the requests to our API pass through Cloudflare’s global network, which serves each request from a location near the visitor.

Where required, we use appropriate safeguards, which may include: contractual clauses; LGPD-approved international transfer mechanisms; adequacy decisions where recognized; and provider terms that include transfer protections. Primary storage is in Microsoft Azure, West US 3 (United States).

You understand that other countries may have different data-protection rules than your home country.

9. Retention

We retain personal data only as long as needed for the purposes above, including:

  • Active account / Organization workspace: for the life of the account plus a reasonable wind-down period;
  • Billing and tax records: 5 years after the end of the year they relate to, or longer where another applicable law requires it;
  • Business verification (an application’s documents and details): 5 years after the decision on the application;
  • Sign-in records (account, IP address and time of each sign-in): 6 months, also after an account is deleted, as Brazil’s Marco Civil da Internet (Law 12.965/2014, art. 15) requires;
  • Other server logs, and Cloudflare’s request logs: up to 30 days;
  • Consent records (your cookie choices): 5 years from each choice.

Account delete: anonymizes and locks the user account. It does not hard-erase all authored operational records that remain necessary for the Organization’s continuity, audit, disputes, or legal retention. Soft-deleted records follow product retention. Business audit logs are retained for the Business plan period and any longer period required by law — at least 2 years.

Sign-in records and consent records are deleted when their period ends. Other data is not yet deleted automatically: a record removed in the Service is hidden and kept, and the files attached to it move to cold storage and are kept, so an Organization’s history, audits and disputes stay whole. You can ask us to erase your personal data at privacy@leasdesk.com; we answer as the applicable law requires, keeping what the periods above oblige us to keep. Database backups rotate out within 35 days.

10. Security

We implement administrative, technical, and organizational measures appropriate to the risk, including access controls, encryption in transit, segregation of customer admin tools from our internal admin app, and least-privilege practices for staff.

No method of transmission or storage is completely secure. You are responsible for protecting account credentials and for configuring Organization roles carefully. Notify us promptly of suspected unauthorized access at privacy@leasdesk.com or security@leasdesk.com.

11. Your rights

Depending on your country and our role (controller vs processor), you may have rights to:

  • Access personal data we hold about you;
  • Correct inaccurate data;
  • Delete data (subject to legal retention and the anonymize/lock product behavior);
  • Port data in a structured format where applicable;
  • Restrict or object to certain processing (including legitimate-interest processing);
  • Withdraw consent where processing is consent-based (without affecting prior lawful processing);
  • Lodge a complaint with a supervisory authority (e.g. ANPD in Brazil; OPC or provincial authorities in Canada; state AGs or privacy regulators in the US; local authorities in Chile/Colombia).

How to exercise: email privacy@leasdesk.com. We may need to verify your identity. If we process your data only as a processor for an Organization, we will redirect you to that Organization or support them in responding.

We will respond within the timeframes required by applicable law (for example LGPD timelines in Brazil).

11.1 Brazil (LGPD)

Data subjects have rights under Law 13.709/2018, including confirmation of processing, access, correction, anonymization/blocking/deletion of unnecessary data, portability, information about sharing, revocation of consent, and petition to the ANPD. Sensitive data (e.g. certain ID documents) receives heightened protection.

11.2 Canada

Rights and safeguards under PIPEDA and applicable provincial laws (e.g. Quebec Law 25 where applicable). You may challenge compliance with our privacy practices via the contact above and, if unresolved, the Office of the Privacy Commissioner of Canada or provincial commissioners.

11.3 United States

Where state laws apply (e.g. California CCPA/CPRA if we meet thresholds), you may have rights to know, delete, correct, and opt out of sale/sharing. We will honor required requests and will not discriminate for exercising rights.

11.4 Chile and Colombia

Rights under applicable personal-data statutes (including access, correction, deletion, and complaint to local authorities) will be honored as required. Local short-form notices may be added as addenda without changing the core Service.

12. Cookies and similar technologies

We use cookies and similar technologies on marketing sites and the app. Essential cookies are required for the Service. On your first visit, a cookie banner lets you accept or reject analytics cookies with one click, or choose under Settings. Google Analytics 4 measures visits on the marketing site and the app, and Microsoft Clarity on the marketing site only (it also records sessions there), only after you accept; in the app, Google Analytics 4 receives only the kind of page, never its identifiers, searches or names. You can change or withdraw your choice at any time through Cookie settings, at the bottom of every page of the marketing site and, in the app, in the account menu and on the sign-in and registration pages. A withdrawal stops both tools from loading, asks Clarity to erase its cookies and deletes the analytics cookies from our domains. We do not set marketing cookies. See the Cookie Policy for the categories, the inventory and the record we keep of your choice.

13. Children

The Service is directed to business and property-management users. We do not knowingly collect personal data from children under the age required by local law for this context (and not under 13 in the United States). If you believe a child provided data, contact us and we will take appropriate steps.

14. Automated decisions

We do not make solely automated decisions that produce legal or similarly significant effects about individuals without human involvement, except limited fraud/payment risk checks with Stripe or security systems. You may request human review where local law requires.

15. Communications preferences

Transactional emails (security, billing, product notices) are part of the Service. Where we send optional marketing, you can unsubscribe via the link in the email or by contacting us. Language of emails follows recipient preference where configured (en / es / pt / fr).

16. Changes to this Policy

We may update this Policy by posting a new version and revising the “Last updated” date. Material changes will be notified by email or in-product notice where required by law or as we reasonably can. Continued use after the effective date constitutes acceptance where permitted; if you do not agree, stop using the Service and request account anonymization/lock as provided in-product.

17. Controller identity and additional notices

Controller (for Section 2(A) data): PixelPleno LTDA, CNPJ 62.416.625/0001-96, São Paulo, Brazil.

Country-specific addenda (LGPD summary, PIPEDA summary, US state notices) may be linked from this page without changing product features across markets.

18. Contact and complaints

Privacy: privacy@leasdesk.com
Legal: legal@leasdesk.com
Security: security@leasdesk.com

If you have an unresolved concern, you may contact your local data protection authority in addition to us.


Leasdesk

Condominium management software.

ProductPlansFAQFor property managersFor management companiesBilling and duesAmenity bookingTickets and maintenanceFree planSign inCreate your account

Legal

Terms of ServicePrivacy PolicyCookie Policysupport@leasdesk.com

Language

EnglishEspañolPortuguêsFrançais

© 2026 Leasdesk

We use necessary cookies to run Leasdesk. With your permission, we also use analytics cookies (Google Analytics and Microsoft Clarity) to see how Leasdesk is used. You can change your choice at any time in Cookie settings. Cookie Policy

Cookie settings

Always on: sign-in, security, the language and time zone you use, and this choice.

Google Analytics and Microsoft Clarity, which also records sessions, show us how Leasdesk is used. Off until you turn them on.