Privacy & Data Governance
CleanFocusy Protocol: Your Data, Our Stewardship
We Don't Collect Data for Collection's Sake
In a service business like cleaning, trust is the currency. We apply that same principle to digital data: we collect the absolute minimum required to book, execute, and improve our service. We do not sell, rent, or trade your personal information to third parties. We do not use your data for advertising profiles. Your contact details are used only for scheduling and service confirmation. Our model is simple: you pay for a clean home, not your data footprint.
Contact, Location, and Payment data only. No browsing history, no device IDs.
Full adherence to General Data Protection Regulation (EU) 2016/679.
Data is retained only for active service relationships, then anonymized or deleted.
The Three Core Data Workflows
We process data in three distinct, segregated workflows. This architectural separation is a technical safeguard—it limits the scope of any single breach and ensures data isn't siloed or aggregated for purposes beyond your direct service.
1 Booking & Communication
Your name, phone, email, and address. Used solely for scheduling, arrival alerts, and post-service feedback. Stored encrypted in our booking system. Not exported to marketing lists.
2 Payment Processing
Processed directly through a PCI-DSS compliant payment gateway (e.g., Stripe). We do not see or store full card numbers. We receive only a token and confirmation.
3 Service Optimization
Anonymized, aggregated data: service duration, area cleaned, frequency patterns. Used only to improve scheduling algorithms and team allocation. Tied to an internal case ID, not your name.
"We believe data should be a temporary tool, not a permanent asset. If we don't need it for the service, we don't keep it." — CleanFocusy Technical Lead
Executive Summary
1. Minimal Collection: We collect only booking and payment data. No tracking pixels, no ad tech, no behavioral profiling.
2. You Control It: You can request a data export or full deletion at any time. Response within 30 days, no questions asked.
3. No Third-Party Sales: Your data is never sold, shared for marketing, or used to train external AI models. It stays within our service loop.
Our Privacy Assumptions & Constraints
Foundational Assumptions
- You want a clean home, not a relationship with our software. Frictionless booking is our only digital goal.
- Parisian privacy expectations are high; default trust requires transparency by design, not as an addendum.
- A cleaner's job is physical; our data handling should be as discreet and respectful as their on-site presence.
Hard Constraints
- Technical: We cannot process payments without a token. This requires a minimal transfer to a PCI-compliant gateway.
- Operational: To provide service, we must know your address and a contact method. This is non-negotiable.
- Legal: French civil code (Article 1384) requires records of commercial transactions for up to 10 years. We anonymize all personal identifiers after 30 months.
What Would Change Our Mind
Our current stance on data minimization is strong, but not dogmatic. Here are the credible scenarios that would force a policy change:
- Regulatory Shift: A new EU-wide law mandating tracking for security or insurance purposes.
- Service Expansion: Offering recurring subscription services would require different retention models.
- Partnership Requirement: If a trusted partner (e.g., a specialty cleaning product brand) needed data for a joint, opt-in workshop, we'd create a clear, separate consent flow.
Your Data Rights, Clearly Defined
Under GDPR (Articles 15-21), you have specific rights. We've built our systems to respect and fulfill them efficiently. No complicated forms, no delays.
How to Exercise Rights
Right to Access
Request a copy of all personal data we hold, in a structured, commonly used format.
Right to Deletion
Request erasure of your data, where no overriding legal or contractual obligation exists.
Right to Portability
Receive your data to transmit to another controller, where technically feasible.
Right to Object
Object to processing based on legitimate interests. We must stop unless we prove compelling grounds.
Third-Party Processors
We use essential processors to deliver our service. Each is bound by strict Data Processing Agreements (DPAs) that mirror our commitment to data protection.
Payment Processor
Stripe (Irish subsidiary, GDPR compliant). They process card tokens; we never handle raw payment data.
Email & Communication
Transactional email provider. Used only for booking confirmations, invoices, and critical service alerts. No marketing lists.
Cloud Hosting
EU-based servers (Hetzner). All data is stored within the European Economic Area.
Contact Our Data Officer
CleanFocusy Data Protection Officer
111 Rue Réaumur, 75002 Paris, France
Mon-Fri: 9:00-18:00
Related Policies
- Cookie Policy — How we use (and don't use) cookies.
- Terms of Service — The contract for our cleaning services.
- Our Services — What this privacy policy applies to.
Last Updated: January 15, 2026. This policy is subject to updates. We will notify you of significant changes via email or on our website.