LEGAL
Privacy Notice
In brief. Lizio uses personal data to provide and secure its business lease-management service, send requested reminders, administer accounts and billing, and offer optional AI-assisted data extraction. Lizio does not replace the Customer’s responsibility to review leases, deadlines or AI suggestions. This Notice describes Lizio’s practices for transparency; it does not itself expand any right or obligation beyond what applicable data-protection law already provides.
1. Scope and roles
This Privacy Notice explains how Lizio Rolli (“Lizio”, “we”, “us” or “our”) processes personal data in connection with its websites, hosted application, accounts, subscriptions, support, communications, reminders and AI-assisted features (the “Service”). It applies to business and professional users, website visitors, customer contacts and other individuals whose personal data Lizio processes for its own purposes. This Notice is provided for transparency and does not create contractual rights for any individual beyond those already granted by applicable data-protection law.
Lizio has two different data-protection roles:
Controller role. Lizio generally acts as controller for account registration, authentication, billing administration, security, support, website operation, service communications, marketing preferences and its legal or business records.
Processor role. A Customer generally acts as controller for personal data contained in lease documents, reminder recipients, Organization records and other Customer Data. Lizio processes that data on the Customer’s documented instructions to provide the Service. Where Lizio and the Customer have entered into a Data Processing Agreement, that agreement governs this processing.
Where Lizio acts only as processor, the Customer determines why and how the personal data is used and is responsible for giving required notices, establishing a lawful basis and handling data-subject requests. Individuals should normally contact the relevant Customer first. Lizio will assist only as required by law and, where applicable, under a Data Processing Agreement entered into with the Customer; Lizio is not obliged to respond directly to a request that should properly be directed to the Customer.
2. Personal data we process
Depending on how the Service is used, Lizio may process the following categories:
Account and identity data, such as name, business email address, password credentials in protected form, account identifiers, preferred language and authentication information.
Organization and role data, such as employer or business name, Organization membership, invitations, Owner or Admin role, permissions, ownership transfers and billing responsibility.
Subscription and transaction data, such as selected plan, billing status, currency, invoice details, tax information, transaction identifiers and limited payment metadata supplied by the payment processor. Lizio does not need to receive full payment-card details.
Customer Data, such as lease documents, property and counterparty information, contract dates and clauses, reminder settings, contact details, uploaded files, notes, exports and other information submitted by or for a Customer.
Reminder and communication data, such as recipients, delivery addresses, reminder configuration, sending attempts, provider responses, delivery status and related audit metadata.
AI input and output data, such as documents or selected content submitted to an AI-assisted feature, extracted text, proposed fields, classifications and User feedback or corrections.
Technical, usage and security data, such as IP address, device and browser information, session and authentication events, timestamps, diagnostic logs, feature usage, error reports and security alerts.
Support and business communications, such as requests, correspondence, feedback, complaints and records of consent or communication preferences.
Lizio does not intentionally require health, biometric or other highly sensitive personal data for ordinary use. Customers should avoid uploading sensitive or unrelated personal data unless it is genuinely necessary, lawful and appropriately protected; the Customer, not Lizio, is responsible for that determination.
3. Sources of personal data
Lizio obtains personal data:
directly from Users and website visitors when they register, subscribe, configure the Service, communicate with Lizio or exercise a right;
from Customers and authorized Users when they upload leases, invite colleagues, enter contacts, configure reminders or otherwise supply Customer Data;
automatically from devices, browsers, cookies, logs and the use of the Service;
from payment, email, authentication, hosting, security, analytics and AI providers used to operate the Service; and
from public sources or business partners where lawful and relevant to a business relationship.
4. Why we process personal data
Lizio processes personal data only for appropriate purposes, including to:
provide accounts, Organizations, lease-management features, reminders, exports, subscriptions and requested support;
authenticate Users, administer roles and ownership, process billing and maintain transaction records;
operate AI-assisted features that extract, classify, summarize or suggest entries for human review;
deliver service, security, billing, ownership and deletion notices;
secure the Service, prevent abuse and fraud, investigate incidents, maintain audit evidence and enforce agreements;
diagnose errors, maintain and improve the Service, understand capacity and develop features;
respond to requests, complaints, disputes and legal claims; and
comply with accounting, tax, sanctions, court, regulatory and other legal obligations.
5. Legal grounds
Swiss data-protection law applies to Lizio. Where the EU or UK GDPR or another law requiring a legal basis applies, Lizio relies on one or more of the following grounds:
Contract. Processing necessary to take requested steps before entering a contract or to perform the agreement for the Service.
Legitimate interests. Operating, securing, supporting and improving a B2B service; preventing misuse; maintaining appropriate evidence; communicating with business contacts; and establishing, exercising or defending legal claims, balanced against the individual’s rights.
Legal obligation. Processing needed to comply with accounting, tax, regulatory, court or other binding requirements.
Consent. Processing based on freely given consent where required, for example certain marketing communications, cookies or optional uses. Consent may be withdrawn prospectively at any time.
Where Lizio acts as processor, the Customer is solely responsible for determining and documenting the applicable legal ground for Customer Data.
6. AI-assisted features
Lizio may use artificial intelligence or machine learning to read lease documents and suggest dates, values, categories, summaries or other data entries. Documents, selected content and related instructions may be transmitted to specialized AI providers acting under appropriate contractual arrangements.
AI outputs are probabilistic and can be incomplete or wrong. They are assistance tools only. A User must compare every material suggestion with the original lease and confirm it before saving or relying on it. Lizio does not use AI Features to make decisions that produce legal or similarly significant effects about individuals without meaningful human involvement.
Lizio will not use identifiable Customer Data to train a general-purpose AI model for unrelated purposes unless that use is expressly disclosed, contractually permitted and supported by any permission or legal ground required by law. Provider-specific data-use restrictions will be selected where reasonably available.
7. When personal data is disclosed
Lizio may disclose personal data only as reasonably necessary to:
the Customer, its Owner, Admins and other authorized Users according to account permissions;
service providers supporting hosting, database, storage, authentication, payment processing, email and reminder delivery, AI processing, analytics, customer support, security, monitoring and professional services;
accountants, insurers, legal advisers and other professional advisers subject to appropriate duties;
courts, regulators, public authorities or other parties where required by law or reasonably necessary to protect rights, safety, security or the Service; and
a buyer, successor or transaction adviser in connection with a possible or completed sale, transfer, financing or closure of Lizio, subject to appropriate confidentiality and data-protection safeguards.
Lizio does not sell personal data for money or use Customer Data for third-party behavioral advertising.
8. Service providers and subprocessors
Lizio uses carefully selected third-party providers because it operates as a small, single-operator software business. Provider categories and locations may change as the Service evolves. Current subprocessor information, including the provider’s function and relevant processing location, is available at contact@lizio.io on request and may also be published on Lizio’s website.
Payment information is handled by the third-party payment processor identified at checkout. Lizio generally receives transaction status and limited billing metadata rather than full card details. Third-party services may also have their own privacy notices for processing they perform as independent controllers, for which Lizio has no responsibility.
9. International transfers
Lizio is established in Switzerland. Providers may process personal data in Switzerland, the European Economic Area, the United Kingdom, the United States and other countries identified in current subprocessor information. A destination country’s laws may differ from Swiss or EEA law.
Where required, Lizio uses an adequacy decision, recognized certification framework, approved standard contractual clauses adapted for Swiss law where appropriate, contractual and technical safeguards, or another lawful transfer mechanism. Information about the relevant safeguards may be requested at contact@lizio.io, subject to protection of confidential and security information.
10. Data retention and deletion
Lizio keeps personal data only for as long as reasonably needed for the stated purposes, the agreement, security, legal claims and applicable law. The following periods or criteria normally apply:
Active accounts and Customer Data. Retained while the relevant account or Subscription is active and as needed to provide the Service.
After a Subscription ends. Unless the Owner requests Organization deletion, dormant Organization Data may be retained for up to 12 months to permit possible reactivation or an authorized export. Access may remain suspended and full retrievability is not guaranteed throughout that period.
Organization deletion. A 30-day scheduled-deletion period applies. After that period, the Organization becomes inaccessible. Customer Data is removed from active systems as Lizio completes periodic manual review before final deletion, which may take a limited additional period. Restricted safety copies and ordinary backups may persist temporarily through controlled retention and backup cycles and are not used for ordinary business purposes. No recovery is guaranteed once the 30-day period has elapsed.
Personal-account deletion. Unnecessary personal profile data may be deleted or anonymized, but Organization records, completed actions and legitimate audit identifiers may remain where needed to preserve business records, security and accountability.
Reminder, security and dispute evidence. Minimized delivery, configuration, audit and security metadata may be retained for up to five years after the relevant event or closure where reasonably needed to address disputes, demonstrate actions taken or defend legal claims. A legal hold or active proceeding may require longer retention.
Deletion audit record. Where a deletion-audit mechanism exists for a given event, it is retained for up to five years after completion of deletion, unless a legal hold requires longer retention.
Accounting, payment and tax records. Retained for the period required by applicable law, generally up to ten years where Swiss accounting or tax rules apply.
Anonymized information. Information genuinely anonymized so that no individual is identifiable may be retained and used without a fixed period.
Lizio may delete data earlier than any period above where requested and lawful, where it is no longer needed, or for security or legal reasons. It may retain limited data longer where a binding legal requirement, dispute, investigation or legal hold applies.
An individual’s request for erasure of their own personal data under applicable data-protection law (see Individual rights, below) is handled separately from, and is not automatically subject to the timing of, the Organization-deletion process described above.
11. Cookies and similar technologies
Lizio’s websites and application may use cookies, local storage and similar technologies for authentication, session continuity, security, preferences, diagnostics and analytics. Strictly necessary technologies may be used without consent where permitted because the Service cannot function securely without them.
Where consent is legally required for analytics or another non-essential purpose, Lizio will request that consent before activating the relevant technology and provide a way to change the choice. Available cookie controls or a cookie banner will provide further details about the technologies currently used, their purposes, providers and durations.
12. Service and marketing communications
Lizio sends essential communications concerning accounts, security, reminders, billing, ownership, deletion, support and legal matters. These are part of operating the Service and generally cannot be disabled while the relevant account or Organization remains active.
Marketing communications are sent only as permitted by law. A recipient may opt out through the message or by contacting Lizio. Opting out of marketing does not stop essential service communications.
13. Security
Lizio uses reasonable technical and organizational measures appropriate to the nature of the data, the risks, and the resources of a single-operator business, which may include access controls, authentication protections, encryption in transit, restricted provider access, logging, backups, vulnerability management and incident procedures.
No internet service or storage system is completely secure, and Lizio makes no representation that any particular security outcome is guaranteed. Customers and Users must protect their credentials, use individual accounts, maintain accurate contact information and promptly report suspected unauthorized access to contact@lizio.io.
14. Individual rights
Depending on the applicable law and Lizio’s role, an individual may have rights to:
request confirmation and access to personal data;
correct inaccurate or incomplete personal data;
request deletion or restriction of processing;
object to processing based on legitimate interests or to direct marketing;
receive certain personal data in a portable format;
withdraw consent for future processing where consent is the basis; and
complain to a competent supervisory authority.
Requests may be sent to contact@lizio.io. Lizio may verify identity and authority, clarify the request and apply lawful exceptions. Rights are not absolute; for example, Lizio may retain data required by law or needed to establish, exercise or defend legal claims.
For Customer Data controlled by a Customer, the individual should contact that Customer directly. If Lizio receives such a request, it may decline to act on it directly and instead refer the request to the Customer, assisting the Customer only as required by law and, where applicable, under a Data Processing Agreement.
In Switzerland, complaints may be addressed to the Federal Data Protection and Information Commissioner (FDPIC), www.edoeb.admin.ch. Individuals in the EEA or United Kingdom may also complain to the supervisory authority responsible for their usual residence, work or the alleged infringement.
15. Children
The Service is intended only for business and professional use by persons aged 18 or older. Lizio does not knowingly offer accounts to children or intentionally collect children’s personal data for its own purposes.
16. Changes to this Notice
Lizio may update this Privacy Notice at any time as the Service, providers or legal requirements change. The updated version will state its effective date. Where a change materially affects individuals or additional notice is legally required, Lizio will provide an appropriate notice through the Service, by email or on the website before the change takes effect where practicable.
17. Contact
Questions, requests or complaints about personal data may be sent to:
Lizio Rolli, Seestrasse 137B, 8800 Thalwil, Switzerland | Email: contact@lizio.io
Language
This Notice is drafted and issued primarily in French, which is the governing language. Translations, including this English version, are provided for convenience only and have no independent legal effect. In case of any conflict, ambiguity or divergence between a translation and the French version, the French version prevails.