Privacy policy
Last updated: 25 September 2026
This page explains which data LetzCheck uses, why, and for how long. We wrote it in simple words. If you have a question, write to us: [email protected].
1. Who is responsible for your data?
Data controller:
- LetzCheck, a service operated by KRP (sole proprietorship, Business Registration BR 41625695)
- Address: 18 Caine Road, Hong Kong
- Contact for all requests about your data: [email protected]
2. Two different roles
LetzCheck does not have the same role for all data.
- Visits (the clock-ins made at a building): the client decides what they are used for. The client is the property manager or owner who subscribed to LetzCheck. We process these visits for the client, following its instructions. Here we are a “processor” (Article 28 GDPR).
- Accounts, website, support, billing and email service: LetzCheck decides. Here we are the “controller”.
For a question about the visits at a building, you can also contact the client (the property manager or owner).
3. Which data do we use?
Your account
- Your first name and last name
- Your email address
- Your job title (if you give it)
- Your phone number and whether you use WhatsApp (if you give them)
- Your language
- The company you belong to
- Your password: it is stored in a protected form (hash). Nobody can read it, not even us.
- For the LetzCheck team: the secret code for two-factor authentication
- The date of your last login
Visits (clock-ins)
- The company doing the work
- The NFC card or place tag
- The date and time
- Arrival or departure
- The service performed
- Only if the person forgot the company code: the reason they wrote
When a person clocks in without an account, their name is not recorded. If a person clocks in while logged in to their account, the visit is linked to that account.
Phone remembered for clock-in
We place a cookie on the phone. It remembers which company the phone belongs to. It does not contain your identity.
Technical data
- IP address and date of logins and important actions (security log)
- A session cookie to keep you logged in
Support
- Your help requests (tickets) and messages
- Screenshots you attach
- Emails sent to [email protected]
Emails sent by LetzCheck
We send invitations, codes, reports and invoices. We keep a copy to check that they were delivered.
The @letzcheck.lu email service
It is only for the LetzCheck team. The content of the mailboxes (emails, contacts, calendars) is stored on our server. The mail server and the anti-spam system also keep technical logs.
Billing
- Company name
- Address
- VAT number
- Billing email
- Invoices
Contract signature
When a client accepts the general terms and conditions of sale, we keep proof of the agreement: the first name, last name and email of the person signing, the place (“signed at”), the date and time, the IP address, the browser, the language and a fingerprint of the signed text.
Automatic reports
The report name, the sites chosen and the recipients’ email addresses. For each sending: the date, the format and the recipients.
Card orders
The delivery address, the number of cards and any comment.
4. Why, and on what legal basis?
| Why | Legal basis (GDPR) |
|---|---|
| Provide the LetzCheck service | The contract (Article 6.1.b) |
| Keep the service secure and prevent fraud | Our legitimate interest (Article 6.1.f) |
| Prove that a service was performed, in case of a dispute | Legitimate interest (Article 6.1.f) |
| Issue invoices and keep accounts | A legal obligation (Article 6.1.c) |
| Answer your help requests | The contract (Article 6.1.b) or our legitimate interest (Article 6.1.f) |
5. How long do we keep your data?
| Data | How long |
|---|---|
| Visits (clock-ins) | 5 years, then deleted automatically. This is the period to prove a service in case of a dispute. |
| Support tickets and messages | 5 years after the last message |
| Invoices and billing data | 10 years (Luxembourg accounting law) |
| Contract signature and card orders | For the whole contract, then 10 years (proof of the contract) |
| Automatic reports | As long as the report exists. Sending history: 12 months. |
| User account | As long as the account exists. Deleted immediately if you delete it. The visits stay, but are no longer linked to a person. |
| Security log (IP addresses, logins, actions) | 12 months |
| Login sessions | 30 days after last use |
| Phone remembered for clock-in | 1 week after last use (immediately if you ask for it to be forgotten) |
| Invitations never activated | 30 days after the last invitation was sent |
| Copies of emails sent | 90 days, attachments included (reports, export of a deleted place) |
| Emails received by support | 90 days after delivery (spam: 30 days) |
| Web server logs | 14 days |
| Mail server logs | 4 weeks |
| @letzcheck.lu mailboxes | As long as the staff account exists. Deleted 30 days after the account is deleted. |
| Temporary export files (Excel, PDF) | 1 day |
| IP address of a card scan | 2 days |
| Record of an individual client (name, address, phone) | Erased when their last account is deleted (invoices keep their copy: 10 years) |
| Change of property manager (names of the presidents who approved) | As long as the building exists |
| Quote requests, senders allowed to write to support | 12 months |
6. Who can see your data?
- The client (property manager or owner) sees the visits at its buildings.
- People invited by the client (colleagues, the building’s owners’ council) see the visits at the sites they have access to.
- Recipients of an automatic report receive the visits in that report. The client chooses them.
- The LetzCheck team accesses data only for support.
- Our hosting provider: Hetzner Online GmbH. Its data centres are in Germany (European Union).
- Cloudflare: protects the website against attacks and speeds it up. Connections to the website pass through its servers. It acts only on our behalf (processor) and is certified under the EU–US Data Privacy Framework.
Nobody else. In practice:
- No advertising.
- No tracking, no analytics tools.
- We never sell your data.
- Your data is stored in the European Union, not elsewhere.
- Our emails are sent from our own server.
7. Cookies
We only use cookies that are strictly necessary for the service to work. There are no other cookies. That is why we do not ask for your consent with a banner.
| What it does | How long |
|---|---|
| Keeps you logged in | 30 days |
| Remembers the phone for clock-in | 1 week |
| Remembers your language | 1 year |
8. How do we protect your data?
- All connections are encrypted (HTTPS).
- Passwords are protected (hashed) and cannot be read.
- The LetzCheck team uses two-factor authentication.
- NFC cards use keys that change (NTAG 424 DNA).
- We make an encrypted backup every day. It is kept 14 days on our server and 30 days on a second server in Germany.
- Each person only sees what they need for their role.
9. Your rights
At any time, you can:
- see your data (right of access);
- correct your data (rectification);
- have your data deleted (erasure);
- ask us to limit its use (restriction);
- object to its use (objection);
- get your data in a file (portability).
Do it yourself
In the app, go to “My profile” then “My data”:
- “Download my data”: you get a file (JSON) with everything linked to your account.
- “Delete my account”: your account is deleted. If you are the last person in charge of a client account, this is possible once no invoice is left to pay and no subscription is running.
Ask us
Write to [email protected]. We answer within one month.
10. Making a complaint
If you are not satisfied, you can complain to the Luxembourg authority:
Commission nationale pour la protection des données (CNPD)
15, boulevard du Jazz, L-4370 Belvaux
11. Children
LetzCheck is a service for professionals. It is not meant for children.
12. Changes
If this policy changes, we will update this page and the date at the top of the page.