Legal

Privacy Policy

ROMM Technology operates LendVoy for financial institutions. This policy explains what data we handle, why, and the controls available to you.

Last updated 28 August 2026

1. Roles

For records your institution creates about its own customers and staff, your institution is the data controller and we act as processor on your instructions. For your account, billing and support interactions with us, we act as controller.

2. Data we handle

Account data (names, work email, role), institution data (registration details, branches), operational records your staff enter (members, applications, loans, repayments, documents), billing records held by our payment processor, and technical logs such as IP address, device and audit events.

3. Why we process it, and on what legal basis

We process account and institution data to create and administer accounts and to perform our contract with you; operational records to provide and support the service on your institution's instructions; technical logs and audit events for security, fraud prevention and product improvement, on the basis of our legitimate interests; billing records to meet legal and tax obligations; and marketing communications only with your consent, which you can withdraw at any time. We do not sell personal data and do not use your operational records for advertising.

4. Tenant isolation and security

Every record is bound to a tenant identifier and access is enforced in the database through row-level security, not only in the application. Data is encrypted in transit and at rest, documents are stored in private buckets, privileged actions are logged immutably, and access is restricted to authorised personnel through role-based controls.

5. Who we share data with

We share personal data with: service providers and subprocessors that host our infrastructure, database, and transactional email delivery; Paddle.com, our Merchant of Record, for the sale of subscriptions, subscription management, payments, tax compliance and invoicing; professional advisers such as legal and accounting firms where needed; and authorities or regulators where required by law. Each provider is bound by data-processing terms. A current list of subprocessors is available on request.

6. Retention

Operational records are retained while your subscription is active and for 30 days after termination to allow export, unless a longer period is required by financial regulation or instructed by your institution. Audit logs are retained for the statutory period applicable to your jurisdiction.

7. Your rights

Depending on your jurisdiction you may request access, correction, deletion, restriction or portability of your personal data. Borrowers and members should contact their institution first; we support institutions in fulfilling those requests. Email privacy@lendvoy.com for privacy enquiries.

8. International transfers

Where data is processed outside your country, we rely on recognised transfer mechanisms such as standard contractual clauses with our providers.

9. Cookies

We use strictly necessary cookies and local storage for authentication and session continuity. We do not use advertising cookies.

10. Changes and contact

We will post updates to this policy on this page and notify customers of material changes. Questions can be sent to privacy@lendvoy.com or to the postal address below.

Contact us

Registered address

Airfield, Sinkor, MonroviaLiberia, West Africa