Getting a credit means sharing personal, sometimes sensitive information: income, expenses, family situation, banking history. We know what that represents, and we don't take it lightly. This charter is not just another legal document in a file — it's the plain-language translation of how we think about our relationship with your data, from the design of our products to the last day of your contract.
It complements our data protection policy, which sets out the legal framework, the legal basis for each processing activity, and the precise procedures for exercising your rights. Here, we'd rather talk to you simply: here's what we promise you, and how we keep that promise every day.
Our principles
It often starts with something simple: you type an amount and a term into our personal loan simulator, in a few seconds, without even creating an account. At this stage, we don't ask for your name, your income, or your family situation — because we simply don't need them to give you a first estimate of your monthly payment. This is the minimisation principle as we understand it at Lendovia: each piece of data is tied to a specific step in your journey, and we only ask for it once it genuinely becomes useful in order to help you.
It's only when you decide to turn that simulation into a financing application that the conversation changes. At that point, we need to know more about you: your income to check your repayment capacity, your expenses to make sure the credit stays affordable, your family situation because it affects your budget, sometimes a credit history to put it all in context. Each piece of information serves a purpose we can explain to you if you ask — never a generic purpose of "profiling" or collecting data just in case.
In practice, this means that every form field we ask you to fill in always has a reason to exist. If a product team wants to add a new question to a journey, they must be able to justify why that piece of information is needed at that specific point — and if the answer isn't convincing, the field doesn't get added. It's a discipline more than a one-off rule, and it applies to every new product we launch.
When you submit a form on our site, the information leaving your screen doesn't travel unprotected across the internet: it's encrypted the whole way, a bit like sending your mail in a sealed envelope rather than on a postcard that anyone could read along the way. This is a technical baseline we consider non-negotiable, whatever the apparent sensitivity of the form — a simple simulation and a complete application receive exactly the same treatment.
Once your data reaches our systems, access isn't open to the whole company. An advisor processing your application can view the information needed to handle it; an advisor who has never had your file in hand cannot. This principle — access organised by role and genuine need to know — means that at every level of the company, permissions are set according to a person's actual job, not their seniority or hierarchical position.
Finally, your data is hosted on servers located within the European Union. This choice isn't a technical detail: it means your data remains subject to the European data protection framework, one of the most demanding in the world, rather than being transferred to jurisdictions where the safeguards would be less certain. For a client entrusting us with their financial situation, this is a guarantee we consider essential, not just a marketing argument.
Many of us have already had this experience elsewhere: signing a contract online, ticking a box without really reading what it involved, then discovering months later — on page 27 of a document nobody reads to the end — that some information had been shared with a partner without any memory of being told. We wanted to avoid that after-the-fact sense of confusion right from the design of our journeys.
In practice, when we ask you for sensitive information — your income, your employment situation — we tell you at that exact moment why we need it, how long we plan to keep it, and whether it's likely to be shared with a third party involved in your application, such as an insurer for borrower insurance. This explanation isn't relegated to the terms and conditions: it appears right when the question arises for you, under the relevant field or in an easy-to-find tooltip.
More broadly, we also try to strip unnecessary jargon out of our communications. "Processing for scoring purposes" becomes "we use this information to assess your repayment capacity"; an abstract retention period becomes a sentence stating a concrete, understandable duration. It isn't always easy to write, but we believe being upfront is something we owe you, not an optional nicety for us.
This principle isn't just a statement of intent: it translates very concretely into your client area, where you can at any time view the information we hold about you, correct an outdated address or phone number, or start a request to exercise one of your rights — access, rectification, erasure, objection. We wanted these actions to be accessible without having to hunt for a hidden form or send a registered letter just for a simple update.
When you submit a more formal request, for example an erasure request, here's what actually happens on our end: your request is received and passed to the team responsible for data protection, which first verifies your identity to make sure it's really you, then identifies all the systems where your data is present. If a legal reason requires us to keep certain information despite your request — an accounting obligation, for example — we explain that to you clearly rather than handling it silently.
We strive to respond to these requests quickly, within a reasonable time and, in any case, within the framework set by applicable regulations. You don't have to justify your request beyond what's strictly necessary to verify your identity: staying in control of your data should remain a simple right to exercise, not an obstacle course.
Data that no longer serves any purpose is, as a matter of principle, data we no longer have any reason to keep. This isn't just a matter of common sense: it's a commitment we actively try to uphold, rather than letting information pile up by default in our systems over the years.
In practice, this means each category of information — your simulation data, your financing application, your exchanges with an advisor — is tied to a defined period, worked out based on its actual use and our legal obligations. A simulation that never became an application isn't meant to stay indefinitely in our systems; the documents of an active credit file are kept for the entire term of the contract, then for the additional period required by regulation for accounting or anti-fraud reasons.
We detail all these periods, category by category, in our data retention policy: that's where you'll find the full, precise table. Here, we'd rather give you the spirit of it: we don't keep data indefinitely — keeping a piece of data must always be justifiable, and the day that justification disappears, deletion must follow.
There are lines we don't cross:
Here's a concrete example: if a business partner wanted access to your file to offer you a product unrelated to your credit — an offer with no connection to your financing, for instance — we would refuse that access, regardless of the nature of our relationship with that partner. Similarly, we never turn a pre-ticked box into implied consent: if we wanted to use your data for a purpose beyond managing your file, we would ask you explicitly, and you would remain free to decline without this affecting the handling of your credit application.
Behind every use of data, there's a team that has thought about the necessity and proportionality of that processing. Our Data Protection Officer oversees compliance with these principles day to day, trains our staff, and regularly audits our practices. This charter evolves alongside our products and the regulations; it nonetheless remains true to a single goal: that the trust you place in us is always deserved.
In practice, this takes the form of periodic internal reviews of our practices, regular training sessions for teams handling sensitive data, and a review of this charter with every significant change to our products or the regulations. This isn't a one-off exercise done once and forgotten: it's ongoing work, carried out by several teams — legal, security, product — who coordinate to make sure our practice stays true to the commitment written here.
Contact
For any question about the protection of your data, contact us from your client area or see our data protection policy for the full legal detail.
If any point in this charter seems unclear to you, or if you'd simply like to know more about how your data is handled, our team is happy to listen.
We'd rather answer a question asked too early than clear up a misunderstanding discovered too late. Whether you're already a client or simply comparing our offers before committing, don't hesitate to reach out: understanding how your data will be handled before entrusting it to us is, in our view, an essential part of a well-built relationship of trust.