The GDPR requires any organisation processing personal data to keep it only for the period strictly necessary for the purposes for which it was collected. This is the "storage limitation" principle: Lendovia does not keep your data indefinitely or by default, but for periods defined in advance for each category of data and each purpose — simulation, processing an application, managing an ongoing contract, accounting or legal obligations, or handling a dispute.
These periods take into account both our operational needs and the legal and regulatory obligations that apply to a consumer credit institution, particularly in accounting, tax, and anti-money-laundering and counter-terrorist-financing (AML-CTF) matters. Once these periods have elapsed, your data is deleted or anonymised, unless a legal obligation requires otherwise.
Key retention periods
3 years — Simulation data (prospects), from the last contact.
3 years — Refused or withdrawn applications, from the decision.
5 years — Client data, after the end of the contract.
5 years — Proof of identity and supporting documents (AML-CTF).
13 months — Cookies and login data.
5 years — Complaints and disputes.
This principle is based on Article 5(1)(e) of the GDPR, which prohibits keeping data in a form that permits identification of data subjects for longer than is necessary for the purposes for which it is processed. This is not merely a best-practice recommendation but an obligation, non-compliance with which exposes an organisation such as ours to penalties imposed by the Commission Nationale de l'Informatique et des Libertés (CNIL), which can reach several million euros or 4% of worldwide annual turnover, whichever is higher, as well as reputational risk and a loss of our clients' trust. Keeping data beyond the justified period is never a neutral choice: every month of unnecessary retention is a month during which that data remains exposed to a risk of leakage, hacking or misuse, without any legitimate purpose still justifying it. This is why we have built, category by category, a policy of precise retention periods rather than a single period applied indiscriminately to all the data we process.
Retention periods
When you enter your situation in our online simulator — income, expenses, amount requested, term envisaged, contact details — without this leading to a formal financing application, you remain what data protection law calls a "prospect". For this type of commercial profile, the CNIL recommends retention capped at three years from your last contact with us, and this is the period we apply.
The concept of "last contact" deserves clarification, as it is often misunderstood. It is not the date on which you filled in the simulator, but the date of the last active exchange between you and Lendovia: a new simulation, opening an email sent by our teams, clicking a link in our communications, or contact with our customer service. Each of these events restarts the three-year counter. On the other hand, simply visiting another page on our site without interacting with our commercial communications does not extend this period — we do not track your general browsing for this purpose.
If, at the end of the three years following this last contact, you have not taken any steps towards subscribing, your simulation data is automatically deleted from our commercial databases. You may also, at any time and without needing to provide any reason, object to receiving our commercial solicitations, by using the unsubscribe link included in each communication or by contacting us directly. This objection is processed immediately and results in the cessation of all prospecting, unless you subsequently take active steps of your own.
Once your simulation is converted into a formal credit application, your file enters what we call the review phase: our teams check the supporting documents submitted, contact the relevant bodies to assess your creditworthiness, and then a credit committee decides whether to grant or refuse the financing. Throughout this period, all the data and documents you have entrusted to us — identity, employment and financial situation, bank statements, civil-status documents — are actively retained, as they are essential to the decision-making process.
When the application results in a refusal, or when you decide to withdraw it before it is completed, this information is not deleted immediately: it is kept for a further three years. This period corresponds to the time during which the Autorité de contrôle prudentiel et de résolution (ACPR) or the CNIL may ask us to justify the criteria applied to grant or refuse a given application, as part of their oversight of the consumer credit sector. It also allows us, should you reapply in the meantime, to retrieve the context of your previous application rather than asking you to reconstruct everything from scratch.
A refused application and a withdrawn application are not treated identically internally, even though the final retention period converges on three years in both cases. A refusal is documented with a recorded rationale, kept to respond to any dispute you may raise or to a regulatory review of our lending practices. A withdrawal — when you decide yourself to abandon the application, for example because you found a better offer elsewhere or changed your project — does not include this rationale, and correspondingly reduces the data retained: only the documents necessary to trace the application are kept.
As soon as a credit contract is signed, you become a Lendovia client rather than simply an applicant, which changes the nature of our relationship with your data. Throughout the term of the contract — whether it is a personal loan repaid over five years or revolving credit used over a longer period — we actively retain all the information necessary for its proper performance: identity, bank details, repayment history, any payment incidents, exchanges with our collections department where applicable, and contractual amendments.
When the contract ends, whether at its normal term or following full early repayment, your data is not deleted overnight. French law provides for a five-year civil limitation period, during which legal action remains admissible — on your initiative in the event of a disagreement over the final account balance, or on ours in the event of an unpaid debt. It is this limitation period that justifies keeping your data for five years after the end of the contract, rather than any wish to use it beyond what is necessary.
In the case of early repayment, the reasoning remains the same, but the starting point of the five years is brought forward to the effective repayment date rather than the term originally set out in the contract. In practice, a personal loan taken out over sixty months but paid off early after thirty months will have its data kept until five years after that thirtieth month, not five years after the sixtieth.
As an institution operating in the consumer credit sector, Lendovia is subject to the due diligence obligations set out by the framework for combating money laundering and terrorist financing (AML-CTF), derived from the French Monetary and Financial Code and successive European directives on the matter. This framework requires us to verify your identity before entering into a business relationship with you, and to keep a record of this verification for a set period after the end of that relationship, independently of the other retention periods applicable to your file.
In practice, this obligation covers the documents used to establish your identity and situation at the time of subscription: national ID card, passport or residence permit, proof of address, as well as documents evidencing your income such as payslips or tax notices. These documents are kept for five years from the end of the contractual relationship linking you to Lendovia, whether this ends through the contract reaching its term, early repayment, or any other means of termination.
Throughout this period, these documents are stored separately from data used day to day for commercial management, in environments whose access is restricted to staff authorised by virtue of their compliance, audit, or judicial or administrative request-response functions. They are neither consulted nor used for commercial purposes during this archiving phase, their sole purpose being to allow Lendovia to respond, where necessary, to requests from TRACFIN, the ACPR, or any competent judicial authority.
Every visit to our site generates what is known as login data: IP address, timestamp of the visit, pages viewed, type of device and browser used, as well as, where applicable, the identifiers placed by the cookies and trackers that we or our partners use to measure audience, facilitate your browsing or, subject to your consent, personalise the advertising content you see elsewhere on the internet.
For this type of data, the CNIL recommends a retention period not exceeding thirteen months from the placement of the tracker or the collection of the data, renewable at each new visit if you consent again. Beyond this, this information must be deleted or made anonymous, otherwise it would no longer serve any legitimate purpose given the actual period during which a browsing profile remains relevant.
This page does not detail all the trackers used by Lendovia or the precise purposes pursued by each of them: this level of detail, as well as the ways to set or withdraw your consent at any time, are described in our cookie policy, which we invite you to consult for full information.
A complaint and a dispute do not refer to exactly the same thing, even though both give rise to extended retention of data concerning you. A complaint refers to the expression of disagreement or dissatisfaction that you address directly to our customer service or our mediator — for example regarding the calculation of an instalment or the handling of a file — and which can be resolved without judicial intervention. A dispute, on the other hand, involves initiating a formal legal remedy, before a civil court or, more rarely, as part of criminal proceedings.
In both cases, the related data — correspondence exchanged, documents produced, and any decisions rendered — is kept for five years, a period corresponding to the legal remedies available under French civil law and which allows you, just as it allows us, to assert your rights or defend yourself should the matter be brought before a court after an initial unsuccessful attempt at amicable resolution.
When a dispute is resolved quickly and amicably, this does not systematically reduce this five-year period: the possibility that a disagreement may resurface, or that a party may go back on an agreement reached, justifies keeping a complete record of the file throughout this period, even in the absence of legal proceedings. However, this retention does not mean that this data is used for purposes other than following up on the file concerned: it remains confined to its original purpose and is never used, for example, to feed our commercial prospecting activities.
When the applicable retention period comes to an end, your personal data is either permanently deleted from our systems or irreversibly anonymised where it is of statistical interest, in which case it no longer allows you to be identified. In certain cases provided for by law, particularly to meet our accounting obligations or to manage a dispute, data may be subject to interim archiving: it is then kept separately, with access strictly limited to authorised individuals, until the applicable legal period expires, before being permanently deleted.
The distinction between deletion and anonymisation is more than a technical nuance. Deleting data means erasing it from our systems entirely, so that it can no longer be consulted or reconstructed. Anonymising data, by contrast, consists of transforming it so that it can no longer, by any means, be linked back to you: for example, a simulation file deleted after three years disappears entirely, whereas the average amounts borrowed or the most commonly requested repayment terms may be kept in aggregated, anonymised form in our internal statistics, without these figures ever again referring to your identity, your file, or any other data allowing you to be individually recognised. It is this second path that allows us to improve our offers and our simulator over time, without keeping any personal data concerning you within the meaning of the GDPR.
You have rights over your personal data at any time — access, rectification, erasure, restriction, portability and objection. For full details of these rights and how to exercise them, see our data protection policy.
It sometimes happens that a client asks us to delete their data early, before the applicable retention period has expired, by exercising their right to erasure. This right is not, however, absolute: the GDPR itself provides that it does not apply where processing is necessary for compliance with a legal obligation to which Lendovia is subject, for example our accounting obligations or those arising from the AML-CTF framework described above. In this case, we cannot immediately delete the data concerned, but we strictly limit its access and use: it ceases to be used for any purpose other than the one justifying its retention, and in particular for any commercial prospecting, until the legal period expires. Whenever we receive such a request, we systematically inform you of the data we must continue to keep, the legal basis obliging us to do so, and the date on which it will actually be deleted.