Data protection policy

Data controller

The GDPR defines the data controller as the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data. Being a data controller therefore involves more than collecting information: it means deciding why this data is collected, how long it is kept, who can access it, and by what means it is protected against loss, alteration or unauthorised access. Lendovia acts in this capacity for all the processing described here: simulation forms, financing applications, and the creation and management of a client area.

This status carries an obligation to demonstrate compliance, known as the accountability principle: the data controller must be able to show, at any time and in particular to the CNIL, that its processing complies with GDPR principles. In practice, this involves keeping a record of processing activities listing each purpose, carrying out impact assessments where the level of risk warrants it, and formalising internal security procedures and processes for handling data subject requests.

This policy applies to all Lendovia's visitors, prospective and existing clients, regardless of the product concerned (personal loan, revolving credit, debt consolidation, borrower insurance). The point of contact for any question relating to data protection is Lendovia's Data Protection Officer (DPO), reachable via the client area, "My data and privacy" section. The DPO is responsible for informing, advising and monitoring compliance with the GDPR within the organisation; they are the natural point of contact with the CNIL as well as with you.

Data collected

The volume of information Lendovia holds about you is not fixed: it grows progressively as you move through your journey, and we never collect data in advance for which we would not yet have a use. This progression illustrates in practice the data minimisation principle set out by the GDPR, under which only data relevant to each step should be collected.

When you visit our credit simulator anonymously, without providing any contact details, we hold no data that directly identifies you: the amounts, terms and rates tested remain simple calculation parameters not linked to a person, except for the technical browsing data described in our cookie policy. As soon as you start a simulation by leaving your contact details to receive a personalised result — first name, email address, phone number — we process data that identifies you, but within a scope limited to what is necessary to contact you again and refine your proposal.

Submitting a complete financing application marks a change of scale: we then collect a much more detailed file, including proof of identity, proof of address, your payslips or tax notices, a bank account statement, details of your recurring expenses (rent, other credits, alimony paid) and, where applicable, documents relating to your project, such as a home-improvement quote or a vehicle purchase order — essential to process your application and assess your repayment capacity. Once the contract is signed, we enrich this file throughout the life of the credit: your client area login details, the history of your instalments and any incidents, exchanges with your advisor, and updated supporting documents in the event of renegotiation.

These categories of data break down as follows:

Purposes of processing

Your data is processed by Lendovia for five specific purposes, each based on its own legal basis detailed below:

We do not process your data for purposes incompatible with these initial purposes, and we limit collection to only the data relevant to each of them, in accordance with the data minimisation principle set out by the GDPR.

Legal bases

Performance of the contract, or pre-contractual steps taken at your request before it is signed (Article 6(1)(b) GDPR), is the basis for the majority of our processing: it allows us to process your simulation, assess your application, and then manage the signed credit — repayment schedules, collection of monthly payments, early repayment or restructuring. Without this legal basis, we simply could not fulfil the mutual commitments the contract places on us and on you.

Legal obligation (Article 6(1)(c)) is the basis for all processing that regulations impose on us regardless of your wishes: verifying your identity and the origin of funds for anti-money-laundering and counter-terrorist-financing purposes, reporting certain atypical transactions to TRACFIN, registering with the FICP in the event of a confirmed incident, or retaining documents for the periods required by the French Monetary and Financial Code or the General Tax Code.

Legitimate interest (Article 6(1)(f)) covers processing we consider necessary for conducting our business, without disproportionately affecting your rights: fraud detection, securing your client area against fraudulent access, and prospecting addressed to our current and former clients regarding products similar to those already taken out. This legal basis requires an ongoing balancing of our interest against yours, and no longer applies as soon as you exercise your right to object.

Consent (Article 6(1)(a)) applies where none of the preceding bases can justify processing — typically for electronic communications sent to prospects not yet in a contractual relationship, or for cookies not strictly necessary for the site to function. It must be freely given, specific, informed and unambiguous; you may withdraw it as easily as you gave it, without affecting the lawfulness of processing carried out before withdrawal.

Data recipients

Internally, access to your data is compartmentalised according to the need-to-know principle: sales advisors responsible for assessing applications see the information necessary to review your file (income, expenses, project financed); risk management and fraud prevention teams access the elements necessary to verify your identity and detect anomalies, without necessarily seeing the detail of your commercial exchanges; customer service has an application-tracking-oriented view; collections teams only intervene if a payment incident occurs. Each access is logged and limited to only the data useful for the task performed.

Your data is also passed on to technical processors who act on Lendovia's behalf and according to its written contractual instructions, governed by the safeguards required by the GDPR: confidentiality clauses, security measures, and audit rights. These are typically a hosting provider ensuring secure storage of data within the European Union, an electronic signature provider for contracts signed online, and a letter, email or SMS sending provider for your repayment schedules, reminders or notifications. None of these providers is authorised to reuse your data for its own purposes.

Finally, your data may be passed on to public authorities in cases precisely governed by law: registration with the FICP (the French register of individuals' credit repayment incidents) held by the Banque de France in the event of a confirmed incident on your credit; reporting to TRACFIN, the French financial intelligence unit, where a transaction suggests a risk of money laundering; disclosure to judicial authorities on request or by court order; or transmission to banking and financial sector supervisory authorities as part of their oversight duties.

Transfers outside the European Union

The data processing described in this policy is hosted within the European Union. Should a processor nevertheless process all or part of your data outside the Union — for example as part of international technical support — such a transfer could only take place within a legal framework guaranteeing a level of protection equivalent to that offered by the GDPR.

The mechanism most commonly used for this purpose is the standard contractual clauses (SCCs). These are model contracts drafted and approved by the European Commission, which the data exporter and importer undertake to sign without altering their substance. The Commission designed them to address a concrete difficulty: enabling the international data flows required for economic activity, while imposing precise obligations on the organisation outside the Union — data security, limited access, notification in the event of an access request by a foreign authority, and the data subject's right to act directly against the importer in the event of a breach. These clauses thus recreate, by contractual means, a level of safeguards comparable to that prevailing within the Union, even where the destination country does not benefit from a European Commission adequacy decision.

In the absence of standard contractual clauses, other mechanisms recognised by the GDPR could be used: an adequacy decision, by which the Commission finds that a third country offers a level of protection deemed sufficient, or binding corporate rules within a single group. You may, on request to our Data Protection Officer, obtain information on the safeguards governing a particular transfer.

Your rights

The GDPR grants you seven rights over your personal data, which you may exercise with Lendovia at any time:

To exercise these rights, you can write to our Data Protection Officer via your client area, "My data and privacy" section, specifying the right you wish to exercise and enclosing proof of identity if necessary. We undertake to respond to you within one month, extendable by two months for complex or numerous requests, with an indication of the reasons for this extension.

Complaints

If, after contacting us, you consider that your rights are not being respected, you have the right to lodge a complaint with the competent supervisory authority. In France, this is the Commission Nationale de l'Informatique et des Libertés (CNIL), the reference authority for personal data protection.

Before contacting the CNIL, we recommend that you contact us directly: most difficulties are resolved at this stage, particularly where a simple data update or a shorter response time is involved. If, despite this approach, your rights are still not respected, you can lodge a complaint online at cnil.fr, by post, or in person during the CNIL's opening hours.

For your complaint to be handled effectively, it is helpful to prepare in advance the identity of the organisation concerned, a precise description of the facts and the processing being disputed, the dates of any exchanges already had with Lendovia, and any correspondence exchanged with our Data Protection Officer. Once lodged, the CNIL acknowledges receipt of the complaint, examines it and may request further explanations from the organisation in question; depending on the case, it carries out checks, issues recommendations, or initiates enforcement proceedings if a serious breach of the GDPR is found. Lodging a complaint is free of charge and does not deprive you of any other remedy, in particular the possibility of bringing the matter before the competent civil or administrative courts.

Frequently asked questions

Your data, in detail

Yes, at any time and without needing to provide any justification. Commercial prospecting is based on our legitimate interest or, depending on the channel used, on your consent: in both cases, you can object via your client area or by using the unsubscribe link included in our communications, without this affecting the management of your financing application. Your objection is taken into account promptly and applies to all our solicitation channels — post, email and SMS alike.

Retention periods vary depending on the purpose of the processing and the applicable legal obligations: an abandoned simulation file is not kept for as long as a credit contract that is still being repaid, and certain accounting documents must be kept for several years after the contract is closed. Full details of our retention periods, purpose by purpose, are available in our data retention policy.

No. Lendovia neither sells nor rents your personal data to third parties, whatever the purpose invoked. It is only shared with our technical processors acting strictly on our instructions to carry out a specific task, and, where the law requires it, with the competent public authorities as described in this policy.

You can exercise your rights of access, rectification, erasure, restriction, portability and objection by writing to our Data Protection Officer via your client area, "My data and privacy" section. You may be asked for proof of identity to verify your identity before your request is processed, and we undertake to respond within the legal period of one month.

If your financing application is not accepted, the data already collected is kept for the time strictly necessary to manage this decision and to meet our legal obligations, before being deleted or anonymised. This period allows us in particular to respond to any dispute you may raise or to justify our decision to supervisory authorities. You retain all of your GDPR rights over this data for the entire period it is kept, including the right to request its early deletion if no legal obligation prevents this.