This privacy notice is to let you know how Lendable gathers and processes your personal information.
We are committed to ensuring that your personal data is kept safe and we have put in place appropriate technical and other security measures to protect it.
We are Lendable Limited. Our registered office is at 128 Shoreditch High Street, London, E1 6JE. We are registered in England and Wales under company number 08828186. We are registered on the Information Commissioner’s Office (ICO) Register of Data Controllers under registration number ZA041704.
We can be contacted:
by post at 128 Shoreditch High Street, London, E1 6JE;
by email at email@example.com;
or by phone on 020 3322 1948.
Our Data Protection Officer can be contacted by post at the address above.
We collect personal data about you in the following ways:
We may hold and use various types of personal information collected at the start of, and during your relationship with us. We will limit the collection and processing of these personal data to what is necessary to achieve the purposes identified in this notice.
The information you provide to us must be correct, accurate, complete and not misleading.
Personal information may include:
In some circumstances we may also collect and process special categories of personal information. This is to help ensure that our services are accessible and so that we can offer appropriate levels of support where required. We will only process special category data with appropriate explicit consent.
We may use your information:
We may monitor and record calls, emails, SMS and other communications to ensure transactions are executed correctly and for security, quality control, training and fraud prevention purposes.
If we cannot offer you a product, we may check your eligibility for loans and/or other relevant credit products from our panel of trusted lenders and brokers. We will always seek your consent to do this and in assessing eligibility our partners will always use soft checks which will not impact your credit file. Our partners include:
We collect and use your personal information where it is necessary for us to carry out our lawful business activities. Our grounds for processing your data are as follows:
We may process your information where it is necessary to enter into a contract with you or to perform our obligations under that contract. This may include processing to:
We may process your data where it is a legal or statutory obligation on us. This may include processing to:
We may process your information when we have a business or commercial reason to do so. If we do, it must not unfairly go against what is right and best for you. If we rely on our legitimate interest, we will tell you what that is. This may include processing to:
We may use third party companies to provide services on our behalf. This may require these organisations to access and process your personal data. These may include:
One of our communications service providers that we use to send customer emails is located in the USA and is covered by Privacy Shield. Data in or attached to these emails will be processed outside the EEA. It may also be processed by staff operating outside the EEA who work for our provider.
You can find out more about international controls on the ICO Website by clicking on https://ico.org.uk.
To process your application, we will perform credit and identity checks on you with one or more credit reference agencies ("CRAs"). Where you take services from us we may also make periodic searches at CRAs to manage your account with us. To do this, we will supply your personal information to CRAs and they will give us information about you. This will include information from your credit application and about your financial situation and financial history. CRAs will supply to us both public (including the electoral register) and shared credit, financial situation and financial history information and fraud prevention information.
We will use this information to:
We will continue to exchange information about you with CRAs while you have a relationship with us. We will also inform the CRAs about your accounts including settled accounts. If you borrow and do not repay in full and on time, CRAs will record the outstanding debt and payment performance. This information may be supplied to other organisations by CRAs.
When CRAs receive a search from us they will place a search footprint on your credit file that may be seen by other lenders.
Where you have a financial association with someone your records may be linked, so you should discuss your application with them before you make it. CRAs will also link your records together and these links will remain on your and their files until such time as you or your partner successfully file for a disassociation with the CRAs to break that link.
The identities of the CRAs, their role also as fraud prevention agencies, the data they hold, the ways in which they use and share personal information, data retention periods and your data protection rights with the CRAs are explained in more detail at https://www.callcredit.co.uk/crain. Credit Reference Agency Information Notices (CRAIN) are also accessible from each of the three CRAs – clicking on any of these three links will also take you to the same CRAIN document:
Before we lend to you, we undertake checks for the purposes of preventing fraud and money laundering, and to verify your identity. These checks require us to process personal data about you.
The personal data you have provided, we have collected from you, or we have received from third parties will be used to prevent fraud and money laundering, and to verify your identity.
Details of the personal information that will be processed include: name, address, date of birth, contact details, financial information, employment details and device identifiers including IP address.
We and fraud prevention agencies may also enable law enforcement agencies to access and use your personal data to detect, investigate and prevent crime.
We process your personal data on the basis that we have a legitimate interest in preventing fraud and money laundering, and to verify identity, in order to protect our business and to comply with laws that apply to us. Such processing is also a contractual requirement of the services or financing you have requested.
Fraud prevention agencies can hold your personal data for different periods, and if you are considered to pose a fraud or money laundering risk, your data can be held for up to six years.
We use a tool provided by TrueLayer Limited (www.truelayer.com) ("TrueLayer") that allows you to send information on your payment accounts to us and other service providers.
In order to use this service, you will be asked to agree to their Terms of Service and enter your payment account details with TrueLayer or, for Open Banking connections, you will be redirected to your bank by TrueLayer in order to authenticate yourself. The Terms of Service set out the terms on which you agree to TrueLayer accessing information on your payment accounts for the purposes of transmitting that information to us.
TrueLayer is authorised by the UK Financial Conduct Authority under the Payment Services Regulations 2017 to provide account information services and payment initiation services (Firm Reference Number: 793171 ).
If we, or a fraud prevention agency, determine that you pose a fraud or money laundering risk, we may refuse to provide the services or financing you have requested, or we may stop providing existing services to you.
A record of any fraud or money laundering risk will be retained by the fraud prevention agencies and may result in others refusing to provide financing to you. If you have any questions about this, or believe that your information has been processed inaccurately, please contact us at the address above.
Whenever fraud prevention agencies transfer your personal data outside of the European Economic Area, they impose contractual obligations on the recipients of that data to protect your personal data to the standard required in the European Economic Area. They may also require the recipient to subscribe to ‘international frameworks’ intended to enable secure data sharing.
When we first collect your data, we will give you the opportunity to confirm your preferences. Any electronic marketing communications we send you will include clear instructions to follow should you wish to unsubscribe at any time. You may also amend your contact preferences in the following ways:
As a data subject, you have a number of rights:
Your data protection rights are subject to certain restrictions and conditions and financial organisations are required to retain a range of your information for legal and regulatory reasons including responsible lending and the prevention of financial crime. Lendable is required to keep a record of the information reported to the Credit Reference Agencies about you and will therefore retain repayment information regarding your loan for six years from the date that the loan is settled/closed. If your account is recorded as defaulted, the data is kept for six years from the date of the default. This may be extended where we require this to bring or defend legal claims.
If you think that any of the personal data we hold about you is wrong or incomplete you have the right to challenge it.
We will not make a charge for handing your rights request, unless we consider it to be manifestly unfounded or excessive involving a disproportionate effort (particularly if this is repeated request). If you would like to exercise any of the rights outlined above, you can make a request verbally by calling 020 3322 1948 or in writing by emailing firstname.lastname@example.org.
We will assess your request and if we decided not to act upon it or place certain restrictions on it, we will inform you of our reasons for this.
You have the right to complain to us and to the data protection regulator, the Information Commissioner’s Office. Their address is: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. They can be contacted by phone on 0303 123 1113 (local rate) or 01625 545745 if you prefer to use a national rate number.
You can find details on how to report a concern at: https://ico.org.uk/make-a-complaint/
We will not typically ask you for any ‘special categories’ of personal data. This is also referred to as ‘sensitive personal data’ and includes information revealing an individual's political opinions, racial or ethnic origin, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data, data concerning health or data concerning an individual's sex life or sexual orientation.
We may process personal data about your health or medical conditions, where we need to understand this to provide you with support, or to make adjustments in how we provide you with information. Companies acting on our behalf specialising in customer reconnection and information gathering visits may also process personal data about your health or medical conditions for this purpose.
This information will only be processed where you have provided your explicit consent or we are otherwise allowed or required to by law.
We will retain your personal data for as long as we are required to under relevant legislation and regulation, and where no specific rules apply, for no longer than it is necessary for our lawful purposes. This will usually be no more than six years from the end of our relationship with you. The retention period of your personal data may need to be extended where we require this to bring or defend legal claims.
We may also retain data for longer periods for statistical purposes, and if so we will anonymise this.
We may use your personal data in automated processes to make decisions about you. You have the right not to be subject to a decision based solely on automated processing, if this will have a legal or other significant effect on you (certain exceptions apply).
We use automated decision making in:
We may use cookie technology on our website to collect some of the information detailed in this policy.
When a visitor requests any page from our website, our web servers automatically obtain that visitor’s domain name and IP address. This information does not contain sensitive data about our users and is critical to the functioning of all websites. An IP address serves as the return address, much like a post code, of your device when you request to see a webpage which allows us to send the information you want back to you. We only use this data to investigate and prevent fraud or abuse of our website.
This site uses the web analytics service called Inspectlet. Inspectlet can record user clicks, movements, scrolling and selected non-personal text users enter into our website. The service does not gather personally identifiable information. We use this service to improve our website, make it more user-friendly and monitor that everything is performing as intended.