Data processing agreement
These processing terms apply whenever Lendlogix handles personal data on a lender's behalf. They form part of the terms of service.
Last updated 12 August 2026
1. Roles and scope
The lender is the controller; Lendlogix Ltd is the processor. Processing covers applicants, borrowers, guarantors and lender staff, for the purpose of operating the lender's workspace, for the duration of the subscription.
2. Instructions
We process personal data only on the lender's documented instructions, which include the configuration made in the workspace, unless required otherwise by law — in which case we notify the lender where permitted.
3. Security measures
- Tenant isolation enforced by row-level security on every table, for staff and borrower access alike.
- Encryption in transit, and at rest for stored data and lender payment credentials.
- Role-based access: admin, underwriter, collections, viewer and borrower scopes.
- Audit logging of staff actions on applications, loans and arrears cases.
- Least-privilege access for our personnel, under confidentiality obligations.
4. Sub-processors
We may appoint sub-processors under equivalent written terms, and remain responsible for their performance. Lenders are notified before a new sub-processor is added and may object on reasonable data-protection grounds.
5. Assistance
We assist the lender with data subject requests, data protection impact assessments and regulator engagement, taking into account the nature of processing and the information available to us.
6. Breach notification
We notify the lender without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting their workspace, with the information needed for the lender's own reporting duties.
7. International transfers
Data is stored in the UK/EU. Any transfer outside that area relies on an adequacy decision or the UK International Data Transfer Addendum to the EU standard contractual clauses.
8. Return and deletion
On termination the lender may export its data for 30 days, after which we delete it from active systems and from backups on the normal backup rotation.
9. Audit
On reasonable notice, and no more than once a year unless required by a regulator, we provide the information needed to demonstrate compliance with these terms.
10. Contact
dpo@lendlogix.app — Lendlogix Ltd, company number 17323677, registered office 128 City Road, London, United Kingdom, EC1V 2NX.
