Global Privacy & Data Protection Policy
Data protection policy detailing compliance with ODPC (Kenya DPA 2019), GDPR, and SOC 2 security standards for financial data processing.
LOANVAULT MFI GLOBAL PRIVACY & DATA PROTECTION POLICY
Effective Date: September 16, 2026
Document Reference:LV-POL-2026-V2
Compliance Standards: Office of the Data Protection Commissioner (ODPC Kenya), EU GDPR, SOC 2 Type II Security Principles
---
1. LEGAL FRAMEWORK & STATUS DESIGNATION
Tenant Organization as Data Controller: The Tenant Organization (the specific SACCO, Chama, or MFI to which a member belongs) serves as the Data Controller. The Controller establishes the business reasons for member information collection, KYC evaluations, and credit scoring.
Loan Vault MFI as Data Processor: Loan Vault MFI operates strictly as the Data Processor. We host, structure, and compute records solely under the direct instruction of the Controller and to provide cloud SaaS services.
---
2. DATA CATEGORIES COLLECTED AND PROCESSED
Demographic & KYC Data:Full legal name, National ID/Passport number, date of birth, residential and postal address, contact phone numbers, and email accounts.
Beneficiary Allocations: Next of Kin records, relationship details, percentage benefit splits, and emergency contact points.
Ledger & Transaction History:** Loan principal requests, repayment references, Safaricom M-Pesa receipts, Stripe card-payment references, savings deposits, share allocations, and historical statement lines.
Telemetry & System Logs: Network IP addresses, browser fingerprint headers, immutable administrative event logs, and timestamped audit entries retained for compliance and anti-fraud monitoring.
---
3. LEGAL GROUNDS FOR DATA PROCESSING
All processing through LoanVault MFI is anchored on recognized statutory bases:
Contractual Necessity: Processing essential to calculate repayment terms, disburse borrowed sums, track shares, and uphold membership contracts.
Statutory Compliance: Record retention required by financial accounting, anti-money laundering (AML), and counter-terrorist financing (CTF) mandates.
Explicit User Consent: Express opt-in confirmations given during onboarding, Next of Kin nominations, or optional testimonial publication.
---
4. SYSTEM ENCRYPTION & MULTI-TENANT ISOLATION (SOC 2 CONTROLS)
Cryptographic Safeguards: Communications in transit are encrypted via TLS 1.3. Tenant credentials and payment secrets (such as M-Pesa Consumer Keys, Secrets, and Passkeys) are encrypted at rest using AES-256 with dedicated master key segregation (`MPESA_MASTER_KEY`).
Row-Level Partitioning:The infrastructure strictly enforces database-level Row-Level Security (RLS). No organization, administrator, or member can view, query, or expose data belonging to another tenant workspace.
Tamper-Evident Audit Trails: Administrative actions—such as balance overrides, role reassignments, and loan decisions—are written to an append-only audit trail to prevent untraceable record adjustments.
---
5. SUB-PROCESSORS & THIRD-PARTY TRANSFERS
Personal and financial records are never sold, rented, or distributed to advertising platforms. Information transfer is strictly restricted to essential service sub-processors:
Payment Switches (Mobile Money): Safaricom Daraja M-Pesa and integrated banking rails solely for validating payment amounts and executing member-directed transactions.
Card Payment Processor (Stripe): For Tenant Organizations operating outside Kenya, or members who elect card-based payment, Stripe, Inc. independently processes checkout sessions, cardholder data, currency conversion, and cross-border payouts under its own PCI-DSS Level 1 certification. Card numbers are never transmitted to or stored on LoanVault MFI servers.
Automated System Messaging: Dedicated cloud mail relays configured to distribute transactional receipts, login tokens, and status reminders from platform domains (`no-reply@loanvaultmfi.com`).
Law Enforcement & Regulators: Regulatory bodies (e.g., ODPC, Central Bank, judicial courts) solely upon presentation of a lawful, valid, and enforceable court order.
---
6. MANDATORY DATA BREACH PROTOCOL (72-HOUR NOTIFICATION)
If a confirmed system breach or security incident compromises personal data, the Platform Provider will inform impacted Tenant Administrators within seventy-two (72) hours of technical verification, providing an impact analysis and containment report in accordance with ODPC guidelines.
---
7. DATA RETENTION, DISPOSAL & SUBJECT RIGHTS
Statutory Retention: Financial transaction entries and immutable audit logs are archived for the statutory duration required by financial recordkeeping laws (typically 5 to 7 years) and cannot be deleted while outstanding liabilities remain.
Member Rights: In accordance with the Kenya Data Protection Act 2019 and global privacy standards, members retain rights to request access to their personal records, demand updates to inaccurate information, and lodge privacy concerns.
Support Inquiries: Privacy requests should first be submitted to the Tenant Organization's compliance officer. System inquiries may be directed to platform support through the support drawer or by emailing `support@loanvaultmfi.com` / `loanvaultmfi@gmail.com`.