Terms of Service & Platform SaaS Agreement
Legal terms governing software access, separating LoanVault's software infrastructure from tenant microfinance and lending activities.
LOANVAULT MFI TERMS OF SERVICE (SaaS AGREEMENT)
Effective Date: September 16, 2026
Document Reference: LV-TOS-2026-V2
Jurisdiction: Republic of Kenya & International Commercial Arbitration
---
1. B2B SOFTWARE-AS-A-SERVICE PROVISION
Infrastructure Exclusivity:LoanVault MFI ("Platform Provider", "we", "us") delivers enterprise cloud software infrastructure designed for loan portfolio administration, ledger keeping, and cooperative management.
Non-Financial Institution Status: The Platform Provider is not a bank, deposit-taking SACCO, non-deposit-taking credit provider (NDTCP), digital credit provider (DCP), underwriter, or financial broker under the Central Bank of Kenya Act or any corresponding international financial authority.
Decoupling of Credit Liability: All underwriting evaluations, credit checks, loan authorizations, interest rate settings, default penalty enforcement, and debt recovery are carried out entirely by independent tenant organizations ("Tenant Organizations", "MFIs", "SACCOs", "Chamas"). The Platform Provider holds no fiduciary or financial obligations toward borrower end-users.
---
2. STATUTORY LICENSING & REGULATORY OBLIGATIONS
Tenant Warranties: Tenant Organizations confirm that they maintain all mandatory statutory operating licenses, registrations, and corporate governance filings with relevant supervisory bodies (including the Central Bank of Kenya, SASRA, the ODPC, or equivalent cross-border agencies).
Zero Liability for Tenant Non-Compliance: The Platform Provider disclaims all liability for any Tenant Organization's failure to adhere to statutory lending caps, predatory lending restrictions, or financial reporting standards.
---
3. ACCOUNT INTEGRITY & ROLE-BASED ACCESS
Access Separation:** Platform access strictly differentiates between Tenant Administrators and invited Members. Invited Members are restricted strictly to member-facing dashboards without access to administrative configurations or underwriting parameters.
Credential Safeguards: Users are solely responsible for maintaining the confidentiality of login accounts, passwords, and multi-factor authentication tokens. Every transaction or change logged under an authenticated profile is legally attributed to that user.
Session Integrity & Alerts: The platform employs route-guard mechanisms to alert users regarding unsaved edits; however, users remain solely responsible for validating data submissions and saving form records.
---
4. USER CONDUCT, FRAUD MITIGATION & SYSTEM PROTECTION
The Platform Provider reserves the right to immediately suspend accounts, freeze workspace access, and submit forensic reports to criminal and supervisory agencies if any user:
Falsifies Identity: Enters fabricated National Identity numbers, counterfeit passport profiles, forged collateral instruments, or unauthorized mobile lines.
Attempts Exploitation: Initiates automated queries, denial-of-service scripts, SQL injections, vulnerability probing, or reverse-engineering of system logic.
Breaches Tenant Isolation: Attempts to bypass, manipulate, or query row-level security (RLS) barriers that partition independent tenant institutions.
Fabricates Testimonials: Aligns or falsifies member testimonials. Platform security rules strictly prohibit tenant administrators from altering submitted member review text.
---
5. PAYMENT TELECOMMUNICATION APIS & SETTLEMENTS (M-PESA / STRIPE / BANKING)
API Connectivity Only:The platform provides software connectivity to third-party payment switches, including Safaricom Daraja M-Pesa STK push services, Stripe card-payment checkout, and partner clearing rails.
Card Processing (Stripe): For Tenant Organizations operating outside Kenya, or members electing card-based payment, the platform integrates Stripe Checkout for card deposits, loan repayments, and cross-border payouts. Stripe independently receives, processes, and custodies cardholder data under its own PCI-DSS compliance program; the Platform Provider never stores card numbers.
No Fund Custody: The Platform Provider does not intermediate, hold, or custody user payments. All disbursements and repayments transit directly between the user's account and the Tenant Organization's validated Paybill, Till, Stripe, or bank account.
Network Exclusions: The Platform Provider is not liable for carrier downtime, USSD drops, network timeouts, payment routing failures, currency conversion variances, or funds reversal disputes. Dispute inquiries must be directed to the respective carrier, payment processor, or lending organization.
---
6. DISCLAIMER OF CONSEQUENTIAL DAMAGES & "AS-IS" PROVISION
As-Is" Service:** The platform is provided on an "as-is" and "as-available" basis without representations of uninterrupted availability.
Damage Exclusion:To the fullest extent permissible by law, the Platform Provider, its founders, and technical personnel shall not be liable for direct or indirect losses, unrecovered principal, defaulted loan balances, foregone profits, or business disruption resulting from software downtime or network interruptions.
---
7. MUTUAL INDEMNIFICATION & JURISDICTION
Indemnification: The Tenant Organization agrees to indemnify, defend, and hold harmless the Platform Provider from any administrative penalties, civil actions, regulatory sanctions, or third-party liabilities stemming from the tenant's lending practices, member disputes, or statutory breaches.
Dispute Resolution: This Agreement is governed by the laws of the Republic of Kenya. Formal disputes shall be submitted to binding commercial arbitration in Nairobi under the Nairobi Centre for International Arbitration (NCIA) rules prior to pursuing civil litigation.