Scope and responsibility
LendFlow (“LendFlow”, “we”, “us” or “our”) is responsible for personal data collected through this website and used for product enquiries, demonstrations, sales follow-up, website security and related business administration.
This policy applies to visitors, prospective business customers and people who submit information on behalf of an organization. It does not describe how a LendFlow customer uses the LendFlow software to process its own customer data; that processing is governed by the applicable customer agreement and product documentation.
Personal data we collect
Information you provide
- Contact details such as your name, business email, mobile number and WhatsApp number.
- Business information such as business name, business type, district, branch count and approximate active-customer range.
- Operational information such as your current record-keeping method, areas of interest, preferred contact method and preferred demonstration time.
- The content of messages, notes and other information you choose to provide.
- Your consent to be contacted about a demonstration or enquiry.
Information collected automatically
- Landing page, referring page and source domain.
- Campaign parameters such as UTM source, medium, campaign, term and content.
- Advertising click identifiers, where present in the URL, such as Google or Meta click identifiers.
- Browser and device information, submission time and basic request information.
- A protected one-way representation of the submitting IP address for security, rate-limiting and coarse attribution purposes.
Do not submit passwords, payment-card details, national identity documents or confidential borrower records through the public enquiry forms.
How we collect personal data
We collect information directly when you complete a demo or contact form, contact us by phone or WhatsApp, or communicate with our team. Technical and attribution data is collected when you visit the website or submit a form. We may also receive business contact information from a colleague who requests a demonstration on behalf of your organization.
How and why we use personal data
Depending on the context, we process data with your consent, to take requested pre-contractual steps, for legitimate business and security purposes, or to comply with applicable legal duties. Where processing relies on consent, you may withdraw it for future processing.
Lead qualification and human review
Information such as branch count, customer-volume range, current operating method and selected requirements may be used to assign an internal priority category. This helps our team route and prepare enquiries efficiently.
This qualification does not approve or refuse credit, determine eligibility for a financial service, or make a decision that produces legal or similarly significant effects. A team member reviews the enquiry and decides how to follow up.
International processing
Some service providers may process information outside Sri Lanka. Where personal data is transferred internationally, we take reasonable steps to use lawful transfer mechanisms, contractual protections and security measures appropriate to the destination and the nature of the information.
How long we retain data
We retain information only for as long as it remains necessary for the purpose collected, subject to legal, security and dispute-resolution requirements.
If an enquiry becomes a customer relationship, relevant information may be transferred to customer records and retained according to the applicable agreement and operational retention requirements. Data may be deleted, anonymized or restricted when the retention period ends.
How we protect information
We use technical and organizational safeguards appropriate to the type of information processed. These include restricted administrative access, password hashing, secure sessions, request throttling, anti-spam controls, encrypted transport when HTTPS is enabled, server-side validation, prepared database queries, security headers, activity records and internal error logging.
No internet service can guarantee absolute security. If you believe information submitted to LendFlow may have been compromised, contact us promptly using the details below.
Your privacy rights
Subject to the Sri Lankan Personal Data Protection Act, No. 9 of 2022, as amended, and other applicable law, you may have the right to:
- Ask whether we process your personal data and request access to it.
- Request correction of inaccurate or incomplete information.
- Request deletion where the information is no longer necessary or processing is not otherwise justified.
- Withdraw consent for future processing where consent is relied upon.
- Object to or request restriction of certain processing in circumstances recognized by law.
- Seek review of qualifying automated processing and submit a complaint to the relevant authority.
To protect your information, we may need to verify your identity and clarify the scope of the request. Some rights are subject to lawful exceptions, including record-retention and legal-claim requirements.
Children’s information
LendFlow is a business-to-business service and this website is not directed to children. Do not submit information about a child through the public lead forms. If we learn that such information was submitted unnecessarily, we will take reasonable steps to remove it.
Changes to this policy
We may revise this policy when our website, business processes, service providers or legal obligations change. The effective date at the top of the page identifies the current version. Material changes will be presented through an appropriate website notice where required.
Contact and complaints
To ask a privacy question or exercise a privacy right, contact LendFlow using one of the following channels:
If you are not satisfied with our response, you may contact the Data Protection Authority of Sri Lanka. You may also have the right to seek another remedy available under applicable law.
