Data Privacy
Last updated: May 2, 2026
This Data Privacy Notice describes how Lodfy ("we", "us", "our") processes customer data entrusted to us by business users of the platform (the "Service"). It complements our Privacy Policy, which covers personal data we collect as a controller from individuals who interact with our public site, account holders, and visitors.
1. Scope
This Notice applies to data uploaded, generated, or transmitted by a customer (the "Customer") through the Service in the ordinary course of using Lodfy — including KYB documentation, supply-chain and fund-chain disclosures, marketplace listings, deal artefacts (LOI, ICPO, FCO, BCL), contracts, messages, and other content ("Customer Data"). It does not cover data processed for our own purposes (which is governed by the Privacy Policy).
2. Roles of the parties
- Customer as controller: The Customer determines the purposes and means of processing Customer Data and is the controller (or independent controller, where the data relates to counterparties).
- Lodfy as processor: Where we process Customer Data on the Customer's instructions to provide the Service, we act as a processor under GDPR Art. 28 / UK GDPR.
- Lodfy as controller: For account administration, billing, security monitoring, sanctions and AML screening, aggregated analytics, and legal-compliance obligations, we act as an independent controller.
3. Categories of data processed
- Identification data: company name, registration numbers, ultimate beneficial owners, directors, signatories, authorised users.
- KYB and AML evidence: constitutional documents, proof of address, sanctions check results, source-of-funds, risk-assessment notes.
- Trade and commercial data: commodity specifications, allocations, prices, payment terms, counterparty references, performance bonds.
- Communications: deal-room messages, comments, attachments, notifications.
- Operational metadata: log records, audit trails, timestamps, IP addresses, access events.
4. Purposes and lawful bases
We process Customer Data only to (i) deliver the Service per the Customer's documented instructions, (ii) meet our legal and regulatory obligations (notably AML, sanctions and tax), (iii) maintain platform security and integrity, and (iv) where strictly necessary, support our legitimate interests in operating, improving and securing the Service. Where consent is the lawful basis, we rely on the consent obtained by the Customer from the relevant data subjects.
5. Sub-processors
We engage carefully selected sub-processors under written data-processing agreements that flow down equivalent obligations:
- Hosting & database: Supabase (managed PostgreSQL, authentication, storage, edge functions).
- Transactional email: Resend.
- Payment processing: our subscription processor (e.g. Stripe), for billing and invoicing only.
- Sanctions and PEP screening: compliance data providers used to validate counterparties.
- Customer support tooling: ticketing and in-product messaging providers.
A current list is available on request via the contact form. We will give reasonable notice before adding or replacing a sub-processor that materially affects the processing of Customer Data, allowing the Customer to object on reasonable grounds.
6. International transfers
Customer Data may be processed in countries outside the Customer's own. Where data leaves the UK or the European Economic Area, we rely on appropriate safeguards — typically the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision — together with supplementary technical and organisational measures where required by a transfer-impact assessment.
7. Security measures
We implement and maintain a documented information-security programme that includes encryption in transit and at rest, role-based access controls, row-level security in our database, tenant isolation, audit logging, vulnerability management, and incident-response procedures. Full details are set out in our Cyber Protection statement.
8. Data-subject rights
We assist Customers, by appropriate technical and organisational measures, in fulfilling their obligation to respond to requests from data subjects exercising their rights of access, rectification, erasure, restriction, portability, and objection. Where a data subject contacts us directly about Customer Data, we will, unless legally prohibited, refer them to the relevant Customer.
9. Retention, return and deletion
Customer Data is retained while the Customer's account is active. On termination, the Customer may export their data through in-product tools for a reasonable period before deletion. KYB and AML records are retained for the minimum period required by law (typically five years from the end of the business relationship). Backups are rotated on a short cycle and overwritten in due course.
10. Personal-data breaches
We notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data, and provide the information needed for the Customer to meet its own notification obligations. We maintain documented incident-response runbooks and post-incident review processes.
11. Audits and certifications
We make available to the Customer all information reasonably necessary to demonstrate compliance with applicable data-protection law, including, where available, third-party assurance reports (such as SOC 2 or ISO/IEC 27001 attestations), security questionnaires, and the results of penetration tests, subject to confidentiality.
12. Confidentiality
Personnel authorised to process Customer Data are bound by contractual or statutory confidentiality obligations and receive regular data-protection and security training.
13. Data Protection Officer and contact
For data-privacy enquiries, requests under this Notice, or to obtain a copy of our Data Processing Agreement template, please use the contact form. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office).
14. Updates
We may update this Notice from time to time. Material changes will be communicated by email or in-app at least 14 days before they take effect.