Lodfy

    Privacy Policy

    Last updated: August 26, 2026

    This Privacy Policy explains how Lodfy ("we", "us", "our") collects, uses, shares, and protects personal data when you use our platform and services (the "Service"). It applies to account holders, invited users, and visitors to our public pages.

    1. Data controller

    Lodfy is the controller of personal data processed through the Service. You can reach us through the contact form for any privacy enquiry, including requests to exercise your rights.

    2. Data we collect

    • Account data: name, business email, role in your company, password hash, communication preferences.
    • KYB and trade documents: company registration, beneficial ownership, banker's comfort letters (BCL), letters of intent (LOI), certificates of origin, proof of goods, supplier agreements, and other files you upload.
    • Chain data: supply-chain and fund-chain disclosures, including suppliers, allocations, and end-buyer information you choose to share.
    • Usage data: log data, device and browser information, approximate location derived from IP, pages viewed, actions taken.
    • Communications: messages you send through the platform or to our support team.

    3. Why we use your data and the legal bases

    • To provide the Service (contract — GDPR Art. 6(1)(b)): create and operate your account, run KYB, host listings, deliver chain tools, process payments via our subscription processor.
    • To meet legal obligations (GDPR Art. 6(1)(c)): anti-money laundering, sanctions screening, tax, and audit duties — including retaining KYC records for the period required by applicable AML rules (typically five years after the end of the business relationship).
    • For our legitimate interests (GDPR Art. 6(1)(f)): keeping the Service secure, preventing fraud and abuse, improving features, understanding usage, and communicating about your account.
    • With your consent (GDPR Art. 6(1)(a)): marketing emails and any optional analytics where required. You can withdraw consent at any time.

    4. Who we share data with

    • Other users: profile information you choose to publish, and trade or chain data you explicitly share with a counterparty during a deal.
    • Service providers (processors): hosting and database (Supabase), site hosting and cookieless traffic analytics (Vercel), transactional email (Resend), payment processing (Stripe), product analytics (PostHog) and web analytics (Google Analytics) — the last two only with your consent — and AI processing (OpenAI, see the section on AI below). All are bound by data-processing agreements.
    • Compliance and authorities: sanctions and AML screening providers, and competent authorities where we are legally required to disclose.
    • Corporate transactions: in connection with a merger, acquisition, or sale of assets, with appropriate safeguards.

    We do not sell personal data.

    4a. AI processing

    Two optional features send content to an AI provider (OpenAI) for processing on our behalf: the document translator sends the document you ask to have translated, and the contract generator sends the deal terms you enter. This happens only when you actively use those features — nothing you upload is sent to an AI provider otherwise, and we do not permit the provider to use this content to train its models. AI output is a drafting aid, not legal advice; review it before relying on it.

    5. International transfers

    Your data may be processed in countries outside your own. Where data leaves the UK or EEA we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses or UK IDTA).

    6. Retention

    We keep account data while your account is active and for a reasonable period after closure. KYB and AML records are retained for the minimum period required by law (typically five years). Backups are rotated on a short cycle.

    7. Your rights

    Subject to applicable law (including UK GDPR and EU GDPR), you have the right to access, rectify, erase, restrict, or port your personal data, and to object to certain processing. You can exercise these rights via the contact form. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office).

    8. Security

    We use encryption in transit, encryption at rest for sensitive fields, row-level security in our database, role-based access controls, and audit logging. No system is perfectly secure; please use a strong, unique password and notify us immediately if you suspect unauthorised access.

    9. Cookies

    We use a small number of cookies and similar technologies. See our Cookie Policy for details.

    10. Children

    The Service is intended for businesses. We do not knowingly collect data from anyone under 18.

    11. Changes to this policy

    We may update this policy. Material changes will be notified by email or in-app at least 14 days before they take effect.

    This document is provided for general information and does not constitute legal advice. If you need advice about your specific situation, please consult a qualified lawyer.