FINLOOP PRIVACY POLICY
- Who is responsible
FinLoop AG, Chamerstrasse 172, 6300 Zug, Switzerland (UID CHE-408.195.837), is the controller for the processing described in this policy. Privacy contact: dpo@finloop.com.
- Who and what this policy covers
This policy covers: visitors to www.finloop.com and the FinLoop platform environment at [PLATFORM DOMAIN]; personnel of organisations that use the FinLoop platform (each a "customer organisation"); and individuals whose personal data appears in documents and records submitted to the platform — for example directors, beneficial owners, guarantors, tenants, brokers, valuers and counterparty personnel (see section 10). For a white-label deployment, the customer organisation provides the primary on-screen notice for processing for which it is controller; that notice identifies FinLoop's role and links to this policy where FinLoop acts as an independent controller, and where FinLoop acts only as the customer's processor, the customer's notice governs.
- What we process, and where it comes from
- Account and contact data of personnel: name, business contact details, role, authentication data.
- Platform and transaction records: financing applications, loan and security documentation, financial information, portfolio data and communications submitted by customer organisations. These may contain personal data of the individuals described in section 10.
- Contract formation and evidence data: acceptance and decline events — the person acting, role, authority statement, timestamps, session references, notice-delivery status and document identifiers (section 4(c)).
- Verification data where checks are performed (section 4(b)).
- Enquiry and demo-request data (section 4(h)) and website usage data (section 4(f)).
Sources may include: the relevant customer organisation and its authorised users; transaction counterparties and their advisers; documents supplied by those parties; identity, company-register, sanctions and fraud-prevention providers; and public registers or other publicly accessible professional sources. We do not obtain private consumer-marketing lists for these purposes.
What we do not want submitted: the platform does not require special-category data (for example health or religion), criminal-offence data beyond what lawful sanctions or anti-money-laundering screening produces, or private (non-business) identifiers. Our submission rules instruct submitters not to upload such data and to redact it where feasible, and we exclude it from analytics and model development. If such data is nevertheless received, we restrict access and delete or redact it unless retention or other processing is required or permitted under a specifically documented condition of Article 9(2) GDPR or applicable Article 10 law; the applicable condition, purpose and retention rule are recorded before any use beyond secure isolation and deletion.
- Why we process, and on what legal basis
(a) Providing the platform. For customer organisations: performance of the contract (Article 6(1)(b) GDPR; General Conditions or enterprise agreement). For their personnel, who are not themselves party to the contract: our legitimate interest (Article 6(1)(f) GDPR) in providing, securing and administering the services their organisation requests — a use personnel reasonably expect in a business context; the impact is limited to professional data, and personnel may object (section 8). Business identity, authentication and role data marked as required is necessary to create and secure an authorised-user account; without it, the person cannot receive platform access. Optional profile fields are identified as optional. An account administrator may provide a colleague's business details when inviting that person; FinLoop provides this notice at invitation and first access.
(b) Verification, sanctions screening and financial-crime prevention. Where a check is performed for FinLoop's own purposes, FinLoop is the controller and relies on our and our customers' legitimate interests (Article 6(1)(f) GDPR) in preventing fraud, money laundering and sanctions breaches; where a specific legal obligation applies directly to FinLoop, we rely on that obligation (Article 6(1)(c) GDPR) [cite the specific provisions per the financial-crime perimeter memorandum before publication]. Where FinLoop performs a check only on a customer organisation's documented instructions, that customer is the controller and its notice applies; FinLoop acts as its processor.
(c) Contract formation and evidence. We keep records proving who accepted or declined our terms, when and on whose behalf: our legitimate interest in evidencing contracts and defending claims, and legal record-keeping obligations where applicable. Retention: section 7.
(d) Market analytics. Platform data is processed by FinLoop for market analytics for the commercial real estate debt market. Most external outputs are released only after a documented anonymisation assessment. A limited category of controlled-access loan-level comparables may remain personal data; those records are subject to the restrictions in section 5 and to applicable data-protection rights. The analytics operations are: benchmarking and index production; controlled-access loan-level comparables; product development; model development (restricted to designated structured fields — never communications, identification or KYC documents, privileged material or document repositories); validation and back-testing; and restatement of historical series. Legal basis: the legitimate interests of FinLoop and market participants in reliable market transparency and benchmarking. Where an operation qualifies as processing for statistical purposes, the safeguards of Article 89 GDPR apply, including anonymisation or aggregation at the earliest practicable stage. You can object at any time (section 8).
(e) Historical platform data. Data submitted before a customer organisation's effective date under the current General Conditions may be processed for the analytics purposes in (d) on the same terms as current data, limited to designated analytics-eligible fields; the cut-off is the relevant organisation's effective date. This further processing is subject to a documented compatibility assessment, the safeguards in (d), the recipient limits in section 5 and the retention rules in section 7. Where an organisation's participation has ended, its data is processed after that point only to create, validate, maintain, correct, restate and back-test anonymised and aggregated outputs and to meet legal, audit and regulatory requirements — it is not used for new controlled-access records, to contact anyone, or to make decisions about an identified person or organisation. Historical records are processed to maintain longitudinal datasets, correct and restate series, validate models and compare market conditions over time. Objection: section 8.
(f) Website analytics and session replay. Google Analytics and Hotjar run only after you opt in via the cookie banner, and Hotjar runs only on public pages — never on logged-in platform pages. Your consent is the legal basis for this processing; if you refuse or withdraw it, we do not carry out equivalent tracking on another basis. Details: [Cookie Policy].
(g) Marketing. We send electronic marketing only where we have consent (Article 6(1)(a) GDPR) or a documented country-specific business-contact exception (Article 6(1)(f) GDPR together with the applicable e-privacy rules). Every message identifies FinLoop and provides a free, effective opt-out. We maintain suppression records after an opt-out so that the choice is respected. We do not sell contact data.
(h) Enquiries and demo requests. We process the name, business contact details, organisation, selected department, message, scheduling details and anti-spam signals you provide through our contact and demo forms to respond to the request and administer follow-up. Legal basis: our legitimate interest in responding to business enquiries (Article 6(1)(f) GDPR) and, where the request is a pre-contractual step you ask us to take, Article 6(1)(b) GDPR; consent where required for subsequent electronic marketing. Recipients: our CRM, email, scheduling and anti-spam providers acting as processors. Retention: [•] months after closure of the enquiry, unless a longer period is needed for a resulting customer relationship or a legal claim.
- Who receives personal data
- FinLoop personnel, on a need-to-know basis.
- Processors — hosting, communications, support, CRM, scheduling and verification providers acting on our documented instructions. A current list of categories is available on request.
- Professional advisers, auditors, insurers and competent authorities — strictly where necessary for legal, audit, insurance or regulatory purposes.
- Analytics customers and distribution partners. We do not provide raw platform data or direct identifiers to third parties as a standalone data sale. Most external analytics are released only as anonymised, aggregated outputs in which no organisation or person is identifiable, following a documented anonymisation assessment. FinLoop may charge for analytics products that include controlled access to de-identified records which can remain personal data. Controlled access means: named users in a restricted environment, no bulk download, contractual prohibitions on re-identification, on combining data for re-identification, on contacting anyone on the basis of an output and on onward disclosure, plus access auditing. Where such records remain personal data, all rights in section 8 continue to apply to them. Those disclosures are limited to the stated analytics purpose and contractual controls.
- A successor to FinLoop or its analytics business, with notice under section 11.
- International transfers
Personal data is processed in Switzerland and the EEA; some providers process data in the United Kingdom and the United States. Safeguards are applied per exporting regime: transfers from the EEA rely on adequacy decisions (including, for certified US providers, the EU-US Data Privacy Framework) or the EU Standard Contractual Clauses, with transfer risk assessments and supplementary measures where needed; transfers from the UK rely on UK adequacy regulations, the IDTA or the UK Addendum to the EU SCCs; transfers from Switzerland rely on FADP adequacy or recognised contractual clauses adapted to Swiss law. You can request a copy of the applicable safeguards via dpo@finloop.com.
- How long we keep personal data
Data Period / criterion Account and contact data Duration of the relationship plus twelve (12) months, then deleted or anonymised Statutory accounting and business records Ten (10) years from the end of the relevant financial year where Swiss law so requires Contract acceptance/decline and notice evidence Ten (10) years after termination of the relevant agreement (limitation of contract claims) Transaction workspace content (documents, data rooms) [24] months after closure of the relevant transaction or account, except to the extent a document forms part of the statutory accounting and business records or the acceptance evidence above, or is on a documented legal hold Communications and drafts [24] months after account closure, unless on legal hold Enquiry and demo-request data [•] months after closure of the enquiry (section 4(h)) Analytics source records (including historical data) Reviewed at least annually against a documented necessity test; fields no longer required are deleted or irreversibly anonymised; identifiable source fields are retained no longer than [10] years from submission unless a documented review approves continued retention Verification records The period required by the law applicable to the check Cookie-consent records Five (5) years (see Cookie Policy) Backups Deleted or overwritten within the backup cycle of [BACKUP CYCLE]; deletion propagates on restore Legal holds suspend scheduled deletion only for the affected material. Information that has been anonymised so that no natural person is identifiable by means reasonably likely to be used ceases to be personal data and may be retained. De-identified controlled-access records that remain personal data are not treated as anonymous and stay subject to this table and to your rights.
- Your rights
Depending on the regime applying to you (GDPR, UK GDPR, FADP), you have the right to access your personal data; to rectification; to erasure; to restriction of processing; to object; to withdraw consent at any time for consent-based processing (such as section 4(f)) — withdrawal does not affect the lawfulness of processing carried out on the basis of your consent before the withdrawal; and to data portability where processing is based on contract or consent and carried out by automated means.
Objection: you may object at any time to processing based on legitimate interests, including the analytics processing in sections 4(d)–(e). We will stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. If you object to direct marketing, we will stop using your personal data for direct marketing without applying that balancing test. An upheld objection stops further use of your identifiable data for the relevant purposes; it does not affect outputs that no longer contain personal data.
Automated decision-making: we do not make decisions based solely on automated processing that produce legal or similarly significant effects for individuals.
Contact and identity: dpo@finloop.com or FinLoop AG, Chamerstrasse 172, 6300 Zug, Switzerland. We may ask for information reasonably necessary to verify your identity where we have reasonable doubts; we do not routinely require identity documents.
Complaints: you may complain to the authority for your habitual residence, place of work or the place of the alleged infringement, subject to the rules of the applicable regime — in particular the Swiss Federal Data Protection and Information Commissioner (FDPIC), the supervisory authority of your EU/EEA member state, or the UK Information Commissioner's Office (ICO).
- Security
FinLoop applies appropriate technical and organisational measures — access controls, encryption in transit, logging and personnel confidentiality — proportionate to the risk. No internet service can guarantee absolute security. FinLoop assesses personal-data breaches under the law and applicable contracts and notifies competent authorities, affected controllers and affected individuals where and within the periods required.
- If your data was submitted by someone else
Documents submitted by customer organisations may contain personal data about you even though you do not use FinLoop — for example as a director, beneficial owner, guarantor, tenant, broker, valuer or counterparty employee. FinLoop is responsible for ensuring that the required information reaches you for processing for which FinLoop is controller. Customer organisations must either deliver FinLoop's short privacy notice to you at or before submitting your data and record that delivery, or provide FinLoop with the contact information needed for FinLoop to deliver it; our upload flows remind submitters of this duty and link the notice for forwarding. Where FinLoop delivers the information directly, it does so within one month of obtaining the data and, at the latest, at first communication with you or first disclosure to another recipient. Any reliance on a statutory exception — for example where informing every individual in a historical transaction archive proves impossible or would involve disproportionate effort — is decided and documented for the specific dataset and purpose, with the safeguards described in sections 4(d)–(e); the public availability of this policy is an additional safeguard, not a substitute for notice unless the statutory exception applies. You can exercise every right in section 8 regardless of how your data reached us.
- Changes to this policy
Material changes are notified in a durable form before they take effect — in particular a change of controller or a successor taking over FinLoop's analytics business (with the successor's identity, effective date and contact), new analytics purposes, new controlled-access product categories, and material changes to recipients or international transfers. The version and effective date appear at the top; prior versions are archived and available on request.
- Contact
dpo@finloop.com · FinLoop AG, Chamerstrasse 172, 6300 Zug, Switzerland