Privacy Policy
This policy explains how Codero Digital Labs Services OPC handles personal information in the Lenduh platform — the office portal, Lenduh Field (formerly the collector app), the member portal, our APIs, and this website. It covers both the data you give us directly and the data our customers process through Lenduh about their own borrowers and members.
01Who we are and what this covers
Lenduh is a lending and cooperative management platform operated by Codero Digital Labs Services OPC (“Codero”, “we”, “us”, “our”), a One Person Corporation registered with the Philippine Securities and Exchange Commission.
This policy applies to:
- the public website at lenduh.com, including the contact and assessment forms;
- the office portal used by our customers' staff;
- the Lenduh Field app used by field officers;
- the member portal used by cooperative members and borrowers;
- our developer API, webhooks and notification services.
It does not apply to a cooperative's or lending company's own separate systems, offices, or paper records, nor to third-party sites we link to.
02The two roles we play
Philippine data privacy law distinguishes between a personal information controller, who decides why and how personal data is processed, and a personal information processor, who processes it on the controller's behalf. Which role we occupy depends on whose data it is.
| Whose data | Our role | What that means |
|---|---|---|
| Visitors to lenduh.com, sales enquiries, marketing contacts | Controller | We decide what we collect and why, and we answer directly to you. |
| Staff accounts our customers create (administrators, finance, managers, field officers) | Controller | We manage authentication, security and billing for these accounts. |
| Borrowers, members, co‑makers, references and beneficiaries recorded inside a customer's Lenduh workspace | Processor | The cooperative or lending company decides what to collect. We process it only on their documented instructions. |
If you are a borrower or a cooperative member and you want to access, correct or delete your records, contact your cooperative or lending company first — they control that data. If you contact us, we will refer you to them and assist them in responding.
03Information we collect
From website visitors
When you submit the contact form or the maturity assessment, we collect your name, email address, organisation, phone number where given, and the content of your message or answers. If you book a demo, the scheduling provider collects the details you enter there.
From our customers and their staff
Account and identity details (name, work email, mobile number, role and branch assignment), authentication data (password hashes, two‑factor authentication secrets, single sign‑on identifiers, session and device records), billing and subscription details, and support correspondence.
From borrowers and members, on our customers' instructions
Depending on how a customer configures Lenduh, their workspace may contain:
- Identity: full name, date of birth, address, contact number, email address, employer, government-issued ID type and number, photographs of the front and back of an ID, and a selfie taken with the ID.
- Relationships: co‑makers, character references and their contact details, beneficiaries, and household or group affiliations.
- Financial: loan applications and approvals, principal, interest, fees and penalties, repayment schedules, payments and allocations, arrears and days past due, collateral and its valuation, post‑dated cheques, salary‑deduction arrangements, credit limits, and restructuring history.
- Cooperative: membership records, share capital subscriptions and ledgers, savings and deposit accounts, dividends, patronage refunds, welfare fund participation, training attendance, and officer positions.
- Field collection: the date, time and GPS coordinates recorded when a field officer posts a payment or logs a visit, visit outcomes such as not‑home or promise‑to‑pay, and the collector's device identifier.
- Documents: KYC files, proof of income, signed agreements, and any other files a customer uploads.
Collected automatically
Server and application logs (IP address, timestamp, browser and device type, pages or endpoints accessed, and the action taken), audit-trail entries recording who did what and when, error diagnostics, and cookies as described in section 12.
04Why we process it, and on what legal basis
| Purpose | Basis under the Data Privacy Act |
|---|---|
| Providing the platform to a customer under our subscription agreement | Contract; the customer's lawful basis for the underlying records |
| Authenticating users, preventing fraud, and keeping the service secure | Legitimate interests; legal obligation |
| Processing subscription payments and issuing invoices | Contract; legal obligation (tax and accounting) |
| Sending transactional messages — receipts, one‑time codes, due‑date reminders | Contract; the customer's instruction |
| Responding to enquiries and providing support | Legitimate interests; steps taken at your request before entering a contract |
| Producing regulatory outputs our customers are required to file — CDA reports, AMLA covered‑transaction reports, PESOS ratings | The customer's legal obligation |
| Maintaining audit trails and backups | Legal obligation; legitimate interests |
| Marketing our own products to business contacts | Consent, or legitimate interests where permitted; you can opt out at any time |
We do not sell personal information, and we do not carry out automated decision‑making that produces legal effects about a borrower. Credit decisions in Lenduh are made by our customers' own staff; the platform records and enforces the rules they configure, but it does not decide who receives a loan.
05Payments
Online payments made through Lenduh — whether a member paying a loan or a customer paying their subscription — are processed by PayMongo, a payment service provider regulated in the Philippines.
When a payment is made, the payer is handed to PayMongo's hosted checkout. Card numbers, CVV codes, e‑wallet credentials and bank login details are entered on PayMongo's systems and are never transmitted to or stored by us. What we receive back is a payment reference, the amount and currency, the method used, the status, and a masked descriptor such as the last four digits of a card.
PayMongo processes that data as an independent controller under its own privacy policy and its obligations to the card networks. We use the result solely to record the payment against the correct loan, subscription or savings account and to issue a receipt.
Amounts are shown and charged in Philippine pesos (PHP).
06The built-in AI assistant
Lenduh includes an optional AI assistant that answers a customer's questions about their own workspace. It is read‑only: it can retrieve and summarise records, and it cannot create, modify, approve or delete anything.
When a user asks a question, the question and the specific records needed to answer it are sent to our AI provider (Anthropic) for processing and are returned as an answer. Under our agreement with that provider, this data is not used to train their models and is retained only briefly for abuse monitoring.
The assistant respects the same branch scoping and role permissions as the rest of the platform: it cannot surface a record the person asking is not already allowed to see. Customers who prefer not to use it can leave it disabled.
08Where your data is stored and transferred
Lenduh's application servers, database and file storage are hosted on Amazon Web Services in the Asia Pacific (Singapore) region. Backups are held in the same region.
Some of the sub‑processors listed above operate outside the Philippines, which means personal information may be transferred across borders. Where that happens we rely on contractual safeguards with the recipient requiring a comparable level of protection, consistent with the Data Privacy Act of 2012 and National Privacy Commission issuances. Our customers remain responsible for confirming that these arrangements suit their own regulatory position.
09How we protect information
- Encryption in transit for all traffic to the platform, and encryption at rest for the database and file storage.
- Field‑level encryption of sensitive borrower identifiers — contact numbers, email addresses, government ID numbers and reference contacts — so they are not readable directly from the database.
- Tenant isolation: every query is scoped to the cooperative that owns the data, enforced at the database layer, so one organisation cannot read another's records.
- Role-based permissions and branch scoping, so staff see only what their role and assigned branch allow.
- Two‑factor authentication for staff logins, one‑time codes rather than shared passwords for members, an optional administrator IP allowlist, and single sign‑on via OpenID Connect.
- Maker‑checker approvals on sensitive financial actions, and an immutable audit trail recording who did what and when.
- Collector device registration with immediate revocation when a device is lost or an employee leaves.
No system is perfectly secure. Philippine law sets firm deadlines for a personal data breach involving sensitive personal information, or one likely to give rise to a real risk of serious harm, and our duty depends on which role we are in.
- Where we are the controller — website enquiries, staff accounts — we notify the National Privacy Commission and the affected data subjects within 72 hours of knowing or reasonably believing a breach has occurred, and submit the full report within five (5) days, as required by NPC Circular No. 16-03.
- Where we are the processor — a cooperative's or lender's own borrower and member records — we notify that customer without undue delay upon knowing or reasonably believing a breach has occurred, so their own 72-hour clock can run, and we give them the information and assistance they need to notify the Commission and their data subjects.
Notification is delayed only to the extent needed to determine the scope of a breach, prevent further disclosure, or restore the integrity of the affected system — and never where the breach involves 100 or more data subjects or sensitive personal information likely to harm them.
10How long we keep it
| Data | Retention |
|---|---|
| Customer workspace data (borrowers, loans, members, payments) | For the life of the subscription. After termination, retained for 60 days to allow export and recovery, then deleted or irreversibly anonymised. |
| Financial and accounting records we must keep as a business | Up to 10 years, as required by Philippine tax and corporate law. |
| Audit logs | Retained for the subscription term and for as long as needed to evidence a transaction. |
| Website enquiries and assessment submissions | 24 months from last contact, unless you ask us to erase them sooner. |
| Backups | Rolling window; deleted records disappear from backups as the window rotates. |
| Server and security logs | 12 months. |
A customer may ask us to delete their workspace sooner. Where a record must be kept to satisfy a legal obligation — for example an AMLA covered‑transaction report — we retain only what the obligation requires.
11Your rights
Under the Data Privacy Act of 2012 (Republic Act No. 10173) you have the right to be informed; to object to processing; to access your personal data; to correct inaccurate or outdated data; to erasure or blocking in the circumstances the law allows; to damages for a violation of your rights; to data portability; and to lodge a complaint with the National Privacy Commission.
To exercise a right, contact our Data Protection Officer at info@codero.ph, with “Data privacy request” in the subject line. We will acknowledge within 5 working days and respond substantively within 30 working days. Where a request is complex or we receive several from you at once, we may extend by a further 15 working days and will tell you why before the first period ends. We may ask you to verify your identity before we act.
Borrowers and members: as explained in section 2, your cooperative or lending company controls your records. Please direct your request to them; we will support them in fulfilling it.
If you are not satisfied with our response, you may complain to the National Privacy Commission, 5th Floor, Delegation Building, PICC Complex, Roxas Boulevard, Pasay City, or through privacy.gov.ph.
12Cookies and similar technologies
lenduh.com sets a small number of cookies. Strictly necessary cookies keep the site working and remember your cookie choice; we cannot switch these off. Analytics and marketing cookies — which may include Google Analytics, Google Ads and the Meta pixel — load only after you accept them in the banner, and are governed by Google's and Meta's own policies.
Campaign tags. If you reach lenduh.com through one of our ads or links, the campaign tags in that link (such as utm_source and utm_campaign) are kept in your browser's session storage while you browse, added to our sign‑up link, and saved with your organisation's account if you sign up, so we can tell which campaigns bring in new customers. They name the campaign, not you: no advertising cookie or identifier is involved, and session storage is cleared when you close the tab.
You can change your choice at any time through the Cookie preferences link in the footer, or by clearing cookies in your browser. Declining analytics does not reduce access to any part of the site.
The office portal, Lenduh Field and member portal use cookies and local storage strictly to keep you signed in, remember your branch selection, and hold offline payments in the collector outbox until they sync. These are functional, not advertising, and cannot be disabled without breaking the apps.
The sign‑up page. The one exception is the sign‑up page at app.lenduh.com/signup. If you accepted analytics and marketing cookies on lenduh.com, that page also loads the Meta pixel and tells Meta once that a new organisation was created, so we can see which ads bring in customers. It never sends your name, email or anything else you type into the form. Your choice on lenduh.com reaches the sign‑up page through a cookie on lenduh.com that holds only that choice; if you declined, or never answered the banner, the pixel does not load there at all.
13Children
Lenduh is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 18 through this website. A cooperative may lawfully hold records for minor members — for example youth savings accounts — under its own authority and with the consent of a parent or guardian; in that case the cooperative is the controller and its own privacy notice governs.
14Changes to this policy
We may update this policy as the platform, our sub‑processors or the law change. The “Last updated” date at the top always reflects the current version. Where a change materially affects how we handle personal information, we will notify customers by email or in‑app before it takes effect.