U.S. terms for referral partners who submit applicant personal information to Loanable. This DPA forms part of your Referral Partner Agreement (or Partner API access) unless you have a separately signed DPA.
Last Updated: August 25, 2026
This Data Processing Addendum (including the annexes, this "DPA") is between the referral partner or other customer who submits applicant information ("Customer") and Nextgen Capital Solutions LLC, doing business as Loanable ("Provider" or "Loanable"). It forms part of the Referral Partner Agreement, Partner API terms, or other written agreement between the parties (the "Agreement"). If you need a countersigned copy, email apply@loanableusa.com.
This DPA applies to U.S. state privacy laws. It is not a GDPR Article 28 agreement. Loanable does not currently offer the marketplace as an EEA/UK targeting service.
This DPA remains in effect so long as Provider Processes Personal Data, even after the Agreement ends, until that Personal Data is deleted or anonymized as described below. Processing of Personal Data subject to State Privacy Laws is also subject to Annex 2.
Capitalized terms not defined here have the meaning in the Agreement.
Service provider / processor. For Customer Data that Customer causes Provider to Process to submit, package, and status a referred deal, Customer is the business/controller and Provider is a service provider, contractor, and/or processor as those terms are used in State Privacy Laws.
Independent controller. When Loanable uses application data to operate the marketplace — including matching lending partners, fraud prevention, improving matching, and complying with law — Loanable acts as an independent controller. That processing is described in the Privacy Policy and is not "on Customer's behalf." Annex 2's "no combine / no sell" service-provider limits apply to Customer Data only to the extent State Privacy Laws require them for service-provider processing; they do not prohibit Loanable's independent-controller marketplace activities that are disclosed to applicants and permitted by those laws.
Provider will Process Personal Data only on Customer's documented instructions, including this DPA, the Agreement, order forms, and other written instructions consistent with the Agreement. By entering this DPA, Customer instructs Provider to Process Personal Data to provide the Services (receive deals, scan and store documents, match lenders, notify status, and operate webhooks). Details are in Annex 1.
If Customer asks for instructions outside the Services, the parties must agree in writing. Provider will notify Customer if Provider believes an instruction violates Applicable Data Protection Laws (unless law prohibits that notice).
Provider will maintain technical and organizational measures designed to protect Personal Data as described in Annex 3, taking into account the state of the art, cost, nature of Processing, and risk. Provider may update those measures if the overall protection is not materially decreased.
Personnel authorized to access Personal Data are subject to confidentiality obligations.
Provider will notify Customer without undue delay after becoming aware of an Information Security Incident, with available details, mitigation steps, and recommended Customer steps. Notification is not an admission of fault. Provider will reasonably cooperate, at Customer's request, to investigate. Customer is responsible for notices Customer must give to regulators, Data Subjects, or the public. If those notices identify Provider, Customer will, where law allows, consult Provider in good faith on wording that relates to Provider.
Customer is responsible for its use of the Services, protecting API keys and portal logins, securing Customer's own systems, and obtaining consents. Customer acknowledges it has evaluated the Services and Security Measures and determined they are appropriate for the risk, including that funding files may include SSN, EIN, and bank statements.
Taking into account the nature of Processing, Provider will provide assistance reasonably necessary and technically feasible for Customer to respond to Data Subject requests regarding Personal Data in Provider's possession. Work beyond the ordinary Services may be charged at then-current professional-services rates, with a good-faith estimate on request.
If Provider receives a Data Subject request that identifies Customer, Provider will (unless prohibited) notify Customer and direct the individual to Customer. Customer is responsible for responding unless law requires otherwise. Applicants may also contact Loanable directly under the Privacy Policy; Loanable may respond as an independent controller for marketplace data.
Customer will provide all notices and obtain all consents and permissions required for Provider to Process Personal Data as contemplated, including credit-authorization and terms consents required for live Partner API deals.
The Services are a commercial-funding marketplace. Customer may submit, and Provider is instructed to Process, the following when needed for a funding file: SSN, EIN/TIN, government-issued ID images, date of birth, bank-account identifiers, bank statements, tax returns, and similar underwriting documents ("Application Sensitive Data"). Provider will encrypt SSN/EIN/TIN and bank-account details at rest as described in Annex 3.
Customer represents that Customer Data does not and will not contain: protected health information subject to HIPAA; biometric identifiers used to uniquely identify a person; passwords or credentials for third-party accounts (other than credentials created solely to use the Services); payment-card data subject to PCI DSS (do not upload full PAN/CVV); personal data of children under 16; or other data the parties have not agreed in writing to Process ("Restricted Data"). Application Sensitive Data listed above is not Restricted Data.
Customer authorizes Provider's Affiliates and the Subprocessors in Annex 4 (as updated). When engaging a Subprocessor, Provider will impose data-protection obligations no less protective than this DPA to the extent applicable to that Subprocessor's work, and remains responsible for the Subprocessor's performance.
Provider may add Subprocessors by updating Annex 4 on this page and, for material new vendors that Process Customer Data, providing notice (including email to Customer's services contact). Customer may object within 15 days on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. If they cannot, Customer's exclusive remedy is to terminate the Agreement and pay amounts then due.
Customer may audit Provider's compliance with this DPA up to once per year, and additionally when required by Applicable Data Protection Laws or a competent regulator, upon written request with reasonable detail. If a third-party auditor is used, Provider may object if the auditor is not independent, is a competitor, or is unsuitable; Customer must then use another auditor or audit itself.
Customer must propose an audit plan at least two weeks in advance. Any third-party auditor must sign a mutually acceptable NDA. Audits occur during business hours, follow Provider's security policies, and may not unreasonably disrupt operations. If the controls are covered by a SOC 2 Type 2, ISO, NIST, or similar report issued within 12 months and Provider confirms no known material control changes, Customer will accept that report in lieu of auditing those controls.
Customer will promptly notify Provider of non-compliance discovered, may use reports only to confirm DPA/regulatory compliance, and will reimburse Provider's reasonable documented costs (including internal time at professional-services rates). Nothing in this section requires Provider to breach confidentiality owed to others.
When Services involving Personal Data cease (the "Cessation Date"), Provider will stop Processing Personal Data except to store it as needed to return, delete, or anonymize it, or as this DPA or law allows. Within 30 days after the Cessation Date, Customer may request return by secure transfer or deletion/anonymization. If Customer does not instruct Provider, Provider may delete or anonymize remaining Personal Data after that period, to the extent technically feasible.
Provider may retain Personal Data as required or permitted by law (including lender, tax, fraud, and recordkeeping obligations), under the Security Measures, and only for those purposes, then delete or anonymize it when no longer required.
Independent-controller copies (marketplace files matched to lenders) may be retained under the Privacy Policy even after a partner relationship ends, to the extent legally required or permitted.
Provider uses AI tools (including OpenAI and Anthropic) to classify documents, parse inbound email, and review file completeness. That use is reasonably necessary to provide the Services and is part of Customer's instructions.
Provider will not use Personal Data to train, fine-tune, or improve a general-purpose AI model of Provider or a third party, except (a) as reasonably necessary to provide the Services on Customer's instructions, or (b) with Customer's written authorization. Provider will prohibit Subprocessor AI providers from using Personal Data for their own model training where the applicable product terms allow that prohibition.
Automated matching of files to lenders may affect which lenders see a deal; it does not by itself approve or deny credit. Meaningful information about matching logic may be limited where it would disclose confidential lender criteria or trade secrets. Provider will reasonably cooperate with Customer on Data Subject rights related to automated decision-making as required by Applicable Data Protection Laws.
Except as this DPA modifies the Agreement, the Agreement remains in effect. If they conflict, this DPA controls for data-protection of Customer Data. Provider's access to Personal Data is not consideration exchanged under the Agreement. Notices under this DPA may be given as in the Agreement, to Annex 1 contacts, or to Customer's primary email for the Services.
Provider may vary this DPA on written notice solely as needed to stay compliant with Applicable Data Protection Laws, without materially reducing protections or increasing Customer's obligations without Customer's agreement. Aggregate liability under this DPA is subject to the limitations and exclusions in the Agreement.
Use of the Partner Portal or Partner API to submit deals constitutes agreement to this DPA. Countersignature is available on request.
For this annex, "business," "controller," "processor," "sell," "share," "service provider," and "contractor" have the meanings in the applicable State Privacy Laws. It is the parties' intent that, with respect to Customer Data Processed on Customer's behalf, Provider is a service provider, contractor, and/or processor.
Provider (a) acknowledges Customer Data is disclosed only for the limited purposes in the Agreement; (b) will comply with applicable State Privacy Law obligations and provide the same level of privacy protection those laws require; (c) agrees Customer may take reasonable steps to help ensure Provider's Processing is consistent with Customer's obligations; (d) will notify Customer if Provider determines it can no longer meet those obligations; and (e) agrees Customer may, on reasonable notice, take reasonable steps to stop and remediate unauthorized use of personal information.
With respect to Customer Data Processed as a service provider, Provider will not (a) sell or share that personal information; (b) retain, use, or disclose it for a commercial purpose other than providing the Services, except as those laws permit; (c) retain, use, or disclose it outside the direct business relationship, except as those laws permit; or (d) combine it with personal information from another person or from Provider's own interaction with the Data Subject, except as those laws permit and as needed to provide the Services (including marketplace matching disclosed in the Privacy Policy). Provider certifies it understands these obligations.
Subprocessor notice under Section 8 satisfies State Privacy Law notice-and-objection requirements. Customer may audit under Section 9 to help confirm compliance. The parties acknowledge that Processing authorized by Customer's instructions is integral to the Services.
Customer approves the following categories. Specific vendors may change; material changes will be reflected here.
| Subprocessor / category | Location | Processing |
|---|---|---|
| Cloud hosting (e.g. Railway / cloud VM and object storage) | United States | Application hosting, databases, file storage |
| Auth0 / Okta | United States | Authentication for portal/accounts |
| Plaid | United States | Bank-account connection when an applicant connects an account |
| Email and SMS providers (e.g. Resend, SendGrid, Twilio) | United States | Transactional email and opted-in SMS |
| OpenAI; Anthropic | United States | Document classification, inbound mail parse, completeness review |
| Lending partners (as recipients, not subprocessors in every legal sense) | United States | Evaluate and potentially fund referred deals — independent controllers of data they receive |
Lending partners receive application packages as independent businesses. They are not Loanable subprocessors for data they process for their own underwriting.