Data Processing Addendum

U.S. terms for referral partners who submit applicant personal information to Loanable. This DPA forms part of your Referral Partner Agreement (or Partner API access) unless you have a separately signed DPA.

Last Updated: August 25, 2026

On This Page

  • Parties & scope
  • Definitions
  • Roles
  • Instructions
  • Security
  • Data subject rights
  • Partner responsibilities
  • Subprocessors
  • Audits
  • Return & deletion
  • AI
  • Miscellaneous
  • Annex 1 — details
  • Annex 2 — state laws
  • Annex 3 — security
  • Annex 4 — subprocessors

This Data Processing Addendum (including the annexes, this "DPA") is between the referral partner or other customer who submits applicant information ("Customer") and Nextgen Capital Solutions LLC, doing business as Loanable ("Provider" or "Loanable"). It forms part of the Referral Partner Agreement, Partner API terms, or other written agreement between the parties (the "Agreement"). If you need a countersigned copy, email apply@loanableusa.com.

This DPA applies to U.S. state privacy laws. It is not a GDPR Article 28 agreement. Loanable does not currently offer the marketplace as an EEA/UK targeting service.

1. Duration and scope

This DPA remains in effect so long as Provider Processes Personal Data, even after the Agreement ends, until that Personal Data is deleted or anonymized as described below. Processing of Personal Data subject to State Privacy Laws is also subject to Annex 2.

2. Definitions

Capitalized terms not defined here have the meaning in the Agreement.

  • Affiliate means an entity that controls, is controlled by, or is under common control with a party.
  • Applicable Data Protection Laws means U.S. privacy, data-protection, and data-security laws applicable to Provider's Processing of Personal Data under the Agreement, including State Privacy Laws.
  • Customer Data means information Customer provides or makes available to Provider to Process on Customer's behalf to perform the Services (for example deals submitted through the Partner API or portal).
  • Data Subject means the identified or identifiable natural person to whom Personal Data relates.
  • Information Security Incident means a breach of Provider's security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Provider's possession. It does not include unsuccessful attempts such as pings, port scans, or failed logins that do not compromise Personal Data.
  • Personal Data means Customer Data that is personal information under Applicable Data Protection Laws. It does not include Provider's own business-contact data about Customer's staff, or information Provider collects independently of the Services (for example when an applicant applies directly on loanableusa.com).
  • Process means any operation performed on Personal Data for Customer under the Agreement.
  • Services means the marketplace, partner portal, Partner API, and related services in the Agreement.
  • State Privacy Laws means comprehensive U.S. state consumer privacy laws applicable to the Processing.
  • Subprocessors means Affiliates and third parties Provider engages to Process Personal Data for the Services.

3. Roles

Service provider / processor. For Customer Data that Customer causes Provider to Process to submit, package, and status a referred deal, Customer is the business/controller and Provider is a service provider, contractor, and/or processor as those terms are used in State Privacy Laws.

Independent controller. When Loanable uses application data to operate the marketplace — including matching lending partners, fraud prevention, improving matching, and complying with law — Loanable acts as an independent controller. That processing is described in the Privacy Policy and is not "on Customer's behalf." Annex 2's "no combine / no sell" service-provider limits apply to Customer Data only to the extent State Privacy Laws require them for service-provider processing; they do not prohibit Loanable's independent-controller marketplace activities that are disclosed to applicants and permitted by those laws.

4. Customer instructions

Provider will Process Personal Data only on Customer's documented instructions, including this DPA, the Agreement, order forms, and other written instructions consistent with the Agreement. By entering this DPA, Customer instructs Provider to Process Personal Data to provide the Services (receive deals, scan and store documents, match lenders, notify status, and operate webhooks). Details are in Annex 1.

If Customer asks for instructions outside the Services, the parties must agree in writing. Provider will notify Customer if Provider believes an instruction violates Applicable Data Protection Laws (unless law prohibits that notice).

5. Security

Provider measures

Provider will maintain technical and organizational measures designed to protect Personal Data as described in Annex 3, taking into account the state of the art, cost, nature of Processing, and risk. Provider may update those measures if the overall protection is not materially decreased.

Staff

Personnel authorized to access Personal Data are subject to confidentiality obligations.

Incidents

Provider will notify Customer without undue delay after becoming aware of an Information Security Incident, with available details, mitigation steps, and recommended Customer steps. Notification is not an admission of fault. Provider will reasonably cooperate, at Customer's request, to investigate. Customer is responsible for notices Customer must give to regulators, Data Subjects, or the public. If those notices identify Provider, Customer will, where law allows, consult Provider in good faith on wording that relates to Provider.

Customer's security

Customer is responsible for its use of the Services, protecting API keys and portal logins, securing Customer's own systems, and obtaining consents. Customer acknowledges it has evaluated the Services and Security Measures and determined they are appropriate for the risk, including that funding files may include SSN, EIN, and bank statements.

6. Data subject rights

Taking into account the nature of Processing, Provider will provide assistance reasonably necessary and technically feasible for Customer to respond to Data Subject requests regarding Personal Data in Provider's possession. Work beyond the ordinary Services may be charged at then-current professional-services rates, with a good-faith estimate on request.

If Provider receives a Data Subject request that identifies Customer, Provider will (unless prohibited) notify Customer and direct the individual to Customer. Customer is responsible for responding unless law requires otherwise. Applicants may also contact Loanable directly under the Privacy Policy; Loanable may respond as an independent controller for marketplace data.

7. Partner (Customer) responsibilities

Customer will provide all notices and obtain all consents and permissions required for Provider to Process Personal Data as contemplated, including credit-authorization and terms consents required for live Partner API deals.

Permitted sensitive application data

The Services are a commercial-funding marketplace. Customer may submit, and Provider is instructed to Process, the following when needed for a funding file: SSN, EIN/TIN, government-issued ID images, date of birth, bank-account identifiers, bank statements, tax returns, and similar underwriting documents ("Application Sensitive Data"). Provider will encrypt SSN/EIN/TIN and bank-account details at rest as described in Annex 3.

Restricted Data (do not submit)

Customer represents that Customer Data does not and will not contain: protected health information subject to HIPAA; biometric identifiers used to uniquely identify a person; passwords or credentials for third-party accounts (other than credentials created solely to use the Services); payment-card data subject to PCI DSS (do not upload full PAN/CVV); personal data of children under 16; or other data the parties have not agreed in writing to Process ("Restricted Data"). Application Sensitive Data listed above is not Restricted Data.

8. Subprocessors

Customer authorizes Provider's Affiliates and the Subprocessors in Annex 4 (as updated). When engaging a Subprocessor, Provider will impose data-protection obligations no less protective than this DPA to the extent applicable to that Subprocessor's work, and remains responsible for the Subprocessor's performance.

Provider may add Subprocessors by updating Annex 4 on this page and, for material new vendors that Process Customer Data, providing notice (including email to Customer's services contact). Customer may object within 15 days on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. If they cannot, Customer's exclusive remedy is to terminate the Agreement and pay amounts then due.

9. Audits

Customer may audit Provider's compliance with this DPA up to once per year, and additionally when required by Applicable Data Protection Laws or a competent regulator, upon written request with reasonable detail. If a third-party auditor is used, Provider may object if the auditor is not independent, is a competitor, or is unsuitable; Customer must then use another auditor or audit itself.

Customer must propose an audit plan at least two weeks in advance. Any third-party auditor must sign a mutually acceptable NDA. Audits occur during business hours, follow Provider's security policies, and may not unreasonably disrupt operations. If the controls are covered by a SOC 2 Type 2, ISO, NIST, or similar report issued within 12 months and Provider confirms no known material control changes, Customer will accept that report in lieu of auditing those controls.

Customer will promptly notify Provider of non-compliance discovered, may use reports only to confirm DPA/regulatory compliance, and will reimburse Provider's reasonable documented costs (including internal time at professional-services rates). Nothing in this section requires Provider to breach confidentiality owed to others.

10. Return and deletion

When Services involving Personal Data cease (the "Cessation Date"), Provider will stop Processing Personal Data except to store it as needed to return, delete, or anonymize it, or as this DPA or law allows. Within 30 days after the Cessation Date, Customer may request return by secure transfer or deletion/anonymization. If Customer does not instruct Provider, Provider may delete or anonymize remaining Personal Data after that period, to the extent technically feasible.

Provider may retain Personal Data as required or permitted by law (including lender, tax, fraud, and recordkeeping obligations), under the Security Measures, and only for those purposes, then delete or anonymize it when no longer required.

Independent-controller copies (marketplace files matched to lenders) may be retained under the Privacy Policy even after a partner relationship ends, to the extent legally required or permitted.

11. Artificial intelligence

Provider uses AI tools (including OpenAI and Anthropic) to classify documents, parse inbound email, and review file completeness. That use is reasonably necessary to provide the Services and is part of Customer's instructions.

Provider will not use Personal Data to train, fine-tune, or improve a general-purpose AI model of Provider or a third party, except (a) as reasonably necessary to provide the Services on Customer's instructions, or (b) with Customer's written authorization. Provider will prohibit Subprocessor AI providers from using Personal Data for their own model training where the applicable product terms allow that prohibition.

Automated matching of files to lenders may affect which lenders see a deal; it does not by itself approve or deny credit. Meaningful information about matching logic may be limited where it would disclose confidential lender criteria or trade secrets. Provider will reasonably cooperate with Customer on Data Subject rights related to automated decision-making as required by Applicable Data Protection Laws.

12. Miscellaneous

Except as this DPA modifies the Agreement, the Agreement remains in effect. If they conflict, this DPA controls for data-protection of Customer Data. Provider's access to Personal Data is not consideration exchanged under the Agreement. Notices under this DPA may be given as in the Agreement, to Annex 1 contacts, or to Customer's primary email for the Services.

Provider may vary this DPA on written notice solely as needed to stay compliant with Applicable Data Protection Laws, without materially reducing protections or increasing Customer's obligations without Customer's agreement. Aggregate liability under this DPA is subject to the limitations and exclusions in the Agreement.

Use of the Partner Portal or Partner API to submit deals constitutes agreement to this DPA. Countersignature is available on request.

Annex 1 — Data processing details

Provider

  • Name: Nextgen Capital Solutions LLC dba Loanable
  • Address: 5940 S Rainbow Blvd, Suite 4101, Las Vegas, NV 89118
  • Data-protection contact: apply@loanableusa.com · (888) 816-2682
  • Activities: U.S. small-business funding marketplace (not a lender)

Customer

  • Name / address / contact: as in the Agreement or partner portal profile
  • Activities: referring and submitting funding applications as permitted in the Agreement

Processing

  • Data Subjects: applicants, owners/guarantors, and Customer's personnel whose data is included in a submission
  • Personal Data: identity and contact data; business data; financial and credit data; Application Sensitive Data; documents; communications; device/technical data generated by API or portal use
  • Sensitive categories: Application Sensitive Data as described in Section 7, with AES-256 encryption for SSN/EIN/TIN and bank-account details at rest, TLS in transit, and role-based access
  • Frequency: ongoing, as Customer submits deals and documents
  • Nature and purpose: receive, validate, store, classify, package, and transmit files to lending partners; status webhooks; support; security and fraud prevention
  • Duration: as in the Agreement and Section 10

Annex 2 — State Privacy Laws

For this annex, "business," "controller," "processor," "sell," "share," "service provider," and "contractor" have the meanings in the applicable State Privacy Laws. It is the parties' intent that, with respect to Customer Data Processed on Customer's behalf, Provider is a service provider, contractor, and/or processor.

Provider (a) acknowledges Customer Data is disclosed only for the limited purposes in the Agreement; (b) will comply with applicable State Privacy Law obligations and provide the same level of privacy protection those laws require; (c) agrees Customer may take reasonable steps to help ensure Provider's Processing is consistent with Customer's obligations; (d) will notify Customer if Provider determines it can no longer meet those obligations; and (e) agrees Customer may, on reasonable notice, take reasonable steps to stop and remediate unauthorized use of personal information.

With respect to Customer Data Processed as a service provider, Provider will not (a) sell or share that personal information; (b) retain, use, or disclose it for a commercial purpose other than providing the Services, except as those laws permit; (c) retain, use, or disclose it outside the direct business relationship, except as those laws permit; or (d) combine it with personal information from another person or from Provider's own interaction with the Data Subject, except as those laws permit and as needed to provide the Services (including marketplace matching disclosed in the Privacy Policy). Provider certifies it understands these obligations.

Subprocessor notice under Section 8 satisfies State Privacy Law notice-and-objection requirements. Customer may audit under Section 9 to help confirm compliance. The parties acknowledge that Processing authorized by Customer's instructions is integral to the Services.

Annex 3 — Security measures

  • Assigned responsibility for the information-security program
  • Periodic risk assessment and internal reporting on security and compliance
  • Encryption in transit (TLS) and AES-256 encryption at rest for SSN, EIN/TIN, and bank-account details; industry-standard encryption for other data at rest where applicable
  • Role-based access, unique user IDs, and revocation when roles change
  • Password hashing (or SSO/MFA via Auth0) consistent with industry practice; API secrets hashed with a server pepper; webhook secrets encrypted at rest
  • Logging and monitoring of access and system activity
  • Physical and environmental protections at hosting providers (cloud data centers)
  • Secure configuration, media disposal, and change management
  • Incident response procedures aligned with Section 5
  • Network controls (firewalls, segmentation, intrusion detection/prevention as applicable)
  • Vulnerability management, patching, and malware protections
  • Backup and recovery procedures appropriate to the Services
  • Inbound file scanning (type/content checks; rejection of executable, zip, HTML, and SVG uploads on the Partner API)

Annex 4 — Subprocessors

Customer approves the following categories. Specific vendors may change; material changes will be reflected here.

Subprocessor / category Location Processing
Cloud hosting (e.g. Railway / cloud VM and object storage) United States Application hosting, databases, file storage
Auth0 / Okta United States Authentication for portal/accounts
Plaid United States Bank-account connection when an applicant connects an account
Email and SMS providers (e.g. Resend, SendGrid, Twilio) United States Transactional email and opted-in SMS
OpenAI; Anthropic United States Document classification, inbound mail parse, completeness review
Lending partners (as recipients, not subprocessors in every legal sense) United States Evaluate and potentially fund referred deals — independent controllers of data they receive

Lending partners receive application packages as independent businesses. They are not Loanable subprocessors for data they process for their own underwriting.

Questions or countersignature

  • Email: apply@loanableusa.com
  • Phone: (888) 816-2682
  • Mail: 5940 S Rainbow Blvd, Suite 4101, Las Vegas, NV 89118

Privacy Policy · Terms of Service · Partner API · Security

Loanable

Making business funding simple, fast, and accessible for entrepreneurs everywhere.

Products

  • Business Loans
  • SBA Loans
  • Business Line of Credit
  • Equipment Financing

Resources

  • Partner API
  • Referral partners
  • FAQs

Company

  • Contact
  • Security

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Notice
  • Data Processing Addendum
  • Cookie Settings

© 2026 Loanable. All rights reserved.

Loanable is not a lender. This DPA is for approved referral partners submitting applicant data.