Subscribe annually and save 20% — limited time offer.Claim discount

Microsolvant Logo
Microsolvant
LEGAL & GOVERNANCE

Microsolvant Privacy Policy

This Policy sets out the principles governing how Microsolvant. processes, stores, and protects corporate subscriber data and end-user financial records uploaded to the Microsolvant loan management engine.

Last Revised: 13 July 2026
Effective Date: 15 July 2026
Document Ref: MS-POL-PRV-2026-V1

1. Preamble & Regulatory Roles

This Privacy Policy establishes the standards applied by Microsolvant. ("Microsolvant", "Company", "We", "Us", or "Our") concerning the personal and commercial data handled through the Microsolvant Software-as-a-Service (SaaS) platform.

Data Controller vs. Data Processor Distinction:

  • Subscriber Accounts (Controller Role): Where a Microfinance Institution, SACCO, or Money Lender registers an organization account with us, Microsolvant serves as a Data Controller for administrative profile data, billing records, and subscriber credential logs.
  • Operational Client & Financial Data (Processor Role): When subscribers enter data regarding their end-borrowers, guarantors, loans, collateral, and repayments, the Subscriber acts as the Data Controller. Microsolvant acts exclusively as a Data Processor acting under the Subscriber’s documented instructions.

2. Information Categories Processed

Depending on the degree of platform usage, we collect and store structured information categorised below:

1. Subscriber & Account Information

Basis: Contractual Necessity / Legitimate Interest

Data collected when creating and managing an administrative or staff user account on behalf of a tenant financial institution.

  • Full Legal Name
  • Corporate Email Address
  • Phone Number
  • Company / Institution Name
  • Encrypted Authentication Credentials (PBKDF2/Bcrypt Password Hashes)
  • Role & System Access Permissions

2. Tenant Business & Customer Data (Processor Role)

Basis: Performance of Service Agreement (Data Processing Contract)

Financial, identifying, and operational data uploaded or entered by subscribers in the course of using our loan management engine. Subscribers act as Data Controllers for this information.

  • End-Client Identification Data (Names, IDs, Contact Info, Address)
  • Loan Applications, Terms, Principal Amounts, Interest Rates, Schedules
  • Repayment Histories, Schedules, and Transaction Logs
  • Collateral Records, Current Valuation Estimates, and Supporting Media
  • Guarantor Profiles (Names, Phone Numbers, Relations, IDs)
  • Institutional Expenses, Revenue Tracking, and Financial Ledger Records
  • Uploaded Verification Media (National IDs, Passports, Contracts)

3. Technical & Behavioral Telemetry

Basis: Legitimate Interest / Legal & Compliance Obligations

Automatically captured metadata generated during interaction with the platform web application and APIs to ensure operational safety and audit traceability.

  • Internet Protocol (IP) Address & Coarse Geolocation
  • Browser Type, Version, and User-Agent Headers
  • Operating System Details & Device Identifiers
  • Authenticated Session Tokens, Login History, and Timestamped Audit Logs
  • System Error Logs & Performance Metrics

3. Purposes of Processing

Microsolvant processes information strictly for defined operational, technical, and regulatory compliance objectives:

Processing PurposePrimary Data UsedLegal Basis
Provisioning of Core Loan ServicesBusiness Data, Account InfoPerformance of Contract
Authentication & Identity VerificationCredentials, IP, Session DataContractual Requirement / Security
Automated Audit & Fraud PreventionAudit Trails, Technical DataLegitimate Interest / Legal Duty
Platform Performance & Issue ResolutionError Diagnostics, TelemetryLegitimate Interest

4. Third-Party Sharing & Sub-Processors

We do not sell, rent, or trade subscriber or borrower data. Information is disclosed to third parties only under strict contractual safeguards or statutory mandates.

Approved Sub-Processors

Cloud Infrastructure Provider

Primary Database, File Storage, & Compute Services

Location: EU / US Central

Transactional Email Operator

Automated System Alerts, Notifications, & Reports

Location: Global

Payment Gateway Aggregators

Subscription Billing & Automated Disbursement APIs

Location: Regional / Global

Statutory & Legal Disclosures

We may disclose data to regulatory bodies, enforcement authorities, or legal courts if required by valid subpoena, law enforcement mandate, or applicable financial services regulation.

5. Information Security Protocol

We employ layered technical, administrative, and physical safeguards designed to preserve data confidentiality, integrity, and availability:

Cryptographic Controls

Data in transit is protected using Transport Layer Security (TLS 1.3). Sensitive data stored within primary stores is encrypted using industry-standard AES-256 primitives.

Logical Data Isolation

Multi-tenant data architectures utilize tenant-level scoping parameters preventing unauthorized cross-organizational data leakage or access.

Role-Based Access Controls (RBAC)

Internal access to client records is strictly controlled via principle-of-least-privilege guidelines and mandatory multi-factor authentication (MFA).

Backups & Disaster Recovery

Automated encrypted snapshots are maintained in redundant geographic zones to facilitate point-in-time recovery during disruption events.

6. Data Retention Schedule

We maintain data only as long as necessary to fulfill contractual obligations or meet legal compliance metrics:

Active Subscriber Account DataDuration of active subscription agreement plus 90 days.
Financial Audit & Transaction LogsUp to 7 years following contract termination to comply with statutory accounting requirements.
System Diagnostics & Security Logs12 months on a rolling execution basis.

7. International Data Transfers

Microsolvant cloud hosting facilities may be located in regional data centers globally. Where data transfers cross jurisdictional boundaries, we rely on statutory data protection frameworks, standard contractual clauses (SCCs), or equivalent local regulatory mechanisms.

8. Data Subject Rights

Depending on applicable local privacy laws, data subjects maintain enforceable rights regarding their personal information:

  • Right of Access & Rectification: Right to request a copy of held records or update inaccurate information.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of personal records where legal retention limits allow.
  • Data Portability: Export institutional records in standard machine-readable formats (e.g., JSON/CSV).
  • Right to Object & Restrict: Limit specific processing operations or lodge formal complaints with relevant Supervisory Authorities.

* Note: End-borrowers seeking to exercise privacy rights regarding data held inside a Subscriber’s tenant workspace should direct requests directly to the respective lending organization (Data Controller).

9. Cookies & Web Telemetry

Microsolvant utilizes essential cookies for active session handling, cross-site request forgery (CSRF) mitigation, and user authentication state maintenance. Optional web telemetry is collected to monitor service availability and improve platform usability.

10. Children's Privacy

Our platform is designed strictly for commercial lending institutions and corporate entities. We do not knowingly process data pertaining to individuals under 18 years of age.

11. Modifications to Policy

Microsolvant reserves the right to amend this Privacy Policy. Subscribers will be notified of material modifications via email or administrative platform alerts at least 30 days prior to enforcement.

12. Contact Information & Governance

For legal inquiries, data protection requests, or compliance inquiries, please contact our legal office:

Privacy & Data Compliance Office

hello@microsolvant.com

Ref: Legal Compliance Division

Data Protection Officer (DPO)

dpo@microsolvant.com

Corporate HQ Inquiry