LeriFlow
← Back to Home

Privacy Policy

Last updated: 16 August 2026
LeriFlow ("we", "us", "our", operated as a project of Innocent Mathew, Tanzania) provides software that microfinance institutions, SACCOS, and agency banking operators ("Customers") use to manage their own borrowers, loans, and financial records. This policy explains how we handle data on the platform. If you are a borrower or guarantor whose information was entered by one of our Customer institutions, please also refer to that institution's own privacy practices — they are the data controller for your loan information; LeriFlow acts as their data processor.

1. Information We Collect

We collect two categories of information:

2. How We Use Information

3. Data Isolation Between Institutions

LeriFlow is a multi-tenant platform: multiple institutions use the same infrastructure, but each institution's data is logically isolated at the database level. Users of one institution cannot access another institution's customers, loans, or reports. We treat cross-tenant data leakage as a critical security defect and actively audit for it.

4. Where Data Is Stored

Platform data is currently hosted on cloud infrastructure provided by Hetzner Online GmbH, with servers located in Europe. We are evaluating options for data residency closer to our primary markets in East Africa. If data residency is a regulatory requirement for your institution, please contact us before onboarding so we can discuss current arrangements.

5. Credit Reference Bureau (CRB) Sharing

Where your institution enables this feature and obtains borrower consent (via the built-in consent clause in our Loan Application Form), your institution may submit or query borrower credit information with Credit Reference Bureaux licensed by the Bank of Tanzania. LeriFlow does not initiate CRB submissions on its own; this is a feature your institution controls.

6. Data Retention

We retain operational data for as long as your subscription is active, plus a reasonable period afterward to allow you to export your records or reactivate your account. Daily automated backups are retained on a rolling basis for disaster-recovery purposes.

7. Security Measures

We have not yet completed a formal third-party security audit or penetration test. We disclose this openly rather than making unverified claims, and welcome due-diligence questions from institutions considering LeriFlow.

8. Your Rights

If you are an authorized user of a Customer institution, you may request access to, correction of, or export of data your institution holds through your institution's administrator, or by contacting us directly. We aim to comply with the principles of Tanzania's Personal Data Protection Act, 2022.

9. Contact Us

For privacy questions or data requests, contact us at hello@leriflow.com or support@leriflow.com, or via WhatsApp at +255 762 449 492.

This policy describes our current practices in good faith. LeriFlow is an early-stage product and this document has not yet been reviewed by outside legal counsel. If your institution requires a signed Data Processing Agreement or has specific compliance requirements, please contact us to discuss before migrating live customer data.