Privacy Policy of VivaLend (Revised Version)
Last Updated: May 29, 2026
1. Introduction & Overview
Welcome to VivaLend, a premium digital financing platform built to deliver secure, transparent, and accessible micro-lending solutions. This digital service is owned, maintained, and operated by G.A. OROBIA LENDING CORP., a legitimate financing institution authorized under Philippine laws with SEC Registration Number CS201911568 and Certificate of Authority No. 3035.
We ("VivaLend," "our," "us," or "the Company") hold the privacy of our ecosystem participants in the highest regard. To ensure strict transparency, this document details how we handle information across its entire lifecycle, including capture, structuring, evaluation, archiving, and definitive destruction. Our protocols strictly adhere to the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations (IRR), and global mobile market security updates, including the latest Google Play Developer policies.
2. Data Categories We Process
To deliver automated credit evaluations and secure loan provisions, VivaLend classifies processing operations into two primary streams:
A. Information Mandated via User Submission
During profile generation and credit assessment workflows, you explicitly input the following parameters into our system:
- Bio-demographic Data: Full legal name, date of birth, biological sex, civil status, and educational attainment.
- Contact Specifics: Active mobile communication networks, email endpoints, and verifiable residential physical addresses.
- Professional & Economic Status: Employment categorization, documented monthly revenue scale, employer identifiers, and active financial settlement endpoints (bank account details or registered Electronic Wallet routing keys).
- Official Identification: Clear, high-resolution photographic captures of government-endorsed identification cards along with their alphanumeric indexes.
- Selected Reference Profiles: Selected contact information (name, familial or professional association, and mobile numbers) voluntarily designated to assist during validation or standard administrative notifications.
B. Supplemental External Intelligence
Following your explicit authorization, VivaLend may integrate credit reports, risk indicators, and verification statuses from external licensed organizations. This includes state-authorized credit registries, centralized credit bureaus, anti-fraud consortiums, and third-party identity verification vendors. This external data helps reinforce your baseline credit evaluation and flags potential identity spoofing or systemic platform abuse.
3. System Permissions & Hardware Interface Requirements
To run safely on the Android operating platform and maintain compliant risk frameworks, VivaLend requires specific runtime hardware permissions. We only collect this data after you grant explicit consent through standard OS-level dialogs:
- Camera Access (CAMERA): Required strictly to execute the Real-time Liveness Check (KYC anti-spoofing) and to capture physical government ID cards. The application cannot access, scan, or extract any pre-existing photographs, personal albums, or media metadata stored on your physical device storage.
- Emergency Contacts (Custom UI Selection): Users manually select up to five (5) distinct contacts to serve as references for administrative validation. VivaLend handles this selection via an isolated device interface; we do not download, scrape, or mirror your master address book or contact directory. The selected references are safely transmitted over isolated protocols.
- Location Services (ACCESS_FINE_LOCATION): Collects network-based and satellite-derived coordinates (GPS) during application engagement. This verifies that operations remain within the legal jurisdiction of the Republic of the Philippines and helps mitigate fraudulent remote account takeovers. Continuous background location tracking is strictly deactivated.
- Application Metadata (Custom Discovery): Scans a structural checklist of installed software components (limited to package names, version keys, and installation timelines) to screen for malicious automated tools, debt-evasion scripts, or high-risk unauthorized cloning environments. No data within those individual apps is ever opened, analyzed, or copied.
- Network & Wi-Fi Metrics (ACCESS_WIFI_STATE & ACCESS_NETWORK_STATE): Analyzes network connectivity states, basic carrier parameters, and device IP assignments. This ensures transmission security, stabilizes data traffic pipelines, and blocks multi-device automated network attacks.
- Google Advertising Keys (AD_ID): Processes the standard Google Advertising Identifier to track the performance of digital acquisition campaigns and rule out automated traffic. You can reset or fully turn off this tracking whenever you want via your Android System Settings.
4. Technical Infrastructure & Transmission Encryption
All data traffic passing through the VivaLend mobile architecture is protected by industry-standard 128-bit Transport Layer Security (TLS/SSL) encryption protocols. Information moves exclusively via secure, authenticated endpoints routed to our production gateway at https://phloan.vivalend.net.
Once data arrives at our servers, it is saved in compartmentalized cloud networks. These setups are fortified by enterprise-grade firewalls, continuous intrusion detection monitors, and strict access controls. These measures ensure that personal information stays secure against unauthorized leaks, modifications, or external technical attacks.
5. Purpose of Data Processing
VivaLend processes data strictly under legitimate business frameworks. These operations are limited to the following objectives:
- Eligibility Assessment: Processing personal and professional parameters to determine loan limits and build dynamic credit scores.
- Verification Operations: Executing Know-Your-Customer (KYC) validations to confirm identity authenticity and cross-reference official anti-money laundering registries.
- Platform Security: Monitoring infrastructure metrics to detect fraudulent behavior, device emulation, and coordinated system abuse.
- Service Administration: Distributing critical account statements, payment milestones, and administrative change logs via encrypted notifications.
- Legal Compliance: Meeting statutory mandates managed by the Securities and Exchange Commission (SEC), the National Privacy Commission (NPC), and the Anti-Money Laundering Council (AMLC).
6. Information Sharing Practices
VivaLend does not sell, lease, or trade user profiles to third-party brokers. We only share information with external entities under clear, structured legal frameworks:
- Regulatory Frameworks: Direct disclosure to legal authorities, judicial bodies, or state commissions (such as the SEC or NPC) when required by law or official subpoenas.
- Authorized Service Providers: Sharing targeted data elements with trusted technical partners (such as licensed SMS delivery services, accredited KYC systems, and official collection partners) working under strict non-disclosure agreements.
- Credit Networks: Submitting relevant performance histories to centralized credit registries as mandated by Philippine financing platform rules.
7. Data Retention and Account Deletion
We preserve personal data only as long as necessary to fulfill active financial agreements, resolve accounting histories, or satisfy statutory retention laws under Philippine financing guidelines.
Account Deletion Protocol: You can initiate a full profile deletion request by reaching out to our customer care team at cs@vivalend.net.
Please note that account removal is permanent and cannot be undone. If you have an outstanding financial balance or active contractual obligations, data deletion will be paused. In these cases, your data must be legally preserved until all financial liabilities are completely settled and verified.
8. Statutory Data Rights
Under the provisions of the Philippine Data Privacy Act of 2012, you hold comprehensive rights regarding your personal information. You can confidently exercise the following options:
- Right to Information: Query the platform regarding the current logic and status of your processed data elements.
- Right to Correction: Request immediate updates to inaccurate, outdated, or incomplete details in your user profile.
- Right to Object: Halt processing actions tied to secondary business activities, including marketing campaigns or elective promotional tracks.
- Right to Redress: Secure legal remedies or file formal grievances with the National Privacy Commission (NPC) if you suspect unauthorized data processing or a breach of privacy protocols.
9. Revisions & Administrative Updates
VivaLend reviews and updates this Privacy Policy periodically to maintain alignment with regulatory adjustments, new mobile operating system updates, and changing risk management protocols. When updates occur, we will adjust the "Last Updated" marker at the top of this document and provide clear notices within the application interface or via your registered email address. We encourage you to review this policy periodically to stay informed about how we protect your information.
10. Contact & Communication Terminal
For clarifications regarding this privacy framework, to exercise your statutory data options, or to connect with our Data Protection Officer, please reach out to our dedicated support channels:
- Support Email: cs@vivalend.net