LENDFLOW THIRD-PARTY DATA EXCHANGE POLICY

Last Updated: 07/11/2025

This Lendflow Third-Party Data Exchange Policy (this “Data Exchange Policy”) is incorporated into and forms part of the Lendflow Services Agreement and Terms of Service (collectively, the "Agreement"). Capitalized terms used but not defined herein shall have the meanings assigned in the Agreement.

1. DEFINED TERMS.  The following terms, when capitalized, have the meaning given below:

"Applicant Data" means any information transmitted by or relating to a business seeking financing through the Services.

"Customer" means the entity that has entered into an Agreement with Lendflow to access and use the Services.

"Third-Party Recipient" means any entity that is not directly contracted with Lendflow but to whom or from whom data may be shared or received at the direction of the Customer.

"Data Sharing" means any transmission, exchange, or access of data (including Applicant Data) between Lendflow and a Third-Party Recipient, initiated or authorized by a Customer.

"Services" means the products, software, platform, APIs, and related services offered by Lendflow.

2. PURPOSE AND SCOPE

This Policy governs the terms under which Customers may request that Lendflow transmit or receive Applicant Data or other information to or from Third-Party Recipients. This Policy applies to any data-sharing initiated, authorized, or permitted by the Customer.

3. CUSTOMER DIRECTION AND AUTHORIZATION

3.1. By initiating or requesting a connection between Lendflow and a Third-Party Recipient, the Customer: (a) Instructs Lendflow to share or receive data on its behalf; (b) Acknowledges that such sharing is solely at the Customer's direction and risk; (c) Confirms it has all legal rights and consents required to permit the data exchange.

3.2. Customer shall not request data transmission to or from any party that would result in a violation of applicable law, the Agreement, or any third-party rights.

4. RESPONSIBILITIES AND LIMITATIONS

4.1. Customer assumes all responsibility for ensuring that Third-Party Recipients: (a) Comply with applicable data privacy and security laws; (b) Use shared data solely for lawful and authorized purposes; (c) Do not further share or misuse the data.

4.2. Lendflow is not responsible for the actions or omissions of any Third-Party Recipient and disclaims all liability for any loss, misuse, or unauthorized access to data once it has been shared at Customer’s request.

4.3. Lendflow may log, rate-limit, or audit any data-sharing transaction and reserves the right to disable or reject integrations that present regulatory, legal, reputational, or security risks.

5. THIRD-PARTY INITIATED INTEGRATIONS

5.1. Any third party that proactively accesses Lendflow systems or APIs, including at the direction of a Customer, agrees to be bound by this Policy and the Agreement.

5.2. By submitting API requests, receiving data, or initiating a connection to Lendflow, such third party represents and warrants that it: (a) Has appropriate authorization to receive such data; (b) Accepts and agrees to be bound by this Policy and the Agreement; (c) Will handle all data in compliance with applicable law and data protection standards.

5.3. Lendflow may request, and Customer agrees to provide, reasonable cooperation or documentation regarding its relationship with a Third-Party Recipient, including audit rights or compliance representations, as necessary to comply with applicable law or due diligence obligations.

6. SECURITY AND DATA HANDLING

Lendflow will transmit data using reasonable administrative, technical, and physical safeguards. However, Lendflow cannot control how third parties handle received data and disclaims liability for any downstream data usage outside of its control

Customers are solely responsible for ensuring that any data shared is accessed and processed by Third-Party Recipients in a manner consistent with this Policy and the Agreement..

7. TERMINATION OR RESTRICTION OF SHARING

Lendflow may, in its sole discretion, restrict or terminate data flows to or from any Third-Party Recipient upon notice to the Customer or without notice if required by law or necessary to prevent harm.

8. CHANGES TO THIS POLICY

We may revise this Policy at any time. Material changes will be posted at [www.lendflow.com/data-exchange-policy] with an updated effective date. Continued use of the Services or data-sharing functionality after the updated date constitutes acceptance.

9. CONTACT

Questions or concerns about this Policy should be directed to:
legal@lendflow.com
Lendflow, Inc.
2222 Rio Grande Street, Suite 110
Austin, TX 78705