Privacy Policy
This Privacy Policy explains how the Company handles data collected and processed in the course of providing alternative-data credit scoring and lending decision support to lending institutions.
1. Who this policy applies to
This policy applies to two distinct categories of data subjects:
- Applicants - borrowers whose consented alternative-data signals are processed by the Company's Platform on behalf of a lending institution.
- Institutional users - employees or authorized representatives of lending institutions who interact with the Company's product surfaces or contact the Company through this website.
Where the Company processes applicant data, it does so as a processor on behalf of the lending institution that acts as the data controller. The lending institution's own privacy notice remains the primary applicant-facing document.
2. Signal categories processed
The Company processes only the four categories of consented alternative-data signals its Platform is designed to read:
- Utility payment records, in the applicant's name, drawn from utility providers or authorized aggregators.
- Mobile recharge and account activity consistency, drawn from mobile operators or authorized aggregators.
- Transaction pattern data, drawn from consented account linkage or verified statements.
- Community and group-lending repayment history, drawn from the originating institution where such records exist.
The Company does not read protected attributes (identity characteristics, demographic categories) as scoring inputs.
3. Consent
Every signal category is bound to a specific, revocable consent captured from the applicant. Consent is stored per applicant, per source and per lending institution. An applicant may revoke consent for any signal source at any time.
Revocation blocks all future reads of that source. Past scored decisions retain a full audit trail of which sources were active at the time of scoring so that any prior decision remains reproducible and defensible.
4. How signals are used
Consented signals are used solely to:
- Compose a credit score and a recommendation tier for the specific lending institution the applicant approached.
- Attribute per-signal contribution and produce reason codes to support the lending institution's underwriting review.
- Retain the exact signal set, sub-scores, weights and rule version associated with each scored decision for audit, regulatory and defensibility purposes.
- Monitor portfolio-level trends across the lending institution's scored applicant base, in aggregate form.
Consented signals are never sold, licensed or otherwise disclosed to third parties for any commercial purpose.
5. Retention
Signal data is retained only for as long as required to score, defend and reproduce a lending decision, and only for the duration agreed with the lending institution acting as data controller. Retention windows are conservative by default and configurable per deployment.
Aggregate portfolio metrics are retained in a de-identified form for the ongoing monitoring purposes described above.
6. Security
All signal ingestion moves over TLS 1.2 or higher. Data at rest is encrypted with AES-256 keys held in a dedicated key management service. Access to raw signal data is scoped to the specific service accounts required for scoring, and human access is short-lived and audited.
The Company's technical and organizational security posture is described in more detail on its Security page.
7. Website visitors and contact form submissions
When you use the Sign Up or Talk to Us forms on this website, the Company collects the details you submit (name, work email, institution name, role, institution type, application volume, message content) solely to respond to your request and to progress the resulting business conversation.
This information is stored in the Company's outbound business communication systems and is not used for any purpose beyond responding to your inquiry and any resulting business relationship.
8. Rights of applicants
Applicants may:
- Request confirmation of which signal categories the Company has processed on their behalf.
- Withdraw consent for any signal source at any time via the lending institution that originally captured the consent.
- Request an explanation of any scored decision that affects them, in the form of the per-signal attribution retained for that decision.
Applicant requests are routed via the lending institution acting as data controller, which is the direct point of contact for applicants.
9. Rights of institutional users
Institutional users interacting with this website may request the Company update or delete the information they submitted through the Sign Up or Talk to Us forms by contacting the Company via the Contact page.
10. Sub-processors
The Company uses a limited number of sub-processors for cloud infrastructure, transactional email delivery and audit logging. Sub-processors are selected against the same security posture the Company holds itself to and are used only for the purposes described in this policy.
11. Changes to this policy
The Company may update this policy as its product surfaces evolve or as applicable law changes. Any material change will be reflected in the version accessible at this URL. Where a change materially affects existing deployments, the Company will notify the affected lending institution directly.
12. Contact
Questions about this Privacy Policy or the Company's data handling may be sent through the Contact page.