CREDEITY INC.

Data Handling & Privacy

Credeity Inc. · Delaware C-Corporation · Effective August 2026

Overview

Credeity processes borrower-authorized accounting data solely for the purpose of generating independent underwriting intelligence reports, derived from observed payment behavior, for regulated lenders.

Data Usage

Data accessed through the Credeity platform is used exclusively for the authorized credit evaluation. Credeity does not sell or license borrower data and does not use borrower data for marketing. Credeity retains de-identified derived statistics used to maintain and validate its methodology and to construct aggregated benchmarks, described in Section 4 of the Terms of Service. Derived statistics contain no information from which a borrower, practice, or lender can be identified.

Access & Storage

Data is accessed on a read-only basis and is limited to authorized evaluation processes. Findings, verification statuses, evidence citations, the Case Evidence Manifest, and the methodology version in force at issuance are retained for the contracted retention period, with a standard term of 84 months to align with lender credit file retention and SBA guaranty purchase review windows. Source documents (including original bank-statement PDFs and accounting-file uploads) are delivered to the lender with the report and are retained by Credeity for 90 days after delivery, then deleted. The lender is the system of record for source documents from issuance forward. A lender may elect extended Credeity custody of source documents up to the findings retention term. Derived transaction data, meaning structured extracts parsed from bank statements such as date, description, debit, credit, account, and running balance, are retained for the same contracted findings retention term and are not deleted when the source PDF is deleted. Derived transaction data are not findings. They are retained so that a finding remains reproducible from its inputs after the source document window closes. All deletions are logged, and a deletion certificate is available to the lender or borrower on request. Lender account data is retained only as long as the institutional relationship remains in effect.

Security

Data in transit is protected using TLS 1.2 or higher. Data at rest is encrypted using AES-256. Access controls are enforced at the application and database level to limit exposure to authorized processes only.

Borrower Authorization

All analyses are performed only after explicit borrower authorization for the specific evaluation. Authorization is one-time and read-only. Credeity does not retain ongoing access to borrower accounting systems.

Regulatory Position

Credeity is not a consumer reporting agency as defined under the Fair Credit Reporting Act (FCRA). Reports are delivered solely for internal institutional credit evaluation purposes.

Privacy Inquiries

For data handling or privacy-related inquiries, contact info@credeity.com.