CREDEITY INC.

Terms of Service

Credeity Inc. · Delaware C-Corporation

Version 1.0 · Effective date: July 11, 2026

Section 1. Scope of Service and Commercial Purpose

Credeity, Inc. ("Credeity") provides an independent underwriting intelligence and data validation layer solely for commercial-purpose business transactions. The platform, its automated analysis pipelines, and the resulting Evidence Reports and Analytics Supplements are engineered exclusively for the evaluation of commercial credit risk, business cash flows, and institutional underwriting diligence.

Section 2. Restriction Against Consumer Use

Lenders, users, and clients are strictly prohibited from using the Services, reports, or any data artifacts for any personal, family, or household purpose, or for determining any individual's eligibility for personal credit, insurance, employment, housing, or any other purpose covered by the Fair Credit Reporting Act. By accessing the platform, the User certifies that each inquiry and validation action is initiated solely for the evaluation of a business entity or the commercial purpose of a commercial borrower, and the User covenants to maintain controls sufficient to enforce this restriction within its organization.

Section 3. Commercial Purpose and FCRA Position

The User acknowledges and agrees that Credeity is not a "consumer reporting agency" and that Credeity's reports and validation artifacts are not "consumer reports" as defined under the Fair Credit Reporting Act, 15 U.S.C. Section 1681 et seq. Reports are prepared on business entities, for commercial credit purposes, at the request of a lender, and with the business's authorization.

Certain authoritative-source records used by Credeity concern individuals acting in a professional or business capacity, including provider enumeration (NPI), state professional licensure status, and federal exclusion and debarment screening. These are public registry records bearing on the practice's authority to operate and bill, and Credeity reports them as such.

Credeity does not analyze, score, or furnish personal financial information relating to guarantors, principals, or payors. Personal credit history, personal income, personal assets, and personal financial condition are outside the scope of every report. Where Source Data incidentally contains personal financial information, Credeity excludes it from analytical outputs or de-identifies it under Credeity's De-Identification Standard. Credeity does not furnish information bearing on any individual's eligibility for personal credit, insurance, employment, or housing.

Section 4. Source Data and Derived Data

"Source Data" means data accessed by Credeity from systems designated and authorized by the business, together with documents and information the business submits directly. "Derived Data" means de-identified data, features, metrics, statistics, scores, benchmarks, models, and analytical outputs created by Credeity from Source Data, from which no business or individual can reasonably be identified. As between the parties, Credeity owns all right, title, and interest in the platform, its methodologies (including the Payment Discipline Index), its benchmarks, and all Derived Data. Credeity may retain and use Derived Data after any authorization ends solely to maintain, validate, and improve its methodology and to construct aggregated benchmarks. Benchmarks are constructed only from populations large enough that no individual business, borrower, or lender can be identified or reverse-engineered, subject to a minimum population threshold stated in the De-Identification Standard. Credeity does not disclose any Derived Data attributable to an identifiable borrower or lender to any third party, and does not disclose a lender's case activity, volume, or findings to any other lender.

Section 5. Data Protections

Credeity does not sell Source Data, does not disclose Source Data except to the authorizing lender and to Credeity's service providers under confidentiality obligations, and does not attempt to re-identify Derived Data. Revocation of a business's authorization ends Credeity's prospective access to designated systems; Source Data is retained and disposed of under Credeity's retention schedule and applicable lender file-retention requirements; revocation does not apply to Derived Data created before revocation.

Additional standard terms (acceptable use, disclaimers, limitation of liability, governing law) will be incorporated in a subsequent version.