Privacy Notice

Effective date: 10th November 2024

Crediflow AI is committed to protecting your personal data and to handling it transparently, lawfully, and securely.

For privacy requests, contact privacy@crediflow.ai.

Introduction

Welcome to Crediflow AI's Privacy Notice.

Crediflow AI respects your privacy and is committed to protecting your personal data.

This Privacy Notice explains how we collect, use, store, and protect your personal data when you use our website, support channels, and platform services.

We do not sell your personal data and we do not share it with third parties unless you explicitly authorize it or a legal basis applies.

About Our Privacy Policy

This policy explains your relationship with our company and how we process information you provide to us.

It applies to personal data collected through your use of our website, including when you use our solutions and credit underwriting platform.

This website is not intended for children and we do not knowingly collect data related to children.

This Privacy Notice supplements other specific privacy notices and is not intended to override them.

About Crediflow AI

Crediflow AI is the trading name of Generative Technology Ltd, registered in the United Kingdom.

We operate in alignment with applicable frameworks including UK GDPR, UK DPA 2018, UK PECR, EU GDPR, and CPRA where relevant.

You can contact us by post at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, or by email at privacy@crediflow.ai.

Changing Your Preferences

You can request changes to your contact, web, and marketing preferences at any time by contacting privacy@crediflow.ai.

This notice covers use of our website (https://www.crediflow.ai/), support channels (including Slack and Notion), and platform services.

Our website may link to trusted third-party websites. Those sites operate under their own privacy notices.

How We Do Business

Crediflow AI is committed to upholding your personal data rights and enabling you to change or withdraw consent where applicable.

We can also guide you on making formal complaints to relevant authorities, including the Information Commissioner's Office (ICO).

Sensitive Data

Crediflow AI does not intentionally collect sensitive personal data such as racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation, criminal records, or health data.

Who This Policy Applies To

This policy applies to individuals and companies interacting with Crediflow AI as users, customers, administrators, or in other operational roles.

What Information This Policy Applies To

We process personal data you provide directly and data collected indirectly through website and platform usage.

This may include information provided during registration, onboarding, account management, communications, product usage, and support interactions.

  • Identity and contact data, such as full name, email, phone number, and username.
  • Operational data, such as IP address, usage timestamps, session duration, and user behavior.
  • Business-related context, such as place of work and service configuration data.
  • Feedback and communication data from email, social media, Slack, or support channels.

How We Use Personal Data

We use personal data to operate, secure, and improve our website and platform services.

  • Register and manage your account.
  • Provide and maintain requested services.
  • Process transactions (without storing bank/card data on the platform).
  • Send service updates and relevant product notifications.
  • Fix issues and improve service quality and reliability.
  • Customize content and experience where appropriate.

Legal Bases for Processing

Where required, we rely on one or more legal bases depending on the purpose of processing.

  • Consent.
  • Contract necessity.
  • Legal obligation.
  • Legitimate interests, unless overridden by your rights.

Consent and Opt-Out

By submitting personal data through our website, you consent to processing consistent with this Privacy Notice where consent is the applicable basis.

You can amend preferences, withdraw consent, or object to certain processing by emailing privacy@crediflow.ai.

Data Processing and Storage

Crediflow AI collects and stores data in the UK.

Unless otherwise required, we store data for up to 5 years after your last recorded login attempt.

Transaction and order related data may also be retained up to 5 years, with extensions where required by applicable law.

We use selected third-party vendors for payments, commercial operations, and account management, and some may process data outside the EU/UK.

Data processing reasons, data types, and legal bases

Marketing and Communications

We may send marketing communications if you provided contact details and opted in.

You can opt out and manage preferences at any time.

Our Company Obligations

As a data controller, Crediflow AI is responsible for personal data processed under our control.

As a data processor in certain contexts, we apply appropriate technical and organizational safeguards to protect data.

  • We only process data fairly and lawfully.
  • We only process data for purposes described in this policy or required by law.
  • We implement safeguards to prevent unauthorized access, misuse, loss, or corruption.

Third Parties

We share personal data with third parties only under limited and specific circumstances.

  • Vendors and service providers supporting infrastructure, collaboration, and operations (for example cloud, communication, or workspace tools).
  • Authorities or law enforcement when required by law or to protect rights, security, and legal claims.
  • We do not disclose data to other third parties without a lawful basis or your consent.

Data Controller and Data Processor Roles

Crediflow AI can act as a data controller and/or data processor depending on the relationship and processing activity.

We are generally controller for website visitors, support communications, newsletter subscriptions, onboarding, and platform user account management.

We are generally processor for data you ingest into the platform on your own behalf.

You remain responsible for access permissions, dataset sharing decisions, and retention policies in your organization.

Our Security Measures

Protecting personal data is a core priority for Crediflow AI.

We implement technical, organizational, and administrative controls, including encryption in transit and at rest, access controls, backup procedures, network defenses, and regular security maintenance.

We also use internal policies, DPIAs, and role-based data access limitations.

Legitimate Interests

Where permitted by law, we may share selected information for non-marketing legitimate interests such as fraud prevention, identity verification, and credit-related risk controls.

Children's Privacy and Age Limits

Crediflow AI does not knowingly process children's personal data without the required legal basis and safeguards.

Our services are not directed to children under 18 years of age.

If you believe a child has provided personal data without valid authorization, contact privacy@crediflow.ai and we will take appropriate action.

Advertising

We may work with partners that support marketing across third-party websites and apps.

These providers may use cookies, web beacons, or similar technologies under their own policies and controls.

Crediflow AI does not advertise to children and does not use child activity data for personalized advertising.

Your Rights

You may have the following rights under applicable data protection laws.

  • Right to be informed.
  • Right of access (including DSAR/SAR requests).
  • Right to rectification.
  • Right to erasure, restriction, portability, and objection in applicable cases.
  • Rights related to automated decision-making and profiling.

How We Handle Rights Requests

We aim to provide a response within one month where required by applicable law, including reasons if we cannot act on a request.

You may also have the right to lodge a complaint with a competent supervisory authority or seek judicial remedy.

Requests involving children under 18 must be made by a parent or legal guardian.

Other Jurisdictions

Rights and response obligations may vary depending on your jurisdiction.

We may require additional information to verify identity before responding.

Certain information may be exempt from disclosure where necessary for legal compliance or legal claims.

Contact Us

If you have questions, concerns, or requests related to this Privacy Notice or your personal data, contact us at privacy@crediflow.ai.

We aim to process requests within 30 days. Subject Access Requests are generally free of charge, though we may charge for excessive or unreasonable requests where law allows.