Privacy Policy
This is a draft template describing the platform's actual technical behaviour. It is not a substitute for review by qualified Nigerian legal counsel before publication or reliance.
What we process, and on whose behalf
CreditPulse is operated by lenders as a processor of their customers' data — loan, mandate, salary-window, and contact records belong to the lending organisation using the platform, not to CreditPulse.
Each lending organisation is a separate, isolated tenant. Records are scoped to a tenant at both the application and database level, and cross-tenant access is denied and tested for.
Sensitive data handling
Mandate credentials, call transcripts, and message bodies are excluded from ordinary application logs and are masked in API responses according to the requesting user's role.
Money amounts are stored as integer minor units, never floating point, to avoid rounding-related data integrity issues.
Automated decisions
Salary-window predictions and recovery outreach decisions are produced by explicit, versioned rules — not by an opaque model. Every automated action is attributable to the specific rule version that produced it, and to the input data evaluated at the time.
A prediction alone never creates authority to debit an account; that authority comes only from an active, valid mandate.
Data subject rights
Requests from an end customer of a lending organisation (access, correction, deletion, or objection) should be directed to that lending organisation, which controls the underlying data and is the appropriate party to respond under applicable Nigerian data protection law.
Retention
Audit events are append-only and retained for the duration required by the lending organisation's regulatory obligations, which this platform does not itself determine.