Due diligence

Data and suppliers

What is kept, what is never kept, and who else touches it.

What we keep, and for how long

WhatKept by Creditcrest
Bank statements and transactionsNever. Read while the request is open, then gone
Applications, loans, documents, identity resultsNever. Kept in the lender’s own database
Counts of what a lender used, for invoicingSeven years, as tax records. They name the lender, never a borrower
Request logs: time, address, statusNo more than 30 days. Never a request’s body
Sandbox entriesCleared at least once a day. Invented details only

No borrower’s data is used to train or tune anything. Nothing is sold.

Where it is processed

Cloudflare is a global network: a request is usually handled in Australia but may be handled elsewhere. A lender must say so in its own privacy policy (APP 8), and we give it the wording.

Suppliers

Each is used only for its job, and only once the lender has switched that service on. We tell lenders 30 days before adding one.

SupplierWhat forWhereWhen
Cloudflare, Inc.Hosting, network, storage, cookieless visit countsGlobal; United States companyAlways
DiditID document, selfie and liveness checksSpanish companyWhen identity checks are on
ResendEmail codes and noticesUnited StatesWhen email is on
TwilioText-message codesUnited StatesWhen SMS is on
A bank-data provider accredited under the Consumer Data RightBank transactions, with the applicant’s consentAustraliaWhen bank connection is on; named in the order form
ZeptoPaying out loans, checking the account name, and collecting repayments by PayToAustraliaWhen payments are on

Credit reporting bodies are not our suppliers: a lender contracts with them itself, and we run the enquiries and reports on its behalf.

A breach

We tell an affected lender within 24 hours of becoming aware of a breach that touches its data, with what it needs for its own assessment and any notice to the OAIC.