This Privacy Policy explains how CreditVantage AI collects, processes, protects, retains, and handles information in connection with the AI Credit Analyst platform.
CreditVantage AI is the brand and website through which the AI Credit Analyst platform is made available. AI Credit Analyst is an AI-assisted credit analysis and report-generation platform for authorized institutional users.
The platform is operated by Robert Franklyn, located at 1B Diego Martin Main Road, Diego Martin, Trinidad and Tobago. References to “we”, “us”, and “our” refer to the operator of the platform, trading under or using the CreditVantage AI brand. References to “Client Institution” mean an approved credit union, bank, lender, mortgage provider, or other authorized institution that subscribes to or uses the platform. References to “Authorized User” mean an officer, employee, agent, or representative authorized by a Client Institution to access the platform.
Privacy questions may be directed to [email protected].
This Privacy Policy explains how we collect, receive, use, process, store, disclose, protect, retain, and delete information in connection with the AI Credit Analyst website, portal, forms, workflows, report generation services, email delivery, and related support services.
This Policy applies to:
• visitors to our website;
• Client Institutions and Authorized Users;
• borrower or applicant information submitted by a Client Institution through the platform;
• uploaded credit bureau reports and related credit information, where applicable;
• generated credit analysis reports, credit memos, workflow records, and platform logs.
This Policy applies whether access to the platform is provided during a beta testing period, free trial, demonstration or evaluation period, or standard commercial arrangement.
Borrowers and applicants are generally not direct users of the platform, but their information may be processed where it is submitted by a Client Institution for credit analysis, report generation, review, recordkeeping, support, security, or related platform purposes.
AI Credit Analyst is not a credit bureau, lender, debt collection agency, or final credit decision-maker. The platform does not collect borrower or applicant information from independent sources for general credit reporting purposes, does not maintain a consumer credit database for general searching by subscribers, and does not provide independent borrower credit files or credit bureau reports to institutions.
The platform receives borrower/application data, uploaded credit bureau reports, supporting documents, and related credit information only where such information is submitted by a Client Institution or Authorized User for the limited purpose of supporting credit analysis, credit-risk assessment, report generation, review, recordkeeping, security, support, and related platform functions.
The platform is designed to support credit officers, supervisors, and credit committees. It does not replace institutional lending policies, professional judgment, credit committee authority, or any legal or regulatory obligations of the Client Institution.
This Policy is designed with regard to the following Trinidad and Tobago legal and regulatory considerations:
This Policy is designed with regard to applicable Trinidad and Tobago data protection, cybersecurity, electronic records, and institutional governance considerations.
| CATEGORY | EXAMPLES | SOURCE |
|---|---|---|
| Website and contact information | Name, business email, phone number, institution name, message content, demo requests, inquiry forms, IP address, device/browser information, and website analytics data. | Website visitors, prospective clients, Authorized Users, and technical systems. |
| Client Institution and Authorized User information | Institution name, institution and branch codes, role/title, business contact details, login credentials or account identifiers, access permissions, onboarding records, suspension or offboarding instructions, access-removal and restoration records, support requests, training records, and usage logs. | Client Institution and Authorized User. |
| Borrower/application data entered into forms | Income, employment, loan request details, obligations, expenses, assets, liabilities, repayment capacity information, purpose of loan, collateral information, and other credit-relevant application data submitted by the Client Institution. | Client Institution or Authorized User. |
| Uploaded credit report information | Credit bureau report information uploaded by the Client Institution, which may contain personal identifiers, account history, arrears, defaults, judgments, inquiries, and other credit bureau data. | Client Institution or Authorized User. |
| Generated reports and workflow records | AI-assisted credit analysis reports, credit memos, risk flags, DSR calculations, summaries, audit logs, file links, timestamps, and delivery records. | Generated by the platform from submitted information and workflow processing. |
| Security and technical logs | Login events, timestamps, access logs, error logs, processing status, API activity, email delivery status, and similar operational records. Website, hosting, security, authentication, form, workflow, database, email, and support systems may also automatically process technical information such as IP addresses, device/browser information, or similar metadata for security, authentication, troubleshooting, audit, platform operation, and system performance purposes. | Platform, hosting, automation, security, and service-provider systems. |
The platform is designed not to require unnecessary personal identifiers as form fields for the credit analysis workflow. The standard credit analysis form does not require Client Institutions or Authorized Users to enter borrower names, residential addresses, identification numbers, phone numbers, email addresses, employer names, or similar personal identifiers.
However, uploaded credit bureau reports or other supporting documents may contain personal identifiers or other personal information that the platform does not require as separate form fields. This may include, for example, borrower names, addresses, identification details, employer information, contact information, or other identifying details included in the uploaded document by the issuing credit bureau or by the Client Institution.
Where such documents are uploaded by a Client Institution or Authorized User, the platform may receive, route, process, store, and retain the uploaded document as part of the platform workflow. The platform does not use personal identifiers contained in uploaded documents for borrower profiling, marketing, or final credit decision-making.
Generated reports are designed to focus on credit-relevant analysis and to avoid surfacing unnecessary personal identifiers where possible. Client Institutions and Authorized Users are responsible for reviewing uploaded documents and generated reports, avoiding unnecessary circulation of personal information, and complying with their own borrower confidentiality, consent, and recordkeeping obligations.
We collect and process information for the following purposes:
The Client Institution is responsible for ensuring that it has obtained all borrower consents, notices, authorizations, lawful bases, internal approvals, and regulatory permissions required to submit borrower/application information and uploaded credit reports to the platform. The Client Institution must not submit information to the platform unless it is authorized to do so and unless the information is being submitted for a legitimate credit assessment or related institutional purpose.
The Client Institution is also responsible for ensuring that the information it submits is accurate, complete, current, relevant, and limited to what is reasonably necessary for the intended credit assessment purpose. Client Institutions and Authorized Users are responsible for avoiding the upload or entry of unnecessary personal identifiers or unrelated personal information that is not required for the credit analysis workflow.
To operate the platform, we may use trusted third-party service providers and subprocessors that help receive submissions, automate workflows, process information, store records, generate reports, deliver reports, provide security, host the website or portal, maintain backups, and provide support. These providers may include categories of technology vendors such as workflow automation providers, database and cloud storage providers, artificial intelligence processing providers, report and document generation providers, email delivery providers, website hosting providers, cybersecurity providers, analytics providers, and similar technical vendors used in the platform workflow.
We do not sell borrower/application information. Service providers and subprocessors are used to operate, secure, support, maintain, and deliver the platform. Where they process information on our behalf, they are expected to process information only for authorized platform purposes and subject to appropriate confidentiality, security, data protection, access control, and retention obligations. The specific categories and providers used may change as the platform evolves. Material service-provider arrangements are reviewed contractually and legally as appropriate.
Where artificial intelligence processing providers are used, we seek to use providers and service configurations under which submitted Client Institution and borrower/application information is not used to train public AI models.
The platform uses artificial intelligence and structured credit analysis logic to assist with credit review and report generation. The platform may identify risks, summarize credit information, calculate ratios, generate explanations, highlight relevant credit considerations, and provide decision-support observations.
The platform does not make final lending decisions, does not approve or decline borrowers, and does not replace the credit officer, supervisor, credit committee, board, or institutional decision-making process. Final credit decisions remain with the Client Institution and its designated officers, supervisors, committees, or other authorized decision-makers.
We may disclose or make information available to:
Client Institutions and Authorized Users are responsible for ensuring that information is not disclosed outside their institution except in accordance with their own policies, borrower consent, applicable law, and any agreement with us.
Some service providers and subprocessors may process, store, access, or support information from outside Trinidad and Tobago. Where personal information is requested to be disclosed or processed outside Trinidad and Tobago, we aim to use providers that maintain reasonable safeguards appropriate to the sensitivity of the information and the nature of the processing. Client Institutions are responsible for determining whether their own policies or regulatory obligations require additional approvals or contractual safeguards before using the platform.
We retain information only for as long as reasonably necessary for the identified purposes for which it was collected, received, processed, or generated.
The retention periods below are intended as maximum retention periods for ordinary platform operations. Information may be deleted, anonymized, aggregated, or otherwise securely disposed of earlier where it is no longer required for the relevant platform purpose.
In limited circumstances, a record may be retained beyond the stated period where required by law, court order, regulatory request, regulatory examination, law-enforcement request, active security investigation, active dispute or complaint, contractual obligation, or documented legal hold. Where such an exception applies, the information will be retained only for as long as reasonably necessary to address that specific circumstance and will then be deleted, anonymized, aggregated, or otherwise securely disposed of in accordance with the applicable retention and deletion process.
This may include retention of borrower/application form submissions, uploaded credit bureau reports or supporting documents, generated credit analysis reports or memos, workflow records, database records, email delivery records, system logs, audit logs, support records, and backup records, in accordance with the platform workflow, Client Institution requirements, contractual obligations, applicable law, and the retention periods below.
Suspension or removal of an Authorized User, closure of a branch, expiry or non-renewal of a service arrangement, or termination of a Client Institution’s use of the platform does not necessarily result in immediate deletion of all related information.
Following offboarding, we may continue to retain relevant information for the remainder of the applicable retention period where reasonably necessary for:
Information retained after offboarding may include Authorized User identifiers, institution and branch codes, access and authorization records, application and workflow records, generated reports, system and audit logs, support communications, usage records, billing records, and backup copies.
Where a Client Institution requests the return, export, deletion, anonymization, or secure disposal of information following offboarding or termination, we will assess the request against:
Deletion from an active platform system may not result in immediate deletion from backups, system logs, email records, or service-provider systems. Such copies may remain until they are overwritten, deleted, anonymized, or otherwise removed through the applicable retention or backup cycle.
Institution codes, branch codes, Authorized User identifiers, and related reference information may be retained where necessary to preserve the historical accuracy, auditability, and integrity of application, report, usage, and billing records.
| INFORMATION CATEGORY | RETENTION PERIOD | NOTES |
|---|---|---|
| Borrower/application form submissions | Up to 1 year after report generation | Retained for platform workflow, Client Institution review, audit, support, and recordkeeping purposes. |
| Uploaded credit bureau reports or supporting documents | Up to 180 days after report generation | Retained only as necessary for the platform workflow, Client Institution requirements, audit, support, dispute handling, or contractual obligations. |
| Generated credit analysis reports or memos | Up to 2 years after report generation | Retained for Client Institution review, audit trail, recordkeeping, support, and dispute-resolution purposes. |
| Workflow records and database records | Up to 2 years after report generation or final workflow processing | Includes processing records, submission history, status records, file links, timestamps, and related platform records. |
| Email delivery records | Up to 1 year after delivery | Includes records of report delivery, delivery status, timestamps, and related communication logs. |
| System logs and audit logs | Up to 12 months after creation | Retained for security, troubleshooting, access control, misuse detection, audit, and platform integrity purposes. |
| Support records | Up to 2 years after the support matter is closed | Includes support requests, troubleshooting records, training-related records, and client-service communications. |
| Authorized User, institution, branch, onboarding, suspension, and offboarding records | Up to 2 years after access removal or termination, or longer where required for an active contract, dispute, audit, billing matter, security investigation, or legal obligation | Includes usernames, institution and branch identifiers, access dates, authorization instructions, suspension and restoration records, onboarding and offboarding records, and related administrative communications. Historical identifiers may be retained where necessary to preserve application, report, usage, and billing records. |
| Backup records | Up to 90 days, subject to the applicable backup rotation or deletion cycle | Backup copies may remain for a limited period until overwritten or deleted in accordance with the applicable backup schedule. |
Client Institutions remain responsible for determining and complying with their own statutory, regulatory, AML/CFT, credit-file, audit, internal governance, and institutional record-retention obligations. The platform operator’s retention practices do not replace any retention period or recordkeeping obligation that applies to a Client Institution as a bank, credit union, lender, supervised entity, or regulated business.
Where information is no longer required, we will delete, anonymize, aggregate, or otherwise securely dispose of it in accordance with the applicable workflow, contract, retention schedule, legal requirements, and technical deletion cycle. Backup copies may remain for a limited period until overwritten or deleted in accordance with the applicable backup schedule.
We take reasonable technical, administrative, and organizational measures to protect information against unauthorized access, loss, misuse, alteration, disclosure, and destruction. Depending on the final platform configuration, these safeguards may include SSL/TLS encryption for website traffic, web application firewall controls, multi-factor authentication, access controls, password controls, secure hosting, role-based permissions, logging, secure workflow design, secure report delivery, staff confidentiality obligations, and security monitoring.
No method of internet transmission or electronic storage is completely secure. Client Institutions and Authorized Users must also maintain appropriate internal safeguards, including secure devices, secure email practices, account controls, staff training, and proper handling of downloaded reports.
The accuracy of AI-assisted credit analysis reports depends on the accuracy, completeness, currency, and relevance of the information submitted by the Client Institution or its Authorized Users. The platform does not independently verify borrower/application information, uploaded credit bureau reports, supporting documents, or other source data submitted through the platform.
The Client Institution is responsible for verifying submitted information, reviewing generated reports before use, correcting errors in its own records, and resolving any borrower/applicant concerns, disputes, or correction requests relating to source data, credit bureau information, application information, lending records, or institutional decision-making.
Where a borrower or applicant raises a concern about inaccurate information, the borrower or applicant will generally be directed to the relevant Client Institution. Where the concern relates to credit bureau information, the Client Institution is responsible for following its applicable borrower communication, dispute, correction, and credit bureau correction procedures.
We may assist the Client Institution in investigating whether an issue arose from platform processing, report generation, workflow handling, or other technical operation of the platform. We do not determine the accuracy of third-party credit bureau data or source information submitted by the Client Institution.
Individuals may have rights under applicable law to request information about the existence, use, disclosure, correction, or handling of their personal information. Because borrower/application information is generally submitted by the Client Institution, requests from borrowers may need to be directed to or coordinated with the relevant Client Institution.
Privacy requests may be submitted to [email protected]. We may require reasonable information to verify identity, identify the relevant Client Institution, locate the relevant record, and determine whether the request should be handled by us, by the Client Institution, or jointly.
Our public website may use cookies, analytics, security tools, or similar technologies to operate the website, improve performance, understand usage, protect against misuse, and support inquiries or demo requests. These tools may include website analytics and security services, such as Google Analytics, Cloudflare, or similar providers.
These tools may process technical and usage information such as IP addresses, approximate location derived from IP address, browser and device information, pages visited, referring pages, timestamps, traffic patterns, and similar website usage or security data. This information is used for website operation, security, performance monitoring, troubleshooting, analytics, and protection against misuse.
We do not use website analytics or technical metadata for borrower profiling, credit assessment, marketing to borrowers, or final credit decision-making. Borrower/application information submitted through the platform is handled separately from general website analytics data.
We may update this Policy from time to time. The updated version will be posted on our website or otherwise made available. Material changes may be communicated to Client Institutions through the platform, email, contract update, or other appropriate notice method.
CreditVantage AI
Trinidad and Tobago
Email: [email protected]
Website: https://creditvantageai.com
| DPA PRINCIPLE | HOW THIS POLICY ADDRESSES IT | RELEVANT SECTIONS |
|---|---|---|
| Responsibility | The Policy identifies the operator, allocates responsibilities between the platform and Client Institution, and requires service providers to handle information under appropriate obligations. | Sections 1, 8, 9, 14 |
| Identified purpose | The Policy identifies platform purposes before or at collection, including credit analysis, report generation, storage, delivery, security, audit, and support. | Sections 2, 5, 7 |
| Knowledge and consent | The Policy places borrower consent/lawful authority responsibility on the Client Institution and requires authorized submission only. | Sections 8, 16 |
| Limited lawful collection | The Policy limits collection and processing to information necessary for credit assessment and platform purposes. | Sections 5, 6, 7 |
| Limited retention/use/disclosure | The Policy limits use and disclosure to platform purposes and describes retention, deletion, anonymization, and backup handling in relation to the platform workflow, Client Institution requirements, contractual obligations, and applicable law. | Sections 7, 9, 11, 13 |
| Accuracy | The Policy requires the Client Institution to submit accurate/current data and review/correct reports. | Sections 8, 15 |
| Safeguards | The Policy describes security measures proportionate to sensitivity and requires Client Institution safeguards. | Section 14 |
| Sensitive personal information | The Policy recognizes that credit reports may contain sensitive or personal information and limits use/exposure where possible. | Sections 6, 9, 10 |
| Openness | The Policy makes privacy practices available to Client Institutions, Authorized Users, and other relevant persons. | Whole Policy |
| Access and challenge | The Policy provides a route for requests and recognizes coordination with the Client Institution. | Sections 15, 16 |
| Compliance challenge | The Policy provides a contact point for privacy requests and complaints. | Sections 16, 19 |
| Comparable safeguards for cross-border processing | The Policy discloses cross-border service providers and the intent to use reasonable safeguards appropriate to the processing. | Sections 9, 12 |
AI-powered credit assessment support for consumer lending institutions.
© 2026 CreditVantage AI. All rights reserved.