Governed processing
Data protection framework
Effective 24 August 2026 · Version 1.0
Role separation
Institutions control customer purpose, policy and final decisions. CreditCheck processes authorized workflows and evidence. DurujScore assessment remains separate from institution policy, and financial systems remain the system of record.
Control principles
- Purpose limitation and data minimization.
- Institution-scoped authorization and least privilege.
- Encryption in transit and at rest where supported by the approved deployment.
- Audit events for authentication and material workflow decisions.
- Retention schedules, legal holds and controlled deletion.
- Documented incident response and processor assistance.
Data-subject requests
Requests involving institution-controlled customer data are normally routed to the relevant institution. Duruj supports the institution according to the data-processing agreement and does not independently change authoritative financial records.
Subprocessors
An approved subprocessor schedule, hosting configuration and notification process must be attached to or referenced by the institution agreement before production data is enabled.
Questions and formal requests
Email compliance@duruj.io for privacy and data-subject matters, or sales@duruj.io for institutional enquiries. Contract notices must use the address specified in the applicable agreement.