Personal data and transparency
Privacy notice
Effective 24 August 2026 · Version 1.0
Who is responsible
The financial institution normally determines why customer and applicant data is used and acts as controller. The contracting Duruj entity normally processes that data for the institution. Duruj may act as controller for its own business contacts, security logs and service administration.
Data we process
- Institution staff identity, role, organization and audit data.
- Customer identity references, consent evidence, application and affordability information supplied by authorized sources.
- Credit assessment outputs, reasons, confidence and workflow evidence.
- Facility, payment and reconciliation events while institution systems remain authoritative.
- Device, security, diagnostic and support information required to operate and protect the service.
Purposes and lawful authority
Data is processed to authenticate authorized staff, provide contracted credit workflows, maintain evidence, prevent abuse, support consumer rights and meet legal obligations. The institution must establish the applicable lawful basis and obtain consent where required.
Sharing and transfers
Data may be shared with the contracting institution, approved infrastructure and support subprocessors, and authorities where legally required. Cross-border processing is not assumed from the hostname and must follow the institution configuration, contract and applicable safeguards.
Retention and deletion
Retention is purpose- and record-specific. Institution instructions, legal holds, audit requirements and the applicable retention schedule determine deletion. CreditCheck does not promise immediate deletion where regulated evidence must be retained.
Questions and formal requests
Email compliance@duruj.io for privacy and data-subject matters, or sales@duruj.io for institutional enquiries. Contract notices must use the address specified in the applicable agreement.