Privacy Policy
Effective date: 22 August 2026
Entity: OpenBooks
1. Scope
This policy explains how the OpenBooks Console handles personal and business information processed by authorised staff in the course of reviewing SME businesses and deciding loans.
2. Information we process
- Staff account details (name, email, assigned roles) used to authenticate and authorise you.
- Business profile and financial data required to assess creditworthiness.
- Credit scores, AI-generated overviews, and the loan decisions and rationale you record.
- Operational logs used to keep the Service secure and reliable.
3. How information is used
Information is used solely to operate the Service: to authenticate staff, enforce role-based access, present decision-support material, and record human loan decisions. It is not sold or used for advertising.
4. Access controls
Access is limited by role and, where applicable, by the cities your bank operates in. Sensitive credentials never reach the browser — the console authenticates through a server-side session and a same-origin proxy.
5. Retention
Records are retained for as long as required to meet operational, audit, and regulatory obligations, after which they are deleted or anonymised.
6. Your responsibilities
- Keep your credentials confidential and sign out on shared devices.
- Access only the data your role and duties require.
- Report suspected privacy incidents to your administrator immediately.
7. Contact
Privacy questions should be directed to your OpenBooks administrator or data protection contact.