Data Processing Addendum schedule

Creditbase data processing terms inherit the Solharbor DPA.

Creditbase is a Solharbor product. Where Solharbor processes customer personal data for Creditbase as a processor, the Solharbor Data Processing Addendum applies and this page describes the Creditbase-specific processing schedule.

Relationship to the Solharbor DPA

The Solharbor Data Processing Addendum at https://solharbor.com/dpa/ states that it forms part of the agreement between Solharbor Management Ltd and the customer where Solharbor processes personal data on the customer's behalf. It applies to Solharbor consulting, implementation, hosting, support, automation, reporting and software services to the extent Solharbor acts as processor.

This Creditbase schedule does not replace the Solharbor DPA. It identifies the likely Creditbase processing activities that should sit under that DPA for pilot and customer use.

Roles

For customer portfolio data, CRM data, account data, support requests and integration data supplied or connected by a customer, the customer is expected to be the controller and Solharbor is expected to act as processor under the Solharbor DPA.

For public-record intelligence that Creditbase determines to collect, normalise, preserve and publish as part of its own open commercial-credit intelligence layer, Creditbase or Solharbor may act as controller. This controller position must be confirmed before public launch.

Details of Creditbase processing

Subject matter
Processing customer data and relevant public-record data to provide Creditbase Live, Creditbase Graph, Creditbase Risk research, APIs, alerts, integrations, support and related service operations.
Duration
For the term of the customer agreement or pilot and until deletion or return under the Solharbor DPA, unless retention is required by law or the data forms part of Creditbase's independently controlled public-record dataset.
Nature and purpose
Hosting, storage, monitoring, matching, normalisation, enrichment from public sources, portfolio alerting, data delivery, integration, reporting, support, troubleshooting, security and audit logging.
Customer instructions
Customer instructions include the applicable agreement, product settings, uploaded watchlists, connected integrations, support requests and documented written instructions.

Types of personal data

  • Business contact details for customer users and early-access contacts
  • Account, authentication, permission and integration metadata where accounts or integrations are enabled
  • Customer-supplied portfolio records, CRM records, deal records and operational data where connected by the customer
  • Company numbers, company names and public company-event records
  • Public-register personal data relating to directors, officers, PSCs, beneficial owners, insolvency practitioners and other individuals appearing in public company records
  • Support communications, diagnostics, logs and security records
  • Authorised or licensed corporate judgment data where such data is lawfully included

Categories of data subjects

  • Customer users and personnel
  • Customer clients, prospects, suppliers and business contacts where included in customer systems
  • Directors, officers, PSCs, beneficial owners and other individuals appearing in public company records
  • Individuals whose personal data appears in support communications or operational records

Special category, criminal-offence and personal credit data

Creditbase is not intended for special category data. Creditbase is also not intended to process consumer credit data, sole-trader credit files, personal guarantor assessments or personal CCJ searches unless separately agreed in writing with appropriate safeguards and regulatory review.

Customer must not submit special category data or personal credit data unless a written agreement expressly permits it.

Subprocessors, security and transfers

The Solharbor DPA contains the inherited provisions on subprocessors, security, breach notification, audit, deletion or return, and international transfers. The Solharbor DPA currently lists authorised subprocessors including cloud, database, development, AI, website hosting, payment, email, analytics, logging and security providers where used.

No Creditbase-specific additional subprocessor list has been confirmed in this repository. That list must be finalised before production launch.

Open points to confirm before launch

  • Confirm the exact legal entity contracting for Creditbase and its registered address
  • Confirm whether Creditbase-specific customer terms will incorporate the Solharbor DPA by URL or by attachment
  • Confirm the product-specific subprocessor list and hosting regions
  • Confirm whether any AI provider is enabled for Creditbase processing
  • Confirm retention periods for customer portfolio data, logs, account data and independently controlled public-record history
  • Confirm technical and organisational measures specific to Creditbase
  • Confirm the UK GDPR controller position for public-register intelligence and complete any required LIA or DPIA