Relationship to the Solharbor DPA
The Solharbor Data Processing Addendum at https://solharbor.com/dpa/ states that it forms part of the agreement between Solharbor Management Ltd and the customer where Solharbor processes personal data on the customer's behalf. It applies to Solharbor consulting, implementation, hosting, support, automation, reporting and software services to the extent Solharbor acts as processor.
This Creditbase schedule does not replace the Solharbor DPA. It identifies the likely Creditbase processing activities that should sit under that DPA for pilot and customer use.
Roles
For customer portfolio data, CRM data, account data, support requests and integration data supplied or connected by a customer, the customer is expected to be the controller and Solharbor is expected to act as processor under the Solharbor DPA.
For public-record intelligence that Creditbase determines to collect, normalise, preserve and publish as part of its own open commercial-credit intelligence layer, Creditbase or Solharbor may act as controller. This controller position must be confirmed before public launch.
Details of Creditbase processing
- Subject matter
- Processing customer data and relevant public-record data to provide Creditbase Live, Creditbase Graph, Creditbase Risk research, APIs, alerts, integrations, support and related service operations.
- Duration
- For the term of the customer agreement or pilot and until deletion or return under the Solharbor DPA, unless retention is required by law or the data forms part of Creditbase's independently controlled public-record dataset.
- Nature and purpose
- Hosting, storage, monitoring, matching, normalisation, enrichment from public sources, portfolio alerting, data delivery, integration, reporting, support, troubleshooting, security and audit logging.
- Customer instructions
- Customer instructions include the applicable agreement, product settings, uploaded watchlists, connected integrations, support requests and documented written instructions.
Special category, criminal-offence and personal credit data
Creditbase is not intended for special category data. Creditbase is also not intended to process consumer credit data, sole-trader credit files, personal guarantor assessments or personal CCJ searches unless separately agreed in writing with appropriate safeguards and regulatory review.
Customer must not submit special category data or personal credit data unless a written agreement expressly permits it.
Subprocessors, security and transfers
The Solharbor DPA contains the inherited provisions on subprocessors, security, breach notification, audit, deletion or return, and international transfers. The Solharbor DPA currently lists authorised subprocessors including cloud, database, development, AI, website hosting, payment, email, analytics, logging and security providers where used.
No Creditbase-specific additional subprocessor list has been confirmed in this repository. That list must be finalised before production launch.