Sovetta Technologies LLC
Legal Center / Data Processing & Security Statement
Version 1.1 · Effective 2026-07-03 · Print / save as PDF

Data Processing & Security Statement

Sovetta Technologies LLC Version 1.1 — Effective July 3, 2026

This Statement describes how Sovetta processes and protects Customer Content — the merchant bank statements, applications, credit reports, and related data our customers submit to the Platform. It supplements the Terms of Service and Privacy Policy and reflects our commitments as a service provider to financial institutions under the Gramm-Leach-Bliley Act framework, including the expectations for service providers under the FTC Safeguards Rule (16 C.F.R. § 314.4(f)) and the CCPA's service-provider requirements.


1. Our Processing Role

1.1 Processor / service provider. Sovetta processes Customer Content only on the documented instructions of the submitting Customer — the instructions embodied in the Terms of Service and the operation of the Platform itself — and for no other purpose. As required by the CCPA, Sovetta: does not sell or share Customer Content; does not retain, use, or disclose it outside the direct business relationship with Customer or for any purpose other than the business purposes described; does not combine it with information from other sources except as permitted for the contracted business purposes (such as fraud prevention and verification); and certifies that it understands and will comply with these restrictions.

1.2 What processing happens. Document parsing and structured-data extraction; mathematical verification and cross-verification; fraud, tampering, and authenticity analysis; rule-based screening configured for commercial financing evaluation; verification against public-records and business-data sources at Customer's direction; and presentation of results to the Customer's authorized seats.

1.3 Purpose limitation for consumer data. Consumer report information is processed solely as Customer's agent for Customer's certified permissible purpose, and analysis derived from it is returned only to the procuring Customer organization. See the FCRA & Permissible Use Notice.

2. Security Program

We maintain a written security program with administrative, technical, and physical safeguards appropriate to the sensitivity of Customer Content, including:

3. Incident Response and Breach Notice

We maintain an incident-response process covering detection, containment, investigation, and remediation. We will notify affected Customers without undue delay after confirming any unauthorized acquisition of unencrypted Customer Content, and will provide the information reasonably required for the Customer to meet its own obligations — including its obligations under the FTC Safeguards Rule (16 C.F.R. § 314.4(j)) and applicable state breach-notification laws — along with the remediation steps we are taking.

4. Subprocessors and Data Sources

We use a small set of infrastructure providers and, at Customer's direction, data-verification sources. Categories currently in use:

CategoryPurpose
Content delivery / secure tunnelingTLS termination and DDoS protection for the public web layer
E-mail infrastructureReceiving Customer document submissions and sending service notices
AI model and GPU infrastructure providersDocument-analysis assistance for edge cases; bound to no-training commitments on Customer Content
Business-data and public-records sourcesMerchant verification (business listings, registrations, court records, mapping) queried at Customer's direction

We will maintain and provide a current subprocessor list to Customers on request, give notice of material additions, and remain responsible for our subprocessors' performance.

5. Data Minimization, PII Controls, and AI

5.1 PII redaction before cloud processing. The Platform is engineered sovereignty-first: the substantial majority of processing runs on Sovetta-controlled infrastructure. Where a document requires assistance from an external AI provider, the Platform applies automated PII detection and masking of hard identifiers before transmission, and our provider agreements prohibit the use of Customer Content to train their models.

5.2 No training on personal information. Sovetta does not use merchant or consumer personal information to train generalized AI models. Platform improvement relies on de-identified or aggregated data that does not identify any consumer, merchant, or Customer.

5.3 Human review allocation. The Platform is decision support; Customer retains sole responsibility for financing decisions and for meaningful human review (Terms of Service § 1.3). We provide reason-coded, reproducible analysis to support Customer's own compliance processes (including adverse-action workflows).

6. Retention, Return, and Disposal

7. Assessments and Diligence

Upon Customer's reasonable written request (no more than once annually), we will provide a written summary of our safeguards program sufficient to support Customer's service-provider oversight obligations under 16 C.F.R. § 314.4(f), and will reasonably assist Customer with data-protection assessments and rights requests directed to Customer as controller.

8. Questions

Security or data-processing questions, subprocessor list requests, and diligence inquiries: [email protected] (subject: "Security Diligence").


Sovetta Technologies LLC

© 2026 Sovetta Technologies LLC · Legal Center · Privacy · Cookies · Report a vulnerability