Sovetta Technologies LLC
Legal Center / Privacy Policy
Version 1.1 · Effective 2026-07-03 · Print / save as PDF

Privacy Policy

Sovetta Technologies LLC Version 1.1 — Effective July 3, 2026

This Privacy Policy describes how Sovetta Technologies LLC ("Sovetta," "we," "us") collects, uses, discloses, and protects personal information in connection with our underwriting analysis platform, websites, and related services (the "Platform"). It applies to visitors to our websites, the authorized users of our customers who hold Platform seats, and — as described in Section 2 — the merchants, business owners, and guarantors whose information our customers submit.


1. Who We Are

Sovetta provides document-processing and underwriting-analysis software to commercial financing companies. Our customers — funders, brokers, and their personnel — submit business documents (such as merchant bank statements, applications, and credit reports) to the Platform, which returns structured analysis to help them evaluate commercial financing transactions.

2. Our Two Roles

(a) Service provider / processor — merchant deal data. When our customers submit merchant documents and data to the Platform, we process that information on behalf of and at the direction of the customer, which is the "controller" or "business" for that data. We use it only to provide the services described in our Terms of Service and Data Processing & Security Statement, and we do not sell it, share it for advertising, or use it for our own marketing.

If you are a merchant, business owner, or guarantor whose information was submitted to the Platform: the funding company you applied with controls your data. Please direct privacy questions and rights requests to that company; we will assist it in responding as the law requires. You may also contact us at [email protected] and we will route your request to the right controller.

(b) Controller / business — seat, prospect, and website data. For information about our customers' authorized users (seat holders), our business contacts and prospects, and visitors to our websites, we act as the controller, and the rest of this Policy describes our practices.

3. Information We Collect

From seat holders and customers:

From website visitors: standard server logs (IP address, user-agent, pages requested, timestamps) and the strictly-necessary cookies described in our Cookie Policy. We do not run third-party advertising pixels, session-replay tools, or cross-context behavioral advertising.

Merchant deal data (processed for customers): business bank statement transactions and balances; business and owner names, addresses, and contact details; financing application contents; credit report contents (which may include Social Security numbers and other sensitive identifiers); public-records data (such as filings, registrations, and court records); and business-intelligence data (such as business listings and location imagery) gathered at the customer's direction to verify a merchant.

We do not knowingly collect information from children under 18; the Platform is a business tool for adults.

4. How We Use Information

We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising (as those terms are defined in the California Consumer Privacy Act).

5. How We Disclose Information

We disclose personal information only to:

6. Financial Privacy (GLBA)

Much of the merchant and consumer financial information on the Platform is "nonpublic personal information" processed under the Gramm-Leach-Bliley Act framework as a service to financial institutions. We handle it under the GLBA service-provider exception: we use and disclose it only to perform the services our customers engage us for, and we maintain safeguards consistent with the FTC Safeguards Rule expectations for service providers (16 C.F.R. § 314.4(f)). See the Data Processing & Security Statement.

7. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information, including: encryption of data in transit; hardened, access-controlled, single-tenant infrastructure; hashed credentials with lockout protections; role-based access controls that scope each seat to its own deals; comprehensive audit logging; and tested backup and recovery procedures. No system is perfectly secure; we will notify affected customers without undue delay after confirming a breach affecting their data, so they can meet their own legal obligations.

8. Retention

We retain personal information only as long as needed for the purposes above: account and acceptance records for the life of the account plus applicable limitations periods; security and audit logs on a rolling schedule; and merchant deal data for as long as the submitting customer's engagement requires (customers may request export or deletion as described in the Terms of Service). Fraud-prevention records may be retained longer where the law permits, to protect the Platform and its customers. Backups are purged on their normal rotation cycle.

9. Your Privacy Rights

Depending on your state of residence (including under the California Consumer Privacy Act and similar laws in Virginia, Colorado, Connecticut, Texas, and other states), you may have rights to: know/access the personal information we hold about you; correct inaccuracies; delete your personal information; obtain a portable copy; and not be discriminated against for exercising these rights. Because we do not sell or share personal information for advertising, there is nothing to opt out of — and we honor Global Privacy Control signals as an opt-out where they apply.

To exercise a right, e-mail [email protected] with "Privacy Request" in the subject. We will verify your identity (typically by confirming control of the e-mail associated with your account) and respond within the time the applicable law requires. If we deny a request, you may appeal by replying to our response, and we will re-review it as state law requires. Note that for merchant deal data we are a processor — we will route those requests to the controlling customer (Section 2).

10. Other Disclosures

11. Changes to this Policy

We will post updates here with a new version number and effective date, and for material changes we will give notice (by e-mail, in-Platform notice, or re-acceptance prompt) before they take effect.

12. Contact

Sovetta Technologies LLC — Privacy E-mail: [email protected] (subject: "Privacy")


See also: Cookie Policy · Data Processing & Security Statement · Terms of Service

© 2026 Sovetta Technologies LLC · Legal Center · Privacy · Cookies · Report a vulnerability