privacy data use · Privacy Policy
Definite policy finding
“ Account and organization data. When you create an account or accept an invitation, we collect your email address, your organization name, and the authentication credentials required to log in. If your organization configures SSO, your identity provider shares the claims required to authenticate you. Connected source data. The core function of Definite is to check your institution's books. When you connect a data source, Definite takes read-only snapshots of the exports you configure, such as core banking exports, general ledger and subledger extracts, capital schedules, loan-level files, and spreadsheets. Each snapshot is hashed on arrival and stored in your tenant's isolated environment. Depending on what your institution exports, these files may contain personal data about your customers, such as borrower names, account identifiers, and loan attributes. For this data we act as a processor on your instructions. Check results and receipts. Every deterministic check writes a receipt that records the rule, the rule version, hashes of the inputs, the verdict, timestamps, and cryptographic proof artifacts. Receipts are designed around hashes and references rather than raw customer values. Public filings data. We retrieve publicly available regulatory data, such as prior Call Reports and peer filings, from sources like the FFIEC CDR, NCUA, FDIC, and OSFI. This data is already public. Support and contact data. If you contact us through the site or by email, we keep the correspondence and the contact details you provide.”
- Document
- Privacy Policy
- Captured
- 2026-07-20
- Location
- § 2 (What data we collect)
- Snapshot SHA-256
- 02c3246fdfc7635e1ca0e921022fbdc22c89c582c3c4d94004d840177681b372
Informational only, not legal advice. Terms change; verify the source and capture date.