Privacy Policy

Last updated: 28 August 2026 · Effective: 1 May 2026

1. About this policy

This Privacy Policy explains how Genesis Chain Financial Group Pty Ltd (ABN 48 625 098 937, ACN 625 098 937) trading as CreditPolicy.ai and CreditPolicy.com.au (we, us, our) collects, holds, uses and discloses personal information.

We are bound by the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs). This policy applies to:

Together these are the Service.

If you do not agree with this policy, please do not use the Service.

2. Who our users are

The Service is designed for licensed Australian mortgage brokers, commercial finance brokers, their staff and their licensees. It is a business tool. It is not intended for use by consumers seeking credit, and it is not intended for anyone under 18.

An important distinction runs through this policy:

3. What personal information we collect

3.1 Information you give us

CategoryExamples
Account informationName, business email address, phone number, password (hashed), brokerage or aggregator name, job role
Professional informationCredit licence or credit representative number, aggregator, lender panel, ABN
Billing informationBilling name, billing address, subscription plan, transaction records. Card numbers are entered directly with our payment processor (Stripe) and are never stored on our systems.
Content you submitQuestions and prompts, scenario details, notes, client records, deal records, documents you upload, feedback
Support and communicationsEmails, chat messages, support tickets, survey responses

3.2 Information we collect automatically

CategoryExamples
Usage dataFeatures used, tools called, queries run, pages viewed, session times, referring pages
Device and technical dataIP address, browser type and version, operating system, device identifiers, language settings
Log dataRequest timestamps, error traces, API endpoints called, connection metadata
Cookies and similar technologiesSession cookies, authentication tokens, preference cookies, analytics identifiers and session-replay analytics — see section 14

3.3 Information from third parties

3.4 Sensitive information

We do not seek sensitive information as defined in the Privacy Act (such as health information or information about racial or ethnic origin, political opinions or criminal record). Please do not enter sensitive information into the Service unless it is strictly necessary for the scenario you are assessing. If you do, you confirm you have the individual's consent for us to handle it as described in this policy.

Note that credit information and credit eligibility information about your clients may be caught by Part IIIA of the Privacy Act. See section 10.

4. How we collect personal information

We collect personal information directly from you wherever reasonably practicable — when you sign up, subscribe, use the Service, contact support, or connect an AI assistant. We collect information about your clients indirectly, from you, in the course of you using the Service.

Where we collect personal information about an individual from someone other than that individual (for example, your client), we rely on you to have given that individual notice of the matters set out in APP 5. See section 9.

5. Why we collect, hold, use and disclose personal information

We use personal information for the following purposes:

  1. To provide the Service — create and administer your account, authenticate you, answer your policy questions, run scenario assessments, generate comparisons, store your client and deal records, and return cited results.
  2. To operate the AI features — process your queries through our retrieval systems and, where applicable, third-party large language models, so we can generate answers grounded in indexed lender policy documents.
  3. To bill you — manage subscriptions, trials, invoices, renewals, dunning and refunds.
  4. To support you — respond to enquiries, troubleshoot, and provide onboarding and training.
  5. To secure the Service — detect, investigate and prevent fraud, abuse, unauthorised access, and breaches of our Terms; maintain audit logs.
  6. To improve the Service — understand which features are used, diagnose faults, measure performance, and develop new features. Where we use content for improvement we aggregate or de-identify it wherever practicable.
  7. To communicate with you — send service messages, policy update notifications, security notices, billing notices and, where permitted, marketing (see section 13).
  8. To meet our legal obligations — comply with laws, court orders, regulatory requests, and our record-keeping and tax obligations.

We do not sell personal information. We do not disclose personal information to third parties for their own marketing purposes.

6. How the AI features work, and what that means for your data

CreditPolicy answers questions by searching an index of lender credit policy documents and then using large language models to compose an answer with citations back to the source material.

To do this:

Our commitments about AI processing:

AI outputs can be wrong. Generated answers may be incomplete, out of date or incorrect, and lender policy changes frequently. You must verify any output against the lender's current policy document and the lender's own assessment before relying on it. This is reinforced in our Terms of Service.

7. Connecting third-party AI assistants (MCP)

You can connect the Service to third-party AI assistants and developer tools that support the Model Context Protocol — for example Claude (Anthropic), ChatGPT (OpenAI), Perplexity, Cursor, Visual Studio Code and others.

How the connection works. You initiate the connection from within the third-party assistant. You sign in to CreditPolicy through an OAuth 2.0 flow and expressly authorise the assistant to access the Service on your behalf. We never receive your password for the assistant, and the assistant never receives your CreditPolicy password. The assistant receives a scoped access token that you can revoke at any time from your CreditPolicy account settings, or from the assistant's own connector settings.

What data flows where. When you use a connected assistant:

What this means for you. If you include your client's personal information in a prompt to a third-party assistant, or ask that assistant to retrieve a client record from CreditPolicy, that personal information is disclosed to the third-party assistant's operator. You are responsible for deciding whether that disclosure is appropriate, for having the necessary consent, and for satisfying your own privacy obligations to your clients. We strongly recommend you review the privacy policy of any assistant before connecting it, and that you avoid putting client-identifying information into third-party assistants unless you have a clear basis for doing so.

Scope of access. The connector exposes read-only access to the lender policy library, and read and write access to your own client and deal records. It cannot delete records, and it cannot access billing information, payment details or other users' data.

Our role. We do not control, endorse or accept responsibility for any third-party AI assistant. We may suspend, restrict or discontinue MCP access, or access for a particular assistant, at any time.

8. Who we disclose personal information to

We disclose personal information to the following categories of recipient, and only as needed for the purposes in section 5:

RecipientPurposeLocation
SupabaseAuthentication, identity, and primary application databaseSydney, Australia (AWS ap-southeast-2)
VercelWeb hosting, serverless functions, content delivery, and page-speed measurementCompute in Sydney, Australia (syd1); global content delivery network
OpenAIGenerating answers, comparisons, scenario assessments and document embeddingsUnited States
Google (Gemini API)AI-assisted document and form analysisUnited States and other Google infrastructure locations
Amazon Web Services (Amazon SES)Transactional and notification emailEuropean Union (Ireland, eu-west-1)
StripeSubscription billing and payment processingUnited States and other locations
Microsoft (Clarity)Product analytics, session replay and heatmapsUnited States and other Microsoft infrastructure locations
Google (Tag Manager)Tag management for analyticsUnited States and other Google infrastructure locations
Zoho (SalesIQ)Live chat support on our website, and the chat transcriptUnited States and other Zoho infrastructure locations
Third-party AI assistants you connectDelivering results into your assistant, at your directionDetermined by that provider — see section 7
Professional advisersLegal, accounting and audit servicesAustralia
AcquirersIn connection with an actual or proposed sale, merger or restructure of our businessVaries
Law enforcement, regulators, courtsWhere required or authorised by lawAustralia and elsewhere

We require our service providers to protect personal information consistently with the Privacy Act and to use it only for the purposes we engage them for.

9. Your clients' personal information — how responsibility is split

When you enter your client's personal information into the Service, you remain the entity with the relationship to that individual and the primary privacy obligations to them. We handle that information on your behalf and under your instructions.

By using the Service, you represent and warrant that:

You indemnify us in respect of claims arising from your failure to do these things, as set out in our Terms of Service.

If you receive a request from your client for access to, or correction of, their information held in the Service, you can action it yourself in the application. We will assist you on request.

We do not accept responsibility for Client Data you choose to enter. You are responsible for its accuracy and the lawfulness of its collection and disclosure (including any APP 5 notices and any consents required under Part IIIA and the Privacy (Credit Reporting) Code), and for satisfying your obligations to your client. Where you disclose Client Data to a third‑party AI assistant via MCP, that disclosure is yours and is governed by that provider's terms and privacy policy.

10. Credit information

We are not a credit provider, a credit reporting body, or a credit-related service provider under Part IIIA of the Privacy Act, and we do not obtain credit reports or credit eligibility information from credit reporting bodies.

However, information you enter about your client's financial position, credit history, defaults or repayment history may constitute credit information or credit eligibility information in your hands. Where that is so, your handling of it — including your decision to enter it into the Service or into a connected AI assistant — is governed by Part IIIA and the Privacy (Credit Reporting) Code, and remains your responsibility. We handle it as confidential information under this policy and our Terms.

11. Security

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These include:

No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you use the Service at your own risk. You must keep your account credentials confidential and notify us immediately at privacy@creditpolicy.ai if you suspect unauthorised access.

Eligible data breaches. We comply with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. If we suffer an eligible data breach that is likely to result in serious harm, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as required. Where a breach affects your clients' information, we will notify you promptly so you can meet your own obligations.

12. Overseas disclosure

Our core application data — authentication, your account, and your client and deal records — is hosted in Australia (Sydney). However, some of our service providers, and some of the AI assistants you may choose to connect, store or process personal information outside Australia — principally in the United States (AI model processing, billing and analytics) and the European Union (transactional email), and potentially other jurisdictions where those providers operate infrastructure.

Before disclosing personal information to an overseas recipient, we take reasonable steps under APP 8.1 to ensure the recipient does not breach the APPs, including by putting contractual protections in place. By using the Service you acknowledge that:

Overseas recipients may be subject to the laws of their own jurisdictions.

13. Direct marketing

We may send you marketing communications about the Service where you have consented or where you would reasonably expect it, consistent with APP 7 and the Spam Act 2003 (Cth).

Every marketing message includes a functional unsubscribe. You can also opt out at any time by emailing privacy@creditpolicy.ai. Opting out of marketing does not stop service messages — billing notices, security alerts, policy update notifications and changes to these documents — which are part of providing the Service.

We do not provide your personal information to other organisations for their direct marketing.

14. Cookies and analytics

We use cookies and similar technologies to keep you signed in, remember your preferences, secure the Service, and understand how it is used. Categories:

When you first visit, a consent banner lets you accept or decline analytics cookies. If you decline, we do not load Clarity, Google Tag Manager or Speed Insights, and we turn off SalesIQ's page-by-page visitor tracking — the chat widget itself stays available, so declining does not cost you a support channel. Strictly necessary cookies are used regardless, because the Service cannot function without them.

Most browsers also let you block or delete cookies. Blocking strictly necessary cookies will prevent you from signing in.

We do not currently respond to "Do Not Track" browser signals.

15. Data retention

We retain personal information only for as long as we need it for the purposes in section 5, or as required by law.

DataRetention
Account informationFor the life of the account, then 12 months after closure
Client and deal recordsFor the life of the account, then deleted or de-identified within 90 days of closure, unless you ask us to delete them sooner
Query and response history24 months, then deleted or de-identified
Billing and tax records7 years, as required by Australian tax law
Security and audit logs12 months
Marketing recordsUntil you opt out, plus a suppression record so we do not re-contact you

You can request deletion of your data at any time — see section 16. Some records must be retained to meet legal obligations, and backups are overwritten on a rolling cycle rather than deleted on demand.

16. Access, correction and deletion

You have a right under APP 12 and APP 13 to ask for access to the personal information we hold about you, and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.

Most information is available directly in your account settings. For anything else, email privacy@creditpolicy.ai. We will:

If we refuse access or correction, we will tell you why in writing and how to complain.

17. Complaints

If you think we have breached the APPs or mishandled your personal information, contact us first at privacy@creditpolicy.ai with the details. We will acknowledge within 5 business days and aim to resolve the complaint within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:

18. Children

The Service is not directed at, and must not be used by, anyone under 18. We do not knowingly collect personal information from children. If we learn we have, we will delete it.

19. Anonymity and pseudonymity

Under APP 2 you have the option of dealing with us anonymously or under a pseudonym for general enquiries. This is not practicable for the Service itself, because we must identify account holders to authenticate them, bill them, secure their data and meet our legal obligations.

20. Changes to this policy

We may update this policy at any time. The current version is always at creditpolicy.ai/privacy with the "Last updated" date at the top. If we make a change that materially affects how we handle your personal information, we will notify you by email or in-app notice before it takes effect. Continuing to use the Service after a change takes effect means you accept the updated policy.

21. Contact us

Privacy Officer Genesis Chain Financial Group Pty Ltd trading as CreditPolicy.ai and CreditPolicy.com.au ABN 48 625 098 937 | ACN 625 098 937 Registered / office: Ground Floor, 100 Douglas Parade, Williamstown VIC 3016, Australia Email: privacy@creditpolicy.ai General: hello@creditpolicy.ai Victoria, Australia