// Legal

Privacy Policy

Last updated: June 7, 2026

This Privacy Policy describes how LenderAnalyzer ("LenderAnalyzer," "we," "our," or "us") collects, uses, stores, and discloses information about you when you use our platform, APIs, and related services (collectively, the "Service"). Because our core business is the AI-powered extraction of structured data from documents — invoices, contracts, identity documents, medical records, and more — we have written this policy to be specific to that context rather than relying on generic boilerplate. Please read it carefully.

01

Who We Are and Scope of This Policy

LenderAnalyzer is an enterprise software-as-a-service platform that enables organisations to upload documents and receive structured, machine-readable data in return. We are the data controller for account and billing information. For the documents you upload and the data extracted from them, we act as a data processor on your behalf — you remain the controller of that data.

This policy applies to all visitors to our website, registered users, API consumers, and enterprise customers. It does not cover third-party services that you may connect to LenderAnalyzer; those services are governed by their own privacy policies.

02

Information We Collect

Account and identity information

When you register, we collect your name, work email address, password hash, company name, job title, and the IP address used to create the account. For SSO/SAML users, identity attributes are passed from your identity provider.

Uploaded documents and extracted data

The files you upload — PDFs, scanned images, photographs — are the core input to our Service. These may include commercially sensitive or personally identifiable information such as names, addresses, tax identifiers, financial figures, and, on healthcare or identity documents, special-category data. We treat all uploaded content as confidential customer data. The structured fields our AI extracts from those documents are stored alongside the source file and are subject to your chosen retention policy (see Section 6).

Usage and telemetry data

We collect log data including pages visited, API endpoints called, response times, error codes, browser type, operating system, and referring URL. We also collect aggregate feature-usage metrics (e.g., how many documents processed per session) to improve the product. This data does not include the content of your documents.

Payment and billing information

All payment transactions are handled by Stripe, Inc. We do not store full card numbers or CVV codes. We receive and retain billing address, last four card digits, card brand, and subscription status from Stripe for invoicing and fraud prevention purposes.

Support and communications

When you contact our support team by email or live chat, we collect the content of that communication and any attachments you share to resolve your query.

03

How We Process Documents and Extracted Data

When you submit a document, LenderAnalyzer's pipeline performs the following operations: (a) optical character recognition (OCR) to convert image pixels to text, (b) layout analysis to identify blocks, tables, and fields, and (c) AI-model inference to classify and extract the specific fields you have requested. All three steps occur within our secured infrastructure (see Section 7). Documents are not used to train or fine-tune shared AI models without your explicit written consent.

Extraction results — structured JSON containing field names and values — are stored in your account workspace so that you can review, export, or push them to your downstream systems. Our human-review queue, when activated, allows members of your own team to inspect and correct low-confidence fields; LenderAnalyzer staff do not access document content during normal operations and do so only with your explicit authorisation when investigating a support issue.

04

Purposes and Legal Bases for Processing

We process your data for the following purposes and, where GDPR applies, rely on the following legal bases:

  • Service delivery — Processing your documents and returning structured data. Legal basis: performance of contract.
  • Account management — Creating and maintaining your account, authentication, and access control. Legal basis: performance of contract.
  • Billing and payments — Issuing invoices, collecting subscription fees, and detecting fraud. Legal basis: performance of contract and legitimate interests.
  • Product improvement — Analysing anonymised and aggregated usage telemetry to improve accuracy, speed, and reliability. Legal basis: legitimate interests.
  • Security and abuse prevention — Monitoring for anomalous API usage, attempted breaches, or policy violations. Legal basis: legitimate interests and legal obligation.
  • Legal compliance — Responding to lawful requests from courts or regulators and retaining records as required by applicable law. Legal basis: legal obligation.
  • Marketing communications — Sending product updates, release notes, or occasional promotional messages to existing customers. Legal basis: legitimate interests (you may opt out at any time).
05

Data Retention and Zero-Retention Option

By default, uploaded source files and their extracted results are retained in your workspace until you delete them or close your account. You can configure an automatic purge policy — for example, deleting source files immediately after extraction or purging all data after a set number of days — directly from your account settings.

Enterprise plans include a zero-retention mode: source files are discarded from our systems immediately after extraction completes and results are delivered, with only a hashed job identifier and metadata log retained for audit purposes. When you close your account, all workspace data is deleted within 30 days. Account records and billing history are retained for a further seven years to satisfy financial and tax reporting obligations.

06

Encryption and Security Controls

All data transmitted between your browser or API client and our servers is encrypted using TLS 1.2 or higher. Documents and extracted data at rest are encrypted using AES-256. Encryption keys are managed using an industry-standard key management service and are rotated on a scheduled basis.

Access to production systems is restricted to authorised personnel via multi-factor authentication and time-limited credentials. We maintain a SOC 2 Type II programme covering security, availability, and confidentiality; audit reports are available to enterprise customers under NDA. Full activity and access logs are retained for forensic purposes and are available to you through the audit-log feature on qualifying plans.

07

Sub-Processors and International Transfers

We engage the following categories of sub-processors to deliver the Service. We require all sub-processors to maintain security standards consistent with our own and, where applicable, to sign data processing agreements:

  • Cloud infrastructure provider — Provides the compute, storage, and networking infrastructure on which LenderAnalyzer runs. Data residency options (EU or US) are available on enterprise plans.
  • AI and OCR model provider — Provides the large language model and OCR engine APIs used during extraction. Documents submitted to these APIs are subject to contractual data-handling restrictions; they are not used to train shared models.
  • Stripe, Inc. — Processes all card payments. Stripe is certified to PCI DSS Level 1 and operates under its own privacy policy.
  • Transactional email provider — Sends account notifications, invoices, and support communications on our behalf.
  • Live-chat support tool — Facilitates in-app support conversations. Only your name, email, and the content of your chat session is shared.

Where personal data is transferred from the European Economic Area to a country without an adequacy decision, we rely on Standard Contractual Clauses approved by the European Commission, supplemented by appropriate technical safeguards.

08

Your Rights — GDPR and CCPA

Depending on where you are located, you may have the following rights with respect to your personal data. To exercise any of them, contact us at support@lenderanalyzer.com. We will respond within 30 days.

  • Access — Request a copy of the personal data we hold about you.
  • Rectification — Ask us to correct inaccurate or incomplete personal data.
  • Erasure ("right to be forgotten") — Request deletion of your personal data, subject to legal retention obligations.
  • Restriction — Ask us to suspend processing of your data in certain circumstances.
  • Portability — Receive your personal data in a structured, machine-readable format.
  • Objection — Object to processing based on legitimate interests, including direct marketing.
  • Withdrawal of consent — Where we rely on consent, withdraw it at any time without affecting prior processing.
  • CCPA — Do Not Sell or Share — We do not sell or share personal data with third parties for their own advertising purposes. California residents may still submit a verifiable consumer request for access or deletion.

If you are located in the EEA, you also have the right to lodge a complaint with the supervisory authority in your member state.

09

HIPAA and Business Associate Agreements

Certain document types processed through LenderAnalyzer — such as claims forms, explanation-of-benefits documents, and patient intake records — may constitute Protected Health Information (PHI) under the U.S. Health Insurance Portability and Accountability Act (HIPAA). Enterprise plan customers who process PHI may request a Business Associate Agreement (BAA) from our sales team before submitting any such documents. Operating without an executed BAA when processing PHI is a violation of our Acceptable Use Policy.

10

Cookies and Tracking Technologies

We use the following categories of cookies and similar technologies on our website and in the application:

  • Strictly necessary — Session cookies required for authentication, CSRF protection, and core application functionality. These cannot be disabled.
  • Analytics — Anonymised page-view and event data used to understand how the application is used and where to focus product development effort. You may opt out via our cookie preference centre.
  • Support chat — Cookies set by our live-chat provider to identify returning visitors and preserve conversation context.

We do not use advertising or cross-site tracking cookies.

11

Children's Privacy

The Service is designed for business use and is not directed at children under the age of 16. We do not knowingly collect personal information from anyone under 16. If you believe a minor has registered an account, please contact us and we will promptly delete the account and associated data.

12

Changes to This Policy

We may update this Privacy Policy periodically as our practices evolve or as required by law. When we make material changes, we will post the revised policy on this page with an updated effective date and, where appropriate, notify registered users by email. Continued use of the Service after the effective date constitutes acceptance of the updated policy. We encourage you to review this page regularly.

13

Contact and Data Protection Inquiries

For privacy-related questions, data subject requests, or to request a copy of our sub-processor list or DPA, please contact us at:

LenderAnalyzer — Privacy Team

Email: support@lenderanalyzer.com

We aim to acknowledge all privacy requests within 5 business days and resolve them within 30 days.

This document is provided for informational purposes only and does not constitute legal advice. If you have specific legal questions about data protection, please consult a qualified legal professional.