Corentis
EnglishEspañol
Request a demo
Legal

Privacy Policy

How personal data is handled in lending products built on Corentis: what we collect, why, who it is shared with, how long it is kept and the rights you have. Written in plain English for the Spanish market.

Illustrative demo. This is a sample privacy policy for demonstration only. It is not legal advice. The binding privacy notice is the one published by the licensed entity operating the product. Entity-specific details — including the data controller's identity — are confirmed before launch.

Last updated: June 2026 · Illustrative demo

1. Who is responsible

The data controller is the licensed financial entity that operates the lending product and decides why and how your personal data is processed. Corentis is the technology provider and acts as a processor on the controller's instructions; Corentis is not the lender.

The controller's exact legal identity and contact details are entity-specific and confirmed before launch.

2. What data we collect

  • Identity data — name, date of birth, nationality and identification documents.
  • Contact data — postal address, email and phone number.
  • Financial and affordability data — income, expenses, existing obligations, bank and transaction information used to assess repayment capacity.
  • Documents — files you upload or provide to support an application.
  • Device and usage data — IP address, device identifiers, and how you use the website and application.

3. Purposes and lawful basis

  • To provide and administer the loan (contract) — assessing your application, managing the agreement and servicing payments.
  • To meet legal obligations — including anti-money-laundering (AML), know-your-customer and record-keeping duties.
  • Legitimate interests — preventing fraud, securing our systems and improving the service, balanced against your rights.
  • Consent — for marketing communications, where you have opted in; you can withdraw consent at any time.

4. Credit checks and bureaus

To assess creditworthiness and affordability, the controller may consult and report to credit bureaus and similar reference sources, with the disclosures required by law. These checks are part of responsible lending and are described to you before they are carried out.

5. Automated decision-making and your right to human review

Some assessment steps may use automated scoring. Where automated processing significantly affects you, it is designed to be explainable, and you have the right to request human intervention, to express your point of view and to contest the decision. A final rejection is not delivered from an opaque model without a route to a human.

6. Who we share data with

  • Service providers — including technology, identity-verification, screening and hosting providers acting under contract.
  • The lending entity — the controller responsible for the loan.
  • Authorities — regulators, supervisors and law-enforcement bodies where we are legally required to disclose.

7. International transfers

Where data is transferred outside the European Economic Area, appropriate safeguards — such as adequacy decisions or standard contractual clauses — are put in place so that your data remains protected to an equivalent standard.

8. How long we keep data

Personal data is kept only as long as needed for the purposes above and to meet legal and accounting obligations. Records required for anti-money-laundering and other regulatory purposes are typically retained for longer statutory periods after a relationship ends.

Exact retention periods are set by the controller in line with applicable law and confirmed before launch.

9. Your rights

Subject to the conditions in data-protection law, you have the right to:

  • access your personal data;
  • rectify inaccurate data;
  • erase data (the "right to be forgotten");
  • restrict processing;
  • object to processing;
  • data portability;
  • withdraw consent at any time, without affecting prior processing;
  • lodge a complaint with the competent supervisory authority.

10. Cookies

The website uses cookies and similar technologies for essential functions and, with your consent, for analytics. You can manage your preferences through your browser settings and any cookie controls provided on the site. A separate short cookie note describes the categories used.

11. Contact and Data Protection Officer

For any privacy question or to exercise your rights, you can contact us at privacy@corentis.org. Where required, a Data Protection Officer is appointed and can be reached at the same address.

The contact address shown is a placeholder for this demo; the controller's actual DPO and contact details are entity-specific and confirmed before launch.