PRIVACY
Privacy & data handling
Last updated 29 September 2026
What data Credly collects
To assess funding readiness, Credly collects the business information you submit during onboarding (business name, registration number, industry, contact details, approximate revenue and funding requirements), the documents you upload (bank statements, CIPC records, SARS/TCS records and other supporting documents), and the monthly financial figures you enter for your assessment.
We also collect basic account information (name, email address) and system-generated records of sensitive actions (logins, uploads, report publication) for security and audit purposes.
Why it is collected
This information is used solely to produce your funding-readiness assessment and report, to let Credly administrators review submissions, and to maintain a secure, auditable record of who accessed what and when.
How it is stored
Business and assessment data is stored in a PostgreSQL database with row-level security, so a business's records can only be read by that business's own account or by an authorised Credly administrator. Uploaded documents and generated reports are stored in private object storage; there are no public links to your files. Access to a stored file is only granted through a short-lived, authenticated link issued after a server-side permission check.
Who can access it
You can access your own business profile, documents and published reports. Credly administrators can access submissions in order to review documents, enter financial metrics and prepare your report. Internal review notes are visible to Credly administrators only and are never shown to SME accounts.
Retention & deletion
We currently retain submission data for as long as your account is active, so you can track status and revisit past reports. If you would like your data deleted, contact us and we will remove your business profile, documents and reports, subject to any records we are required to keep for legal or security purposes.
Third-party services
Credly is built on Supabase for authentication, database and file storage. Supabase processes data on our behalf under its own security and data-processing terms. We do not sell or share your data with lenders, brokers or advertisers.
A note on compliance
This page describes how Credly currently handles data. It is not a legal statement of compliance with the Protection of Personal Information Act (POPIA) or any other regulation. As Credly grows, this policy and our underlying practices will be reviewed by a qualified legal advisor.