PRIVACY

Privacy & data handling

Last updated 29 September 2026

What data Credly collects

To assess funding readiness, Credly collects the business information you submit during onboarding (business name, registration number, industry, contact details, approximate revenue and funding requirements), the documents you upload (bank statements, CIPC records, SARS/TCS records and other supporting documents), and the monthly financial figures you enter for your assessment.

We also collect basic account information (name, email address) and system-generated records of sensitive actions (logins, uploads, report publication) for security and audit purposes.

Why it is collected

This information is used solely to produce your funding-readiness assessment and report, to let Credly administrators review submissions, and to maintain a secure, auditable record of who accessed what and when.

How it is stored

Business and assessment data is stored in a PostgreSQL database with row-level security, so a business's records can only be read by that business's own account or by an authorised Credly administrator. Uploaded documents and generated reports are stored in private object storage; there are no public links to your files. Access to a stored file is only granted through a short-lived, authenticated link issued after a server-side permission check.

Who can access it

You can access your own business profile, documents and published reports. Credly administrators can access submissions in order to review documents, enter financial metrics and prepare your report. Internal review notes are visible to Credly administrators only and are never shown to SME accounts.

Retention & deletion

We currently retain submission data for as long as your account is active, so you can track status and revisit past reports. If you would like your data deleted, contact us and we will remove your business profile, documents and reports, subject to any records we are required to keep for legal or security purposes.

Third-party services

Credly is built on Supabase for authentication, database and file storage. Supabase processes data on our behalf under its own security and data-processing terms. We do not sell or share your data with lenders, brokers or advertisers.

A note on compliance

This page describes how Credly currently handles data. It is not a legal statement of compliance with the Protection of Personal Information Act (POPIA) or any other regulation. As Credly grows, this policy and our underlying practices will be reviewed by a qualified legal advisor.