Trust and data stewardship
Privacy is part of the operating model.
Fintek Sentinel handles real identities and confidential lender information. This notice explains what enters the service, how the current build handles it, and where the institution retains control.
This notice is for website visitors, institutional contacts, and people whose information may appear in a lender-authorized review. It is not a substitute for a lender's own privacy notice, a data-processing agreement, or an engagement-specific security schedule.
Do not send a lender tape, borrower details, account numbers, government identifiers, or other sensitive records through the public Contact form or ordinary email. We establish an approved, controlled transfer path with an institution before receiving a tape.
Who decides why data is processed
Fintek Capital LLC operates Fintek Sentinel. For an institution's lender tape and related review, the institution determines the review purpose and provides the data under its authority; Fintek operates the service for that engagement and follows the agreed scope. For this public website, business inquiries, and our own administrative records, Fintek determines the purposes described below.
The service is directed to institutional commercial real estate teams, not consumers seeking credit. Its Distress Signal Summary presents evidence for human review; it does not score, rank, recommend action on, or make a lending decision about any person or borrower.
Information we handle
A lender tape may contain borrower, principal, guarantor, entity, property, loan, and related identifiers and relationships, including personal information about real individuals. Optional supplemental records can be added by an authorized Fintek administrator; they are not required from the lender.
For the agreed jurisdictions and sources, the workflow may consult corporate, court, bankruptcy, land, tax, or other public-record material and retain source, match, timing, and limitation context. Source availability and coverage differ by engagement.
The Contact form collects name, institution, work contact details, topic, and message. Standard network/security metadata, such as IP address and request details, may be processed by Cloudflare to deliver and protect the site. The public pages do not currently run advertising pixels or behavioral analytics scripts.
We maintain tenant and run identifiers, authorized administrator identity and audit events, transfer integrity digests, processing status, and delivery/deletion events. The control-plane logs are designed not to contain lender-tape contents.
Use, sources, and disclosures
We use lender data to receive and validate the authorized tape, resolve the relevant entities and relationships, examine configured evidence sources, prepare the confidential summary, deliver it to the registered institution contact, support the review, and perform security, audit, and deletion operations. We use website inquiry data to respond to the inquiry and maintain business correspondence.
The Sentinel workflow does not publish lender tapes or confidential summaries, provide one lender's tape to another lender, or use tape data for public marketing. The current build has no third-party generative-AI call for tape processing or model training. We may disclose information to infrastructure and delivery providers needed to operate the service, including Cloudflare; to record-source providers when an authorized query requires it; to the institution that supplied the tape; and where law or valid process requires. Specific processor, residency, and contractual requirements should be settled in the institution's engagement terms.
Public-record availability does not make a lender's combined tape, identity graph, or summary public. Source records can be incomplete or inaccurate; a similar name alone is not treated as a confirmed identity match.
Restricted access and confidential delivery
The current build uses HTTPS transport; Cloudflare Access and named memberships for Fintek administrators; tenant-scoped records and object keys; one-use, expiring, signed lender-upload links; size and SHA-256 integrity checks; and an isolated processing path. The public website cannot start a portfolio review. Material run actions are recorded for administrative audit without placing tape contents in application logs.
The institution receives an AES-encrypted Excel Distress Signal Summary. The download link and workbook passcode are sent in separate emails to the same registered institution address, and the passcode is not stored in the control database or object storage. Plain processing artifacts remain administrator-only. Ordinary email and the public Contact form are not approved channels for transmitting confidential lender records.
No safeguard eliminates all risk. We investigate suspected incidents and coordinate notice with affected institutions and authorities as required by the applicable contract and law.
Thirty-day policy; documented manual deletion
Our lender-run retention policy is 30 days, with the starting event and any legal exceptions to be defined in the engagement terms. In the current build, age-based deletion is not automatic: a Fintek administrator performs and documents deletion. Run data remains until that deletion is completed; the maintenance process retries incomplete object removals and retains a deletion audit record. We will establish the operational deletion schedule with an institution before accepting its real tape.
Business inquiries and necessary security, audit, and legal records are subject to different retention criteria: they are kept only as needed for the inquiry, service administration, security, contractual obligations, or applicable law, then disposed of under the relevant process. The 30-day tape policy does not automatically apply to a contact email or to records that must be preserved by law.
Privacy requests and legal boundaries
State privacy laws may give an individual rights to know, access, correct, delete, or limit certain personal information, depending on residence, the data, our role, and applicable exceptions. We do not assume that financial-data exemptions remove every obligation. A person whose information came from a lender tape should normally direct a request to that institution, which controls the engagement. If a request reaches Fintek, we will authenticate it as appropriate, coordinate with the institution, and respond or assist as required by law and contract. Please do not include account numbers, full government identifiers, or tape extracts in an initial request.
Federal financial-privacy and security rules, the Fair Credit Reporting Act where its definitions and use conditions are met, and state privacy and breach-notification requirements may apply to a particular use or dataset. A score-free commercial review is not, by itself, a legal exemption. Any proposed eligibility or consumer-report use requires separate legal review before use.
To start a privacy or security inquiry, use the Contact page, select “Security and privacy,” or write to sales@fintekcapitallc.com. We may need to verify identity or institutional authority through a separate secure channel.
Contact and notice changes
Fintek Capital LLC, Alabama Office, 8603 Madison Blvd, Madison, AL 35758. Telephone: 307.533.7712. Email: sales@fintekcapitallc.com.
We may revise this notice as the product, controls, and applicable law change. We will post the updated date here; material changes affecting an active lender engagement will be handled under its contract. This public notice is descriptive and does not override stricter signed terms.
For context on the regulatory framework, see the FTC Safeguards Rule guidance, CFPB Regulation P, and the California Privacy Protection Agency FAQ. These links do not imply that every rule applies to every Sentinel engagement.