Privacy Policy
Cercu Privacy Policy (v1.0)
Effective Date: May 1, 2025
Last Updated: January 11, 2026
1. Introduction
Cercu Inc. (“Cercu”, “we”, “us”, “our”) provides technology services including credit data normalization, community savings facilitation, and consumer reporting capabilities. This Privacy Policy describes our data practices and your privacy rights under applicable laws including PIPEDA (Canada), Ontario Consumer Reporting Act, U.S. Fair Credit Reporting Act (FCRA), and emerging AI regulations.
Our Terms of Use also contain important disclosures about our Services. By using Cercu Services, you consent to the practices described herein.
2. Information We Collect
We collect information necessary to verify identity, facilitate payments, generate insights, and support credit reporting where applicable:
- 2.1 Identity & Contact Data
- Legal name, date of birth, contact information.
- Government-issued identifiers (SIN, SSN, Tax ID where legally permitted).
- Residency and identity verification documents.
- 2.2 Financial Data
- Transaction history from linked accounts via authorized Open Banking partners.
- Payment performance in Community Savings Groups (ROSCAs).
- Alternative data (rent, utility payments) where users opt-in.
- 2.3 Behavioral Data
- App usage patterns, payment timeliness, group participation metrics.
- Device and network information for security and fraud prevention.
3. Culture AI™ & Data Processing
We collect information necessary to verify identity, facilitate payments, generate insights, and support credit reporting where applicable:
- 3.1 Analytics Purpose
Culture AI™ processes behavioral and financial patterns to generate descriptive outputs including Trust Passports™and participation metrics. These support transparency within our community platform.
- 3.2 No Automated Decisions
Culture AI™ does not make automated decisions producing legal effects. All access decisions, suspensions, or material status changes involve human review.
- 3.3 Model Fairness
We conduct regular audits to identify and mitigate bias in analytics models.
4. How We Use Your Information
We use data to:
- Verify identity and prevent fraud.
- Facilitate ROSCA payments and group functionality.
- Generate descriptive Trust metrics and behavioral insights.
- Furnish verified payment datato credit bureaus as a data furnisher (where applicable).
- Comply with AML/KYC obligations.
- Improve Services through aggregated, anonymized analytics.
5. Data Sharing & Disclosures
We do not sell personal data. We share information only as necessary:
- 5.1 Service Providers
- Identity verification (KYC/AML partners).
- Payment processing and Open Banking aggregators.
- Fraud detection and cybersecurity vendors.
- 5.2 Credit Reporting
- As a data furnisher to Tier-1 credit bureaus(Equifax, TransUnion, Experian), we share verified payment performance from eligible Groups and accounts.
- Only for permitted purposes under applicable consumer reporting laws.
- 5.3 Legal Requirements
- Responding to lawful requests from regulators, law enforcement, or courts.
- Fraud prevention and platform integrity.
6. Cross-Border Data Transfers
Your data may be accessed or processed in Canada, the United States, or other jurisdictions where service providers operate.
- Safeguards:We use encryption, standard contractual clauses, and other recognized transfer mechanisms. Data in foreign jurisdictions may be subject to that jurisdiction’s access laws.
7. Your Privacy Rights & Consumer Reporting Rights
- 7.1 Access & Correction (PIPEDA): Canadian residents may request access to their personal information and request corrections. Contact [email protected].
- 7.2 Consumer Reporting Disputes:
- Direct disputes: File disputes about furnished data at [email protected].
- Investigation timeline: We investigate and respond within 30 days (Canada) or FCRA timelines (U.S.).
- Bureau disputes: You may also dispute directly with credit bureaus.
- 7.3 Withdrawal of Consent: Where processing relies on consent, you may withdraw consent (subject to legal or contractual obligations).
- 7.4 Account Deletion:Request deletion of your account. We retain data required for legal, regulatory, or credit reporting purposes (typically up to 7 years for payment history).
8. Data Security & Retention
Security Measures: Encryption at rest and in transit, access controls, regular audits, and employee training.
Retention:
- Account data:Duration of relationship + legal requirements.
- Credit reporting data:Up to 7 years per consumer reporting laws.
- Audit/security logs:2–7 years per regulatory requirements.
9. Children’s Privacy
Our Services are not directed to children under 16. We do not knowingly collect personal information from children.
10. Changes to This Privacy Policy
We may update this Policy. Material changes will be posted here with a new “Last Updated” date. Continued use constitutes acceptance.
11. Contact Information
Cercu Inc. – Data Protection Officer
First Canadian Place 100 King St W, Suite 5700 Toronto, ON M5X 1C7
Email: [email protected] | [email protected] | Phone: 1-800-CERCU-01 (Canada/U.S.)




