Security and data handling
Financial data should have a short, accountable life.
Hola Credit is designed around consent, tenant isolation, auditability and intentionally limited raw-file retention. Here is what that means in practice, in plain language.

The consent artefact is captured before any statement is uploaded, and it stays attached to the case for its entire life.
Consent before processing
The applicant explicitly authorises the organisation to use their bank statement for a defined credit assessment. The consent artefact records purpose, data categories, organisation, retention scope, expiry, and the actor who captured the consent. No preselected or bundled consent is permitted. Withdrawal is recorded as a new event, without rewriting history.
Tenant isolation
Every application, statement and assessment belongs to the organisation that created it. Loan officers see only their own cases. Risk managers can review across their organisation. At no point can one organisation access another's data. The boundary is enforced on the server, not just in the interface.
Every material action is logged
Sign-in, organisation changes, consent capture, upload, file access, extraction correction, score generation, assessment viewing, human decisions, exports and administrative access. Every event is timestamped, actor-attributed, tenant-scoped and protected from ordinary edits. The trail is append-only.
Data minimisation
Hola Credit collects only the data required for the assessment. Full national identifiers are not stored in general application tables. Sensitive values are not placed in URLs or search indexes. Production and development environments are separated, with production access logged and auditable.
Intentionally short retention
Raw bank statement files are retained only for the period necessary to support the assessment and any required review, after which they are scheduled for automated deletion. The system supports per-artifact retention classes, deletion due dates, legal holds with authorised reasons, and deletion confirmation with failure alerting.
Questions about security or data handling?
Contact us to discuss the threat model, audit capabilities and retention policies in detail.