Supplemental terms governing Partner-provided data
Last updated: December 5, 2025
This Addendum governs the receipt, handling, protection, retention, and destruction of Non-Public Personal Information (“NPI”) that Referral Partners send to Credzu.
If this Addendum conflicts with Credzu’s public Privacy Policy or User Agreement, this Addendum controls for all Partner-provided data.
This Addendum applies to all organizations and individuals who refer Consumers to Credzu, including:
This Addendum applies exclusively to NPI transmitted by Partners to Credzu, limited to:
Credzu does not receive financial, credit, or additional personal data from Partners under the referral integration.
Credzu’s application environment is hosted on Kinsta, running on Google Cloud Platform (GCP), which provides container isolation, managed security controls, continuous monitoring, and daily encrypted backups.
Partner data and documents are stored only in Amazon Web Services (AWS) S3, using encrypted, access-restricted storage.
Credzu maintains:
Backup retention follows Credzu’s primary Security & Data Retention Policy.
All Partner-to-Credzu communication uses TLS 1.2+ encryption.
All API and WordPress REST endpoints require HTTPS.
Data is encrypted using AES-256 or equivalent industry-standard methods within AWS and GCP.
Access to Partner NPI is strictly limited to authorized personnel with documented business need.
Administrative access to systems storing or processing Partner NPI requires MFA.
Access to AWS and GCP resources is governed by least-privilege IAM policies, with logged, monitored access.
Credzu uses secure token-based authentication:
Credzu classifies Partner-provided NPI into two categories.
Definition:
A Consumer who clicks a Partner’s call-to-action link and successfully completes Credzu’s account registration.
Retention:
Retained for the life of the account plus seven (7) years after closure.
Purpose:
Supports legal, regulatory, audit, and escrow dispute obligations.
Definition:
Referrals where the Consumer does not complete registration after Credzu’s automated outreach (initial SMS, 72-hour, 7-day, and 15-day follow-ups).
Retention:
Credzu does not store non-converted Partner NPI beyond 90 days.
Credzu uses:
Credzu does not print or physically store Partner NPI.
If Partner NPI is compromised, Credzu will notify the Partner’s designated compliance contact within 72 hours of incident confirmation.
Credzu, LLC
1980 N. Atlantic Avenue, Second Floor
Cocoa Beach, FL 32931
Email: info@credzu.com
We try to provide great articles. Help us share them.