Privacy Policy — Credit Intelligent Platform

Effective date: July 21, 2026
Publisher: Otic Group
Product ID: 604962fb-479d-4dd0-aabb-3c6c9e5d7f1b

Overview

Credit Intelligent Platform (“CIP”, “the service”) is published by Otic Group and offered through the Microsoft Marketplace. This Privacy Policy explains what data we collect, how we use it, how we protect it, and what rights customers and end users have.

Data we process

Customer data

Customer data is information that users upload, enter, or generate while using CIP. This may include:

Customer data belongs to the subscribing organization. Otic Group processes customer data only to provide and support the service.

Account and billing data

When a customer subscribes through the Microsoft Marketplace, Microsoft shares the following with Otic Group:

Service-generated diagnostic data

CIP collects diagnostic and telemetry data needed to operate the service, including:

Personal identifiers are redacted from telemetry wherever possible. See our Security Architecture documentation for details on redaction and sanitization.

How we use data

We do not sell customer data or use it to train third-party AI models.

Data storage and location

Customer data is stored in the customer’s chosen Azure region or, for managed deployments, in the region selected during onboarding. Backups are encrypted and retained according to the subscription plan.

Data sharing

Otic Group shares data only:

Security

CIP uses industry-standard controls including encryption in transit and at rest, Microsoft Entra ID authentication, role-based access control, audit logging, webhook signature validation, and exception sanitization. For more detail, see the CIP Security Architecture documentation.

Customer responsibilities

Customers are responsible for:

User rights

End users may contact their organization’s CIP administrator to:

Administrators may contact cip-privacy@oticgroup.com for data-subject requests that require publisher assistance.

Retention and deletion

Customer data is retained for the duration of the active subscription plus a configurable grace period (default 90 days) to support restoration. After the grace period, data is securely deleted. Diagnostic logs may be retained longer in aggregated or pseudonymized form.

Changes to this policy

Otic Group will update this policy as needed. Material changes will be communicated to customers at least 30 days before taking effect.

Contact

For privacy questions, contact cip-privacy@oticgroup.com.