Privacy Policy
Privacy Policy
Last updated May 30, 2026
Iridium Credit, Inc. ("Iridium," "we," "us," or "our") provides an AI platform that helps invoice-finance providers automate invoice processing, including client and debtor onboarding, invoice verification, collections, cash-posting reconciliation, and fraud detection. This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with our website at iridiumcredit.com (the "Site") and our software-as-a-service platform (together with the Site, the "Services").
Iridium is based in the United States and operates and hosts the Services in the United States. The Services are intended for use by businesses in the United States and are not directed to individuals located outside the United States.
1. Our Role
1.1. Data we process on behalf of our customers.
Our customers are invoice-finance providers (lenders). When a customer uploads or connects data so that we can deliver the Services to them - for example, invoices, debtor and client records, and related documents - we act as that customer's service provider and process the data on their behalf and on their instructions. In that role, the customer is responsible for the data as the controlling party, including for providing any required notices to, and obtaining any required consents from, the individuals the data concerns. If your personal information was provided to us by an Iridium customer, please see Section 9.1 for how to exercise your choices.
1.2. Data we process for our own purposes.
We act as a controller for the personal information we determine the purposes of, including information submitted through the Site, account and identity information for platform users, information we use to secure and operate the Services, de-identified information we use to improve our models and create Aggregate Data (Section 3.4), and information processed through our opt-in Fraud Detection Services (Section 3.3).
2. Information We Collect
2.1. Information you provide through the Site.
When you contact us or request a demo through the Site, we collect the information you submit - typically your name, work email address, company, and any message you include. When you apply for a role through our careers pages, we collect your name, contact details, and the application information and links you provide. The Site uses a third-party form provider to deliver these submissions to us.
2.2. Account and identity information.
When an authorized user accesses the platform, we collect account and authentication information through our identity provider, including name, work email address, login credentials, and records of platform activity such as logins and actions taken. Each customer accesses a dedicated deployment for their organization.
2.3. Customer Data processed through the platform.
In delivering the Services, we process data that our customers provide or that we ingest on their behalf ("Customer Data"). Depending on the features a customer uses, this may include: funded invoices and supporting documentation (such as purchase orders, bills of lading, rate confirmations, timesheets, and delivery receipts); debtor master data (including company name, contact name, business email, phone number, and address); client (borrower) master data and onboarding information; debtor aging and payment history; bank statements, remittance advices, and bank account and routing numbers used for cash-posting reconciliation; email correspondence and inbound document attachments; collections communication logs and AI phone-call recordings and transcripts; and configuration data such as debtor-specific rules, tone preferences, and escalation thresholds.
The personal information within Customer Data is business-context information about third-party debtors and about our customers' employees and clients. We do not seek to collect consumer health information or protected health information, payment card numbers, government-issued identifiers, or biometric identifiers (other than voice contained in call recordings).
2.4. Information collected automatically.
We do not use website analytics, advertising, or cross-site tracking cookies on the Site. We use strictly necessary cookies to maintain authenticated sessions on the platform. We and our infrastructure providers keep server and security logs that may include IP addresses, and we use an IP-geolocation service to help detect sender fraud. The Site loads fonts from third-party font content-delivery networks, which receive request information such as IP address in the ordinary course of serving those fonts.
3. How We Use Information
3.1. To provide and operate the Services.
We use information to deliver, maintain, and support the Services - including onboarding, invoice verification, collections, cash-posting reconciliation, account administration, responding to your inquiries, and providing customer support.
3.2. AI and automated processing.
Our AI components operate as a backend extraction and verification pipeline that produces structured, schema-bound results from documents and data. Funding and other significant decisions are subject to human review; AI-extracted data is treated as unverified until confirmed by a human reviewer or corroborated against source records. Our automated outbound phone calls begin with a disclosure that the call is handled by an automated AI system, and such calls may be recorded and transcribed to carry out the customer's collections workflow and for quality assurance and model improvement as described in Section 3.4.
3.3. Fraud Detection Services (opt-in).
Where a customer elects our Fraud Detection Services, we compare invoice and transaction data across participating customers to detect duplicate or double-pledged invoices. To do this, limited identifiers and transaction data - such as debtor identifiers, client identifiers, invoice identifiers, pledge status, invoice amount, and invoice date - may be made available to other participating customers. We do not disclose a customer's identity as the pledging lender, or the commercial terms of its financing, to other participants except with that customer's express consent on a per-match basis. A customer may withdraw from Fraud Detection Services on prior written notice, after which we cease new uses of its data for that purpose.
3.4. Product improvement and de-identified data.
We use Customer Data to develop, train, retrain, fine-tune, and improve our models and the verification, collections, and cash-posting capabilities of the platform, and we create de-identified and aggregated data sets ("Aggregate Data") that do not directly or indirectly identify any customer or individual. We use de-identified and Aggregate Data, and the resulting model improvements, to operate and improve our products and to develop new features, benchmarks, and insights. We do not share information that identifies a customer or an individual across customers, other than through the opt-in Fraud Detection Services described in Section 3.3.
3.5. Security, compliance, and legal.
We use information to secure the Services, detect and prevent fraud and abuse, enforce our agreements, comply with our legal obligations, and establish, exercise, or defend legal claims.
4. How We Share Information
4.1. Service providers and sub-processors.
We share information with vendors that process it on our behalf to host, operate, secure, and support the Services, under contracts that limit their use of the information to those purposes. See Section 5 for the categories of providers we use.
4.2. Between platform participants.
We share Customer Data among customers only through the opt-in Fraud Detection Services and only as described in Section 3.3.
4.3. Legal, safety, and business transfers.
We may disclose information when we believe it is required by law or legal process, to protect the rights, safety, or property of Iridium, our customers, or others, or in connection with a merger, acquisition, financing, or sale of assets, in which case we will continue to protect the information consistent with this Policy.
4.4. We do not sell personal information.
We do not sell personal information, and we do not use or disclose personal information for cross-context behavioral advertising.
5. Service Providers and Sub-Processors
5.1. Providers that store or process Customer Data.
We use Amazon Web Services for our primary database, compute, and operational logging; Cloudflare R2 for document storage; and our identity provider for authentication. We use third-party providers to power AI extraction and comparison, automated portal-access agents and the proxy network that supports them, and IP-geolocation for fraud checks. Certain providers - for inbound and outbound email, debtor credit reports, and company research and change monitoring - process Customer Data only when the related feature is enabled for a customer.
5.2. Providers that do not handle Customer Data.
Other infrastructure we use - including parts of our cloud environment used for build, deployment, secrets management, source hosting, and font delivery, and generic internet infrastructure such as DNS - does not store or process Customer Data. We can provide our current list of sub-processors on request.
6. Data Retention
6.1. Customer Data.
We retain Customer Data for the duration of a customer's agreement with us. Following expiration or termination, we make Customer Data available for export for 30 days, and we delete operational Customer Data on the earlier of 30 days after the customer's export or 60 days after expiration or termination. De-identified data, Aggregate Data, and model improvements are not customer-identifiable and are retained on an ongoing basis.
6.2. Site and account information.
We retain information submitted through the Site, and account information, for as long as needed to fulfil the purpose for which it was collected, to operate the Services, and to meet our legal, security, and recordkeeping obligations.
7. Data Security
7.1. How we protect information.
We maintain an information-security program with technical and organizational safeguards designed to protect personal information, including encryption in transit and at rest, access controls and least-privilege practices, secrets management, and immutable audit trails on verification decisions. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Where Your Information Is Held
8.1. United States hosting.
We host data in the United States. Our primary database and compute run in Amazon Web Services' US East (Ohio) region, document storage is held in North America, and authentication data is hosted in Amazon Web Services' US East (Virginia) region. We do not transfer personal information outside the United States.
9. Your Privacy Choices and Rights
9.1. Information provided by our customers.
If your personal information was provided to us by an Iridium customer - for example, because you are a debtor, a debtor contact, or a client of that customer - that customer determines how the information is used, and you should direct requests to access, correct, or delete it to that customer. We will support our customer in responding to verified requests as required by our agreement and applicable law.
9.2. Account holders and Site visitors.
For information we hold as a controller, you may contact us using the details in Section 12 to access, correct, or delete it, or to ask a question about this Policy. We may need to verify your identity before acting on a request.
9.3. U.S. state privacy rights.
Depending on where you live, you may have rights under U.S. state privacy laws to request access to, correction of, or deletion of personal information we hold about you as a controller, and to not be discriminated against for exercising those rights. As noted in Section 4.4, we do not sell personal information or use it for cross-context behavioral advertising. To exercise a right, contact us using the details in Section 12.
9.4. Automated calls.
Our automated outbound calls begin with a disclosure that the call is handled by an automated AI system, so that recipients are informed at the outset of the call.
10. Children's Privacy
10.1. Not directed to children.
The Services are intended for businesses and are not directed to children. We do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us with personal information, please contact us so we can delete it.
11. Changes to This Policy
11.1. Updates.
We review this Privacy Policy at least annually and update it when our practices or legal requirements change. When we make changes, we will revise the "Last updated" date above, and we will provide additional notice if the changes are material.
12. Contact Us
12.1. How to reach us.
If you have questions about this Privacy Policy or our handling of personal information, contact us at info@iridiumcredit.com, or by mail at: Iridium Credit, Inc., 1111B S Governors Ave, Suite 41929, Dover, DE 19904.
Questions about this policy or your personal information? Contact us at info@iridiumcredit.com.