Covenant Command Center
Privacy Policy
Effective Date: January 10, 2026
Last Updated: January 10, 2026
đ Quick Summary: How We Protect Your Data
- đĄī¸ Bank-Grade Security: AES-256 encryption, role-based access controls
- â You Own Your Data: We never sell or share your loan documents
- đ Compliant: GDPR (EU), CCPA (California), SOC 2 roadmap (Q3 2026)
- đģ On-Premise Option: Keep all data on your servers (zero cloud storage)
- đ§ Data Requests: Email privacy@covenantcommandcenter.com for access, deletion, or portability
- đī¸ Retention: Data deleted 30 days after account cancellation
- đĒ Cookies: Only essential (login sessions) â no tracking or ads
1. Introduction
Welcome to LPN to RN Program. We are committed to protecting the privacy and security of your data. This Privacy Policy explains how we collect, use, store, and protect information when you use our AI-powered loan covenant monitoring service.
Who We Are:
Covenant Command Center provides AI-powered extraction and monitoring of loan covenants for banking institutions and financial services organizations.
What This Policy Covers:
This policy applies to all users of our Service, including beta participants, paid subscribers, and website visitors.
2. Information We Collect
2.1 Information You Provide Directly
When you use Covenant Command Center, you provide:
| Data Type | Examples | Purpose |
|---|---|---|
| Account Information | Name, email, institution name, job title | Account creation, support, billing |
| Loan Documents | Credit agreements, amendments, loan schedules | Covenant extraction and monitoring |
| Financial Data | Borrower names, loan amounts, covenant thresholds | Breach detection and alerts |
| Payment Information | Credit card (last 4 digits), billing address | Subscription billing (processed by Stripe) |
| Support Communications | Email correspondence, bug reports | Customer support and product improvement |
2.2 Information Collected Automatically
- Usage Data: Features used, documents processed, login timestamps
- Technical Data: IP address, browser type, device type, operating system
- Performance Data: Extraction speed, accuracy rates, error logs
2.3 Information We Do NOT Collect
- â Social Security Numbers or Tax IDs (unless in uploaded loan documents)
- â Personal banking credentials (we never ask for passwords)
- â Browsing history outside our Service
- â Location tracking (GPS data)
- â Biometric data
3. How We Use Your Information
We use your information ONLY for these purposes:
3.1 Service Delivery
- â Extract covenants from loan agreements using AI
- â Monitor covenant compliance and detect breaches
- â Send real-time breach alerts via SMS and email
- â Generate compliance reports and dashboards
3.2 Account Management
- â Create and maintain your user account
- â Process subscription payments
- â Provide customer support
- â Send service updates and security notifications
3.3 Product Improvement
- â Improve AI accuracy (covenant mapping table refinements)
- â Fix bugs and performance issues
- â Develop new features based on usage patterns
3.4 Legal Compliance
- Comply with legal obligations (subpoenas, court orders)
- Enforce our Terms of Service
- Protect against fraud and security threats
4. Data Security & Protection
We implement bank-grade security measures to protect your data:
4.1 Encryption
- At Rest: AES-256 encryption for all stored data
- In Transit: TLS 1.3 encryption for all data transfers
- Database: Encrypted backups with separate encryption keys
4.2 Access Controls
- Role-Based Permissions: Users only see data they're authorized to access
- Multi-Factor Authentication (MFA): Available for all accounts (required for admins)
- Password Requirements: Minimum 12 characters, complexity enforcement
- Session Management: Auto-logout after 30 minutes of inactivity
4.3 Infrastructure Security
- Cloud Provider: AWS (SOC 2 Type II certified) or Azure Government Cloud
- Firewalls: Network segmentation and intrusion detection
- Monitoring: 24/7 security monitoring and alerting
- Penetration Testing: Annual third-party security audits
4.4 On-Premise Deployment
For banking institutions requiring maximum control, we offer on-premise deployment:
- â All data stays on your servers (zero cloud storage)
- â You control access, backups, and retention policies
- â Meets regulatory requirements for data sovereignty
- â Available for Enterprise plans
5. Data Retention & Deletion
5.1 How Long We Keep Your Data
| Data Type | Retention Period | Reason |
|---|---|---|
| Active Account Data | As long as account is active | Service delivery |
| Loan Documents | 30 days after account cancellation | Recovery period (if you change your mind) |
| Billing Records | 7 years | Tax compliance (IRS requirement) |
| Support Emails | 3 years | Product improvement and legal protection |
| Anonymized Usage Data | Indefinitely | Product analytics (cannot identify you) |
5.2 How to Request Data Deletion
You can request immediate deletion by:
- Emailing: privacy@covenantcommandcenter.com
- Subject line: "Data Deletion Request"
- Include: Your account email and institution name
- We will confirm deletion within 7 business days
6. Your Privacy Rights (GDPR & CCPA)
Depending on your location, you have specific privacy rights under GDPR (EU) and CCPA (California).
6.1 Rights for All Users
- Right to Access: Request a copy of all data we hold about you
- Right to Correction: Update inaccurate or incomplete data
- Right to Deletion: Request permanent deletion of your data
- Right to Portability: Export your data in machine-readable format (JSON, CSV)
- Right to Object: Opt out of certain data processing activities
6.2 GDPR-Specific Rights (EU Users)
- Right to Restrict Processing: Limit how we use your data
- Right to Lodge a Complaint: Contact your Data Protection Authority
- Legal Basis for Processing: We process data based on:
- â Contract performance (providing the Service)
- â Legitimate interests (product improvement, security)
- â Your consent (marketing emails â opt-in only)
6.3 CCPA-Specific Rights (California Users)
- Right to Know: Categories of data collected and how it's used
- Right to Opt-Out: We do NOT sell your data (nothing to opt out of)
- Right to Non-Discrimination: We will not penalize you for exercising privacy rights
6.4 How to Exercise Your Rights
Email: privacy@covenantcommandcenter.com with:
- Your full name and account email
- Specific request (access, deletion, portability, etc.)
- Verification: We may ask for proof of identity (last 4 digits of payment method)
Response Time: Within 30 days (GDPR) or 45 days (CCPA)
7. Third-Party Services & Sharing
We use a small number of trusted third-party services to operate Covenant Command Center. We never sell your data.
7.1 Third Parties We Work With
| Service | Provider | Purpose | Data Shared |
|---|---|---|---|
| Cloud Hosting | AWS / Azure | Store and process data | All service data (encrypted) |
| Payment Processing | Stripe | Handle subscription billing | Payment info (we never see full card numbers) |
| Email/SMS Alerts | SendGrid / Twilio | Send breach notifications | Email addresses, phone numbers, alert content |
| AI Processing | Anthropic (Claude API) | Covenant extraction (fallback only) | Loan document text (no identifying info) |
| Analytics | Self-hosted (privacy-focused) | Usage metrics (anonymized) | Aggregated feature usage (no personal data) |
7.2 When We May Share Data
We only share your data in these limited circumstances:
- With Your Consent: If you explicitly authorize sharing (e.g., integration with your core banking system)
- Service Providers: Third parties listed above (under strict data processing agreements)
- Legal Requirements: Court orders, subpoenas, regulatory inquiries
- Business Transfers: If Covenant Command Center is acquired (you'll be notified)
- Security Threats: To prevent fraud, abuse, or security breaches
8. Cookies & Tracking
8.1 Cookies We Use
We use minimal cookies â only what's necessary to operate the Service:
| Cookie Name | Type | Purpose | Duration |
|---|---|---|---|
| session_token | Essential | Keep you logged in | 30 minutes |
| csrf_token | Essential | Security (prevent attacks) | Session |
| preferences | Functional | Remember your settings (alerts, language) | 1 year |
8.2 What We DON'T Use
- â No advertising cookies (we don't show ads)
- â No cross-site tracking (we don't follow you around the web)
- â No social media pixels (Facebook, LinkedIn, etc.)
- â No third-party analytics (Google Analytics, etc.)
8.3 Cookie Controls
You can control cookies via:
- Browser Settings: Block or delete cookies (may break functionality)
- Our Dashboard: Disable non-essential cookies in Account Settings
9. International Data Transfers
Covenant Command Center operates globally. Your data may be processed in different countries:
9.1 Where Data Is Stored
- US Customers: Data stored in AWS US East (Virginia) or US West (Oregon)
- EU Customers: Data stored in AWS EU (Frankfurt) â GDPR compliant
- UK Customers: Data stored in AWS EU (London) â UK GDPR compliant
- On-Premise: Data stays in your jurisdiction (no transfers)
9.2 GDPR Safeguards for EU Data
If you're in the EU and your data is transferred to the US:
- â Standard Contractual Clauses (SCCs): EU-approved transfer mechanism
- â Data Processing Agreements: All vendors sign DPAs
- â Encryption: Data encrypted during transfers
10. Children's Privacy
Covenant Command Center is not intended for children under 18. We do not knowingly collect data from minors.
If you believe a child has provided us with personal information, please contact us at privacy@covenantcommandcenter.com and we will delete it immediately.
11. Changes to This Policy
We may update this Privacy Policy to reflect:
- Changes to our Service (new features)
- Legal or regulatory requirements
- Industry best practices
11.1 How We'll Notify You
- Material Changes: Email notification 30 days before effective date
- Minor Changes: Update "Last Updated" date on this page
- Your Options: If you disagree with changes, you may cancel your account
Continued use of the Service after changes = acceptance of updated policy.
12. Contact Us
For privacy questions, data requests, or concerns:
Email: privacy@covenantcommandcenter.com
General Support: kimn@covenantcommandcenter.com
Website: https://covenantcommandcenter.com
Response Time: Within 2 business days
EU Representative (GDPR)
If you are in the European Union and have concerns about our data practices, you may contact your local Data Protection Authority or reach us at the email above.