Privacy Policy
The purpose of this Privacy Policy is to provide transparent information about how we process the personal data collected through this landing page and the CreditCheck services, managed by Clovr Labs S.L. (“CreditCheck”).
CreditCheck is a service that allows users to assess their financial situation, generate creditworthiness estimates and, where they so authorise, share such information with partner entities in order to receive credit offers suited to their profile. Some analyses are based on real financial data obtained through regulated Open Banking APIs, always with the informed consent of the account holder.
We are committed to protecting your personal data in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) and, where applicable, Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE).
1. Identity of the data controller
The data controller for the personal data processed through CREDITCHECK is: CLOVR LABS, S.L. (hereinafter, «CREDITCHECK»).
NIF: B67306894.
Registered office: Avenida Generalitat, 24, 08840 Viladecans (Barcelona), Spain.
Privacy email: [email protected]
Data Protection Officer (DPO): Giacomo Collini. You may contact the DPO at the address [email protected].
CREDITCHECK will process personal data in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation («GDPR»), Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights («LOPDGDD») and other applicable regulations.
2. Scope and services of CREDITCHECK
CREDITCHECK is a technology platform that allows the user to simulate financing transactions, complete an economic and financial profile and, when the user requests it, verify certain data through Open Banking services and be put in contact with financial providers or intermediaries.
CREDITCHECK does not make the final decision to grant loans or mortgages, nor does it formalise financing transactions. The final assessment and, where applicable, the granting of financing are the responsibility of the intermediaries and/or financial institutions involved in each transaction.
3. Personal data processed
Depending on the service used and the information provided by the user, CREDITCHECK may process the following categories of data:
- Identification and contact data, such as first name, surname, telephone and email address.
- Data relating to the requested transaction, such as amount, purpose, characteristics of the property or the financing sought.
- Professional, employment, asset-related, economic and financial data provided by the user.
When the user requests verification through Open Banking, financial information obtained or generated from the account and transaction data authorised by the user, to the extent necessary to build or verify their profile.
Technical and browsing data necessary for the operation, security and traceability of the service, in accordance with the Cookie Policy and the applicable configuration.
Providing the identification, contact and economic and financial data indicated in the preceding sections is necessary for CREDITCHECK to be able to provide the requested service. Refusal to provide such data will prevent the processing of the request and the provision of the technological intermediation service. The data relating to verification through Open Banking and the technical browsing data are provided, in each case, voluntarily, and their non-provision will not prevent access to the basic service.
4. Purposes and legal bases
CREDITCHECK will process personal data for the following purposes:
| Purpose | Legal basis | Categories of data |
|---|---|---|
| a) Providing the requested service. Managing simulations, forms, enquiries and the generation of the economic and financial profile. | Performance of pre-contractual or contractual measures, Article 6.1.b) GDPR. | Identification and contact data, data relating to the requested transaction, professional, employment, asset-related, economic and financial data. |
| b) Verifying information through Open Banking. Contrasting or enriching the user's economic and financial data. | Explicit consent of the user, Article 6.1.a) GDPR, obtained in a specific and differentiated manner. | Financial information from accounts and transactions authorised by the user through Open Banking. |
| c) Putting the user in contact with financial providers or intermediaries. Communicating data to third-party independent controllers so that they can study the viability of the transaction and offer financing alternatives. | Specific consent of the user, Article 6.1.a) GDPR, obtained in a differentiated manner. The user will be informed in advance of the identity of the recipient and the purposes. Revocable at any time. | Identification, contact and economic and financial data. |
| d) Managing communications related to the request. Sending communications by email or telephone linked to the status of the request, incidents, verification or provision of the service. | Performance of pre-contractual or contractual measures, Article 6.1.b) GDPR. | Identification and contact data. |
| e) Handling enquiries and contact requests. Managing the enquiries submitted through the contact channels. | Pre-contractual measures, Article 6.1.b) GDPR. When the enquiry does not fall within a pre-contractual or contractual relationship, the legitimate interest of CREDITCHECK, Article 6.1.f) GDPR, consisting of handling communications from users or potential users. The user may object to processing based on legitimate interest by contacting [email protected]. | Identification and contact data, and data included in the enquiry. |
| f) Sending commercial communications or content. Sending news, content or commercial offers, only where the user has authorised it. In accordance with Article 21 of the LSSI-CE, sending by electronic means requires express consent, save for the similar products exception under Article 21.2 LSSI-CE, which only applies where there is an effective prior contractual relationship. | Consent of the user, Article 6.1.a) GDPR. Revocable at any time without affecting the lawfulness of the prior processing. | Identification and contact data. |
| g) Security, fraud prevention and legal compliance. Protecting the platform, detecting misuse, responding to requests from authorities and complying with legal obligations. | Compliance with legal obligations, Article 6.1.c) GDPR. Where it does not derive from a specific legal obligation, the legitimate interest of CREDITCHECK, Article 6.1.f) GDPR, consisting of ensuring the security, availability and integrity of the platform and preventing fraudulent activities. | Technical and browsing data, identification and contact data, and any other data processed on the platform to the extent necessary. |
5. Communication of data and recipients
Personal data will not be communicated to third parties except where necessary to provide the requested service, where there is a legal basis permitting it or where it is required by law.
5.1. HELLOHIPOTECA, S.L. («HELLOTECA»)
In the mortgage flow, when the user requests to be contacted and has given their specific consent to this, CREDITCHECK will communicate to HELLOTECA the identification, contact and economic or financial data necessary for HELLOTECA, in its capacity as a real estate credit intermediary registered in the Register of Intermediaries of the Bank of Spain under no. 2019/D071, and acting as an independent data controller, to contact the user, analyse the viability of the transaction and manage the mortgage intermediation.
HELLOHIPOTECA, S.L.
NIF: B88042403.
Address: Travessera de Les Corts, 224-226, Local 6, 08028 Barcelona.
Privacy contact: [email protected].
Where necessary for the management of the transaction, HELLOTECA may process the data received and, under its own responsibility as an independent data controller and in accordance with its privacy information, communicate it to financial institutions or partners involved in the study, negotiation or formalisation of the financing. You may consult additional information about the processing carried out by HELLOTECA or exercise your data protection rights in the Privacy Policy of HELLOTECA (https://helloteca.com/politica-privacidad/).
5.2. Other financial providers or intermediaries
In other CREDITCHECK products or flows other than the mortgage flow managed by HELLOTECA, and only where the user has given their specific consent to this (Article 6.1.a GDPR) or there is another valid legitimising basis duly notified, the identification, contact and economic and financial data may be communicated to banks, credit institutions, financial intermediaries or other partner operators that will act as independent data controllers in order to study the user's request or present them with financing alternatives. Prior to the communication, the user will be informed of the identity of the specific recipient of their data and of the purposes for which the recipient will process it. The updated list of partner entities will be available on the platform or will be provided to the user before obtaining their consent.
5.3. Service providers
CREDITCHECK may rely on technology, hosting, communications, security, support, analytics or other service providers necessary to operate the platform. Where such providers process data on behalf of CREDITCHECK, they will be subject to the contractual obligations required by Article 28 GDPR.
5.4. Authorities and legally authorised third parties
The data may be communicated to courts, tribunals, administrative authorities, law enforcement agencies or other bodies where there is a legal obligation or a valid request.
6. Open Banking and access to financial information
The Open Banking functionality is optional. CREDITCHECK will not ask the user for their banking credentials to store them, nor will it carry out payment transactions or fund movements.
When the user authorises the connection, CREDITCHECK may receive, through the financial aggregation service provider acting as data processor on behalf of CREDITCHECK pursuant to Article 28 GDPR, the read-only information necessary to verify certain financial data and generate or complete their profile. The scope of the information will depend on the authorisation granted by the user and on the Open Banking provider used. The identity of the aggregation provider will be communicated to the user at the time of activating the functionality.
In the mortgage flow with HELLOTECA, the access to or communication of verified financial information will only take place in respect of users who have expressly authorised such processing and to the extent necessary to manage their request.
7. Profiling and financing decisions
CREDITCHECK may use the data provided by the user and, where the user authorises it, verified financial information to generate a profile or indicative analysis of their economic situation and to provide results or offers better suited to the available information. This processing consists of the automated analysis of the economic and financial variables declared or verified by the user (income, existing debt, assets, financial history, among others) in order to generate an estimate of creditworthiness or suitability for certain financial products.
The profile generated by CREDITCHECK has an informational purpose and supports the provision of the service. CREDITCHECK does not, on its own, make binding decisions to grant or deny credit that produce legal effects on the user. The final decision rests, where applicable, with the competent intermediary and/or financial institution, in accordance with their own criteria and legal obligations. Nevertheless, to the extent that the profiling may significantly influence the financing options presented to the user, the user has the right to obtain human intervention, to express their point of view and to contest the result of the analysis, by contacting [email protected].
8. Data retention
The data will be retained for as long as necessary to manage the request and provide the requested services. In particular, the data associated with a simulation or request that does not result in the formalisation of a transaction will be retained for a maximum period of twelve (12) months from the user's last interaction with the platform, unless the user requests its deletion earlier.
Where the processing is based on consent, this may be withdrawn at any time. The withdrawal will not affect the processing lawfully carried out beforehand.
Once the relationship has ended or the request has been handled, the data may be kept duly blocked for the periods legally required to address possible liabilities, in particular the limitation periods provided for in the applicable civil, commercial and tax regulations. The evidence of the consents and authorisations granted by the user may be retained for as long as necessary to demonstrate compliance with the corresponding legal and contractual obligations, including proof of consent in accordance with Article 7.1 GDPR.
9. International transfers
Where a service provider involves the processing of data outside the European Economic Area, CREDITCHECK will adopt the safeguards required by Chapter V of the GDPR. In particular, the transfers will be carried out, as applicable, on the basis of adequacy decisions of the European Commission (Article 45 GDPR), standard contractual clauses approved by the European Commission (Article 46.2.c GDPR) or other legally valid mechanisms. The user may obtain information about the specific safeguards applied to each transfer, as well as a copy thereof, by contacting [email protected].
10. User rights
The user may exercise, where applicable, the rights of access, rectification, erasure, objection, restriction of processing and portability, as well as the right not to be subject to decisions based solely on automated processing, including profiling, and to withdraw the consent granted at any time.
To exercise these rights, you may contact [email protected], indicating the right you wish to exercise and including the information necessary to verify your identity where reasonably necessary. CREDITCHECK will address the request within a maximum period of one month from its receipt, extendable by two additional months in the event of complexity or volume of requests, in accordance with Article 12.3 GDPR.
Furthermore, the user has the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), through www.aepd.es, if you consider that the processing of your data does not comply with the regulations.
11. Cookies and tracking technologies
This site may use its own and third-party cookies for technical and analytical purposes. The conditions of use of cookies are detailed in the CreditCheck Cookie Policy.
12. Minors
The simulation and contact services for financial products are not directed at minors. In accordance with Article 7 of the LOPDGDD, the processing of personal data of minors under fourteen years of age requires the consent of their parents, guardians or legal representatives. CREDITCHECK does not knowingly collect data of minors under fourteen years of age. If CREDITCHECK becomes aware that it has collected data of a minor of that age without the consent of their parents or guardians, it will proceed to delete it without undue delay.
13. Data security
Clovr Labs applies appropriate technical and organisational measures to protect data against loss, alteration or unauthorised access, such as:
- Data encryption.
- Role-based access controls.
- Internal security audits.
- Access monitoring and vulnerability analysis.
14. Changes to this policy
This policy may be updated to reflect legal changes or modifications in the processing of data. In such cases, users will be notified in advance through this website or by email, if they have given their consent.
We recommend reviewing this Policy periodically.
Last updated: 10 September 2026.