Privacy policy

How Feesable Technologies handles information when you visit feesable.ai, when you contact us, and when a client runs a credit facility on the Feesable platform. It covers Singapore and the United Arab Emirates.

Last updated 4 August 2026

01

Who we are and the roles we act in

Feesable Technologies builds treasury and capital orchestration software for fintech and NBFI lenders, and, where separately engaged, performs calculation, reporting and verification work for clients. This policy covers feesable.ai and the Feesable platform. It does not cover our clients' own products, websites or lending programmes.

We act in two different roles, and the difference decides what we can and cannot do with information. For visitors to this site and for people who contact us about our services, we decide why and how information is used, so we are the controller of it. For the loan level and borrower level records a client holds in the platform, the client decides those things and we act only on that client's documented instructions, so we are a processor of it. Singapore law calls that second role a data intermediary.

We process client facility data under a written contract with each client that sets out what we may do with it. The client writes and configures its own credit policy. We do not decide who receives credit, what a facility costs, or what a borrower's record should say, and we do not set, tune or optimise the rules that produce those results.

If you borrowed money from a lender that runs on Feesable, we are not your lender. We cannot answer questions about your loan, change your records or discuss your account. Your agreement is with the lender you dealt with, that lender publishes its own privacy notice, and a request about your loan needs to go to it.

Two short tests. If you came to us through this website, we are answerable to you directly. If you are here because a lender that uses our software holds your loan, that lender is answerable to you, and our job is to help it answer.

02

What we collect

What you give us. When you request a demo, make an enquiry, ask about working with us or write to any of our addresses, we collect your name, your work email address, your employer, your role where you tell us, and whatever you choose to put in the message. We keep the correspondence that follows.

What we observe. Our servers record log data when you use the site, including your IP address, the approximate location it indicates, your browser and device type, the pages you request, the page that referred you and the time of each request. In the platform we record authentication events and an audit trail of actions taken, including reads and writes of facility data, because a client needs that trail to reproduce its own reporting.

What clients load. A client's environment holds the records that client puts there or connects to us, which typically include borrower and loan records, repayment histories, collateral and registry references, and bank and payment records used for verification. We do not collect that information for our own purposes, we do not decide what it contains, and we hold it only to run the service the client has engaged us for.

We do not ask for sensitive personal data through this website, and we do not knowingly collect information from anyone under 18. If you send us something we did not ask for, we may delete it.

03

How we use information and on what basis

Where we are the controller, we use information to answer enquiries and arrange demonstrations, to provide, secure, support and maintain the site and the platform, to keep the records that legal, tax and regulatory obligations require us to keep, to understand how the site and the product are used so that we can improve them, and, where you have agreed to it, to send you marketing.

We rely on more than one legal ground and we use the one that actually fits the purpose. Where you ask us for something, we process what you send in order to answer you and to take the steps you asked for. Where the law requires us to create or keep a record, we rely on that obligation. We rely on the legitimate interests exception under the Personal Data Protection Act to collect, use and disclose personal data for the purposes of security and the prevention of misuse of our services. We rely on the business improvement exception for product and site analytics.

Marketing is different, and we treat it that way. We send marketing only where you have consented, we do not rely on legitimate interests to justify it, and you can withdraw that consent at any time without giving a reason. Withdrawing it does not stop us answering an enquiry you have made.

We do not sell personal information, we do not share it with advertising networks, and we do not use it to build profiles for anyone else. Where we act as a processor, our purposes for client facility data are the ones the client sets in its instructions, and we have no separate purpose of our own.

04

Cookies, analytics and marketing choices

This site sets only the cookies it needs to serve pages and to remember display preferences. The platform sets a session cookie to keep you signed in, and blocking that one will stop sign in from working. Blocking anything else changes nothing about how the site behaves.

Where we measure traffic we do it first party and in aggregate. We do not run advertising trackers, we do not share browsing data with ad networks, and we do not build cross site profiles. This site does not present a consent banner or a preference centre, because it does not set the kind of cookie that would call for one, and your browser controls remain available to you either way.

Where we ask for your consent to anything, we ask for it separately from anything else you are agreeing to, in plain words, and we keep a record of what you agreed to and when. You can withdraw it at any time by writing to privacy@feesable.ai, we will not make withdrawing it difficult, and withdrawal takes effect for the future without making what we did before unlawful.

Every marketing email we send carries an address you can use to unsubscribe, and that address stays able to receive requests for at least 30 days after the message is sent. You can also write to privacy@feesable.ai and ask us to stop, and that one request will stop marketing contact across every channel we use. We do not treat a work address published on a website or in a directory as your consent to receive marketing.

We follow the marketing rules that apply in the markets we contact, including the Do Not Call provisions for telephone channels in Singapore.

05

Automated processing and model training

Automated processing does happen, and it would be misleading to suggest otherwise. Credit rules on the platform are versioned rule sets that the client writes, configures and owns, they run in that client's environment, and they produce a rule by rule trace of how a result was reached. Feesable approves nothing, declines nothing and sets no price.

Because the decision is the client's, so is any review of it. If you want a decision looked at again, ask the lender that made it. We will not review, reconsider or explain a lending decision, because we are not in a position to overturn a result and we will not pretend to a power we do not have. Where a client asks us to help it answer you, we help.

Machine learning is used in one place, in anomaly review that looks across a loan tape for patterns a fixed rule would not catch and raises them for a person to examine. It sits alongside the calculation rather than inside it, and it does not decide anything on its own.

We do not use one client's data to train models for another client, we do not pool client data across clients, and we do not run cross client benchmarking or analytics on facility data. This is not a preference we could quietly change. It is a condition of the role we act in.

Nothing on the Feesable platform decides your application. The rules are the lender's, written by the lender, and the outcome is the lender's to explain.

06

Sharing, sub-processors and confidentiality

For our own operations we use service providers in four categories: cloud hosting and infrastructure, error and performance monitoring, email delivery, and customer relationship and support tooling. The providers we use for this website, our marketing and our own support are located outside the United Arab Emirates, and we will tell you which countries on request. Each is engaged under written terms that require confidentiality and appropriate security, limit them to delivering the service we engaged them for, and prohibit them from using the information for their own purposes.

We treat changes to those providers differently depending on whose data is involved. Providers used for this website, our marketing and our own support we may change from time to time, and we will update this policy when we do. Sub-processors with access to a client's facility data are the ones agreed under that client's engagement terms, which also record where each of them operates, and any change is made under those terms rather than by a notice posted on this page.

We may disclose information where a law, a regulation, a court order or a regulator with jurisdiction over us requires it. Where we are permitted to tell the affected client, we will, and we will disclose no more than what is actually required of us.

We do not disclose one client's facility data to another client, to an investor or to a prospective investor. We do not give any other party access to a client's facility data without that client's authorisation. We do not sell personal information to anyone.

07

Where information is held and international transfers

The hosting region for a client's facility data is fixed in that client's engagement terms and is not moved without that client's agreement. It is a term of the engagement, not a setting, and we reserve no right to move it. Information relating to this website and our own marketing is held in the regions our providers operate in, and we will tell you where on request.

Under Singapore law, where personal data we control leaves Singapore we must satisfy ourselves that it will receive a standard of protection comparable to the Act, and we do that through written terms with each recipient. Where we act as a data intermediary for a client, the cross border transfer obligation under the Act stays with that client as the organisation whose data it is, and we support the client in meeting it rather than assuming it.

We want to be exact about what we are not claiming. We do not rely on an adequacy decision, a certification or an approved transfer mechanism that has not been issued or that we have not obtained. No list of adequate countries and no standard contract terms have been issued under the federal law of the United Arab Emirates, so we claim neither. If a mechanism becomes available and we use it, we will say so here.

Where we hold information as the controller and it moves out of the United Arab Emirates, we rely on the consent you give us when you give us the information, which we ask for separately and which you can withdraw. Clause 11 sets that out.

Clients regulated by the Central Bank of the UAE are subject to requirements about where data is held. Where those requirements apply, residency is dealt with in that client's engagement terms rather than in this policy, and no term of this policy overrides them.

08

Security and incident notification

We protect information with encryption in transit and at rest, least privilege access, audit logging on reads and writes of facility data, scheduled review of who holds which access rights, and separation between client environments. No system is free of risk and we do not claim otherwise.

We are equally careful about what we do not claim. We do not hold a security certification, and we do not describe ourselves as compliant with rules that are addressed to licensed financial institutions rather than to their software providers. Where a client needs independent assessment or audit rights, those are available under its engagement terms. We do not publish availability, recovery or notification timings on this page, because those belong in the engagement where they are agreed and priced.

Where we are the controller, and an incident affects personal data we hold in that role, we assess it and notify the regulator and the people affected where the law requires, within the period that law allows. What makes an incident notifiable, and when we must not or need not tell individuals, is not the same in Singapore as it is in the United Arab Emirates, so clause 11 states each of them rather than merging the two.

Where an incident affects a client's facility data, we notify the affected client without undue delay and support its investigation. It is then for that client to assess the incident, to notify its regulator and to notify any affected individuals. We do not notify a regulator over a client's head, and we do not contact a client's borrowers.

09

Retention and deletion

Enquiry and demonstration records are kept while we are in contact with you and for a reasonable period afterwards, then deleted. We keep some records for longer where a legal, tax or regulatory obligation requires it, and only for as long as that obligation runs.

For client facility data, retention is set by the purpose and by the engagement. Because a certificate must be capable of being reproduced later, the records that support one are kept for the life of the facility and for the period the facility agreement specifies after it.

When an engagement ends, we return or delete client data on the timetable that agreement sets. Backups age out on their own cycle rather than on request, and we do not restore a backup in order to bring back data a client has asked us to delete.

We cannot delete on demand a record that the client rather than Feesable controls. If you are a borrower and you want your record deleted, that request goes to your lender, and we act on the instruction the lender gives us.

10

Your rights and how to exercise them

What you can ask for depends on which law applies to you and on which of our two roles applies to the information. Where we are the controller, you can ask for access to the personal data we hold about you and for correction of it, ask us to stop marketing, and withdraw a consent you gave us. Where applicable law gives you a further right, we will honour it, and clause 11 names the rights that are specific to one market.

There is one route. Write to privacy@feesable.ai. We may need to check who you are before we answer, and we will ask for no more than we need to do that. We aim to answer within 30 days, which is a commitment we make rather than a period the law sets everywhere, and where the law that applies to you allows us less time we work to the shorter period.

Where we hold the information as a processor for a client, we cannot answer your request directly, because the record is the client's and not ours to open, correct or delete. We will pass the request to that client and help it respond. That is not a brush off; it is the only answer we can lawfully give.

If you are not satisfied with how we have handled a request, tell us first and we will look at it again. You can also complain to the data protection authority in your jurisdiction, and clause 11 names the authority in each of the two markets this policy covers.

11

Regional information for Singapore and the UAE

In Singapore, the Personal Data Protection Act 2012 applies. Where we act as a data intermediary for client facility data, our obligations under the Act are to protect it, not to keep it for longer than we need it, and to notify the client of a breach without undue delay. The other obligations under the Act, including consent, purpose, notification, access, correction and cross border transfer, rest with the client as the organisation the data belongs to. Where we act as the controller, for website and prospect information, we carry the full set ourselves.

For an access or correction request about information we control in Singapore, we respond within 30 days, and we will tell you in advance if we need longer. Our marketing is consent based, every marketing email carries an unsubscribe address, and we follow the Do Not Call provisions for telephone channels.

Where we are the controller and an incident is notifiable under the Act, we notify the Personal Data Protection Commission and the individuals affected. There are two situations under the Act in which we will not notify individuals: where a law enforcement agency instructs us not to or the Commission directs otherwise, and where remedial action, or a measure already in place such as encryption, makes serious harm unlikely. Both of those are features of Singapore law and neither of them applies in the United Arab Emirates.

We have designated an individual as responsible for our compliance with the Act. The business contact for that role is privacy@feesable.ai, monitored during Singapore business hours. If you need the name of that individual, our registered entity details or a postal address for a formal request, ask us and we will provide them.

In the United Arab Emirates, the federal law is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. Its executive regulations, which would settle the detail of international transfers, breach reporting and how rights are exercised in practice, had not been issued as at the date at the top of this page, and no schedule of penalties has been made under it. We have therefore written this policy to describe what we actually do, rather than to point at mechanics that do not yet exist, and we will update it when they issue.

That law reaches organisations outside the United Arab Emirates that process the personal data of people inside it, so it applies to us for the website and prospect information we hold as controller. It does not require us to appoint a representative in the United Arab Emirates, and it does not require us to register with any authority there. We have done neither, and we would not want you to read that as a gap.

For loan level and borrower level data we process for a client, we act on that client's documented instructions, and a request about that data goes to the client as the party that answers for it. Where a client is licensed by the Central Bank of the UAE, UAE law places a duty of confidentiality over that client's customer data directly on us as well as on the client, and it reaches our people by the nature of the work they do. We treat that duty as binding on us, which is one reason the last paragraph of clause 6 is a statement of law rather than a preference.

No list of adequate countries and no standard contract terms have been issued under the federal law, so we do not claim to rely on either. Where information we hold as controller moves out of the United Arab Emirates, we rely on your explicit consent to that transfer, asked for at the point of collection, separately from your acceptance of this policy, recorded by us, and withdrawable at any time without difficulty. For a client's facility data, where the data sits is fixed by that client's engagement terms and by the rules that apply to that client, and it is not ours to move.

The federal law gives you rights over information we hold about you as controller: to be told how it is processed, to have it corrected, to have it erased in the cases the law sets out, to have processing restricted, and to object to direct marketing. It also gives you a right to receive data you provided to us in a machine readable form, and to ask us to send it to another controller where that is technically possible. It sets no period for answering any of those requests, so the 30 days in clause 10 is a commitment we have made and not a deadline the law imposes.

The federal law sets no breach notification deadline, and we will not invent one. Where it applies to data we process for a client, our duty is to notify that client immediately on becoming aware, and it is for the client to report to the UAE Data Office and to tell any individuals affected. If you are in the United Arab Emirates and you are unhappy with how we have handled your information, you may complain to the UAE Data Office, which is the federal supervisory authority for personal data.

The data protection contact for both markets is privacy@feesable.ai. This policy is published in English only, and we will answer a request in English.

Where a client is licensed in the Dubai International Financial Centre or the Abu Dhabi Global Market, that centre's data protection regime applies to the personal data we process for that client, and the applicable terms are set out in our agreement with them. Those regimes are separate from the federal law and they do not govern this website.

12

Contact

For anything in this policy, or to make a request about your personal data, write to privacy@feesable.ai and put the word Privacy in the subject line so it reaches the right person. If you need our registered entity name, our registered address or a postal route for a formal request, ask and we will provide them.

If your question is about a loan you took out, please write to the lender you borrowed from instead. We will not be able to help, and sending us your loan details puts information in our hands that we have no standing to act on.

Contact

Feesable Technologies, privacy@feesable.ai. Please put the word Privacy in the subject line so the request reaches the right person.