Privacy Policy
Privacy Policy
Last updated: June 1, 2026
This Privacy Policy describes how and why Unsettled d/b/a D&A Services, LLC (“Unsettled”, “we,” “us,” or “our”) might collect, store, use, and/or share (“process”) your information when you use Unsettled’s services or visit our website. Definitions of terms used in this policy are the same as are found in our Terms of Service. If at any time you have questions about this policy please contact us at Legal@unsettled.io. If you do not agree with our policy or practices, please discontinue use of our services.
Unsettled provides a platform designed to provides debt settlement enrollment services delivered through a proprietary self-service portal under a monthly subscription model and related products and services (the “Service”). Unsettled follows this Privacy Policy according to the applicable law in the places in which we operate. We also work collaboratively with other internet and computer and mobile applications which frequently have their own privacy statements and policies and we encourage you to review them. Please know that our site and applications may contain links to other sites we do not own or control but that you may find useful. Unsettled is not responsible for the privacy practices of those sites.
Our Service is not intended for children or anyone under the age of 18. Unsettled does not knowingly collect personal information from anyone under the age of 18. If you have reason to believe that a child or anyone under the age of 18 has provided personal information to us through the Service please contact us at Legal@unsettled.io and we will endeavor to delete that information from our databases.
1. What Information Do We Collect?
We collect information that you voluntarily provide to us when you register for our Service, express an interest in obtaining information about us or our Service, when you actively participate in the use of the Service, or otherwise access Unsettled’s platform.
Personal Information Provided by You
The personal information that we collect depends on the context of your interactions with us and the Service, the choices you make, and the products and features you use. Generally, this information establishes your account, method/means of identifying institutions in your personal financial network, and potentially also your methods and means of payment, services and other data related to our relationship with you. This information may also be required by applicable laws to verify your identity before you can use certain services. The personal information we collect from you may include the following:
- Names
- Phone numbers
- Email addresses
- Physical addresses
- Usernames that you create
- Passwords that you create
- Contact preferences
- Contact or authentication data
Sensitive Information
When necessary, with your consent or as otherwise permitted by applicable law, we process the following categories of sensitive information:
- Financial data
- Social security numbers
Administrative Data
This information may include device and system information, product license information, and/or usage and preference information including how you want us to communicate with you. This data helps us to understand and best serve your expectations, needs, interests and requirements.
Security Data
This data may include specifics about your financial accounts or transactions, location data and other information you provide to organize your personal financial network.
Diagnostic Data
If and as you use our Service we may capture and preserve application crash reports, information you share regarding your customer experience as necessary to troubleshoot any malfunctioning Service. For example, when you call, message, chat, email, or otherwise communicate with us, we may retain, and review recordings and records and the contents of the communications as required or permitted by law and our recording and information management policies.
Information Automatically Collected
When you visit, use or interact with the Service, we may receive certain information about your visit, use or interactions. For example, we may monitor the number of people that visit the Service, peak hours of visits, which page(s) are visited, the domains our visitors come from (e.g., google.com, yahoo.com, etc.), which browsers are used to access the Service (e.g., Google Chrome, Microsoft Internet Explorer, etc.), and geographical location information. This information does not reveal your specific identity.
In particular, the following information may be created and automatically logged in our systems:
- Log data: Information that your browser automatically sends whenever you visit the Service (“log data”). Log data includes your Internet Protocol address, browser type and settings, the date and time of your request, and how you interacted with the Service.
- Cookies: Please see the “Cookies” section below to learn more about how we use cookies.
- Device information: Includes name of the device, operating system, and browser you are using. Information collected may depend on the type of device you use and its settings.
- Usage Information: We collect information about how you use our Service, such as the types of content that you view or engage with, the features you use, the actions you take, and the time, frequency and duration of your activities.
Cookies
We use essential cookies to operate and administer our Service, gather usage data on our Service and improve your experience on it. A “cookie” is a piece of information sent to your browser by a website you visit. Cookies can be stored on your computer for different periods of time. Some cookies expire after a certain amount of time, or upon logging out (session cookies), others survive after your browser is closed until a defined expiration date set in the cookie (as determined by the third party placing it) and help recognize your computer when you open your browser and browse the Internet again (persistent cookies).
Online Tracking and Do Not Track Signals
When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email or home address.
On most web browsers, you can find the Do-Not-Track (“DNT”) feature or setting where you can choose your privacy preferences. You will find a “help” section on the toolbar. Please refer to this section for information on how to receive a notification when you are receiving a new cookie and how to turn cookies off or otherwise manage them. Unsettled has no control over your choice of browser or the policies and practices of the browser companies. Please ensure you review any browser companies’ own policies and procedures. For your convenience here are links to a few browser companies where you can review the policies and procedures each has:
Please note that if you limit the ability of websites to set cookies, you may be unable to access certain parts of the Service and the choices you make about setting cookies may have an impact on the scope of functions associated with features of the Service you are able to access.
Any User Content provided through the chat platform may interact with third party language models and you are solely responsible for the content of any Message you send through that channel.
If you access the Service on your mobile device, the configuration of the applications or technology on your mobile device may, through no control of Unsettled, limit your opportunities to control tracking, advertising or other settings.
If you feel your information has been tracked or targeted for purposes other than those necessary to maintain the security of our Service as described above, under applicable US Laws, you can opt out of these online tracking technologies by taking the steps outlined above and by submitting a request to legal@unsettled.io for further assistance.
2. How Do We Process Your Information?
Consistent with applicable law and choices and controls that may be available to you, we may use all or some of the personal information we collect from you or from devices associated with you, for purposes including the following:
- To personalize your experience
- To provide and facilitate your engagement with the Service, including account creation, to verify your identity, facilitate user-to-user communications, facilitate payments between you and third-party financial institutions via our platform, and obtain your credit report from a third-party upon your request
- To respond to your inquiries, comments, feedback or questions
- To send administrative information to you, for example, information regarding the Service, and changes to our terms, conditions, and policies
- To analyze how you interact with our Service
- To maintain and improve the content and functionality of the Service and to troubleshoot any issues you or other users may report to us
- To develop new products and services
- To prevent fraud, criminal activity, or misuse of our Service, and to assure the security of our IT systems, architecture and networks
- To comply with our legal obligations and legal process and to protect our rights, privacy, safety or property, and/or that of our affiliates, you or other third parties
Aggregated, Anonymized, and Pseudonymized Information
We may collect or generate aggregated, anonymized, and/or pseudonymized personal information and use the information to analyze the effectiveness of our Service, to improve and add features to our Service, and for any other lawful purpose. In addition, we may share aggregated, anonymized, and/or pseudonymized information with our business partners and other third parties. We may collect or generate aggregated, anonymized, and/or pseudonymized information through the Service, through cookies, and through other means described in this Privacy Policy.
4. How Long Do We Keep Your Information?
We keep personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, while we have a business need to do so, or as required by law (e.g. for tax, legal, accounting or other purposes), whichever is longer. Whenever your personal information is transferred, stored or processed by us, we will take reasonable steps to safeguard the security and privacy of your personal information. These steps may include implementing standard contractual clauses with third parties, encouraging you to review the privacy statement of other companies you direct us to share your information with, and if required by law, obtaining your consent or other lawful approval of transferring your information.
5. How Do We Keep Your Information Safe?
You use the Service at your own risk. We implement reasonable technical, administrative, and organizational measures designed to protect personal information both online and offline from loss, misuse, and unauthorized access, disclosure, alteration or destruction. However, no Internet or email transmission is ever fully secure or error free. In particular, email sent to or from us may not be secure. Therefore, you should take special care in deciding what information you send to us via the Service or e-mail. Please keep this in mind when disclosing any personal information to Unsettled via the Internet. In addition, we are not responsible for circumvention of any privacy settings or security measures contained on the Service, or third-party websites.
6. Do US Residents Have Rights Regarding Their Personal Information?
If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to know or request access to and receive details about the personal information we maintain about you and how we have processed it. You may have the right to correct inaccuracies, get a copy of, or delete your personal information. Unsettled will not discriminate against you for exercising your rights. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances, and we may decline your request as permitted by applicable law.
You may have the right to obtain a list of the categories of third parties to which we have disclosed personal information (as permitted by applicable law, including California’s and Delaware’s privacy laws). Those categories are listed within this Privacy Policy.
You may have the right to obtain a list of specific third parties to which we have disclosed personal information (as permitted by applicable law, including Oregon’s privacy law).
You may have the right to opt out of the collection of sensitive and/or personal information collected through the operation of a voice or facial recognition feature (as permitted by applicable law, including Florida’s privacy law).
You may have the right to limit use and disclosure of sensitive personal information (as permitted by applicable law, including California’s privacy law).
California Residents
You may have the right to opt-out of sharing of your personal information. You can opt-out using the following methods:
- Accessing your Cookie consent settings as described above
- By implementing the Global Privacy Control or similar control that is legally recognized by a government agency or industry standard and that complies with the CCPA. The signal issued by the control must be initiated by your browser and applies to the specific device and browser you use at the time you cast the signal. Please note this does not include Do Not Track signals.
You should know that we have not sold or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months. We have disclosed the categories of data as detailed in this Privacy Policy.
Virginia Residents
In addition to the rights described above, you also have the right opt-out from the processing your personal information for the purposes of profiling in furtherance of decisions that produce legal or similarly significant effects to you, which Unsettled does not do. You also have the right to opt out of targeted advertising and selling (as such terms are defined under the Virginia Consumer Data Protection Act (VCDPA)), however, as noted above, Unsettled does not participate in the selling of your personal information. Regardless, we must inform you that you have a right to appeal if we refuse to take action on a request within a reasonable period of time after receiving your request in accordance with this section. In such an appeal, you must (1) provide sufficient information to allow us to verify that you are the person about whom the original request pertains and to identify the original request, and (2) provide a description of the basis of your appeal. Please note that your appeal will be subject to your rights and obligations afforded to you under the VCDPA. We will respond to your appeal within 60 days of receiving your request. If we deny your appeal, you have the right to contact the Virginia Attorney General using the methods described at https://www.oag.state.va.us/consumer-protection/index.php/file-a-complaint. Virginia residents may submit requests to exercise rights and appeals via email at legal@unsettled.io.
7. How Can You Exercise Your Rights?
Under certain US laws, you can designate an authorized agent to make data requests on your behalf. In accordance with applicable law, we may deny a request from an authorized agent that does not submit adequate proof of your authorization for them to act on your behalf.
Upon receipt of your request, we will need to verify your identity to determine you are the same person about whom we have information in our systems. We will only use personal information provided in your request to verify your identity or authority to make a request. However, if we cannot verify your identity with the information provided and available to us, we may ask for additional information or deny the request for security and fraud-prevention.
8. Changes to This Privacy Policy
The Service, and our business may change from time to time. As a result, we may change this Privacy Policy at any time. When we do, we will post an updated version on this page noting the revision date, unless another type of notice is required by the applicable law. Your continued use of our Service including, by way of example but not limitation, providing us with personal information after we post an updated Privacy Policy, or notify you by other means if applicable, shall be regarded as your consent to revisions to our Privacy Policy and practices related to it.
9. Still Have Questions?
If you have any questions regarding this Privacy Policy, you may contact our Data Privacy Officer (“DPO”) by email at legal@unsettled.io.
10. California Residents: Privacy Policy Notice
This Privacy Policy Notice is intended for California residents pursuant to the California Consumer Privacy Act of 2018 and California Privacy Rights Act of 2020 (collectively “CCPA”), and supplements the information contained in the above Privacy Policy. Any terms defined in the CCPA and applicable California regulations have the same meaning as used in this Privacy Policy Notice. If you have a disability and want this Privacy Policy Notice provided in an alternative format, please call us at (866) 912-8086 or write us at D & A Services, 1400 E. Touhy Ave., Suite G2 Des Plaines, IL 60018. If you have questions about our Privacy Policy or practices, please call (866) 912-8086.
1. Information We Collect About You
We may collect and use personal information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be directly or indirectly linked, with a consumer, device, or household (“personal information”).
Personal information does not include:
- Publicly available information from government records.
- Deidentified or aggregated consumer information.
- Information excluded from the CCPA’s scope, such as (but not limited to) information governed by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), the California Confidentiality of Medical Information Act (“CMIA”), the Fair Credit Reporting Act (“FCRA”), the Gramm-Leach-Bliley Act (“GLBA”), California Financial Information Privacy Act (“FIPA”), and the Driver’s Privacy Protection Act of 1994 (“DPPA”).
We regularly collect (and have collected in the past 12 months) several types of personal information about individuals regarding accounts we service or purchase, including:
| Category | Examples |
|---|---|
| Identifiers | Name, postal address, Internet Protocol address, email address, account number, Social Security number, or other similar identifiers |
| Categories listed in the California Customer Records statute, Cal. Civ. Code § 1798.80(e) | Name, signature, Social Security number, address, telephone number, education, employment, bank account number, credit card number, debit card number, or other financial information, medical information, or insurance information |
| Protected classifications under California or federal law | Age, gender, medical condition, disability, veteran or military status |
| Commercial information | Records of products or services purchased, obtained |
| Internet or other similar network activity | Information on a consumer’s interaction with our website(s) or application(s) |
| Audio, electronic, visual or similar data | Call recordings |
| Professional or employment-related information | Current or past job history |
| Non-public education information (per Family Educational Rights and Privacy Act (20 U.S.C. § 1232g, 34 C.F.R. Part 99)) | Student financial information |
| Inferences drawn from personal information | To create a profile reflecting the consumer’s preferences, characteristics, aptitudes, or behavior |
| Sensitive personal information | A consumer’s social security number, driver’s license, state identification card, or passport number; a consumer’s account log-in in combination with any required security or access code, password, or credentials allowing access to the account |
2. How Your Personal Information is Collected
We collect most of this personal information from our creditor clients or from you or your authorized representative by telephone or written communications. However, we may also collect information:
- From publicly accessible sources (e.g., property or other government records);
- From our service providers (e.g., call analytics, information source, skip-tracing, collections, payment processing, mailing, and other vendors)
3. Why We Use or Disclose Your Personal Information
We regularly use or disclose personal information for one or more of the following business purposes:
- Fulfill the reason you provided the information. For example, if you share your personal information to make a payment, we will use that information to process your payment.
- Perform services on behalf of a business or service provider, including maintaining or servicing accounts, providing customer service, processing transactions, verifying customer information, processing payments, providing analytic services, or providing similar services on behalf of the business or service provider
- Provide you with information or services that you request from us
- Auditing related to consumer interactions
- Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity
- Debugging to identify and repair errors that impair existing intended functionality
- Short-term, transient use, where the personal information is not disclosed to another third party and is not used to build a profile about a consumer or otherwise alter an individual consumer’s experience outside the current interaction
- Undertaking activities to verify or maintain the quality of a service or device that is owned, made by or for, or controlled by us, and to improve, upgrade, or enhance the service or device that is owned, made by or for, or controlled by us
- Respond to law enforcement requests and as required by applicable law or court order
- As appropriate to protect the rights, property, or safety of us, our clients, or others
- As described to you when collecting your personal information or as otherwise set forth in the CCPA.
We will not collect additional categories of personal information or use the personal information we collected for materially different purposes without providing you notice.
We regularly disclose (and have disclosed in the past 12 months) the above listed categories of personal information for business purposes to one or more of the following categories of third parties: our creditor clients, our service providers (payment processing, mailing, collection, call analytics and other vendors), credit reporting agencies, regulatory and law enforcement agencies.
We do not sell or share your personal information under the CCPA.
We do not use or disclose sensitive personal information for purposes other than those necessary to perform services reasonably expected by an average consumer; to help ensure security and integrity where use of the information is reasonably necessary and proportionate for this purpose; for short-term, transient use; for performing services, including maintaining or servicing accounts, providing customer service, processing or fulfilling transactions, verifying customer information, processing payments, or providing similar services; for undertaking activities to verify or maintain the quality of our services, and to improve, upgrade, or enhance our services.
We retain each category of personal information or sensitive personal information no longer than is reasonably necessary for the purposes for which it was collected as stated in this privacy policy, unless extending the retention period is otherwise required or permitted by law. Subject to this limitation, the retention period of each category of personal information or sensitive personal information is determined by considering the following: the time required to retain the information to fulfill our business purposes; the time applicable to maintaining corresponding transaction and business records; the time necessary to respond to consumer queries, complaints or lawsuits; data retention requirements of applicable laws or contracts; and applicable data retention policies as may be in place from time to time.
4. Verifiable Consumer Requests for Information
Upon verification of identity, California residents may in some cases request that a business:
- Disclose the categories of personal information the business collected about the consumer;
- Disclose the categories of sources from which the personal information is collected
- Disclose the categories of personal information that the business sold about the consumer;
- Disclose the categories of personal information that the business disclosed about the consumer for a business purpose;
- Disclose the categories of third parties with whom the business shares personal information
- Disclose specific pieces of personal information the business has collected about the consumer
- Disclose any financial incentives offered by the business for collection, sale, or deletion of personal information
You have a right not to receive discriminatory treatment by a business for your exercise of CCPA privacy rights. A business may charge a different price or rate, or provide a different level or quality of goods or services to you, if that difference is reasonably related to the value provided to you by your personal information.
For applicable personal information access and portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
Please note that we are not required to:
- Carry out information access requests we receive from you if acting as a service provider or contractor to another entity regarding such information
- Retain any personal information about you that was collected for a single one-time transaction if, in the ordinary course of business, that information about you is not retained;
- Reidentify or otherwise link any data that, in the ordinary course of business, is not maintained in a manner that would be considered personal information;
- Provide the requested information disclosure to you more than twice in a 12-month period.
- Provide the requested information disclosure if we cannot verify that the person making the request is the person about whom we collected information, or is someone authorized to act on such person’s behalf; or
- Provide the requested information disclosure if a CCPA or applicable exception applies.
5. Right to Request Deletion of Personal Information
Upon verification of identity, California residents may in some cases request that a business delete personal information about you that the business collected from you and retained, subject to certain exceptions.
We may deny your deletion request if we are acting in the role of a service provider to another business regarding the applicable personal information. If we deny your request on that basis, we will generally refer you to the relevant business. In addition, we may deny your deletion request if retaining the information is necessary for us or our service providers to:
- Complete the transaction for which the personal information was collected, provide a good or service requested by you, or reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform a contract between you and us.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity.
- Debug to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act.
- Enable solely internal uses that are reasonably aligned with your expectations based on your relationship with us.
- Comply with a legal obligation; or
- If another CCPA or applicable exception applies.
6. Right to Request Correction of Inaccurate Personal Information
Upon verification of identity, California residents may in some cases request a business that maintains inaccurate personal information about you correct that inaccurate personal information. We will use commercially reasonable efforts to correct the inaccurate personal information.
California residents may make verifiable requests to disclose, delete, or correct pursuant to the CCPA or obtain more information by calling us at (866) 912-8086, visiting us at https://unsettled.io/#contact, mailing us at 1400 E. Touhy Ave., Suite G2 Des Plaines, IL 60018, or emailing us at legal@unsettled.io.
7. Verifying Your Identity If You Submit CCPA Requests
If you choose to contact us directly via the designated methods described above to exercise your CCPA rights, you will need to:
- Provide enough information to reasonably identify you (e.g., your full name, account number if applicable, and potentially other identifying information); and
- Describe your request with sufficient detail to allow us to properly process and respond to your request.
If seeking to make a verifiable request under the CCPA on behalf of someone else, we require enough information to reasonably identify the subject of the request (including name and other identifying information) and the subject’s written consent to make the CCPA request on his or her behalf, as consistent with applicable law.
We are not obligated to make an information disclosure or carry out a deletion request pursuant to the CCPA if we cannot verify that the person making the request is the person about whom we collected information, or is someone authorized to act on such person’s behalf.
Any personal information we collect from you in order to verify your identity in connection with your CCPA request will be used solely for the purposes of verification.
11. Colorado, Connecticut, Delaware, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah and Virginia Residents: Unsettled’s Privacy Policy Notice
This Privacy Policy Notice is intended for Colorado, Connecticut, Delaware, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah and Virginia residents pursuant to the Colorado Privacy Act, the Connecticut Data Privacy Act, the Delaware Personal Data Privacy Act, the Iowa Consumer Data Protection Act, the Maryland Online Data Privacy Act, the Minnesota Consumer Data Privacy Act, the Montana Consumer Data Privacy Act, the Nebraska Data Privacy Act, the New Hampshire Consumer Data Privacy Act, the New Jersey Data Privacy Act, the Oregon Consumer Privacy Act, the Tennessee Information Protection Act, the Texas Data Privacy and Security Act, the Utah Consumer Privacy Act and the Virginia Consumer Data Protection Act, respectively. This policy supplements the information contained in the above Privacy Policy. Any terms defined in these laws and related regulations have the same meaning as used in this Privacy Policy Notice.
1. Personal Data We Collect About You
We may process personal data that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be directly or indirectly linked, with a consumer, device, or household (“personal data”).
Personal data does not include:
- Publicly available information from government records.
- Deidentified or aggregated consumer information.
- Information excluded from the scope of the above privacy laws, such as (but not limited to) information governed by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), the Fair Credit Reporting Act (“FCRA”), and the Gramm-Leach-Bliley Act (“GLBA”).
We regularly process (and have processed in the past 12 months) several types of personal data about individuals regarding accounts we service or purchase, including:
| Category | Examples |
|---|---|
| Identifiers | Name, signature, postal address, Internet Protocol address, email address, telephone number, account number, Social Security number, or other similar identifiers |
| Financial information | Bank account number, credit card number, debit card number, or other financial information; medical insurance information |
| Protected classifications | Age, gender, medical condition, disability, veteran or military status |
| Commercial information | Records of products or services purchased, obtained |
| Internet or other similar network activity | Information on a consumer’s interaction with our website(s) or application(s) |
| Audio, electronic, visual or similar data | Call recordings |
| Professional, or employment-related information | Current or past job history |
| Non-public education information | Student financial information |
| Inferences drawn from personal information | To create a profile reflecting the consumer’s preferences, characteristics, aptitudes, or behavior |
| Personal information | A consumer’s social security number, driver’s license, state identification card, or passport number; a consumer’s account log-in in combination with any required security or access code, password, or credentials allowing access to the account |
2. Why We Process Your Personal Data
We regularly process personal data for one or more of the following business purposes:
- Fulfill the reason you provided the information. For example, if you share your personal data to make a payment, we will use that information to process your payment.
- Perform services on behalf of a business or service provider, including maintaining or servicing accounts, providing customer service, processing transactions, verifying customer information, processing payments, providing analytic services, or providing similar services on behalf of the business or service provider.
- Provide you with information or services that you request from us
- Auditing related to consumer interactions.
- Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity.
- Debugging to identify and repair errors that impair existing intended functionality.
- Short-term, transient use, where the personal information is not disclosed to another third party and is not used to build a profile about a consumer or otherwise alter an individual consumer’s experience outside the current interaction.
- Undertaking activities to verify or maintain the quality of a service or device that is owned, made by or for, or controlled by us, and to improve, upgrade, or enhance the service or device that is owned, made by or for, or controlled by us.
- Respond to law enforcement requests and as required by applicable law or court order.
- As appropriate to protect the rights, property, or safety of us, our clients, or others.
- As described to you when collecting your personal information or as otherwise permitted by law.
We will not collect additional categories of personal data or use the personal data we collected for materially different purposes without providing you notice.
3. Third Parties To Whom We Disclose Personal Data
We regularly disclose (and have disclosed in the past 12 months) the above listed categories of personal data for business purposes to one or more of the following categories of third parties: our creditor clients, our service providers (payment processing, mailing, collection, call analytics and other vendors), credit reporting agencies, regulatory and law enforcement agencies.
4. We Do Not Sell Personal Data Or Engage In Targeted Advertising Or Profiling
We do not sell your personal data, process your personal data for targeted advertising, or process your personal data for automated decision-making including profiling in furtherance of decisions that produce legal or similarly significant effect on you.
5. How To Request To Exercise Your Rights
Upon our verification of identity through commercially reasonable means, you may request to exercise one or more of the following rights:
- To confirm whether or not we are processing your personal data and to access such personal data;
- To delete personal data provided by or obtained about you;
- To obtain a copy of your personal data that you previously provided to us in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another company without hindrance, where the processing is carried out by automated means.
- To correct inaccuracies in your personal data (excluding Iowa and Utah residents because state law does not currently recognize this right).
Delaware, Maryland, Minnesota and Oregon residents may also obtain confirmation of the specific third parties to whom we have disclosed your personal data.
You may request to exercise these rights by one of the following methods:
- Via our website https://unsettled.io/#contact,
- Calling us at (866) 912-8086
- Emailing us at legal@unsettled.io
- Mailing us at 1400 E Touhy Ave., Ste G2, Des Plaines, IL 60018
You may appeal our decision concerning your request by contacting us using any of the above methods, within 45 days of your receipt of our decision on your request, to advise of your appeal.
6. Data Retention Policy
We retain each category of personal information or sensitive personal information no longer than is reasonably necessary for the purposes for which it was collected as stated in this privacy policy, unless extending the retention period is otherwise required or permitted by law. Subject to this limitation, the retention period of each category of personal information or sensitive personal information is determined by considering the following: the time required to retain the information to fulfill our business purposes; the time applicable to maintaining corresponding transaction and business records; the time necessary to respond to consumer queries, complaints or lawsuits; data retention requirements of applicable laws or contracts; and applicable data retention policies as may be in place from time to time.