Identity of the controller
Sorla is a working product name, not a confirmed legal-entity identity. The final notice must name each data controller, give verified contact details and explain where responsibilities change.
Legal
What the current journey does with data, separated from legal-entity, retention and rights details that still require owner approval.
Draft notice. It deliberately does not invent a legal entity, privacy inbox, retention schedule or response commitment. Those items must be approved and supplied before launch.
Sorla is a working product name, not a confirmed legal-entity identity. The final notice must name each data controller, give verified contact details and explain where responsibilities change.
The implemented journey uses the email submitted for one-time-code sign-in, the read-only transaction history from accounts you choose to connect, connection metadata, acknowledgements and the case summary you choose to submit. Bank credentials stay with your bank.
The service uses that data to maintain a signed-in session, confirm bank access, check the available overdraft evidence, produce a server result and create a case receipt only after submission.
The current case submission sends the selected case and a redress summary for review. The journey states that raw bank transaction data is not included in that submission. Open Banking access is separately approved with the provider and your bank.
The final notice must set out applicable data-protection rights, lawful bases, retention periods, processors, international transfers, complaint routes and a verified method for making a request. Those details are not inferred here.
A careful, read-only check of your lending history. Nothing upfront, and an honest answer either way.