1. Information We Collect
Canter Financial LLC collects, retains, and uses information about our customers only when we reasonably believe it will help us administer our business or provide products, services, and other opportunities to you. We collect and retain information solely for specific business purposes, unless prohibited by law.
Non-public Personal Information (NPI) generally includes any information that is not publicly available that a consumer provides in order to obtain a product or service. Personal information we may collect includes, but is not limited to:
- Individual names
- Social Security Numbers
- Credit or debit card numbers
- State identification card numbers
- Driver's license numbers
- Asset information
- Credit and liability information
- Income information
Personal information does not include publicly available information that is lawfully made available from federal, state, or local government records.
2. How We Use Your Information
We use the information we collect to:
- Comply with applicable laws and regulations
- Administer and improve our products and services
- Understand your financial needs so we can provide quality mortgage products and superior service
- Provide Privacy Notices as required by federal and state law
Only authorized representatives of Canter Financial LLC may access or use your financial information. No employee or contractor is authorized to divulge customer financial information or records to any outside party except as described in this policy.
3. Restrictions on Disclosure
Canter Financial LLC will not share your confidential information with third parties except in the following limited circumstances:
- To affiliates of Canter Financial LLC that now exist or are hereafter established
- As necessary to effect, administer, or enforce a transaction you requested or authorized
- To service or process a financial product or service you requested or authorized
- To protect the confidentiality or security of your records
- To protect against or prevent actual or potential fraud, unauthorized transactions, claims, or other liability
- For required institutional risk control or to resolve consumer disputes or inquiries
- To persons holding a legal or beneficial interest relating to you, or acting in a fiduciary or representative capacity on your behalf
- To insurance rate advisory organizations, guarantee funds or agencies, or agencies rating our customers
- To law enforcement agencies and government regulators as permitted or required under the Right to Financial Privacy Act of 1978
- To a consumer reporting agency in accordance with the Fair Credit Reporting Act
- In connection with a proposed or actual sale, merger, transfer, or exchange of all or a portion of our business, solely as it concerns consumers of that business unit
- To comply with federal, state, or local laws, rules, and other applicable legal requirements
- To comply with a properly authorized civil, criminal, or regulatory investigation, subpoena, or summons by federal, state, or local authorities
- To respond to judicial processes or government regulatory authorities having jurisdiction over us for examination, compliance, or other legally authorized purposes
4. Access & Security
Canter Financial LLC maintains appropriate security standards and procedures to prevent unauthorized access to customer information. Employee and contractor access to personally identifiable information is limited strictly to those with a legitimate business reason for knowing such information.
When we share personally identifiable customer information with a third party, we do so only as necessary to provide products and services to you — and only with third parties who adhere to comparable privacy principles that provide for keeping such information confidential.
Every transaction between Canter Financial LLC and our customers is strictly confidential. Company records, communications, and proprietary information are treated with the same care.
5. Your Right to Opt Out
You have the right to opt out of certain types of information-sharing of your data by Canter Financial LLC or by non-affiliated third parties.
We will not disclose your non-public personal information to a non-affiliated third party outside of the permitted exceptions unless we have first provided you with a Privacy Notice and a reasonable opportunity to opt out, and you have not done so. Text messaging originator opt-in data and consent will not be shared with any third parties, excluding aggregators and providers of the Text Message services.
To exercise your opt-out rights, please contact our Compliance Director using the information provided in Section 9 below.
6. Gramm-Leach-Bliley Act Compliance
As a mortgage broker, Canter Financial LLC is subject to the privacy and safeguards requirements of the Gramm-Leach-Bliley Act (GLBA). We are committed to full compliance with these federal requirements, including those administered by the Consumer Financial Protection Bureau (CFPB).
Privacy Notices
Under the GLBA, we are required to provide customers with initial notices regarding our privacy practices no later than when your customer relationship with us is established — that is, as soon as you provide personally identifiable financial information to obtain a mortgage. As a mortgage broker, initial disclosures are coordinated with the wholesale lender; however, we remain ultimately responsible for ensuring that you receive a Privacy Disclosure detailing what non-public information we share and with whom.
All customers and consumers are entitled to the same protection from disclosure of non-public personal information.
Safeguards Rule
In compliance with the GLBA Safeguards Rule (16 CFR Part 314), Canter Financial LLC maintains a written Information Security Plan. As part of this plan, we have:
- Designated a qualified employee to coordinate our information security program
- Identified and assessed risks to customer information across all relevant areas of our operations
- Designed and implemented a safeguards program that is regularly monitored and tested
- Selected service providers that maintain appropriate safeguards for customer information
7. Data Security Safeguards
Your personal information is protected by layered technical and operational security controls, including:
Network & System Security
- Internet firewalls and individual access credentials protect all systems storing consumer information
- Employees must log in and out of systems individually; sharing credentials is prohibited
- Workstations automatically log off after ten minutes of inactivity
- External system access is limited to authorized IT and senior management personnel
- Passwords are reset at minimum quarterly and must meet complexity requirements
- All information transmitted over the Internet is encrypted using SSL encryption
Mobile Device Security
- All laptops and mobile devices used to access confidential data require user authentication and time out after ten minutes of inactivity
- Approved data encryption must be enabled on all laptops transmitting or storing confidential information
- Laptops are protected with current antivirus software
- Use of unprotected mobile devices to access or store confidential data is prohibited
Virus Detection & Intrusion Prevention
- Virus detection software performs at least weekly full system scans
- All incoming and outgoing email is scanned for viruses
- Software and hardware firewalls are in place to prevent unauthorized network intrusion
Service Provider Oversight
Each third-party service provider that receives or collects consumer non-public information on our behalf must demonstrate the ability to maintain safeguards equivalent to those we apply internally. Our Compliance Director annually reviews all third-party service providers not regulated by a state or federal entity.
Employee Training
All employees receive security awareness training at onboarding and at minimum annually thereafter. Every employee is required to execute a Confidentiality Pledge committing to keep consumer information secure and confidential.
8. Information Disposal
All paper records containing consumer non-public information are disposed of by shredding or equivalent destruction methods designed to render the records unreadable and unrecoverable. Electronic records are handled in accordance with our Information Security Plan.
9. Contact Us
If you have questions about this Privacy Policy, wish to exercise your opt-out rights, or have a concern regarding the handling of your personal information, please contact our Compliance Director:
Privacy & Compliance Inquiries
Grace Maxwell
Canter Financial LLC
[Insert email address]
[Insert phone number]
All complaints are investigated promptly. Written complaints receive a written response. We aim to resolve all complaints within 60 calendar days of receipt.