1.1 Privacy Policy

SEC Regulation S-P

Privacy of Consumer Financial Information and Safeguarding Customer Information

Purpose

Doo Financial US, Inc. (“the Firm”) is committed to protecting the privacy, confidentiality, and security of customer information. The Firm has adopted this Privacy Policy to comply with SEC Regulation S-P and other applicable federal privacy requirements governing the collection, use, protection, and safeguarding of customer information.

The Firm maintains administrative, technical, and physical safeguards reasonably designed to:

Scope

This policy applies to all employees, officers, contractors, temporary personnel, and service providers who have access to customer information.

The requirements apply to individual customer accounts, including U.S. and foreign customers, and govern all nonpublic personal information (“NPPI”) maintained by the Firm.

Nonpublic Personal Information (NPPI)

NPPI includes personally identifiable financial information that is provided by a customer, obtained in connection with providing financial products or services, or otherwise maintained by the Firm, and which is not publicly available.

Public information does not include information that is lawfully obtained from:

Customer Privacy Notice

The Firm provides each customer with its Privacy Notice at the time an account is established.

Thereafter, the Firm provides updated Privacy Notices as required by applicable law. If the Firm qualifies for the annual privacy notice exception under Regulation S-P and its information-sharing practices have not changed, an annual notice is not required.

Customers are provided any required opportunity to opt out of information sharing with nonaffiliated third parties as required by law.

Employee Responsibilities

All employees have an affirmative obligation to safeguard customer information.

Employees may access customer information only as necessary to perform their assigned job responsibilities.

Employees are prohibited from:

Violations of this policy may result in disciplinary action up to and including termination.

Administrative, Technical and Physical Safeguards

The Firm maintains safeguards designed to protect customer information, including:

Administrative Controls

Technical Controls

Physical Controls

Electronic Information Security

Customer information maintained electronically shall be stored only on Firm-approved systems.

The Firm utilizes secure cloud-based service providers to store customer information. The Firm performs appropriate due diligence and oversight of these providers to ensure reasonable safeguards are maintained to protect customer information.

Employees shall not store customer information on unauthorized personal devices or cloud storage applications.

Incident Reporting and Response

Employees must immediately report any actual or suspected:

to the Chief Compliance Officer or designated Information Security Officer.

The Firm will promptly investigate reported incidents and take appropriate steps to:

Service Provider Oversight

The Firm exercises appropriate oversight over third-party vendors that receive, maintain, process, or otherwise have access to customer information.

Service providers are expected to maintain safeguards designed to protect customer information consistent with applicable legal and regulatory requirements.

Disposal of Customer Information

Customer information shall be disposed of in a manner that prevents unauthorized access.

Approved disposal methods include:

Record Retention

Privacy-related records, employee training records, incident documentation, vendor due diligence, and safeguarding documentation shall be maintained in accordance with SEC Rule 17a-4 and the Firm’s Record Retention Policy.

Questions

Questions regarding this policy or the handling of customer information should be directed immediately to the Chief Compliance Officer before any customer information is disclosed.

All personnel are expected to understand and comply with this policy as a condition of employment.