DRAFT — requires legal counsel review. This is not legal advice.

Privacy Policy

Draft prepared for engineering enablement, pending legal counsel review. This document is not legal advice.

Draft version v0 · Effective date: pending counsel review

Overview

This Privacy Policy describes how DEO Finance collects, uses, and protects personal information, and the rights available to you. It is a draft intended to address obligations under the regulations listed below and must be reviewed by qualified counsel before it takes effect.

Information We Collect

We collect account identifiers such as your email address and name, identity verification data processed by our verification partners for know-your-customer checks, wallet and transaction metadata, and device and usage information. Sensitive verification data is encrypted at rest.

How We Use Information

We use personal information to provide and secure the service, verify identity, comply with legal and regulatory obligations, prevent fraud and abuse, and improve the product. We do not sell your personal information.

Data Sharing

We share personal information with service providers that support identity verification, payment processing, blockchain infrastructure, and cloud hosting, each under contractual confidentiality and data protection terms. We may disclose information when required by law or to protect the rights and safety of users and the service.

Data Retention

We retain personal information for as long as needed to provide the service and to meet legal, tax, and regulatory obligations. Financial and transaction records may be retained for a longer statutory period, after which identifying data is anonymized where feasible.

Your Rights Under GDPR (European Union)

If you are located in the European Union, the General Data Protection Regulation applies. You have the right to access, rectify, erase, and port your personal data, to restrict or object to processing, and to withdraw consent where processing is based on consent. Processing relies on lawful bases including performance of a contract, compliance with a legal obligation, and legitimate interests. International transfers are protected by appropriate safeguards. You have the right to lodge a complaint with your local supervisory authority. The data controller identity and representative will be confirmed on counsel review.

Your Rights Under the CCPA (California, USA)

If you are a California resident, the California Consumer Privacy Act, as amended, applies. You have the right to know what personal information is collected and how it is used and shared, the right to delete personal information, the right to correct inaccurate information, and the right to opt out of the sale or sharing of personal information. We do not sell your personal information. You also have the right not to receive discriminatory treatment for exercising these rights. Requests can be submitted through a channel labeled Do Not Sell or Share My Personal Information, which will be published before this policy takes effect.

Your Rights Under Korea PIPA (Republic of Korea)

If you are located in the Republic of Korea, the Personal Information Protection Act applies. You have the right to be informed about processing, to access your personal information, to request correction or deletion, and to request suspension of processing. Personal information is processed on the basis of consent or another lawful ground, and consent for optional processing can be declined or withdrawn. A privacy officer will be designated, and any cross-border transfer of personal information will be disclosed. Contact details for the privacy officer will be confirmed on counsel review.

Exercising Your Rights

You can submit a request to exercise any of the rights above through your account settings or the contact channel published with the final policy. We may need to verify your identity before acting on a request. We will respond within the timeframe required by applicable law.

Contact

Questions about this Privacy Policy, and the identity of the data controller and privacy officer, will be published with the counsel-reviewed version before it takes effect.

This page is a draft for internal enablement only. The content requires legal counsel review and is not legal advice.