DRAGONFLY PRIVACY POLICY

Last Updated: April 3, 2024

TABLE OF CONTENTS
  1. INTRODUCTION
  2. POLICY CONTENT
    1. Collection of Information
    2. Information You Provide to Us
    3. Information We Collect Automatically
    4. Information We Collect from Other Sources
    5. Information We Derive
    6. Use of Information
    7. Disclosure of Information
    8. Analytics
    9. Transfer of Information to The United States and Other Countries
    10. Your Privacy Rights and Choices
    11. Location Information
    12. Cookies
    13. Mobile Push Notifications
    14. SMS Text Notifications
    15. Sensitive Personal Information
    16. Additional Disclosure for Individuals in California
    17. Additional Disclosure
    18. Your Privacy Your Rights
    19. Additional Disclosures for Individuals in Europe
    20. Legal Basis for Processing
    21. Questions or Complaints
    22. Contact Us
  3. POLICY COMPLIANCE
  4. REVIEW OF POLICIES AND PROCEDURES
1.INTRODUCTION

The privacy of your personal information is important to us. This Privacy Policy describes how Dragonfly Financial Technologies Corp. (“Dragonfly", “DFT", “we" or “we") collects, uses, and discloses information about you. This Privacy Policy applies to information we collect when you access or use our website located at dragonflyft.com or the Dragonfly digital banking platform (together with any materials and services available therein, related mobile applications, and successor platform(s) thereto, the “DRAGONFLY PLATFORM") (collectively with the website, the “SERVICES"). We may provide different or additional notices of our privacy practices with respect to certain products or services, in which case those notices will supplement or replace this Privacy Policy.

2. POLICY CONTENT
2.1 Collection of Information

The information we collect and use from you varies depending on the way you use our Services. Below, we describe the different ways we might collect information from you when you access or use our website as a website visitor (“Website Visitor”), or when you directly access or use the Dragonfly Platform as a customer (“Customer”).

2.2 Information You Provide to Us

We collect information you provide directly to us. If you are a Website Visitor, we collect information directly from you when you fill out a form or otherwise communicate with us. The types of information about you that we collect include your name, your company’s name, your company email address, and any other information you choose to provide. If you are a customer, we collect information from you when you create an account or request customer support, such as your name, your company’s name, your address, phone number, account username, account password, Taxpayer Identification Number, and other information that is required to create an account on the Dragonfly Platform.

We may also indirectly collect information from you if you have a direct relationship with a customer that uses the Dragonfly Platform. Dragonfly does not directly collect or control such information and the Customers determine what information they collect. To the extent Dragonfly receives such information, we do so on behalf of our customers.

2.3 Information We Collect Automatically

We automatically collect certain information about your interactions with us or our Services, including:

2.4 Information We Collect from Other Sources

We obtain information from other sources, such as conference organizers, or identity verification services. The information we collect include your name and email address.

2.5 Information We Derives

We may derive information or draw inferences about you based on the information we collect. For example, we may make inferences about your approximate location based on your internet protocol (IP) address.

2.6 Use of Information

We use the information we collect to administer the Services. We also use the information we collect to:

2.7 Disclosure of Information

We disclose personal information in the following circumstances or as otherwise described in this policy:

We also disclose aggregated or de-identified information that cannot reasonably be used to identify you. Dragonfly processes, maintains, and uses this information only in a de-identified fashion and will not attempt to re-identify such information, except as permitted by law.

2.8 Analytics

We may engage others to provide analytics services across the web and in mobile apps. These entities may use cookies, web beacons, SDKs, device identifiers, and other technologies to collect information about your use of our Services and other websites and applications, including your IP address, web browser, mobile network information, pages viewed, time spent on pages or in mobile apps, links clicked, and conversion information. This information may be used by Dragonfly and others to, among other things, analyze and track data and better understand your online activity.

2.9 Transfer of Information to The United States and Other Countries

Dragonfly is headquartered in the United States, and we have operations and vendors in the United States and other countries. Therefore, we and those that perform work for us may transfer your personal information to, or store or access it in, jurisdictions that may not provide levels of data protection that are equivalent to those of your home jurisdiction. Where required by law, we provide adequate protection for the transfer of personal data in accordance with applicable law.

2.10 Your Privacy Rights and Choices

Depending on where you reside, you may have the right to (1) request to know more about and access the categories and specific pieces of personal information we collect, use, and disclose, (2) request deletion of your personal information, (3) request correction of inaccurate personal information, and (4) opt out of certain processing activities, such as selling, sharing, targeted advertising, processing of certain sensitive personal information, or profiling. We will verify your request by asking you to provide information related to your recent interactions with us, such as your name and email address. We will not discriminate against you for exercising your privacy rights.

To request access, correction, or deletion of your personal information or exercise any other rights described above, please contact us at privacy@dragonflyft.com. If you are a customer, you can also access, correct, or delete certain information stored within your account at any time by logging into your account.

2.11 Location Information

If you are a customer using any of our mobile apps that collect precise location information, you will be asked to consent to the app's collection of this information the first time you launch the app. If you initially consent to our collection of such location information, you can subsequently stop the collection of this information at any time by changing the preferences on your mobile device. You may also stop our collection of this location information by following the standard uninstall process to remove all our mobile apps from your device.

2.12 Cookies

Most web browsers are set to accept cookies by default. If you prefer, you can usually adjust your browser settings to remove or reject browser cookies. Please note that removing or rejecting cookies could affect the availability and functionality of our Services.

2.13 Mobile Push Notifications

If you are a customer, we may send push notifications to your mobile device when we have your permission. You can deactivate these messages at any time by changing the notification settings on your mobile device.

2.14 SMS Text Notifications

By providing your mobile phone number, you agree to receive recurring automated text messages from “Dragonfly Financial Technologies” to the mobile telephone number that you provided. You may change your preferences regarding these notifications, including which notifications to receive or disabling such notifications, by logging in to your account through the Dragonfly Financial Technologies website or Mobile Application. Message frequency varies. Message & Data rates may apply. Reply HELP for help, STOP to cancel.

2.15 Data Retention

If you are a customer, we store personal data associated with your account for as long as your account remains active. We store other personal data for as long as necessary to carry out the purposes for which we originally collected it and for other legitimate business purposes, including to meet our legal, regulatory, or other compliance obligations. We will not retain your personal data for longer than is reasonably necessary to carry out the purposes we disclose in this Privacy Policy.

2.16 Sensitive Personal Information

We obtain consent to collect information that is considered “sensitive personal information” where consent is required. If we notify you that we collect sensitive personal information, that means that we collect sensitive personal information within the meaning of the law of that state. We may collect the following types of sensitive personal information: precise geolocation, account login credentials, we only process this information to provide our services to you, or as required by applicable laws or regulations.

2.17 Additional Disclosure for Individuals in California

Certain states afford consumers with certain rights with respect to their personal information. For example, if you are a California resident, this section applies to you.

2.18 Additional Disclosure

In the preceding 12 months, we have collected the following categories of personal information from Customers or Website Visitors: identifiers; categories of information that are protected classifications under California law; internet or other electronic network activity information; geolocation data; inferences drawn from other personal information (e.g., approximate location inferred from IP address) and professional or employment-related information. For details about the precise data points, we collect and the categories of sources of such collection, please see the Collection of Information section above. We collect personal information for the business and commercial purposes described in the Use of Information section above. In the preceding 12 months, we have disclosed the following categories of personal information for business purposes to the following categories of recipients:

Category of Personal Information
Categories of Recipients
Identifiers
Vendors, service providers, contractors, and consultants, including consumer identification verification service providers, fraud prevention service providers, professional advisors, customer relationship management providers, data analytics providers, and other vendors who perform services on our behalf.
Internet or other electronic network activity information
Data analytics providers, internet service providers, operating systems and platforms, and customer management providers.

We do not sell or share your personal information, nor do we knowingly sell or share personal information about consumers under the age of 16.

2.19 Your Privacy Your Rights

Please see the “Your Privacy Rights and Choices” section above for more information about your privacy rights and how to exercise them.

If we receive your request from an authorized agent who does not provide a valid power of attorney, we may ask the authorized agent to provide proof that you gave the agent signed permission to submit the request to exercise rights on your behalf. In the absence of a valid power of attorney, we may also require you to verify your own identity directly with us or confirm to us that you otherwise provided the authorized agent permission to submit the request. If you are an authorized agent seeking to make a request, please email privacy@dragonflyft.com.

2.20 Additional Disclosures for Individuals in Europe

If you are located in the European Economic Area (“EEA”), the United Kingdom, or Switzerland, you have certain rights and protections under the law regarding the processing of your personal data, including the rights outlined in the ““Your Privacy Rights and Choices” section above, and this section applies to you.

When we process your personal data, we will do so in reliance on the following lawful bases:

If you have a concern about our processing of personal data that we are not able to resolve, you have the right to lodge a complaint with the Data Protection Authority where you reside. Contact details for your Data Protection Authority can be found using the links below:

For individuals in the EEA: https://edpb.europa.eu/about-edpb/board/members_en

For individuals in the UK: https://ico.org.uk/global/contact-us/

For individuals in Switzerland: https://www.edoeb.admin.ch/edoeb/en/home/the-fdpic/contact.html

2.23 Contact Us

If you have any questions about this Privacy Policy, please contact us at privacy@dragonflyft.com.

3. POLICY COMPLIANCE

All Employees are expected to comply with all the provisions of this Code, and the Company recognizes the need for this Code to be applied equally to everyone it covers. The Code will be strictly enforced throughout the Company and violations will be dealt with immediately. Violations of the Code that involve illegal behavior will be reported to the appropriate authorities. Failure to adhere to this Code may result in disciplinary action, varying from reprimand to dismissal. Retaliation against any employee for good faith reporting of violations of this Code is strictly prohibited. Any such retaliation will be treated as a serious violation of this Code.

4. REVIEW OF POLICIES AND PROCEDURES

We may change this Policy from time to time. If we make changes, we will notify you by revising the date at the top of this policy. If we make material changes, we may provide you with additional notice (such as by adding a statement to the Services or sending you a notification). We encourage you to review this Policy regularly to stay informed about our information practices and the choices available to you.

Get your digital business banking questions answered

Complete the form, and a member of our team will reach out with more information.

Learn More