Privacy Notice
Last Updated: September 2, 2026
Effective Date: September 2, 2026
This Privacy Notice describes how DRUO, Inc. and its applicable affiliates (“DRUO,” “we,” “us,” or “our”) collect, use, disclose, transfer, store, retain, and otherwise process Personal Information when you use or interact with DRUO.
This Privacy Notice applies to people who use our Services or otherwise interact with us, including:
- Merchants: individuals or organizations that use DRUO to receive payments, request payments, connect financial accounts, receive funds, manage transactions, integrate DRUO Services, or use other DRUO products and services to receive or manage payments. This includes individuals acting on behalf of a Merchant, such as owners, representatives, administrators, employees, contractors, developers, or authorized users.
- Buyers: individuals or organizations that use DRUO to make payments to Merchants, connect or register financial accounts, authorize payments, manage payment methods or authorizations, or make one-time, recurring, scheduled, or other payments. This includes individuals acting on behalf of a Buyer that is an organization, such as owners, representatives, administrators, employees, or authorized users.
- Visitors: individuals who visit our websites, request information about DRUO, interact with our content, participate in events or promotions, or communicate with us without necessarily registering or using a payment Service.
In this Privacy Notice, we collectively refer to Merchants, Buyers, Visitors, and other people who use or interact with DRUO as “Users.”
The same individual or organization may act as a Merchant in one transaction and as a Buyer in another. References to Merchants and Buyers describe the role a User plays in a particular interaction with DRUO and do not necessarily represent permanent or mutually exclusive categories.
Our websites, applications, APIs, components, payment experiences, financial-account connection services, profiles, dashboards, and other products and services are collectively referred to as the “Services.”
Depending on how you interact with DRUO, some provisions of this Privacy Notice may not apply to you. For example, certain business information may be collected about organizations and their representatives, while certain authentication, financial-account, or payment information may be collected about the person who actually uses or authorizes a Service.
The DRUO entity responsible for processing your Personal Information may depend on where you reside, the Services you use, and the DRUO entity providing those Services. Unless otherwise stated in your applicable agreement, within the Services, or in a local notice, DRUO, Inc., a Delaware corporation, is responsible for this Privacy Notice.
For purposes of this Privacy Notice, “Personal Information” means information relating to an identified or identifiable individual. Depending on applicable law, equivalent terms such as “personal data” may be used.
When a Merchant or Buyer is an organization, certain information relating solely to that organization may not constitute Personal Information. However, this Notice applies to Personal Information relating to individuals associated with that organization, including owners, beneficial owners, representatives, administrators, employees, contractors, and authorized users.
1. Personal information we collect
The Personal Information we collect depends on how you interact with DRUO, the Services you use, whether you act as a Merchant, Buyer, Visitor, or in more than one role, your jurisdiction, and applicable legal, regulatory, and operational requirements.
We generally collect Personal Information:
- directly from you;
- when you use or interact with our Services;
- from Merchants, Buyers, or other Users with whom you interact;
- from financial institutions and payment-system participants;
- from our providers and partners; and
- from public sources or other sources permitted by law.
1.1 Identity and contact information
We may collect:
- first and last name;
- organization name;
- trade name;
- email address;
- phone number;
- postal, business, or residential address;
- date of birth;
- nationality or country of residence;
- signature;
- username, handle, alias, or other identifier;
- job title, role, or relationship with an organization;
- information about owners, beneficial owners, representatives, administrators, employees, contractors, or authorized users.
When you act on behalf of an organization, we may associate your Personal Information with that organization’s profile.
1.2 Identity and verification information
When necessary to verify your identity or an organization’s identity, determine eligibility, prevent fraud, comply with law, or satisfy requirements of our financial partners, we may collect:
- passport information;
- national identity documents;
- driver’s license information;
- tax identification numbers or government identifiers;
- Social Security numbers or equivalent identifiers;
- organization formation or registration documents;
- proof of address;
- ownership and beneficial ownership information;
- photographs or copies of identity documents;
- photos, selfies, or facial images;
- identity-verification, liveness, or other biometric-verification results where applicable and permitted by law.
We may use specialized providers to perform identity, business, document, fraud, or compliance verification.
1.3 Information about organizations
When a Merchant or Buyer is a business or other organization, we may collect:
- legal name;
- trade names;
- addresses;
- websites and applications;
- industry or business activity;
- products and services;
- legal structure;
- jurisdiction and date of formation;
- registration information;
- licenses;
- ownership structure;
- beneficial owners;
- directors or administrators;
- authorized representatives;
- tax information;
- geographic markets;
- customers or counterparties;
- current or expected transaction volumes and patterns;
- financial, operational, compliance, and risk information.
We may obtain this information directly from the organization, its representatives, public records, or authorized third parties.
1.4 Financial and financial-account information
When you connect, register, or use a financial account with DRUO, we may collect or receive, depending on the Service, country, financial institution, and applicable permissions:
- financial institution name;
- account holder name;
- account number or identifier;
- masked or partial account numbers;
- bank routing, branch, institution, or similar codes;
- account type;
- currency;
- account status;
- information needed to verify ownership or control of the account;
- verification results;
- balances, where you have authorized access and the Service supports it;
- account transaction information, where you have authorized access and the Service supports it;
- tokens or identifiers used to establish or maintain a connection;
- connection date and status;
- information regarding authorizations and consents related to the account.
The information available to DRUO may vary significantly depending on the country, financial institution, payment network, provider, and permissions granted.
DRUO may receive this information directly from you, from a financial institution, from an open-banking or account-connection provider, from a payment network, or from another authorized participant.
1.5 Payment and transaction information
When you use DRUO to make, receive, request, authorize, schedule, manage, or review a payment, we may collect information such as:
- Merchant;
- Buyer;
- payer;
- beneficiary;
- amount;
- currency;
- date and time;
- description;
- payment reference;
- order or invoice number;
- transaction status;
- financial account used;
- financial institution;
- payment method or network;
- authorization information;
- mandate or consent information;
- payment frequency;
- recurring or scheduled-payment information;
- settlement information;
- payout information;
- refunds;
- reversals;
- returns;
- failed payments;
- disputes;
- retries;
- information relating to goods, services, invoices, or obligations associated with a payment where provided to DRUO.
We may also generate identifiers and records necessary to process, reconcile, investigate, and maintain the history of a transaction.
1.6 Authorization and consent information
When you, as a Buyer, authorize a Merchant or DRUO to initiate or process a payment, we may retain information documenting that authorization, including:
- your identity;
- authorized Merchant;
- related financial account;
- date and time;
- scope of authorization;
- amount or method for determining the amount;
- frequency;
- duration;
- status;
- terms presented;
- evidence of acceptance;
- IP address;
- device information;
- authentication method;
- mandate information;
- subsequent revocations or modifications.
The specific information retained will depend on the type of payment, jurisdiction, and payment system used.
1.7 Communications and support information
When you communicate with DRUO, we may collect:
- emails;
- messages;
- chat conversations;
- support tickets;
- call records;
- information submitted through forms;
- requests;
- complaints;
- feedback;
- survey responses;
- communications relating to payments, returns, or disputes;
- information provided to virtual assistants, chatbots, or other automated tools.
Calls or other communications may be monitored or recorded where permitted by applicable law.
1.8 Contact and recipient information
When you use DRUO to send a payment request, link, invoice, notification, invitation, or other communication, you may provide us with information about another person, including:
- name;
- email address;
- phone number;
- organization;
- customer reference;
- payment identifier;
- other information necessary to complete the interaction.
If you allow a DRUO application to access contacts stored on your device, we will request the appropriate permissions where required by law or platform rules.
1.9 Technical and device information
When you use our Services, we may automatically collect:
- device type;
- model;
- operating system;
- browser and version;
- device identifiers;
- application identifiers;
- IP address;
- network information;
- mobile carrier;
- language;
- time zone;
- application version;
- connectivity information;
- error logs;
- diagnostic information;
- relevant device settings.
1.10 Information about your use of our Services
We may collect information about how you interact with DRUO, including:
- pages visited;
- features used;
- links or buttons selected;
- searches;
- date and time of activity;
- session duration;
- login and logout activity;
- referring pages or sites;
- interactions with communications;
- API calls;
- application events;
- technical logs;
- authentication events;
- interactions with DRUO components or payment experiences.
1.11 Location information
We may infer your approximate location from information such as your IP address.
For certain Services, and subject to applicable law, permissions granted, and your device settings, we may collect more precise location information where necessary to:
- provide in-person functionality;
- identify where a transaction occurs;
- prevent fraud;
- maintain security;
- comply with legal requirements;
- comply with financial-institution or payment-network requirements;
- provide location-dependent functionality.
1.12 Authentication and security information
We may collect:
- login attempts;
- authentication methods;
- verification codes;
- multifactor authentication events;
- device authentication;
- technical information relating to passkeys or WebAuthn;
- session identifiers;
- security tokens;
- recovery information;
- authentication challenges and responses;
- device approvals;
- authentication-related risk signals.
1.13 Information we receive from other sources
We may receive Personal Information from:
- Merchants and Buyers;
- financial institutions;
- banks;
- payment networks;
- clearing and settlement systems;
- ACH operators and equivalent systems;
- real-time payment systems;
- open-banking providers;
- processors;
- account-verification providers;
- identity providers;
- fraud-prevention providers;
- KYC, KYB, and AML providers;
- sanctions and watchlists;
- politically exposed person data sources;
- credit or risk-information providers, where permitted by law;
- business registries;
- government databases;
- public sources;
- partners and integrations;
- other authorized information providers.
The information received may include identity, financial, business, transaction, compliance, fraud, risk, account, payment, or authentication information.
2. DRUO profiles
DRUO Services may allow you to create or maintain a DRUO profile.
A profile may correspond to an individual or an organization and may contain information necessary to identify you, authenticate you, allow you to use the Services, and maintain your relationships with other Users, Merchants, Buyers, and financial accounts.
A DRUO profile may exist independently of a specific transaction or the relationship between a Buyer and a particular Merchant.
For example, as a Buyer you may create a DRUO profile, connect a financial account, and later use DRUO to make payments to different Merchants. Similarly, an organization may use the same profile to make payments as a Buyer and receive payments as a Merchant where the Services allow it.
We may use information associated with a profile to:
- recognize you;
- authenticate you;
- maintain your preferences;
- display your history;
- facilitate future transactions;
- manage connected financial accounts;
- maintain authorizations;
- provide support;
- prevent fraud;
- maintain security;
- comply with legal and regulatory obligations.
When different Merchants use DRUO, this does not necessarily mean that each Merchant receives all information contained in a Buyer’s DRUO profile. We share with each participant only the information appropriate to the interaction, the Service, your instructions, and our legal obligations.
3. Connected financial accounts
The Services may allow you to connect a bank account or other financial account to DRUO.
Depending on the Service, a connection may be used to:
- make payments;
- receive funds;
- verify an account;
- verify ownership;
- authorize future payments;
- make recurring or scheduled payments;
- receive settlements or payouts;
- provide functionality related to financial information.
A connected financial account may remain available in your profile for future interactions with DRUO where you have authorized this and the Service supports it.
Connecting a financial account does not necessarily mean that a Merchant has direct access to your banking credentials, full account number, balance, transaction history, or other financial information. The information we share with a Merchant depends on the Service and what is necessary to complete or manage the relevant interaction.
You may have the ability to disconnect a financial account. However, disconnecting an account does not necessarily delete historical payment, authorization, verification, or other records that DRUO must retain for legal, regulatory, security, fraud-prevention, audit, or dispute-resolution purposes.
4. How and why we use personal information
We use Personal Information to operate DRUO, provide our Services, meet our obligations, protect our network, and develop our business.
4.1 Providing the Services
We may use Personal Information to:
- create and administer profiles;
- register and manage Merchants and Buyers;
- connect and verify financial accounts;
- initiate, process, and receive payments;
- transmit payment instructions;
- process one-time, recurring, and scheduled payments;
- maintain payment methods and connected accounts;
- create and maintain authorizations and mandates;
- provide checkout experiences;
- generate and process links and QR codes;
- operate APIs, components, applications, and dashboards;
- process refunds, reversals, returns, and retries;
- process settlements and payouts;
- provide transaction information;
- reconcile payments;
- calculate and collect fees;
- authenticate Users and transactions;
- provide support;
- send Service-related communications.
4.2 Identity verification and compliance
We may use Personal Information to:
- verify individuals;
- verify organizations;
- identify owners and beneficial owners;
- perform KYC and KYB processes;
- perform AML controls;
- screen sanctions and watchlists;
- identify politically exposed persons;
- monitor transactions;
- identify suspicious activity;
- comply with financial-institution and payment-network requirements;
- comply with tax and recordkeeping obligations;
- respond to authorities;
- determine Service availability or eligibility.
4.3 Fraud prevention, security, and risk management
We may use Personal Information to:
- prevent and detect fraud;
- detect profile takeover;
- verify financial accounts;
- assess transaction risk;
- assess User risk;
- identify unusual activity;
- apply limits;
- detect prohibited uses;
- investigate incidents;
- protect financial accounts;
- protect Merchants and Buyers;
- protect financial institutions and other participants;
- maintain the integrity and security of DRUO.
4.4 Communications
We may use Personal Information to send you:
- payment confirmations;
- payment requests;
- transaction notifications;
- authentication codes;
- security alerts;
- communications about financial accounts;
- authorization notices;
- communications about failed payments, returns, or disputes;
- administrative communications;
- support responses;
- legal or regulatory notices.
4.5 Developing and improving our Services
We may use information to:
- analyze use of DRUO;
- measure performance;
- detect errors;
- improve reliability;
- develop features;
- improve the User experience;
- conduct testing;
- conduct research;
- improve authentication systems;
- improve fraud-prevention and risk-management systems;
- understand aggregated usage patterns.
Where appropriate, we may aggregate, anonymize, or deidentify information for analytics, research, statistics, benchmarking, and product development.
4.6 Personalization
We may use information to personalize:
- payment experiences;
- interfaces;
- features;
- onboarding;
- recommendations;
- communications;
- support.
4.7 Marketing
Subject to applicable law, we may use information to:
- communicate products and features;
- send offers;
- provide information about DRUO;
- invite you to events;
- conduct surveys;
- measure campaigns.
Where law requires consent, we will conduct these activities in accordance with that requirement.
4.8 Legal and corporate purposes
We may use Personal Information to:
- enforce our contracts;
- collect amounts owed;
- manage disputes;
- establish, exercise, or defend legal rights;
- respond to legal process;
- conduct audits;
- manage insurance;
- conduct corporate-governance activities;
- obtain financing;
- conduct investments, mergers, acquisitions, reorganizations, asset sales, or other corporate transactions.
5. Automated decision-making, fraud prevention, and risk management
DRUO operates a payment network in which certain decisions must be made quickly to protect Users, financial accounts, financial institutions, and other participants.
We may use rules, algorithms, models, and other automated systems to support:
- identity verification;
- organization verification;
- account verification;
- fraud prevention;
- transaction monitoring;
- sanctions controls;
- risk assessment;
- suspicious-activity detection;
- authentication;
- payment authorization;
- retries;
- security;
- application of limits;
- eligibility for certain Services.
These systems may consider signals such as:
- identity;
- transaction history;
- amount;
- frequency or velocity of activity;
- device information;
- IP address;
- location;
- financial-account information;
- profile age;
- historical patterns;
- verification results;
- links among Users, accounts, or devices;
- fraud, compliance, or risk indicators.
As a result, a transaction or Service may be approved, declined, delayed, limited, subject to additional authentication, or sent for review.
Where applicable law gives you rights relating to solely automated decisions that produce legal or similarly significant effects, you may exercise those rights as described in this Notice.
6. When and with whom we share personal information
We may share Personal Information where necessary to provide the Services, complete an interaction, meet our obligations, protect DRUO and its Users, or as described below.
6.1 Between Merchants and Buyers
To facilitate a payment or other interaction, we may provide certain information between the Merchant and Buyer.
A Merchant may receive, as applicable:
- Buyer name or identifier;
- contact information;
- customer reference;
- amount;
- payment status;
- date;
- description;
- information necessary to reconcile the payment;
- information about an authorization, return, dispute, or refund.
A Buyer may receive:
- Merchant identity and trade name;
- payment information;
- description;
- amount;
- status;
- authorization information;
- relevant contact or support information.
We do not automatically share all information contained in your DRUO profile with the counterparty to a transaction.
6.2 Financial institutions and payment-system participants
We may share information with:
- banks;
- credit unions;
- financial institutions;
- sponsor banks;
- originating or receiving institutions;
- processors;
- payment networks;
- clearing systems;
- ACH operators;
- real-time payment systems;
- open-banking providers;
- account-verification providers;
- settlement institutions;
- other participants necessary to process a transaction.
The information shared will depend on the Service, payment system, jurisdiction, and transaction.
6.3 Identity, compliance, fraud, and risk providers
We may share information with providers that assist us with:
- identity verification;
- organization verification;
- KYC and KYB;
- AML controls;
- sanctions screening;
- fraud prevention;
- account verification;
- transaction monitoring;
- risk assessment;
- security.
6.4 Technology and service providers
We may share information with providers of:
- infrastructure and hosting;
- storage;
- cybersecurity;
- databases;
- communications;
- email;
- SMS and messaging;
- support;
- analytics;
- monitoring;
- document processing;
- identity services;
- software development;
- artificial intelligence;
- professional services;
- other business operations.
We require our providers to process information in accordance with applicable contractual and legal obligations.
6.5 Partners and integrations
When you use DRUO through an integration, platform, software provider, gateway, financial institution, marketplace, or other partner, we may share information with that third party where necessary to:
- provide the integration;
- authenticate you;
- create or link a profile;
- complete transactions;
- provide support;
- prevent fraud;
- reconcile activity;
- comply with contractual or legal obligations.
Processing carried out directly by that third party may also be subject to its own privacy policy.
6.6 Analytics, advertising, and marketing
We may use analytics providers to understand the use and performance of our Services.
Subject to applicable law and your preferences, we may use advertising or marketing technologies to measure campaigns or provide relevant content.
Where an activity constitutes a “sale,” “sharing,” targeted advertising, or another regulated form of processing under applicable law, we will provide the required notices and opt-out mechanisms.
6.7 Affiliates
We may share Personal Information among DRUO-controlled companies where necessary to operate our Services, provide support, maintain security and compliance, administer our business, and develop products.
6.8 Authorities and legal disclosures
We may disclose information to:
- courts;
- regulators;
- government authorities;
- tax authorities;
- law-enforcement agencies;
- financial intelligence units;
- other competent authorities.
We may do so where necessary or appropriate to comply with law, respond to legal process, investigate suspicious activity, protect rights, prevent fraud, or meet regulatory obligations.
6.9 Corporate transactions
We may disclose Personal Information in connection with an investment, financing, merger, acquisition, reorganization, asset sale, insolvency, or other corporate transaction.
Recipients may include investors, potential acquirers, lenders, advisers, auditors, insurers, and other participants, subject where appropriate to confidentiality obligations.
6.10 At your direction or with your consent
We may share Personal Information with third parties when you direct us to do so or provide your consent.
7. Security
DRUO uses administrative, technical, organizational, and physical safeguards designed to protect Personal Information against unauthorized access, use, disclosure, alteration, loss, or destruction.
These measures may include:
- encryption;
- access controls;
- authentication;
- monitoring;
- network protections;
- vulnerability management;
- secure development practices;
- logging and auditing;
- incident response;
- vendor management;
- business continuity;
- internal policies and controls.
We limit access to Personal Information to personnel, contractors, and providers that need access to perform authorized functions.
No method of transmitting or storing information can guarantee absolute security. Accordingly, although we implement measures designed to protect Personal Information, we cannot guarantee that a security incident will never occur.
8. Cookies and similar technologies
Our websites, applications, communications, and Services may use cookies, pixels, web beacons, local storage, software development kits, and similar technologies.
These technologies may collect:
- IP address;
- browser information;
- device information;
- pages visited;
- sessions;
- referring pages;
- application events;
- interaction with communications;
- approximate location;
- browser or device identifiers.
We may use them to:
- operate our Services;
- maintain sessions;
- remember preferences;
- authenticate Users;
- prevent fraud;
- maintain security;
- perform analytics;
- measure performance;
- detect errors;
- improve products;
- measure communications and campaigns;
- conduct permitted marketing activities.
Where required by applicable law, we will provide mechanisms to manage non-essential cookies.
You may also manage certain cookies through your browser or device. Disabling certain technologies may affect the operation of the Services.
Where legally required, DRUO may recognize opt-out preference signals, such as Global Privacy Control, for processing activities to which they apply.
9. International data transfers
DRUO operates internationally. As a result, Personal Information may be transferred, stored, or processed outside the country where it was collected or where you reside.
Recipient countries may have different data-protection laws.
Where required, we will use appropriate mechanisms to protect international transfers.
For Personal Information subject to the EU GDPR, these mechanisms may include adequacy decisions, Standard Contractual Clauses approved by the European Commission, or other legally recognized mechanisms.
For Personal Information subject to the UK GDPR, we may use an applicable international-transfer mechanism, including the UK Addendum to the EU Standard Contractual Clauses or the International Data Transfer Agreement, as appropriate.
For other jurisdictions, we will apply the international transfer or transmission mechanisms required under applicable law.
10. How long we retain personal information
We retain Personal Information for as long as reasonably necessary to provide our Services and fulfill the purposes described in this Notice.
The applicable retention period depends on factors such as:
- the nature of the information;
- the duration of your relationship with DRUO;
- the existence of a profile;
- the status of a connected financial account;
- payment history;
- authorizations;
- financial-institution requirements;
- payment-system rules;
- return or dispute periods;
- fraud prevention;
- AML and KYC obligations;
- tax, accounting, and financial requirements;
- regulatory obligations;
- legal limitation periods;
- litigation;
- security.
Closing a profile or disconnecting a financial account does not necessarily result in immediate deletion of all related information.
We may retain information after your relationship with DRUO ends where necessary to:
- comply with legal obligations;
- maintain financial records;
- comply with AML or KYC requirements;
- prevent or investigate fraud;
- manage returns and disputes;
- respond to authorities;
- enforce our agreements;
- establish, exercise, or defend legal rights;
- maintain the security and integrity of DRUO.
When information is no longer needed, we may delete, destroy, anonymize, or deidentify it in accordance with applicable law and our retention practices.
11. Your choices and privacy rights
Depending on where you reside and applicable law, you may have rights relating to your Personal Information, including rights to:
- know whether we process your Personal Information;
- access it;
- obtain information about its processing;
- correct inaccurate information;
- update information;
- request deletion;
- request restriction of processing;
- object to certain processing;
- obtain data portability;
- withdraw consent;
- opt out of certain marketing activities;
- opt out of targeted advertising;
- opt out of certain sales or sharing of Personal Information;
- limit certain uses of sensitive Personal Information;
- request review of certain automated decisions;
- appeal certain decisions regarding your privacy rights.
These rights are subject to the conditions and exceptions of applicable law.
For example, we may need to retain information despite a deletion request in order to comply with AML obligations, maintain financial records, prevent fraud, resolve disputes, or comply with other legal requirements.
We may request information reasonably necessary to verify your identity or authority before fulfilling a request.
Where permitted by applicable law, an authorized agent may submit a request on your behalf.
DRUO will not discriminate against you for exercising a right recognized under applicable privacy law.
11.1 Updating information
Certain information may be updated directly through your profile or the Services.
For other information, you may contact DRUO through the channels listed in the “How to contact us” section.
11.2 Closing profiles
Where the Service allows, you may request closure or deactivation of your profile.
Closure does not necessarily result in immediate deletion of all associated Personal Information due to the retention obligations and purposes described in this Notice.
11.3 Financial accounts
Where the Service allows, you may manage or disconnect certain financial accounts through your profile.
Disconnecting an account does not necessarily cancel payments that have already been initiated or delete information that we must retain.
11.4 Payment authorizations
The mechanisms available to modify or revoke an authorization depend on the type of authorization, Merchant, payment system, and applicable law.
Revoking an authorization may prevent future payments under that authorization, but generally does not reverse transactions that have already been properly initiated or processed.
11.5 Marketing communications
You may unsubscribe from promotional emails using the instructions included in those messages.
Even if you opt out of promotional communications, we may continue to send operational or legal communications, including:
- authentication codes;
- payment requests or confirmations;
- transaction notices;
- security alerts;
- support communications;
- profile or financial-account notices;
- regulatory or legal notices.
11.6 Location
You may control certain location permissions through your browser or device.
Some features may not be available if you disable location information necessary to provide them.
12. Minors
DRUO Services are not primarily directed to minors.
Certain Services may require you to be at least 18 years old or to have the legal capacity required to enter into the applicable agreement in your jurisdiction.
We do not seek to knowingly collect Personal Information directly from minors where doing so is not permitted by applicable law.
In circumstances permitted by law, a payment involving a minor may be made or administered by a parent, guardian, organization, financial institution, or other duly authorized person.
If we determine that we have collected Personal Information from a minor in a manner not permitted by law, we will take appropriate action in accordance with applicable law.
13. Additional jurisdictional disclosures
The provisions in this section supplement the rest of this Notice. Where local law provides additional rights or imposes additional obligations, we will apply those requirements.
13.1 European Economic Area and United Kingdom
Where the European Union General Data Protection Regulation (“EU GDPR”) or United Kingdom General Data Protection Regulation (“UK GDPR”) applies, we process Personal Information on one or more applicable legal bases.
These may include:
- performance of a contract;
- steps taken before entering into a contract;
- compliance with legal obligations;
- legitimate interests of DRUO or third parties;
- consent.
Our legitimate interests may include operating a secure payment network, preventing fraud, maintaining cybersecurity, developing and improving our Services, providing support, administering our business, and protecting our rights.
Subject to applicable conditions and exceptions, you may have the right to:
- access;
- rectification;
- erasure;
- restriction;
- objection;
- portability;
- withdrawal of consent;
- object to direct marketing;
- certain rights relating to solely automated decisions;
- lodge a complaint with the competent supervisory authority.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
13.2 United States
Privacy laws in certain states may provide you with additional rights.
Depending on the jurisdiction, these may include rights to:
- know;
- access;
- correct;
- delete;
- obtain a portable copy;
- opt out of sale;
- opt out of sharing for cross-context behavioral advertising;
- opt out of targeted advertising;
- limit certain uses of sensitive Personal Information;
- opt out of certain profiling or automated decisions;
- appeal certain decisions.
California
This section supplements this Notice for California residents and describes practices subject to the California Consumer Privacy Act, as amended (“CCPA”).
Depending on your interaction with DRUO, we may collect categories of Personal Information including:
- identifiers;
- consumer-record information;
- commercial information;
- financial information;
- internet or electronic network activity;
- geolocation;
- professional or employment-related information;
- sensory information;
- biometric information where applicable;
- inferences;
- sensitive Personal Information.
Sensitive Personal Information may include government identifiers, financial-account information, credentials, authentication information, precise geolocation where applicable, and biometric information used for verification.
Subject to applicable exceptions, if you reside in California you may have the right to know, access, correct, or delete Personal Information, as well as exercise applicable rights regarding sale, sharing, and certain uses of sensitive Personal Information.
DRUO does not sell Personal Information in the conventional sense of exchanging Personal Information for money.
Certain advertising or analytics activities may, however, be considered a “sale” or “sharing” under broader legal definitions. Where applicable, we will provide the required opt-out mechanisms.
13.3 Canada
Where Canadian privacy law applies, we will process Personal Information in accordance with applicable federal and provincial requirements.
Your Personal Information may be processed outside Canada, including in the United States and other countries where DRUO or its providers operate.
Subject to applicable law, you may request access or correction and raise concerns regarding the processing of your Personal Information.
13.4 Colombia
Where Colombian data-protection law applies, you may exercise the rights recognized under applicable law, including:
- know, update, and correct your data;
- request proof of authorization where applicable;
- obtain information regarding the use of your data;
- submit inquiries or complaints;
- withdraw authorization or request deletion where legally available;
- access your data in the cases established by law.
DRUO will carry out domestic and international transfers and transmissions of Personal Information in accordance with applicable requirements.
13.5 Mexico
Where Mexican data-protection law applies, you may exercise rights of Access, Rectification, Cancellation, and Opposition (“ARCO Rights”), subject to applicable legal conditions.
You may also have rights relating to withdrawal of consent, limitation of certain uses or disclosures, and transfers of Personal Information.
13.6 Peru
Where Peruvian data-protection law applies, you may exercise the rights recognized under applicable law, which may include information, access, updating, inclusion, rectification, deletion or cancellation, and opposition.
International transfers necessary to provide the Services will be carried out in accordance with applicable requirements.
13.7 Chile
Where Chilean data-protection law applies, we will process Personal Information in accordance with applicable requirements and recognize the rights available to you under applicable law, including, where applicable, access, rectification, deletion, opposition, and portability.
14. Changes to this Privacy Notice
We may modify this Privacy Notice from time to time to reflect changes in our Services, practices, corporate structure, or legal requirements.
Where we make material changes, we will provide notice as required by applicable law. We may do so by:
- posting the updated version;
- changing the date shown at the beginning of this Notice;
- providing notices within our Services;
- sending email or other communications where appropriate.
Unless otherwise stated, an updated version will become effective on the date shown at the beginning of this Notice.
15. How to contact us
If you have questions, requests, or concerns about this Privacy Notice or how DRUO processes Personal Information, you may contact DRUO through the privacy, support, or legal channels published on our websites or available within the Services.
DRUO, Inc.
United States
Where required by applicable law, DRUO may designate an affiliate, local representative, or privacy contact responsible for a particular jurisdiction.
To exercise a privacy right, please provide enough information for us to understand your request and identify the relevant Personal Information. We may request additional information where reasonably necessary to verify your identity or authority.
Where applicable, you may also lodge a complaint with the competent privacy or data-protection authority in your jurisdiction.
Nothing in this Privacy Notice is intended to limit any right that cannot lawfully be limited under applicable law.