Effective Date: January 1, 2026

Our Commitment to Privacy

OTRO Financial respects the privacy of applicants, clients, business owners, and other individuals who provide information to us. We collect and use information to evaluate and arrange financing, provide advisory services, communicate with funding sources, and operate our business. We maintain safeguards designed to protect information against unauthorized access, use, disclosure, alteration, or destruction.

Information We May Collect

Depending on the services requested, we may collect information such as name, address, phone number, email address, date of birth, Social Security number or taxpayer identification number, identification documents, credit information, credit reports, income and revenue information, tax returns, bank statements, financial statements, debt information, business ownership information, loan history, and other information needed to evaluate financing or provide services.

How We Use Information

We may use information to evaluate financing opportunities; prepare, submit, and monitor financing requests; communicate with lenders and funding sources; perform underwriting and eligibility analysis; provide advisory services; verify information; maintain records; protect against fraud and unauthorized activity; comply with applicable legal and contractual requirements; and operate and improve our business.

When We Share Information

We may share information with lenders, banks, finance companies, funding sources, credit-reporting providers, underwriting and processing partners, technology and service providers, professional advisors, and other parties when reasonably necessary to provide requested services or conduct legitimate business operations. We seek to limit disclosures to information reasonably necessary for the purpose.

Security

OTRO maintains administrative, technical, and physical safeguards designed to protect confidential information. These safeguards may include access controls, authentication, multi-factor authentication where available, encryption where appropriate, secure systems, device security, employee confidentiality obligations, vendor controls, and secure disposal practices.

Information From Third Parties

We may receive information from credit-reporting agencies, financial institutions, lenders, service providers, public records, referral partners, and other sources in connection with a financing request or business relationship.

Your Choices and Questions

If you have questions about how OTRO handles your information, believe information has been improperly disclosed, or want to understand the information practices applicable to a particular service, contact OTRO management using the contact information provided in your engagement documents or on OTRO’s current website.

Important Scope Note

This notice is intended to describe OTRO’s general privacy practices. The specific disclosures, notices, consents, opt-out rights, and other requirements that apply to a particular transaction may depend on the type of service, the information involved, the parties receiving the information, and applicable federal or state law. Where a law requires a more specific notice or consent, OTRO will provide the applicable notice.

Security Incidents

If OTRO determines that a security incident requires notification under applicable law, OTRO will provide notices to affected individuals, regulators, law enforcement, or other parties as required. OTRO will also take reasonable steps to contain and remediate the incident.

Contact

Privacy questions should be directed to OTRO Financial management. OTRO will periodically review this notice and update it when its information practices materially change or when required by applicable law.