PRIVACY POLICY

INTRODUCTION
‍

William Hood & Company, LLC (“WHC” or the “Firm”) is a broker-dealer registered with the Securities and Exchange Commission and a member of the Financial Industry Regulatory Authority (“FINRA”). The Firm is committed to protecting the confidentiality and security of personal information entrusted to it.

The Firm provides investment banking services, including participating in underwritings and providing merger and acquisition advisory services. The Firm focuses primarily on the consumer, food, and retail industries, with particular expertise in health and wellness and other developing consumer trends.

The Firm’s clients are private and public companies. The Firm does not provide retail brokerage services or maintain securities accounts for individual retail customers.

In conducting its business, the Firm may obtain personal information concerning individuals associated with its clients, prospective clients, transaction participants, and other business relationships. These individuals may include directors, officers, employees, representatives, shareholders, beneficial owners, control persons, investors, and professional advisers.

This Privacy Policy describes the types of personal information the Firm may collect, how that information may be used and disclosed, and the measures the Firm maintains to protect it.
‍

INFORMATION THE FIRM MAY COLLECT
‍

Depending upon the nature of the relationship, the Firm may collect the following categories of personal information:
—Name, business address, telephone number, email address, job title, employer, and other contact information;
—Where applicable, information required for identity verification, due diligence, sanctions screening, anti-money laundering, and other regulatory or compliance purposes, including residential address, date of birth, citizenship, taxpayer identification number, government identification number, and copies of government-issued identification;
—Employment, professional, financial, ownership, control, and affiliation information;
—Information concerning beneficial owners, control persons, authorized representatives, investors, and transaction participants; and
—Communications, agreements, instructions, transaction information, and other records relating to the Firm’s services or business relationships.
The Firm may obtain this information directly from clients and other individuals. The Firm may also obtain information from employers, service providers, regulatory databases, public records, and other sources permitted by law.
‍

USE OF PERSONAL INFORMATION
‍

The Firm may use personal information to:
—Provide investment banking and other securities-related services;
—Establish, administer, and maintain client and prospective client;
—Verify identities and conduct due diligence, sanctions screening, anti-money laundering, conflicts, and risk reviews;
—Evaluate, structure, execute, document, and maintain records of transactions;
—Communicate with clients, prospective clients, representatives, investors, and other business contacts;* Protect the security and integrity of the Firm’s systems, records, and operations;
—Prevent, detect, and investigate fraud, cybersecurity incidents, unlawful activity, or violations of Firm policies;
—Comply with legal, regulatory, supervisory, recordkeeping, reporting, examination, and audit obligations;
—Enforce the Firm’s agreements and protect its legal rights; and* Conduct other legitimate business activities consistent with the applicable relationship and permitted by law.

The Firm uses personal information for the purposes described in this Privacy Policy and as otherwise permitted or required by applicable law.
‍

DISCLOSURE OF PERSONAL INFORMATION
‍

The Firm may disclose personal information, as appropriate, to:
—Service providers that perform business, professional, compliance, or technology services for the Firm, including identity-verification and due-diligence providers, attorneys, accountants, auditors, consultants, information-technology providers, and data-storage providers;
—Parties involved in an actual or proposed underwriting, merger, acquisition, financing, restructuring, or other transaction for which the Firm provides services;
—The Securities and Exchange Commission, FINRA, other self-regulatory organizations, governmental authorities, law-enforcement agencies, courts, and other parties in response to a regulatory request, examination, investigation, subpoena, court order, or other legal process;
—Other parties when the Firm reasonably believes disclosure is necessary to prevent or investigate fraud, unlawful activity, or an information-security incident, or to protect the Firm’s legal rights; and
—Other persons when authorized or directed by the client or affected individual, or when otherwise permitted or required by law.

The Firm requires its service providers to use personal information only for the purposes for which it was disclosed and to maintain appropriate safeguards for that information, as applicable to the services provided.
‍
The Firm does not sell or rent personal information or disclose personal information to unaffiliated third parties for their independent marketing purposes.
‍

PROTECTION OF PERSONAL INFORMATION
‍

The Firm maintains administrative, technical, and physical safeguards reasonably designed to protect personal information against unauthorized access, use, disclosure, alteration, loss, or destruction.

These safeguards include, as appropriate, access controls, authentication procedures, cybersecurity protections, employee training, vendor oversight, record-retention and disposal procedures, and incident-response measures. Access to personal information is limited to personnel and service providers who require the information to perform authorized business, operational, legal, compliance, or regulatory functions.

Although the Firm takes reasonable measures to protect personal information, no information-security program can eliminate every risk. The Firm reviews its safeguards and updates them as appropriate based on its business, applicable regulatory requirements, and reasonably foreseeable risks.
‍

INFORMATION-SECURITY INCIDENTS
‍

The Firm maintains written policies and procedures reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information.

If the Firm determines that notification concerning an information-security incident is required, the Firm will provide notification to affected individuals in accordance with applicable legal and regulatory requirements.
‍

‍RETENTION AND DISPOSAL
‍

The Firm retains personal information for as long as reasonably necessary to fulfill the purposes for which it was collected and to satisfy applicable legal, regulatory, contractual, supervisory, recordkeeping, examination, dispute-resolution, and business requirements.

When personal information is no longer required to be retained, the Firm disposes of it in a manner reasonably designed to protect against unauthorized access to or use of the information.
‍

CHANGES TO THIS PRIVACY POLICY
‍

The Firm may update this Privacy Policy periodically to reflect changes in its business, information practices, or applicable legal and regulatory requirements.

The effective date shown at the beginning of this Privacy Policy indicates when it was most recently updated. Any updated Privacy Policy will be posted on the Firm’s website, and additional notice of material changes will be provided when required by applicable law.
‍

PRIVACY QUESTIONS
‍

Questions concerning this Privacy Policy may be directed at William Hood, Chief Compliance Officer at whood@williamhoodandcompany.com