SecProbe.io

Filing text and metadata
Intelligence Terminal Search Topics Monthly Activity About

Correspondence 0001104659-23-119330 from Yiren Digital Ltd. (YRD)

Yiren Digital Ltd.
Date: Nov. 17, 2023 · CIK: 0001631761 · Accession: 0001104659-23-119330

AI Filing Summary & Sentiment

File numbers found in text: 001-37657

Referenced dates: September 13, 2023

Date
December 31, 2022
Author
Not clearly detected
Form
CORRESP
Company
Yiren Digital Ltd.

Letter

Yiren Digital Ltd.

28/F China Merchants Bureau Building

118 Jianguo Road

Chaoyang District, Beijing 100080

People’s Republic of China

November 17,

VIA EDGAR

William Schroeder

Ben Phippen

Madeleine Joy Mateo

Susan Block

Office of Finance

Division of Corporation Finance

U.S. Securities and Exchange Commission

100 F Street, N.E.

Washington, D.C. 20549

Re: Yiren Digital Ltd. (the “Company”)

Form 20-F for the Fiscal Year Ended December 31, 2022

Filed April 28, 2023

File No. 001-37657

Ladies and Gentlemen:

This letter sets forth the Company’s responses to the comments of the staff (the “Staff”) of the Securities and Exchange Commission contained in its letter dated September 13, 2023 (the “Comment Letter”) on the Form 20-F for the Company for the fiscal year ended December 31, 2022 (the “2022 Form 20-F”). All capitalized terms used but not defined in this letter shall have the meaning ascribed to such terms in the 2022 Form 20-F.

For the Staff’s convenience, the Staff’s comments are repeated below in bold followed by the Company’s responses set forth in regular font. The Company respectfully advises the Staff that where the Company proposes to add or revise disclosure to its future filings on Form 20-F in response to the Staff’s comments, the changes to be made will be subject to relevant factual updates and changes in relevant laws or regulations, or in interpretations thereof. All the page references in this letter are made to the 2022 Form 20-F to illustrate the approximate location of the disclosure.

U.S. Securities and Exchange Commission Page 2

Form 20-F for the Fiscal Year Ended December 31, 2022

Our Holding Company Structure and Contractual Arrangements with the Consolidated Variable Interest Entities, page 3

1. In future filings, clearly disclose how you will refer to the holding company, subsidiaries, and VIEs when providing the disclosure throughout the document so that it is clear to investors which entity the disclosure is referencing and which subsidiaries or entities are conducting the business operations. Refrain from using terms such as “we” or “our” when describing activities or functions of a VIE. For example, disclose, if true, that your subsidiaries and/or the VIE conduct operations in China, that the VIE is consolidated for accounting purposes but is not an entity in which you own equity, and that the holding company does not conduct operations. Please include your proposed disclosure in your response letter.

RESPONSE:

In response to the Staff’s comment, in future Form 20-F filings, the Company proposes to refer to the holding company, subsidiaries, and VIEs when providing the disclosure throughout the document so that it is clear to investors which entity the disclosure is referencing and which subsidiaries or entities are conducting the business operations. The Company further undertakes to refrain from using terms such as “we” or “our” when describing activities or functions of the consolidated variable interest entities, and make necessary revisions throughout its future 20-F filings.

In particular, the Company respectfully proposes to revise the referenced disclosure on page 3 under “Item 3. Key Information—Our Holding Company Structure and Contractual Arrangements with the Consolidated Variable Interest Entities” in its future Form 20-F filings (with changes marked in italics, deletions as strike-through and additions underlined):

“Yiren Digital Ltd. is not a Chinese an operating company but a Cayman Islands holding company with no equity ownership in the consolidated variable interest entities. We conduct our operations conducted by in China through (i) our PRC its subsidiaries and (ii) the consolidated variable interest entities with which we its subsidiaries have maintained contractual arrangements. PRC laws and regulations restrict and impose conditions on foreign investment in internet culture business and certain value-added telecommunication services such as internet content provision services. Accordingly, we operate these businesses in China through the consolidated variable interest entities, and rely on contractual arrangements among our PRC subsidiaries, the consolidated variable interest entities and their shareholders to conduct the business operations of consolidate the financial results of the consolidated variable interest entities in accordance with U.S. GAAP. Revenues contributed by the consolidated variable interest entities accounted for 64.4%, 71.3% and 53.0% of our total revenues for the years of 2020, 2021 and 2022, respectively. As used in this annual report, “we,” “us,” “our company” and “our” refers to Yiren Digital Ltd., its subsidiaries, and, only in the context of describing our operations and consolidated financial information, the consolidated variable interest entities in China, including but not limited to the following entities:

· CreditEase Puhui Information Consultant (Beijing) Co., Ltd. or CreditEase Puhui, which was established in March 2011 and holds our a Domestic Call Center Service Permit, operates our a website and primarily engages in the credit business;

· Hexiang Insurance Broker Co., Ltd. or Hexiang Insurance Brokers, which was established in September 2011 and holds our Business Licenses to Professional Insurance Intermediaries, operates our a website and primarily engages in the insurance brokerage business;

U.S. Securities and Exchange Commission Page 3

· Dekai Yichuang Asset Management (Shenzhen) Co., Ltd. or Dekai Yichuang, which was established in March 2016 and primarily engages in the business of asset management had no business operation other than holding shares as of the date of this annual report;

· Hainan Haijin Yichuang Data Information Service Co., Ltd. or Yichuang Data, which was established in December 2016 and had no business operation other than holding shares as of the date of this annual report;

· Haijin Yichuang Financial Leasing Co., Ltd. or Yichuang Financial Leasing, which was established in March 2017 and primarily engages in the business of financial leasing;

· Hainan Haijin Yichuang Micro-lending Co., Ltd. or Yichuang Micro-lending, which was established in May 2017 and primarily engages in the micro-lending business;

· Yiren Financial Information Service (Beijing) Co., Ltd. or Yiren Wealth, which was established in October 2016 and operates our a website and a mobile application and primarily engages in the comprehensive wealth business;

· Heilongjiang Changtuo Technology Development Co., Ltd. or Changtuo Technology, which was established in January 2014 and had no business operation other than holding shares as of the date of this annual report;

· Tianjin Linyang Information and Technology Co., Ltd. or Tianjin Linyang, which was established in July 2019 and primarily engages in the borrower acquisition services;

· Beijing Yiding Technology Co., Ltd. or Yiding Technology, which was established in August 2019 and operates our a website and primarily engages in the insurance referral business;

· Beijing Kechuang Xinlian Technology Co., Ltd. or Kechuang Xinlian, which was established in November 2019 and holds our an Internet Culture Business Permit, an Internet Content Provider License and an Electronic Data Interchange License, operates our a website and a mobile application and primarily engages in the electronic commerce business; and

· Beijing Yiyouxuan Technology Information Service Co., Ltd. or Yiyouxuan, which was established in July 2022 and holds our an Internet Content Provider License and an Electronic Data Interchange License, operates our a mobile application and primarily engages in the electronic commerce business.

Yiren Digital Ltd. has no equity ownership in the consolidated variable interest entities. Therefore, investors investing in our ADSs are not purchasing equity interest in the consolidated variable interest entities in China but instead are purchasing equity interest in a holding company incorporated in the Cayman Islands.”

U.S. Securities and Exchange Commission Page 4

Risk Factors

Our business is subject to complex and evolving Chinese and international laws, page 35

2. In light of recent events indicating greater oversight by the Cyberspace Administration of China (CAC) over data security, particularly for companies seeking to list on a foreign exchange, in future filings, please revise your disclosure to explain how this oversight impacts your business and your offering and to what extent you believe that you are compliant with the regulations or policies that have been issued by the CAC to date. Please provide us your proposed draft disclosure in your response letter.

RESPONSE:

In response to the Staff’s comment, the Company respectfully proposes to revise the referenced disclosure on pages 35 to 37 under “Item 3. Key Information—D. Risk Factors—Risks Related to Our Business” in its future Form 20-F filings (with changes marked in italics, deletions as strike-through and additions underlined):

“Our business is subject to complex and evolving Chinese and international laws and regulations regarding data privacy and cybersecurity. Failure to protect confidential information of our customers and network against security breaches could damage our reputation and brand and substantially harm our business and results of operations.

As the regulations regarding data privacy and cybersecurity are quickly evolving in China and globally, we may become subject to new laws and regulations applying to the solicitation, collection, processing or use of personal or consumer information that could affect how we store, process and share data with our customers, suppliers and third-party merchants. Significant capital, managerial and human resources may be required to comply with those legal requirements, enhance information security and to address any issues caused by security failures.

For example, the PRC Data Security Law and Civil Code are relatively new and subject to interpretation by the regulators. The exact scopes of certain critical concepts such as important data and state core data remain unclear and may be subject to further interpretation. If any data that we are in possession of constitutes important data or state core data, we may be required to adopt stricter measures for protection and management of such data. See “Item 4. Information on the Company—B. Business Overview—Regulations.”

In addition, the Regulations on the Network Data Security (Draft for Comments), or the Draft Regulations, as of the date of this annual report, were released for public comment only, and its provisions and the anticipated adoption or effective date may be subject to change with substantial uncertainty. The Draft Regulations provide that data processors shall apply for a cybersecurity review for certain activities. The Draft Regulations remain unclear on whether the relevant requirements will be applicable to companies that have been listed in the United States or Hong Kong, such as us. For more details of such cybersecurity review requirements, see “Item 4. Information on the Company—B. Business Overview—Regulations,” and “Item 3. Key Information—D. Risk Factors—Risks Related to Doing Business in China—The approval of and filing with the CSRC or other PRC government authorities may be required in connection with our offshore offerings under PRC law, and, if required, we cannot predict whether or for how long we will be able to obtain such approval or complete such filing.” As of the date of this annual report, we, our PRC subsidiaries, and the consolidated variable interest entities, were not required to go through a cybersecurity review by CAC for our previous issuance of securities to foreign investors according to the Measures for Cybersecurity Review. Pursuant to the Overseas Listing Regulations issued on February 17, 2023, companies in China that directly or indirectly offer or list their securities in an overseas market must file with the CSRC within three business days after submitting their listing application documents to the regulator in the place of intended listing. The Overseas Listing Regulations also provide that a company in China must file with the CSRC within three business days after completion of its follow-on offering of securities after it is listed in an overseas market. Thus, the Company will be required to file with the CSRC within three business days after completion of any of its follow-on offering of securities in the New York Stock Exchange, i.e., the overseas market where it is listed, or after submitting its listing application documents to the overseas regulator related to a secondary or dual primary listing of securities in any other overseas market. For secondary listing, dual primary listing or other new foreign listings, the Company also needs to apply for a CAC cybersecurity review if it falls in the categories that require such a review under the Measures for Cybersecurity Review.

U.S. Securities and Exchange Commission Page 5

Furthermore, Measures for Cybersecurity Review, or the Measures, further restate and expand the applicable scope of the cybersecurity review. Pursuant to the Measures, critical information infrastructure operators that procure internet products and services, and online platform operators engaging in data processing activities, must be subject to the cybersecurity review if their activities affect or may affect national security. As of the date of this annual report, we have not been informed as a critical information infrastructure operator by any government authorities. However, the exact scope of “critical information infrastructure operators” under the current regulatory regime remains unclear, and the PRC government authorities may have wide discretion in the interpretation and enforcement of these laws. If we are deemed as a critical information infrastructure operator under the PRC cybersecurity laws and regulations, we must fulfill certain obligations as required under the PRC cybersecurity laws and regulations and we may be subject to cyber security review when purchasing internet products and services or engaging in data processing activities. See “Item 4. Information on the Company—B. Business Overview—Regulations.” We cannot predict the impact of the Measures and the Draft Regulations, if any, at this stage, and we will closely monitor and assess any development in the rule-making process. See “Item 4. Information on the Company—B. Business Overview—Regulations.”

In addition, given that the Measures on Security Assessment of Cross-border Transfer of Data were recently promulgated in July 2022, it is unclear whether and to what extent we will be subject to these new requirements. As of the date of this annual report, the Company has not conducted any of cross-border transfer of critical data or personal data generated from or collected in the PRC that should be subject to a security assessment.

We may also need to comply with increasingly complex and rigorous regulatory standards enacted to protect business and personal data in the U.S., Europe and elsewhere. For example, the European Union adopted the General Data Protection Regulation, or the GDPR, which became effective on May 25, 2018. Compliance with existing, proposed and recently enacted laws (including implementation of the privacy and process enhancements called for under GDPR) and regulations can be costly; any failure to comply with these regulatory standards could subject us to legal and reputational risks.

We generally comply with industry standards and are subject to the terms of our own privacy policies. We update our privacy policies from time to time to meet the latest regulatory requirements of the CAC and other authorities and adopt technical measures to protect data and ensure cybersecurity in a systematic way. As of the dat

Show Raw Text
CORRESP
1
filename1.htm

Yiren
Digital Ltd.

28/F China Merchants Bureau Building

118 Jianguo Road

Chaoyang District, Beijing 100080

People’s Republic of China

November 17,
2023

VIA EDGAR

William Schroeder

Ben Phippen

Madeleine Joy Mateo

Susan Block

Office of Finance

Division of Corporation Finance

U.S. Securities and Exchange Commission

100 F Street, N.E.

Washington, D.C. 20549

 Re: Yiren Digital Ltd. (the “Company”)

Form 20-F
for the Fiscal Year Ended December 31, 2022

Filed
April 28, 2023

File No. 001-37657

Ladies and Gentlemen:

This letter sets forth the Company’s responses
to the comments of the staff (the “Staff”) of the Securities and Exchange Commission contained in its letter dated
September 13, 2023 (the “Comment Letter”) on the Form 20-F for the Company for the fiscal year ended December 31,
2022 (the “2022 Form 20-F”). All capitalized terms used but not defined in this letter shall have the meaning
ascribed to such terms in the 2022 Form 20-F.

For the Staff’s convenience, the Staff’s
comments are repeated below in bold followed by the Company’s responses set forth in regular font. The Company respectfully advises
the Staff that where the Company proposes to add or revise disclosure to its future filings on Form 20-F in response to the Staff’s
comments, the changes to be made will be subject to relevant factual updates and changes in relevant laws or regulations, or in interpretations
thereof. All the page references in this letter are made to the 2022 Form 20-F to illustrate the approximate location of the
disclosure.

    U.S. Securities and Exchange Commission
 Page 2

Form 20-F for the Fiscal Year Ended December 31, 2022

Our Holding Company Structure and Contractual
Arrangements with the Consolidated Variable Interest Entities, page 3

 1. In future filings, clearly disclose how you will refer to the holding company, subsidiaries, and VIEs
when providing the disclosure throughout the document so that it is clear to investors which entity the disclosure is referencing and
which subsidiaries or entities are conducting the business operations. Refrain from using terms such as “we” or “our”
when describing activities or functions of a VIE. For example, disclose, if true, that your subsidiaries and/or the VIE conduct operations
in China, that the VIE is consolidated for accounting purposes but is not an entity in which you own equity, and that the holding company
does not conduct operations. Please include your proposed disclosure in your response letter.

RESPONSE:

In
response to the Staff’s comment, in future Form 20-F filings, the Company proposes to refer to the holding company, subsidiaries,
and VIEs when providing the disclosure throughout the document so that it is clear to investors which entity the disclosure is referencing
and which subsidiaries or entities are conducting the business operations. The Company further undertakes to refrain from using
terms such as “we” or “our” when describing activities or functions of the consolidated variable interest entities,
and make necessary revisions throughout its future 20-F filings.

In
particular, the Company respectfully proposes to revise the referenced disclosure on page 3 under “Item 3. Key Information—Our
Holding Company Structure and Contractual Arrangements with the Consolidated Variable Interest Entities” in its future Form 20-F
filings (with changes marked in italics, deletions as strike-through and additions underlined):

“Yiren
Digital Ltd. is not a Chinese an operating company but a Cayman Islands holding company with no
equity ownership in the consolidated variable interest entities. We conduct our operations conducted by in China
through (i) our PRC its subsidiaries and (ii) the consolidated variable interest
entities with which we its subsidiaries have maintained contractual arrangements. PRC laws and regulations
restrict and impose conditions on foreign investment in internet culture business and certain value-added telecommunication services
such as internet content provision services. Accordingly, we operate these businesses in China through the consolidated variable interest
entities, and rely on contractual arrangements among our PRC subsidiaries, the consolidated variable interest entities and their shareholders
to conduct the business operations of consolidate the financial results of the consolidated
variable interest entities in accordance with U.S. GAAP. Revenues contributed by the consolidated variable interest entities
accounted for 64.4%, 71.3% and 53.0% of our total revenues for the years of 2020, 2021 and 2022, respectively.
As used in this annual report, “we,” “us,” “our company” and “our” refers to Yiren Digital
Ltd., its subsidiaries, and, only in the context of describing our operations and consolidated financial information, the
consolidated variable interest entities in China, including but not limited to the following entities:

 · CreditEase Puhui Information Consultant (Beijing) Co., Ltd. or CreditEase Puhui, which was established
in March 2011 and holds our a Domestic Call Center Service Permit, operates our a
website and primarily engages in the credit business;

 · Hexiang Insurance Broker Co., Ltd. or Hexiang Insurance Brokers, which was established in September 2011
and holds our Business Licenses to Professional Insurance Intermediaries, operates our a
website and primarily engages in the insurance brokerage business;

    U.S. Securities and Exchange Commission
 Page 3

 · Dekai Yichuang Asset Management (Shenzhen) Co., Ltd. or Dekai Yichuang, which was established in
March 2016 and primarily engages in the business of asset management had no business operation other than
holding shares as of the date of this annual report;

 · Hainan Haijin Yichuang Data Information Service Co., Ltd. or Yichuang Data, which was established
in December 2016 and had no business operation other than holding shares as of the date of this annual report;

 · Haijin Yichuang Financial Leasing Co., Ltd. or Yichuang Financial Leasing, which was established
in March 2017 and primarily engages in the business of financial leasing;

 · Hainan Haijin Yichuang Micro-lending Co., Ltd. or Yichuang Micro-lending, which was established in
May 2017 and primarily engages in the micro-lending business;

 · Yiren Financial Information Service (Beijing) Co., Ltd. or Yiren Wealth, which was established in
October 2016 and operates our a website and a mobile application and primarily engages
in the comprehensive wealth business;

 · Heilongjiang Changtuo Technology Development Co., Ltd. or Changtuo Technology, which was established
in January 2014 and had no business operation other than holding shares as of the date of this annual report;

 · Tianjin Linyang Information and Technology Co., Ltd. or Tianjin Linyang, which was established in
July 2019 and primarily engages in the borrower acquisition services;

 · Beijing Yiding Technology Co., Ltd. or Yiding Technology, which was established in August 2019
and operates our a website and primarily engages in the insurance referral business;

 · Beijing Kechuang Xinlian Technology Co., Ltd. or Kechuang Xinlian, which was established in November 2019
and holds our an Internet Culture Business Permit, an Internet Content Provider License and
an Electronic Data Interchange License, operates our a website and a mobile
application and primarily engages in the electronic commerce business; and

 · Beijing Yiyouxuan Technology Information Service Co., Ltd. or Yiyouxuan, which was established in
July 2022 and holds our an Internet Content Provider License and an Electronic Data
Interchange License, operates our a mobile application and primarily engages in the electronic commerce
business.

Yiren
Digital Ltd. has no equity ownership in the consolidated variable interest entities. Therefore, investors investing
in our ADSs are not purchasing equity interest in the consolidated variable interest entities in China but instead
are purchasing equity interest in a holding company incorporated in the Cayman Islands.”

    U.S. Securities and Exchange Commission
 Page 4

Risk Factors

Our business is subject to complex and evolving
Chinese and international laws, page 35

 2. In light of recent events indicating greater oversight by the Cyberspace Administration of China (CAC)
over data security, particularly for companies seeking to list on a foreign exchange, in future filings, please revise your disclosure
to explain how this oversight impacts your business and your offering and to what extent you believe that you are compliant with the regulations
or policies that have been issued by the CAC to date. Please provide us your proposed draft disclosure in your response letter.

RESPONSE:

In
response to the Staff’s comment, the Company respectfully proposes to revise the referenced disclosure on pages 35 to 37 under
 “Item 3. Key Information—D. Risk Factors—Risks Related to Our Business” in its future Form 20-F filings (with
changes marked in italics, deletions as strike-through and additions underlined):

“Our business is subject
to complex and evolving Chinese and international laws and regulations regarding data privacy and cybersecurity. Failure to protect confidential
information of our customers and network against security breaches could damage our reputation and brand and substantially harm our business
and results of operations.

As the regulations regarding data privacy
and cybersecurity are quickly evolving in China and globally, we may become subject to new laws and regulations applying to the solicitation,
collection, processing or use of personal or consumer information that could affect how we store, process and share data with our customers,
suppliers and third-party merchants. Significant capital, managerial and human resources may be required to comply with those legal
requirements, enhance information security and to address any issues caused by security failures.

For example, the PRC Data Security
Law and Civil Code are relatively new and subject to interpretation by the regulators. The exact scopes of certain critical concepts such
as important data and state core data remain unclear and may be subject to further interpretation. If any data that we are in possession
of constitutes important data or state core data, we may be required to adopt stricter measures for protection and management of such
data. See “Item 4. Information on the Company—B. Business Overview—Regulations.”

In addition, the
Regulations on the Network Data Security (Draft for Comments), or the Draft Regulations, as of the date of this annual report, were
released for public comment only, and its provisions and the anticipated adoption or effective date may be subject to change with
substantial uncertainty. The Draft Regulations provide that data processors shall apply for a cybersecurity review for certain
activities. The Draft Regulations remain unclear on whether the relevant requirements will be applicable to companies that have been
listed in the United States or Hong Kong, such as us. For more details of such cybersecurity review requirements, see “Item 4.
Information on the Company—B. Business Overview—Regulations,” and “Item 3. Key Information—D. Risk
Factors—Risks Related to Doing Business in China—The approval of and filing with the CSRC or other PRC government
authorities may be required in connection with our offshore offerings under PRC law, and, if required, we cannot predict whether or
for how long we will be able to obtain such approval or complete such filing.” As of the date of this annual report, we, our
PRC subsidiaries, and the consolidated variable interest entities, were not required to go through a cybersecurity review by CAC for
our previous issuance of securities to foreign investors according to the Measures for Cybersecurity Review. Pursuant to the
Overseas Listing Regulations issued on February 17, 2023, companies in China that directly or indirectly offer or list their
securities in an overseas market must file with the CSRC within three business days after submitting their listing application
documents to the regulator in the place of intended listing. The Overseas Listing Regulations also provide that a company in China
must file with the CSRC within three business days after completion of its follow-on offering of securities after it is listed in an
overseas market. Thus, the Company will be required to file with the CSRC within three business days after completion of any of its
follow-on offering of securities in the New York Stock Exchange, i.e., the overseas market where it is listed, or after submitting
its listing application documents to the overseas regulator related to a secondary or dual primary listing of securities in any
other overseas market. For secondary listing, dual primary listing or other new foreign listings, the Company also needs to apply
for a CAC cybersecurity review if it falls in the categories that require such a review under the Measures for Cybersecurity
Review.

    U.S. Securities and Exchange Commission
 Page 5

Furthermore, Measures for Cybersecurity
Review, or the Measures, further restate and expand the applicable scope of the cybersecurity review. Pursuant to the Measures, critical
information infrastructure operators that procure internet products and services, and online platform operators engaging in data processing
activities, must be subject to the cybersecurity review if their activities affect or may affect national security. As of the date of
this annual report, we have not been informed as a critical information infrastructure operator by any government authorities. However,
the exact scope of “critical information infrastructure operators” under the current regulatory regime remains unclear, and
the PRC government authorities may have wide discretion in the interpretation and enforcement of these laws. If we are deemed as a critical
information infrastructure operator under the PRC cybersecurity laws and regulations, we must fulfill certain obligations as required
under the PRC cybersecurity laws and regulations and we may be subject to cyber security review when purchasing internet products and
services or engaging in data processing activities. See “Item 4. Information on the Company—B. Business Overview—Regulations.”
We cannot predict the impact of the Measures and the Draft Regulations, if any, at this stage, and we will closely monitor and assess
any development in the rule-making process. See “Item 4. Information on the Company—B. Business Overview—Regulations.”

In addition, given that the Measures
on Security Assessment of Cross-border Transfer of Data were recently promulgated in July 2022, it is unclear whether and to what
extent we will be subject to these new requirements. As of the date of this annual report, the Company has not conducted any of cross-border
transfer of critical data or personal data generated from or collected in the PRC that should be subject to a security assessment.

We may also need to comply with
increasingly complex and rigorous regulatory standards enacted to protect business and personal data in the U.S., Europe and elsewhere.
For example, the European Union adopted the General Data Protection Regulation, or the GDPR, which became effective on May 25, 2018.
Compliance with existing, proposed and recently enacted laws (including implementation of the privacy and process enhancements called
for under GDPR) and regulations can be costly; any failure to comply with these regulatory standards could subject us to legal and reputational
risks.

We generally comply with industry
standards and are subject to the terms of our own privacy policies. We update our privacy policies from time to time to meet the latest
regulatory requirements of the CAC and other authorities and adopt technical measures to protect data and ensure cybersecurity in a systematic
way. As of the dat