PRIVACY POLICY
ROBINSON HOLDINGS, INC. D/B/A ROBINSON GROUP CONSULTING, INC. CADENZA.AI PLATFORM
PRIVACY POLICY FOR AI FEATURE USAGE & SUBSCRIPTION SERVICES
Effective Date: April 10, 2026
Last Modified: August 24, 2026
Cadenza.AI is a subscription-based AI-powered virtual Chief Information Officer platform offered by Robinson Holdings, Inc., an Illinois corporation d/b/a Robinson Group Consulting, Inc. (“Company,” “we,” “us,” or “our”) that delivers technology advisory services, Gap Analysis, and strategic IT recommendations based on user provided organizational data.
We are committed to providing you with ownership, control and privacy over your business data. This Privacy Policy (“Policy”) sets out how we collect, store, process, transfer, share, protect, disclose and use data that identifies or is associated with the Customer (“Customer,” “you,” or “your”) in connection with Company’s subscription-based artificial intelligence-powered virtual Chief Information Officer platform and related services (collectively, the “Services”).
This Policy forms part of and is incorporated into the applicable Terms and Conditions, Order Form, or other agreement governing Customer’s use of the Services
1. DEFINITIONS
1.1 “Business Data”
“Business Data” means all non-public business, commercial, operational, technical, financial, strategic, organizational, information technology, cybersecurity, infrastructure, vendor, contractual, and other proprietary information submitted to, uploaded to, transmitted through, or otherwise made available to the Services by or on behalf of Customer.
Business Data may include, without limitation, information concerning Customer’s information technology environment, hardware and software inventories, network architecture and configurations, cloud infrastructure, cybersecurity posture and assessments, vulnerabilities, risks and security findings, technology policies and procedures, IT budgets and technology expenditures, vendor and supplier information, vendor contracts and agreements, technology licensing information, business continuity and disaster recovery information, IT governance information, technology roadmaps, strategic plans, organizational information, operational processes, internal assessments, technology-related financial information, compliance and risk management information, business reports, documents and files, system and application information, and other confidential or proprietary business information provided by Customer.
“Business Data” means all non-public business, commercial, operational, technical, financial, strategic, organizational, information technology, cybersecurity, infrastructure, vendor, contractual, and other proprietary information submitted to, uploaded to, transmitted through, or otherwise made available to the Services by or on behalf of Customer.
Business Data may include, without limitation, information concerning Customer’s information technology environment, hardware and software inventories, network architecture and configurations, cloud infrastructure, cybersecurity posture and assessments, vulnerabilities, risks and security findings, technology policies and procedures, IT budgets and technology expenditures, vendor and supplier information, vendor contracts and agreements, technology licensing information, business continuity and disaster recovery information, IT governance information, technology roadmaps, strategic plans, organizational information, operational processes, internal assessments, technology-related financial information, compliance and risk management information, business reports, documents and files, system and application information, and other confidential or proprietary business information provided by Customer.
Business Data also includes information generated by the Services specifically for Customer based upon Customer’s Business Data, including reports, assessments, analyses, recommendations, technology roadmaps, risk assessments, and other Customer-specific outputs, except that Company retains ownership of its underlying software, models, algorithms, methodologies, know-how, and other intellectual property.
1.2 “Confidential Information”
“Confidential Information” means non-public information disclosed by one party to the other party that is identified as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure. Customer’s Business Data will be considered Customer’s Confidential Information.
1.3 “AI Services”
“AI Services” means artificial intelligence, machine learning, generative artificial intelligence, large language models, predictive analytics, automated reasoning, or similar technologies incorporated into or used to provide the Services.
1.4 “AI Provider”
“AI Provider” means a third-party provider of artificial intelligence, machine learning, large language model, cloud computing, or related technology used by Company in connection with the Services.
1.5 “Security Incident”
“Security Incident” means a confirmed unauthorized access to, acquisition of, disclosure of, alteration of, loss of, or destruction of Customer Business Data within Company’s systems.
1.6 “Subprocessor”
“Subprocessor” means a third party engaged by Company to process or host Customer Business Data on behalf of Company in connection with the Services.
1.7 “Personal Information”
“Personal Information” means information relating to an identified or identifiable individual that is protected as personal information, personal data, personally identifiable information, or a substantially similar category under applicable privacy or data protection law. The Services are not designed or intended to collect or process Personal Information as a primary purpose.
2. NATURE OF THE SERVICES AND DATA
2.1 Business-Focused Platform
The Services are designed to function as an AI-powered virtual Chief Information Officer for businesses and organizations. The Services are intended primarily to process Business Data rather than Personal Information.
2.2 No Intended Processing of Personal Information
Customer acknowledges that the Services are not intended to serve as a repository for consumer, employee, patient, customer, or other Personal Information. Customer agrees not to intentionally submit Personal Information to the Services unless expressly authorized in writing by Company.
2.3 Incidental Personal Information
The parties acknowledge that Business Data may occasionally contain incidental information relating to individuals, such as business names, business email addresses, business telephone numbers, employee names, job titles, vendor contacts, or similar information ordinarily contained within business records. Such incidental information does not change the fundamental business-to-business nature of the Services. If Customer submits Personal Information that is outside the intended scope of the Services, Customer remains responsible for ensuring that such submission and processing is legally permissible.
3. OWNERSHIP OF BUSINESS DATA
3.1 Customer Ownership
As between Company and Customer, Customer retains all right, title, and interest in and to Customer’s Business Data. Nothing in this Agreement transfers ownership of Customer Business Data to Company.
3.2 Company Intellectual Property
Company retains all right, title, and interest in and to the Services, software, source code, object code, algorithms, AI models, model architecture, prompts and prompt frameworks developed by Company, methodologies, templates, workflows, documentation, know-how, system architecture, and other Company intellectual property.
3.3 Customer-Specific Outputs
Customer owns reports, assessments, recommendations, technology roadmaps, analyses, and other outputs generated specifically for Customer from Customer’s Business Data, subject to Company’s ownership of its underlying technology, methodologies, models, templates, and intellectual property.
4. PERMITTED USE OF BUSINESS DATA
Customer grants Company a limited, non-exclusive right to access, use, reproduce, transmit, store, analyze, and otherwise process Business Data solely as reasonably necessary to provide the Services, operate and maintain the Services, provide AI-powered analysis and recommendations, generate Customer-specific reports and outputs, provide customer support, maintain system security, prevent fraud, abuse, and unauthorized access, perform backup and disaster recovery, comply with applicable law. Company will not sell Customer Business Data.
5. CONFIDENTIAL BUSINESS INFORMATION
5.1 Confidential Treatment
Company will treat Customer Business Data as Customer Confidential Information and will use reasonable administrative, technical, and organizational safeguards to protect Customer Business Data against unauthorized access, use, disclosure, alteration, or destruction.
5.2 Limited Disclosure
Company will disclose Customer Business Data only to authorized Company personnel, authorized AI Providers, authorized Subprocessors, professional advisors subject to confidentiality obligations, or other third parties as required to provide the Services. Company may also disclose Business Data where required by applicable law.
6. ARTIFICIAL INTELLIGENCE DATA USE
6.1 No General-Purpose Model Training
Company will not use Customer Business Data to train, fine-tune, or otherwise improve any general-purpose artificial intelligence or machine learning model unless Customer has expressly authorized such use in writing.
6.2 Customer-Specific AI Processing
Company may use Customer Business Data as input to AI Services for the purpose of generating Customer specific IT assessments, cybersecurity assessments, technology recommendations, risk analyses, technology roadmaps, executive reports, summaries, strategic recommendations, and other outputs requested through the Services.
6.3 No Cross-Customer Disclosure
Company will maintain reasonable technical and organizational controls designed to prevent Customer Business Data from being disclosed to or used to generate Customer-specific outputs for another customer.
6.4 AI Provider Restrictions
Where Company uses third-party AI Providers, Company will use commercially reasonable efforts to ensure that such providers process Customer Business Data only as necessary to provide the applicable services and do not use Customer Business Data to train general-purpose models except where Customer has authorized such use.
6.5 AI Processing Locations
Customer acknowledges that Business Data may be transmitted to and processed by Company’s authorized AI Providers and infrastructure providers in accordance with this Agreement.
7. AI OUTPUTS AND HUMAN OVERSIGHT
7.1 Advisory Nature
AI-generated information, assessments, recommendations, analyses, and other outputs are intended to assist Customer and its management in making business and technology decisions.
7.2 No Guarantee of Accuracy
AI-generated outputs may contain inaccuracies, omissions, outdated information, or other errors. Company does not warrant that every AI-generated recommendation will be accurate, complete, or suitable for Customer’s particular circumstances
7.3 Customer Responsibility
Customer remains responsible for reviewing and validating material recommendations before implementing them, including decisions concerning cybersecurity, technology investments, infrastructure, software, vendors, compliance, business continuity, risk management, and other material business decisions.
8. SECURITY
Company will maintain commercially reasonable administrative, technical, and physical safeguards appropriate to the nature of the Services and the sensitivity of Customer Business Data. Such safeguards may include encryption of Business Data in transit and at rest, access controls, least-privilege access, authentication for privileged access, employee confidentiality obligations, security awareness training, vulnerability management, logging and monitoring, incident response procedures, backup procedures, disaster recovery procedures, secure software development practices, and periodic security assessments.
9. SECURITY INCIDENTS
9.1 Notification
If Company confirms a Security Incident affecting Customer Business Data, Company will notify Customer without undue delay and, where reasonably practicable, within 72 hours after confirmation
9.2 Incident Information
To the extent reasonably known, Company will provide information concerning the nature of the Security Incident, the affected systems, the categories of Business Data affected, the approximate scope of the incident, mitigation measures taken, and measures being implemented to prevent recurrence.
9.3 Cooperation
Company will reasonably cooperate with Customer in investigating and responding to a Security Incident.
10. SUBPROCESSORS AND AI PROVIDERS
10.1 Authorization
Customer authorizes Company to use third-party Subprocessors and AI Providers reasonably necessary to provide the Services.
10.2 Subprocessor Requirements
Company will require material Subprocessors that have access to Customer Business Data to maintain appropriate confidentiality and security obligations.
10.3 Subprocessor List
Company may maintain a list of current material Sub-processors available upon written request. Company may update its Subprocessors from time to time as reasonably necessary to operate the Services.
11. DATA RETENTION
Company will retain Customer Business Data for the duration of Customer’s subscription and for a reasonable period thereafter as necessary for backup, disaster recovery, legal compliance, dispute resolution, security, fraud prevention, or enforcement of contractual rights. Unless otherwise specified in the Terms and Conditions, Customer Business Data will be deleted from active production systems following termination of the applicable subscription, subject to Company’s standard backup and deletion procedures.
12. DATA RETURN AND DELETION
Following termination of the Services, Customer may request an export of its Business Data during the period specified in the Subscription Agreement. Company will use commercially reasonable efforts to provide Customer Business Data in a commonly used and reasonably accessible format. Following the applicable retention period, Company will delete Customer Business Data from active systems. Backup copies may remain until deleted in accordance with Company’s normal backup lifecycle.
13. AGGREGATED AND DE-IDENTIFIED INFORMATION
Company may create aggregated, statistical, or de-identified information derived from use of the Services (“Aggregated Information”). Aggregated Information will not identify Customer or disclose Customer’s Confidential Information. Company may use Aggregated Information for legitimate business purposes, including analytics, benchmarking, service performance, security, research, product development, and business intelligence. Company will not attempt to reverse engineer or reidentify Aggregated Information except where reasonably necessary for security, compliance, or other legitimate purposes.
14. SYSTEM TELEMETRY
Company may collect technical and operational information relating to Customer’s use of the Services, including system performance information, error logs, application activity, feature utilization, device and browser information, security events, usage metrics, and other technical telemetry. Company may use such information to operate, maintain, secure, troubleshoot, and improve the Services. Company will not use telemetry to disclose Customer Confidential Information to another customer.
15. CUSTOMER RESPONSIBILITIES
Customer is responsible for determining what Business Data is appropriate to submit to the Services, ensuring that Customer has the necessary rights to provide Business Data to Company, ensuring that Customer’s use of the Services complies with applicable law, maintaining appropriate account credentials, controlling access to Customer accounts, configuring integrations appropriately, protecting authentication credentials, reviewing AI-generated outputs before making material decisions, and not intentionally submitting prohibited or regulated information unless expressly authorized.
16. PROHIBITED DATA
Unless expressly agreed in writing, Customer will not intentionally submit Social Security numbers, government identification numbers, payment card information, protected health information, private encryption keys, passwords or authentication secrets, biometric information, classified information, highly sensitive personal information, or other specially regulated information.
If Customer requires the Services to process such information, the parties must first agree in writing on appropriate additional contractual, technical, and security requirements.
17. LEGAL AND REGULATORY REQUIREMENTS
Each party will comply with laws applicable to its respective activities under the Terms and Conditions. Because the Services are intended primarily to process Business Data rather than Personal Information, Company’s obligations under privacy laws will generally apply only to the extent Company actually processes information subject to such laws. Nothing in this Agreement prevents either party from complying with a legal obligation applicable to it.
18. INTERNATIONAL PROCESSING
Customer acknowledges that Company and its authorized service providers may process Business Data in countries other than Customer’s jurisdiction. Company will maintain commercially reasonable safeguards appropriate to the nature of the Business Data and applicable legal requirements.
19. GOVERNMENT REQUESTS
Company may disclose Customer Business Data where required by law, subpoena, court order, or governmental authority. Where legally permitted, Company will provide Customer with reasonable notice and reasonably cooperate with Customer’s efforts to limit or challenge the disclosure. Company will disclose only the information it is legally required to disclose.
20. AUDITS AND SECURITY INFORMATION
Upon reasonable request, Company may provide Customer with available information reasonably necessary to demonstrate Company’s compliance with its contractual security obligations. Such information may include security policies, security questionnaires, third-party audit reports, certifications, penetration testing summaries, and descriptions of technical and organizational security measures. Any Customer audit will be conducted in a manner designed to minimize disruption to Company and protect the confidential information of Company and its other customers.
21. CONFIDENTIALITY SURVIVAL
Company’s obligations concerning the confidentiality and protection of Customer Business Data will survive termination of the Terms and Conditions for so long as Company retains Customer Business Data.
22. CHANGES TO THIS AGREEMENT
Company may modify this Agreement from time to time to reflect changes in the Services, technology, business practices, or applicable law. If Company makes a material change that materially reduces the protections applicable to Customer Business Data, Company will provide reasonable advance notice.
23. NO PERSONAL INFORMATION WARRANTY
Customer acknowledges that the Services are designed primarily for Business Data and that Customer is responsible for determining whether information submitted to the Services contains Personal Information. Company does not undertake to provide the Services as a platform for the collection, storage, or processing of Personal Information unless expressly agreed in writing.
24. ORDER OF PRECEDENCE
In the event of a conflict, applicable mandatory law will control; this Agreement will control with respect to privacy, confidentiality, and Business Data protection; the Terms and Conditions will control with respect to commercial terms; and an applicable Order Form will control with respect to Customer-specific commercial terms.
25. TERM AND TERMINATION
This Agreement will remain effective for so long as Company processes Customer Business Data. Provisions concerning ownership, confidentiality, security, data deletion, intellectual property, and any other provisions that by their nature should survive termination will survive termination.
26. CONTACT INFORMATION
Privacy and Business Data inquiries may be directed as described in the Terms and Conditions.
EXHIBIT A
AI DATA PROTECTION PRINCIPLES
1. Customer Ownership
Customer retains ownership of its Business Data.
2. No Unauthorized Training
Customer Business Data will not be used to train general-purpose AI models without Customer’s express written authorization.
3. No Cross-Customer Use
Customer Business Data will not be used to provide Customer-specific services or outputs to another Customer.
4. Confidentiality
Customer Business Data will be treated as Confidential Information.
5. Controlled AI Providers
Company will use reasonable measures to ensure that third-party AI Providers are subject to appropriate contractual and security requirements.
6. AI Advisory Function
AI-generated outputs are intended to assist, rather than replace, Customer’s management and technology professionals.
7. Customer Review
Customer remains responsible for reviewing material AI-generated recommendations before implementation.