...

PRIVACY POLICY

ROBINSON HOLDINGS, INC. D/B/A ROBINSON GROUP CONSULTING, INC. CADENZA.AI PLATFORM

PRIVACY POLICY FOR AI FEATURE USAGE & SUBSCRIPTION SERVICES

Effective Date: April 10, 2026

Last Modified: August 24, 2026

Cadenza.AI is a subscription-based AI-powered virtual Chief Information Officer platform offered by Robinson  Holdings, Inc., an Illinois corporation d/b/a Robinson Group Consulting, Inc. (“Company,” “we,” “us,” or “our”)  that delivers technology advisory services, Gap Analysis, and strategic IT recommendations based on user provided organizational data. 

We are committed to providing you with ownership, control and privacy over your business data. This Privacy  Policy (“Policy”) sets out how we collect, store, process, transfer, share, protect, disclose and use data that  identifies or is associated with the Customer (“Customer,” “you,” or “your”) in connection with Company’s  subscription-based artificial intelligence-powered virtual Chief Information Officer platform and related  services (collectively, the “Services”). 

This Policy forms part of and is incorporated into the applicable Terms and Conditions, Order Form, or other  agreement governing Customer’s use of the Services

1. DEFINITIONS

1.1 “Business Data”

“Business Data” means all non-public business, commercial, operational, technical, financial, strategic,  organizational, information technology, cybersecurity, infrastructure, vendor, contractual, and other  proprietary information submitted to, uploaded to, transmitted through, or otherwise made available to the  Services by or on behalf of Customer.  

Business Data may include, without limitation, information concerning Customer’s information technology  environment, hardware and software inventories, network architecture and configurations, cloud  infrastructure, cybersecurity posture and assessments, vulnerabilities, risks and security findings, technology  policies and procedures, IT budgets and technology expenditures, vendor and supplier information, vendor  contracts and agreements, technology licensing information, business continuity and disaster recovery  information, IT governance information, technology roadmaps, strategic plans, organizational information,  operational processes, internal assessments, technology-related financial information, compliance and risk management information, business reports, documents and files, system and application information, and  other confidential or proprietary business information provided by Customer.  

“Business Data” means all non-public business, commercial, operational, technical, financial, strategic,  organizational, information technology, cybersecurity, infrastructure, vendor, contractual, and other  proprietary information submitted to, uploaded to, transmitted through, or otherwise made available to the  Services by or on behalf of Customer.  

Business Data may include, without limitation, information concerning Customer’s information technology  environment, hardware and software inventories, network architecture and configurations, cloud  infrastructure, cybersecurity posture and assessments, vulnerabilities, risks and security findings, technology  policies and procedures, IT budgets and technology expenditures, vendor and supplier information, vendor  contracts and agreements, technology licensing information, business continuity and disaster recovery  information, IT governance information, technology roadmaps, strategic plans, organizational information,  operational processes, internal assessments, technology-related financial information, compliance and risk management information, business reports, documents and files, system and application information, and  other confidential or proprietary business information provided by Customer.  

Business Data also includes information generated by the Services specifically for Customer based upon  Customer’s Business Data, including reports, assessments, analyses, recommendations, technology  roadmaps, risk assessments, and other Customer-specific outputs, except that Company retains ownership  of its underlying software, models, algorithms, methodologies, know-how, and other intellectual property.

1.2 “Confidential Information”

“Confidential Information” means non-public information disclosed by one party to the other party that is  identified as confidential or that reasonably should be understood to be confidential given the nature of the  information and the circumstances of disclosure. Customer’s Business Data will be considered Customer’s  Confidential Information.

1.3 “AI Services”

“AI Services” means artificial intelligence, machine learning, generative artificial intelligence, large language  models, predictive analytics, automated reasoning, or similar technologies incorporated into or used to  provide the Services.

1.4 “AI Provider”

“AI Provider” means a third-party provider of artificial intelligence, machine learning, large language model,  cloud computing, or related technology used by Company in connection with the Services.

1.5 “Security Incident”

“Security Incident” means a confirmed unauthorized access to, acquisition of, disclosure of, alteration of, loss  of, or destruction of Customer Business Data within Company’s systems.

1.6 “Subprocessor”

“Subprocessor” means a third party engaged by Company to process or host Customer Business Data on  behalf of Company in connection with the Services.

1.7 “Personal Information”

“Personal Information” means information relating to an identified or identifiable individual that is protected  as personal information, personal data, personally identifiable information, or a substantially similar category  under applicable privacy or data protection law. The Services are not designed or intended to collect or process  Personal Information as a primary purpose.

2. NATURE OF THE SERVICES AND DATA

2.1 Business-Focused Platform

The Services are designed to function as an AI-powered virtual Chief Information Officer for businesses and  organizations. The Services are intended primarily to process Business Data rather than Personal Information. 

2.2 No Intended Processing of Personal Information

Customer acknowledges that the Services are not intended to serve as a repository for consumer, employee,  patient, customer, or other Personal Information. Customer agrees not to intentionally submit Personal  Information to the Services unless expressly authorized in writing by Company.

2.3 Incidental Personal Information

The parties acknowledge that Business Data may occasionally contain incidental information relating to  individuals, such as business names, business email addresses, business telephone numbers, employee  names, job titles, vendor contacts, or similar information ordinarily contained within business records. Such  incidental information does not change the fundamental business-to-business nature of the Services. If Customer submits Personal Information that is outside the intended scope of the Services, Customer remains  responsible for ensuring that such submission and processing is legally permissible.

3. OWNERSHIP OF BUSINESS DATA

3.1 Customer Ownership

As between Company and Customer, Customer retains all right, title, and interest in and to Customer’s  Business Data. Nothing in this Agreement transfers ownership of Customer Business Data to Company.

3.2 Company Intellectual Property

Company retains all right, title, and interest in and to the Services, software, source code, object code,  algorithms, AI models, model architecture, prompts and prompt frameworks developed by Company,  methodologies, templates, workflows, documentation, know-how, system architecture, and other Company  intellectual property.

3.3 Customer-Specific Outputs

Customer owns reports, assessments, recommendations, technology roadmaps, analyses, and other outputs  generated specifically for Customer from Customer’s Business Data, subject to Company’s ownership of its  underlying technology, methodologies, models, templates, and intellectual property.

4. PERMITTED USE OF BUSINESS DATA

Customer grants Company a limited, non-exclusive right to access, use, reproduce, transmit, store, analyze,  and otherwise process Business Data solely as reasonably necessary to provide the Services, operate and  maintain the Services, provide AI-powered analysis and recommendations, generate Customer-specific  reports and outputs, provide customer support, maintain system security, prevent fraud, abuse, and  unauthorized access, perform backup and disaster recovery, comply with applicable law. Company will not  sell Customer Business Data.

5. CONFIDENTIAL BUSINESS INFORMATION

5.1 Confidential Treatment

Company will treat Customer Business Data as Customer Confidential Information and will use reasonable  administrative, technical, and organizational safeguards to protect Customer Business Data against  unauthorized access, use, disclosure, alteration, or destruction.

5.2 Limited Disclosure

Company will disclose Customer Business Data only to authorized Company personnel, authorized AI  Providers, authorized Subprocessors, professional advisors subject to confidentiality obligations, or other  third parties as required to provide the Services. Company may also disclose Business Data where required by  applicable law.

6. ARTIFICIAL INTELLIGENCE DATA USE

6.1 No General-Purpose Model Training

Company will not use Customer Business Data to train, fine-tune, or otherwise improve any general-purpose  artificial intelligence or machine learning model unless Customer has expressly authorized such use in writing. 

6.2 Customer-Specific AI Processing

Company may use Customer Business Data as input to AI Services for the purpose of generating Customer specific IT assessments, cybersecurity assessments, technology recommendations, risk analyses,  technology roadmaps, executive reports, summaries, strategic recommendations, and other outputs  requested through the Services.

6.3 No Cross-Customer Disclosure

Company will maintain reasonable technical and organizational controls designed to prevent Customer  Business Data from being disclosed to or used to generate Customer-specific outputs for another customer.

6.4 AI Provider Restrictions

Where Company uses third-party AI Providers, Company will use commercially reasonable efforts to ensure  that such providers process Customer Business Data only as necessary to provide the applicable services and  do not use Customer Business Data to train general-purpose models except where Customer has authorized  such use.

6.5 AI Processing Locations

Customer acknowledges that Business Data may be transmitted to and processed by Company’s authorized  AI Providers and infrastructure providers in accordance with this Agreement.

7. AI OUTPUTS AND HUMAN OVERSIGHT

7.1 Advisory Nature

AI-generated information, assessments, recommendations, analyses, and other outputs are intended to  assist Customer and its management in making business and technology decisions.

7.2 No Guarantee of Accuracy

AI-generated outputs may contain inaccuracies, omissions, outdated information, or other errors. Company  does not warrant that every AI-generated recommendation will be accurate, complete, or suitable for  Customer’s particular circumstances

7.3 Customer Responsibility

Customer remains responsible for reviewing and validating material recommendations before implementing  them, including decisions concerning cybersecurity, technology investments, infrastructure, software,  vendors, compliance, business continuity, risk management, and other material business decisions.

8. SECURITY

Company will maintain commercially reasonable administrative, technical, and physical safeguards  appropriate to the nature of the Services and the sensitivity of Customer Business Data. Such safeguards may  include encryption of Business Data in transit and at rest, access controls, least-privilege access,  authentication for privileged access, employee confidentiality obligations, security awareness training,  vulnerability management, logging and monitoring, incident response procedures, backup procedures,  disaster recovery procedures, secure software development practices, and periodic security assessments.

9. SECURITY INCIDENTS

9.1 Notification

If Company confirms a Security Incident affecting Customer Business Data, Company will notify Customer  without undue delay and, where reasonably practicable, within 72 hours after confirmation

9.2 Incident Information

To the extent reasonably known, Company will provide information concerning the nature of the Security  Incident, the affected systems, the categories of Business Data affected, the approximate scope of the  incident, mitigation measures taken, and measures being implemented to prevent recurrence.

9.3 Cooperation

Company will reasonably cooperate with Customer in investigating and responding to a Security Incident.

10. SUBPROCESSORS AND AI PROVIDERS

10.1 Authorization

Customer authorizes Company to use third-party Subprocessors and AI Providers reasonably necessary to  provide the Services.

10.2 Subprocessor Requirements

Company will require material Subprocessors that have access to Customer Business Data to maintain  appropriate confidentiality and security obligations.

10.3 Subprocessor List

Company may maintain a list of current material Sub-processors available upon written request. Company  may update its Subprocessors from time to time as reasonably necessary to operate the Services.

11. DATA RETENTION

Company will retain Customer Business Data for the duration of Customer’s subscription and for a reasonable  period thereafter as necessary for backup, disaster recovery, legal compliance, dispute resolution, security,  fraud prevention, or enforcement of contractual rights. Unless otherwise specified in the Terms and Conditions, Customer Business Data will be deleted from active production systems following termination of  the applicable subscription, subject to Company’s standard backup and deletion procedures.

12. DATA RETURN AND DELETION

Following termination of the Services, Customer may request an export of its Business Data during the period  specified in the Subscription Agreement. Company will use commercially reasonable efforts to provide  Customer Business Data in a commonly used and reasonably accessible format. Following the applicable  retention period, Company will delete Customer Business Data from active systems. Backup copies may  remain until deleted in accordance with Company’s normal backup lifecycle.

13. AGGREGATED AND DE-IDENTIFIED INFORMATION

Company may create aggregated, statistical, or de-identified information derived from use of the Services  (“Aggregated Information”). Aggregated Information will not identify Customer or disclose Customer’s  Confidential Information. Company may use Aggregated Information for legitimate business purposes,  including analytics, benchmarking, service performance, security, research, product development, and  business intelligence. Company will not attempt to reverse engineer or reidentify Aggregated Information  except where reasonably necessary for security, compliance, or other legitimate purposes.

14. SYSTEM TELEMETRY

Company may collect technical and operational information relating to Customer’s use of the Services,  including system performance information, error logs, application activity, feature utilization, device and  browser information, security events, usage metrics, and other technical telemetry. Company may use such  information to operate, maintain, secure, troubleshoot, and improve the Services. Company will not use  telemetry to disclose Customer Confidential Information to another customer.

15. CUSTOMER RESPONSIBILITIES

Customer is responsible for determining what Business Data is appropriate to submit to the Services, ensuring  that Customer has the necessary rights to provide Business Data to Company, ensuring that Customer’s use  of the Services complies with applicable law, maintaining appropriate account credentials, controlling access  to Customer accounts, configuring integrations appropriately, protecting authentication credentials,  reviewing AI-generated outputs before making material decisions, and not intentionally submitting prohibited  or regulated information unless expressly authorized.

16. PROHIBITED DATA

Unless expressly agreed in writing, Customer will not intentionally submit Social Security numbers,  government identification numbers, payment card information, protected health information, private encryption keys, passwords or authentication secrets, biometric information, classified information, highly  sensitive personal information, or other specially regulated information. 

If Customer requires the Services to process such information, the parties must first agree in writing on  appropriate additional contractual, technical, and security requirements.

17. LEGAL AND REGULATORY REQUIREMENTS

Each party will comply with laws applicable to its respective activities under the Terms and Conditions.  Because the Services are intended primarily to process Business Data rather than Personal Information,  Company’s obligations under privacy laws will generally apply only to the extent Company actually processes  information subject to such laws. Nothing in this Agreement prevents either party from complying with a legal  obligation applicable to it.

18. INTERNATIONAL PROCESSING

Customer acknowledges that Company and its authorized service providers may process Business Data in  countries other than Customer’s jurisdiction. Company will maintain commercially reasonable safeguards  appropriate to the nature of the Business Data and applicable legal requirements.

19. GOVERNMENT REQUESTS

Company may disclose Customer Business Data where required by law, subpoena, court order, or  governmental authority. Where legally permitted, Company will provide Customer with reasonable notice and  reasonably cooperate with Customer’s efforts to limit or challenge the disclosure. Company will disclose only  the information it is legally required to disclose.

20. AUDITS AND SECURITY INFORMATION

Upon reasonable request, Company may provide Customer with available information reasonably necessary  to demonstrate Company’s compliance with its contractual security obligations. Such information may  include security policies, security questionnaires, third-party audit reports, certifications, penetration testing  summaries, and descriptions of technical and organizational security measures. Any Customer audit will be  conducted in a manner designed to minimize disruption to Company and protect the confidential information  of Company and its other customers.

21. CONFIDENTIALITY SURVIVAL

Company’s obligations concerning the confidentiality and protection of Customer Business Data will survive  termination of the Terms and Conditions for so long as Company retains Customer Business Data.

22. CHANGES TO THIS AGREEMENT

Company may modify this Agreement from time to time to reflect changes in the Services, technology,  business practices, or applicable law. If Company makes a material change that materially reduces the  protections applicable to Customer Business Data, Company will provide reasonable advance notice.

23. NO PERSONAL INFORMATION WARRANTY

Customer acknowledges that the Services are designed primarily for Business Data and that Customer is  responsible for determining whether information submitted to the Services contains Personal Information.  Company does not undertake to provide the Services as a platform for the collection, storage, or processing  of Personal Information unless expressly agreed in writing.

24. ORDER OF PRECEDENCE

In the event of a conflict, applicable mandatory law will control; this Agreement will control with respect to  privacy, confidentiality, and Business Data protection; the Terms and Conditions will control with respect to  commercial terms; and an applicable Order Form will control with respect to Customer-specific commercial  terms.

25. TERM AND TERMINATION

This Agreement will remain effective for so long as Company processes Customer Business Data. Provisions  concerning ownership, confidentiality, security, data deletion, intellectual property, and any other provisions  that by their nature should survive termination will survive termination.

26. CONTACT INFORMATION

Privacy and Business Data inquiries may be directed as described in the Terms and Conditions.

EXHIBIT A

AI DATA PROTECTION PRINCIPLES

1. Customer Ownership

Customer retains ownership of its Business Data.

2. No Unauthorized Training

Customer Business Data will not be used to train general-purpose AI models without Customer’s express  written authorization.

3. No Cross-Customer Use

Customer Business Data will not be used to provide Customer-specific services or outputs to another  Customer.

4. Confidentiality

Customer Business Data will be treated as Confidential Information. 

5. Controlled AI Providers

Company will use reasonable measures to ensure that third-party AI Providers are subject to appropriate  contractual and security requirements.

6. AI Advisory Function

AI-generated outputs are intended to assist, rather than replace, Customer’s management and technology  professionals.

7. Customer Review

Customer remains responsible for reviewing material AI-generated recommendations before implementation.

Back to Top