Privacy Policy Effective Date: June 23, 2026 Last Updated: June 23, 2026 This Privacy Policy explains how an agentic AI platform for alternative investment managers (the “Platform,” “Company,” “we,” “us,” or “our”) collects, uses, shares, stores, and protects personal information and other data processed through the Platform. This draft is intended as a working template for a business serving private equity firms, hedge funds, venture capital firms, credit funds, real assets managers, fund-of-funds, and related advisory businesses. It should be tailored to the Company’s specific products, workflows, deployment model, and applicable laws before publication. 1. Scope This Privacy Policy applies to information collected when: Visitors access the Company’s websites, landing pages, and online services. Prospective and current customers, investors, consultants, and vendors interact with the Company. Authorized users use the Platform, including any web application, API, browser extension, workflow automation tool, analytics tool, or AI agent functionality. The Company receives information from customers or third parties in connection with onboarding, implementation, support, security review, or product usage. This Privacy Policy does not govern information processed by the Company solely on behalf of customers under a separate master services agreement, data processing agreement, or similar contract where the Company acts as a service provider, processor, or similar role. In those cases, the customer remains responsible for its own privacy notices and for ensuring it has a lawful basis to provide data to the Company. 2. Information Collected Depending on the nature of the relationship with the Company and how the Platform is used, the Company may collect the following categories of information: A. Business Contact Information Name, title, employer, department, work email address, work phone number, office address, and account identifiers. Communications preferences and records relating to demos, sales, onboarding, contracting, billing, and support. B. Account and Authentication Information Usernames, hashed passwords, single sign-on identifiers, multi-factor authentication data, account status, role-based permissions, and administrator settings. Security credentials and authentication logs necessary to verify access and maintain account integrity. C. Customer Content and Instructions Files, prompts, workflows, documents, spreadsheets, investment memos, due diligence materials, portfolio company data, policies, research notes, transcripts, messages, and other content submitted to the Platform by or on behalf of customers. Configuration settings, agent instructions, automations, and task definitions created by customer users. D. Usage and Technical Information IP address, device identifiers, browser type, operating system, approximate location derived from IP, timestamps, referring URLs, session activity, feature usage, error logs, and performance telemetry. Audit trails relating to user actions, API calls, workflow execution, model interactions, and administrative events. E. AI Interaction Data User prompts, system instructions, retrieved context, model outputs, feedback signals, evaluation results, and safety review metadata generated through use of agentic or generative AI features. Human review records when outputs are escalated for quality assurance, incident response, abuse prevention, or support. F. Compliance and Due Diligence Information Information submitted during security reviews, vendor diligence, sanctions screening, anti-money laundering reviews, know-your-business reviews, regulatory questionnaires, or procurement processes. Professional and organizational details needed to assess eligibility, contractual authority, risk, or legal compliance. G. Payment and Commercial Information Billing contact details, invoicing information, subscription records, transaction history, and limited payment-related metadata. Payment card information may be collected and processed by third-party payment processors rather than stored directly by the Company. H. Information from Third Parties Information from customer administrators, identity providers, data integration partners, CRM systems, analytics vendors, public sources, and service providers. Information provided by recruiters, references, or business partners where relevant to an employment or commercial relationship. 3. Sensitive and Regulated Data The Platform is designed for professional use in investment management environments. Customers may choose to submit information that is confidential, material nonpublic, sensitive, or subject to legal or contractual restrictions. Unless expressly agreed in writing, the Company does not intend the Platform to be used for: Consumer-facing processing of special category or sensitive personal data requiring enhanced legal protections. Protected health information regulated by HIPAA. Payment card data requiring PCI DSS handling beyond approved processor workflows. Any data the customer is prohibited from sharing under applicable law, fiduciary duty, contract, court order, or internal policy. Customers are responsible for configuring the Platform and their internal workflows appropriately, including applying access controls, review procedures, retention settings, and human oversight for high-risk use cases. 4. How Information Is Used The Company may use collected information to: Provide, operate, maintain, secure, and improve the Platform and related services. Authenticate users, enforce permissions, prevent fraud, detect abuse, and protect systems, data, and users. Process customer requests, execute workflows, generate outputs, and support AI-assisted search, analysis, summarization, extraction, monitoring, and automation. Respond to inquiries, provide customer support, troubleshoot issues, and communicate about the Platform. Manage contracts, invoicing, collections, procurement, audits, and vendor relationships. Conduct analytics, service monitoring, testing, debugging, forecasting, and product development. Comply with legal obligations, enforce agreements, establish or defend legal claims, and protect the rights, safety, and security of the Company, customers, and third parties. Create aggregated or de-identified insights, where permitted by law and contract. If the Company uses customer content to train or fine-tune general models, such use should be disclosed expressly in customer contracts and product settings. A customer-facing version of this policy should state clearly whether customer content is or is not used for model training. 5. Legal Bases for Processing Where required by applicable law, the Company processes personal information on one or more of the following legal bases: Performance of a contract or steps taken at the request of the data subject before entering into a contract. Legitimate interests, such as securing systems, improving services, managing business relationships, and preventing misuse, provided those interests are not overridden by applicable rights. Compliance with legal obligations. Consent, where required and obtained. Jurisdiction-specific rights and disclosures may apply depending on the location of the individual, the customer, and the Company’s operations. 6. AI-Specific Processing Disclosures Because the Platform includes agentic and generative AI capabilities, additional disclosures are important: Inputs may be processed by foundation model providers, cloud infrastructure providers, retrieval systems, and workflow orchestration tools acting on the Company’s behalf. Outputs may be probabilistic and may contain errors, omissions, or outdated information; they should be reviewed by qualified personnel before being relied upon for investment, compliance, legal, tax, accounting, or valuation decisions. Agentic workflows may trigger downstream actions such as drafting documents, updating records, routing tasks, sending notifications, or initiating analyses, based on user configuration and permissions. The Company may log prompts, outputs, and execution metadata to monitor performance, investigate incidents, enforce usage restrictions, and improve safety and reliability. The Company may apply automated filtering, classification, redaction, policy enforcement, and human review to reduce security, privacy, legal, and model risk. 7. Sharing of Information The Company may share information with: Service providers and subprocessors that support hosting, infrastructure, analytics, monitoring, identity management, payments, security, customer support, communications, and AI functionality. Customer-authorized integrations and third-party applications at the customer’s direction. Professional advisors, auditors, insurers, lenders, and corporate transaction counterparties subject to appropriate confidentiality obligations. Law enforcement, regulators, courts, or other third parties where required by law, subpoena, legal process, or where reasonably necessary to protect rights, property, or safety. Affiliates or successors in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets. The Company does not sell personal information in the ordinary sense of exchanging personal information for money. However, some privacy laws define “sale,” “sharing,” or “targeted advertising” broadly, and supplemental disclosures may be needed depending on cookie and advertising practices. 8. Data Retention The Company retains information for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, including to provide services, comply with legal obligations, resolve disputes, enforce agreements, maintain security logs, and support legitimate business needs. Retention periods may vary based on: The type and sensitivity of the information. The duration of the customer relationship. Applicable contractual commitments. Legal, regulatory, tax, accounting, and recordkeeping requirements. Backup, disaster recovery, and security logging practices. Customers may have administrative tools or contractual rights to manage deletion and retention of customer content. Deletion from active systems may not occur immediately and may be delayed in backups or archived environments for a limited period. 9. Data Security The Company uses administrative, technical, and physical safeguards designed to protect information against unauthorized access, loss, misuse, alteration, and disclosure. These measures may include: Encryption in transit and at rest where appropriate. Access controls, least-privilege permissions, and role-based administration. Logging, monitoring, anomaly detection, and incident response procedures. Vendor risk management and contractual security commitments. Secure development and change management practices. No system is completely secure, and the Company cannot guarantee absolute security. 10. International Data Transfers The Company and its service providers may process information in the United States and other jurisdictions where the Company or its providers operate. Where required by law, the Company will implement appropriate safeguards for cross-border transfers, which may include contractual clauses, adequacy mechanisms, or other approved transfer measures. 11. Cookies and Similar Technologies The Company may use cookies, pixels, SDKs, local storage, and similar technologies to: Keep users signed in and remember preferences. Understand website and product usage. Maintain security and prevent fraud. Measure campaign effectiveness and improve marketing. Where required by law, the Company will provide notice and obtain consent for non-essential cookies or similar technologies. Additional details may be provided in a separate Cookie Notice. 12. Individual Rights Depending on applicable law, individuals may have the right to request: Access to personal information. Correction of inaccurate personal information. Deletion of personal information. Restriction of or objection to certain processing. Portability of personal information. Withdrawal of consent where processing is based on consent. Appeal of certain privacy-related decisions. These rights may be limited in some circumstances, including where information is processed on behalf of a business customer, where legal exemptions apply, or where the Company must retain information to comply with law or defend legal claims. The Company may take reasonable steps to verify identity before responding. 13. Customer Responsibilities Because the Platform is built for institutional investment workflows, customers are responsible for: Determining whether their use of the Platform complies with applicable securities, privacy, employment, consumer protection, intellectual property, and confidentiality laws. Providing required notices to employees, investors, counterparties, portfolio companies, and other individuals whose information may be submitted to the Platform. Obtaining necessary rights, consents, and authorizations before uploading or connecting data sources. Reviewing and validating AI outputs before making decisions or taking action. Configuring permissions, retention settings, approval steps, and escalation rules consistent with internal governance. 14. Children’s Privacy The Platform is intended for business use and is not directed to children. The Company does not knowingly collect personal information from children in connection with the Platform. 15. Changes to This Privacy Policy The Company may update this Privacy Policy from time to time to reflect changes in the Platform, legal requirements, technical practices, or business operations. When required, the Company will provide notice by updating the effective date, posting the revised policy, or using other appropriate communication channels. 16. Contact Information Questions or requests relating to this Privacy Policy may be directed to: [Company Legal Name] [Privacy Team or Data Protection Officer] [Email Address] [Mailing Address] [Phone Number] 17. Optional Addenda To Consider Before Publication A production-ready version may need one or more supplemental sections covering: U.S. state privacy disclosures, including California-specific rights and notice requirements. UK and EEA disclosures, representative details, and transfer mechanisms. Subprocessor disclosures and infrastructure locations. Whether customer data is used for model training, fine-tuning, benchmarking, or product improvement. Automated decision-making disclosures where legally required. Sector-specific restrictions relating to broker-dealers, registered investment advisers, commodity pool operators, or other regulated entities. A standalone cookie notice. Contractual controller/processor language aligned with the Company’s DPA and terms of service.
