Version 1.0 — Draft for Attorney Review
PRIMEMATCH AI™
PRIVACY POLICY
Enterprise Partner Intelligence Platform
Version 1.0 — Draft for Attorney Review
Effective Date: February 2026
Last Updated: September 2026
Controller / Provider: Lyfe Share Inc., 6991 Peachtree Industrial Blvd. #400, Suite. A-15, Peachtree Corners, GA 30092
Privacy Contact: michael@lyfeshare.io
IMPORTANT LEGAL NOTICE
This Privacy Policy is a comprehensive first draft prepared for business and legal planning and for review by qualified privacy and technology counsel. It is designed to address a sophisticated AI-enabled, multi-tenant enterprise platform and should be finalized against PrimeMatch AI’s actual data flows, vendors, deployment architecture, cookie configuration, mobile application behavior, international operations, and jurisdictional obligations before publication. Bracketed placeholders require completion or legal confirmation.
TABLE OF CONTENTS
1. Scope and Relationship to Other Agreements
2. Definitions and Proprietary Intelligence Concepts
3. PrimeMatch AI’s Roles as Controller, Business, Processor, and Service Provider
4. Categories of Personal Information and Business Data We Process
5. Sources of Information
6. Purposes of Processing
7. Account Registration, Identity, and Organization Administration
8. Organization DNA™, Opportunity DNA™, and Business Profile Intelligence
9. Partner Intelligence™, Team DNA™, Relationship DNA™, and Reputation Intelligence
10. Proposal DNA™, Proposal Intelligence™, and AI-Assisted Content
11. AI Systems, Inferences, PrimeMatch Confidence™, Trust Score™, and Automated Analysis
12. Knowledge Graph™, Semantic Matching Engine™, and Learning Engine™
13. Opportunity Intelligence™, Forecasting, and Executive Intelligence™
14. Marketplace Intelligence™ and Marketplace Transactions
15. Communications, Messaging, and AI-Generated Communications
16. White-Label Enterprise Portals and Multi-Tenant Environments
17. APIs, Integrations, Connected Services, and Third-Party Data
18. Usage Data, Cookies, Analytics, and Similar Technologies
19. Mobile Applications and Device Information
20. Sensitive, Regulated, and Restricted Information
21. Government Contracting, Procurement, and Public-Sector Information
22. How We Disclose Information
23. Service Providers, Subprocessors, and AI Infrastructure Providers
24. Advertising, Sale, Sharing, and Cross-Context Behavioral Advertising
25. De-Identification, Aggregation, Benchmarking, and Platform Improvement
26. Data Retention and Deletion
27. Security and Incident Response
28. International Data Transfers
29. Privacy Rights and Request Procedures
30. California Privacy Notice
31. Other U.S. State Privacy Rights
32. EEA, United Kingdom, and Switzerland
33. Children and Minors
34. Employment, Applicant, and Business Contact Information
35. Customer Responsibilities and User-Directed Processing
36. Data Processing Addenda and Enterprise Privacy Terms
37. Third-Party Websites, Sources, and Marketplace Providers
38. No Professional Advice; AI Decision-Support Limitations
39. Changes to this Privacy Policy
40. Contact Information; Complaints; Supervisory Authorities
Appendix A. Data Category and Purpose Matrix
Appendix B. Proprietary Intelligence Data Map
Appendix C. U.S. State Privacy Rights Summary
Appendix D. Enterprise / Government Deployment Review Checklist
PRIVACY POLICY
PrimeMatch AI™ is an AI-powered Partner Intelligence Platform designed to help organizations discover potential partners, evaluate teaming opportunities, analyze government and commercial opportunities, develop proposal teams, generate business intelligence, use workflow automation, and receive AI-assisted recommendations. This Privacy Policy explains how [PRIMEMATCH AI LEGAL ENTITY] ("PrimeMatch AI," "we," "us," or "our") collects, uses, derives, discloses, retains, secures, and otherwise processes Personal Information in connection with the Platform.
PrimeMatch AI is not a traditional single-purpose SaaS application. The Platform may operate through multi-tenant cloud services, white-label enterprise portals, APIs, future mobile applications, marketplace functions, AI Agents™, semantic search, machine learning, Reputation Intelligence, partner and team recommendations, proposal assistance, executive dashboards, opportunity forecasting, analytics, business intelligence, and workflow automation. Accordingly, information processed through PrimeMatch AI may include data supplied directly by users, data supplied by enterprise customers, information obtained from public or licensed sources, metadata, relationship information, and proprietary inferences generated by PrimeMatch AI’s intelligence systems.
This Policy is intended to be read together with the PrimeMatch AI™ Master Terms of Service, any applicable Order Form, Enterprise Agreement, Data Processing Addendum ("DPA"), security addendum, marketplace terms, or other written agreement. If a signed agreement imposes more specific privacy or data-protection obligations, that agreement controls to the extent of the conflict.
This Privacy Policy applies to Personal Information processed through PrimeMatch AI’s websites, web applications, enterprise portals, white-label deployments, APIs, support channels, marketplace functions, events or demonstrations where this Policy is presented, and mobile applications when released. It also applies to Personal Information that PrimeMatch AI receives from customers, authorized users, prospects, partners, vendors, public sources, and integrated third-party services in connection with operating and improving the Platform.
This Policy does not apply to third-party products or services that display their own privacy notices, nor does it govern a customer’s independent processing of information outside the Platform.
Where PrimeMatch AI processes Personal Information solely on behalf of an enterprise customer and under that customer’s documented instructions, the enterprise customer generally determines the purposes and means of that processing. In that context, individuals should ordinarily direct privacy requests to the enterprise customer, and PrimeMatch AI will provide reasonable assistance as required by contract and applicable law.
This Policy describes PrimeMatch AI’s privacy practices. It does not create contractual warranties, service levels, security guarantees, audit rights, data-residency commitments, regulatory certifications, or other obligations beyond those expressly stated in an applicable agreement or required by law.
“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an identified or identifiable individual or household, and includes analogous concepts such as “personal data” under applicable privacy laws. Personal Information does not include information excluded from the applicable statutory definition, such as properly de-identified or aggregated information where recognized by law.
“Customer Data” means information, documents, records, prompts, profiles, communications, files, opportunity materials, proposal materials, business information, and other content submitted to or processed through the Platform by or for a customer. Customer Data may include Personal Information, confidential business information, or public information.
The following names describe proprietary PrimeMatch AI methodologies, software systems, analytical frameworks, scoring systems, marks, or other intellectual property: PrimeMatch AI™, PrimeMatch Confidence™, Organization DNA™, Opportunity DNA™, Team DNA™, Relationship DNA™, Proposal DNA™, Growth DNA™, Trust Score™, Team Strength Index™, PrimeMatch Intelligence™, Partner Intelligence™, Opportunity Intelligence™, Proposal Intelligence™, Executive Intelligence™, Marketplace Intelligence™, Enterprise Intelligence™, AI Agent™, Intelligence Engine™, Semantic Matching Engine™, Knowledge Graph™, and Learning Engine™.
These terms do not describe governmental certifications, regulated credit scores, consumer reports, legal determinations, professional opinions, security clearances, responsibility determinations, or guaranteed predictions. Their use in this Privacy Policy explains how information may be organized or processed and does not transfer any ownership interest in PrimeMatch AI intellectual property.
“AI Output” includes text, summaries, rankings, recommendations, predictions, classifications, forecasts, match results, generated communications, proposal assistance, scores, confidence indicators, and other results produced or assisted by AI, machine learning, semantic matching, rules, retrieval, or automated analytics. “Inference” means information derived, estimated, predicted, classified, or generated from other data, including attributes or relationships that a user did not directly enter.
PrimeMatch AI may determine the purposes and means of processing for account administration, billing, security, fraud prevention, service analytics, product operations, legal compliance, direct customer relationships, marketing subject to applicable law, and certain platform-level improvement activities. In those circumstances, PrimeMatch AI acts as a controller, business, or analogous regulated entity under applicable law.
When an enterprise customer supplies Personal Information and instructs PrimeMatch AI to process that information to provide contracted services, PrimeMatch AI may act as a processor, service provider, contractor, or analogous role. The applicable DPA, Order Form, or enterprise agreement may further define those roles, processing instructions, subprocessors, transfer mechanisms, and assistance obligations.
The same individual’s information may be processed under different legal roles for different purposes. For example, PrimeMatch AI may act as processor for an enterprise customer’s user directory while acting as an independent controller for platform security logs necessary to protect PrimeMatch AI and its customers.
We may process names, usernames, business email addresses, telephone numbers, mailing addresses, organization names, job titles, account identifiers, authentication identifiers, profile images, signatures, and related contact or identity information.
We may process professional history, capabilities, certifications, socioeconomic or business-designation information, NAICS and PSC codes, CAGE or UEI information, organization roles, skills, credentials, contract experience, business size, operating locations, service offerings, industry information, past-performance descriptions, bonding or insurance representations, facility or personnel-clearance representations, and other information relevant to partner and opportunity analysis.
We may process solicitation information, opportunity identifiers, requirements, agency or commercial buyer information, proposal documents, draft narratives, compliance matrices, pricing-related inputs if supplied by a user, teaming information, capture notes, bid/no-bid information, schedules, evaluation criteria, attachments, and generated proposal-assistance content.
We may process relationship histories, introductions, saved partners, match requests, collaboration activity, marketplace listings, provider profiles, transaction-related data, ratings, feedback, disputes, engagement signals, and other data used to support Relationship DNA™, Reputation Intelligence, Trust Score™, Team DNA™, or Marketplace Intelligence™.
Depending on enabled features, we may process subscription plan information, billing contacts, invoices, transaction history, marketplace purchase records, discounts, credits, and payment-status information. Full payment-card information may be collected directly by third-party payment processors rather than PrimeMatch AI.
We may process IP addresses, device identifiers, browser type, operating system, referring URLs, session timestamps, API identifiers, authentication events, feature use, search activity, page interactions, crash data, performance telemetry, security events, audit logs, approximate location derived from IP address, and similar technical information.
We may process customer-support requests, recorded or transcribed meetings where disclosed and permitted, survey responses, product feedback, training interactions, emails, messages, attachments, and communications sent through or about the Platform.
PrimeMatch AI may derive inferred capabilities, keywords, differentiators, gaps, affinity indicators, opportunity fit, partner relevance, relationship signals, proposal issues, confidence levels, team-composition indicators, marketplace signals, and other analytical information through proprietary intelligence systems. Such inferences may be Personal Information when they can be associated with an identifiable individual.
We receive information from users when they register, create profiles, upload capability statements or resumes, configure organization information, search for opportunities, evaluate partners, create teams, use proposal tools, communicate with other users, submit support requests, make marketplace transactions, or otherwise interact with the Platform.
Organizations may provide information about their personnel, contractors, affiliates, subsidiaries, business units, marketplace providers, invited users, or prospective partners. Enterprise administrators may assign roles, permissions, hierarchies, or account attributes and may have authority to access or manage information associated with their tenant.
PrimeMatch AI may obtain or ingest information from public government databases, procurement notices, official agency websites, public business records, corporate websites, publicly available professional profiles, and other lawfully accessible sources relevant to government or commercial contracting. Public availability does not necessarily mean information ceases to be Personal Information under applicable law.
We may receive information from data providers, integration partners, marketplace providers, identity or security vendors, analytics vendors, payment processors, and customer-authorized connected services. Use of third-party data remains subject to applicable licenses and contractual restrictions.
We collect technical, usage, cookie, security, and audit information automatically when individuals access or use the Platform, subject to applicable consent and notice requirements.
We process information to authenticate users, maintain accounts, deliver licensed functionality, operate white-label portals, execute customer-configured workflows, facilitate search and matching, support APIs, provide marketplace functions, and maintain availability and performance.
We process information to produce PrimeMatch Intelligence™, Partner Intelligence™, Opportunity Intelligence™, Proposal Intelligence™, Executive Intelligence™, Marketplace Intelligence™, and Enterprise Intelligence™; to calculate PrimeMatch Confidence™, Trust Score™, and Team Strength Index™; and to create Organization DNA™, Opportunity DNA™, Team DNA™, Relationship DNA™, Proposal DNA™, and Growth DNA™ representations. These functions are decision-support tools and not autonomous business decision-makers.
We process information to protect accounts and tenants, detect anomalous activity, investigate fraud or misuse, enforce access controls, maintain audit logs, prevent unauthorized scraping or API abuse, protect intellectual property, and comply with legal and contractual obligations.
We use information to respond to requests, provide onboarding and training, troubleshoot issues, administer subscriptions and orders, process or reconcile billing, maintain customer relationships, and communicate service notices.
Subject to contractual restrictions and applicable law, we may use Usage Data, feedback, de-identified or aggregated information, and other permitted information to evaluate performance, improve relevance, test features, refine user experience, develop new capabilities, and enhance the Platform. Customer-specific training restrictions, if any, are governed by the applicable DPA or enterprise agreement.
We may process information to establish, exercise, or defend legal claims; comply with subpoenas, court orders, procurement obligations, tax or accounting requirements; conduct corporate transactions; manage insurance; maintain records; and protect the rights, safety, and property of PrimeMatch AI, customers, users, and others.
Account creation may require business contact information, organization affiliation, credentials, authentication factors, and profile information. Users must provide accurate information and maintain appropriate control over credentials.
Enterprise customers may configure business units, subsidiaries, teams, roles, approval rights, and access permissions. The Platform may process these relationships to determine what users can view, edit, approve, export, or share. Customer administrators are responsible for configuring permissions consistent with their legal, contractual, and internal security requirements.
Authorized customer administrators may access certain account, activity, configuration, and content information associated with users under their organization. Users of enterprise accounts should understand that their organization may control the account and may retain or access associated content under its policies and agreements.
Organization DNA™ may synthesize submitted, public, licensed, and inferred information about an organization’s capabilities, certifications, services, experience, differentiators, operating characteristics, preferences, and potential gaps. Where individual professionals are associated with an organization, their professional information may contribute to the organization-level representation.
Opportunity DNA™ may structure and analyze solicitation requirements, scope, timing, agency or buyer characteristics, capability needs, evaluation factors, competition signals, and other relevant information. Information may be extracted from public procurement sources, uploaded documents, customer notes, or integrated systems.
PrimeMatch AI may normalize, summarize, infer, or classify information to support analysis. Users should verify profile, opportunity, qualification, and certification information before relying on it for business or procurement decisions. PrimeMatch AI does not independently certify a business’s legal status, responsibility, financial capability, licensing, insurance, security clearance, or eligibility for a set-aside or award.
Partner Intelligence™ may evaluate semantic similarity, capability complementarity, geographic reach, qualifications, opportunity relevance, past interactions, user preferences, and other signals to identify potential partners. Match results may involve inferred information and may change as source information, weighting, or Platform logic changes.
When users form or evaluate teams, Team DNA™ and Team Strength Index™ may combine information about multiple organizations or individuals to identify capability coverage, gaps, relationships, qualifications, roles, and other teaming factors. The Platform does not determine whether a proposed team satisfies a solicitation or legal requirement.
Relationship DNA™ may organize contact history, saved relationships, prior collaborations, introductions, interaction patterns, opportunity overlap, and other relationship signals. Relationship information may be supplied by customers or inferred from permitted activity and should not be interpreted as proof of endorsement, affiliation, or willingness to partner.
Reputation Intelligence and Trust Score™ may use ratings, activity, profile completeness, public signals, transaction information, dispute data, verification indicators, or other permitted inputs to support user judgment. They are not consumer reports, background checks, credit scores, governmental responsibility determinations, or guarantees of honesty, performance, financial stability, insurance, licensing, compatibility, or marketplace quality.
Users may upload solicitations, draft proposal materials, past-performance narratives, resumes, technical content, pricing inputs, compliance matrices, and other materials. Such information may contain Personal Information, confidential business information, trade secrets, or third-party data and should be uploaded only when the user and customer have appropriate rights and authorization.
Proposal DNA™ and Proposal Intelligence™ may extract requirements, compare draft content to solicitation language, identify gaps, suggest themes, organize source material, produce draft text, or generate compliance-support information. These processes may create new inferences and generated content based on submitted materials and authorized sources.
AI-generated proposal assistance must be independently reviewed before submission. PrimeMatch AI does not guarantee originality, accuracy, responsiveness, non-infringement, factual correctness, regulatory compliance, evaluation outcome, proposal success, or contract award.
The Platform may use generative AI, machine learning, embeddings, retrieval-augmented generation, semantic search, rules engines, statistical methods, ranking systems, and other automated techniques. Depending on configuration, AI systems may process prompts, documents, structured fields, usage signals, public information, or customer-authorized integration data.
PrimeMatch Confidence™ is a proprietary confidence indicator intended to communicate estimated relevance, data sufficiency, analytical confidence, or similar characteristics of an output. It is not an actuarial probability, award probability, professional certification, legal conclusion, credit score, or guarantee of correctness.
Recommendations, rankings, scores, confidence values, predictions, forecasts, classifications, and AI Outputs are informational decision-support tools only. Users and customers remain solely responsible for all business, procurement, legal, financial, staffing, security, contracting, teaming, proposal, and marketplace decisions.
PrimeMatch AI does not intend proprietary scores or recommendations to independently make legally significant decisions about individuals unless specifically documented for a separate use case and permitted by applicable law. Customers must not use Platform intelligence as the sole basis for employment, credit, housing, insurance, eligibility, or other legally significant decisions unless they independently determine and document that such use is lawful and contractually authorized.
Automated systems may produce incomplete, inaccurate, outdated, biased, or unexpected outputs because of source data, statistical limitations, model behavior, ambiguity, configuration, or other factors. PrimeMatch AI may apply safeguards, testing, monitoring, or human review to certain processes but does not represent that AI Output is error-free or free from bias.
The Knowledge Graph™ may represent connections among organizations, people, capabilities, opportunities, requirements, relationships, teams, documents, and other entities. Graph relationships may be directly supplied, derived from public or licensed information, inferred through permitted analytics, or created through user activity.
The Semantic Matching Engine™ may convert text or structured information into mathematical or semantic representations used to compare relevance and similarity. These representations may constitute Personal Information where they can reasonably be linked to an identifiable person.
The Learning Engine™ may use feedback, user selections, corrections, outcome signals, performance measures, or other permitted information to improve ranking, classification, relevance, workflow, and user experience. PrimeMatch AI will apply contractual data-use restrictions and applicable privacy law to such processing. Enterprise customers may have additional controls or negotiated restrictions regarding use of Customer Data for generalized model improvement.
Nothing in this Policy grants a right to inspect, extract, reverse engineer, reproduce, or obtain the underlying models, embeddings, graph structures, weights, prompts, algorithms, scoring logic, proprietary taxonomies, or other PrimeMatch AI intellectual property.
Opportunity Intelligence™ may combine opportunity data, organization information, market signals, historical information, customer inputs, and generated inferences to support pursuit prioritization, pipeline management, and opportunity analysis.
Executive Intelligence™ and Enterprise Intelligence™ may aggregate information across teams, portfolios, business units, pipelines, proposals, partners, marketplace activity, or workflows to create dashboards, trends, forecasts, alerts, and operational insights. Access is governed by customer-configured permissions and organization hierarchy.
Forecasts, probabilities, timing estimates, recompete indicators, market observations, growth projections, and similar outputs are informational estimates based on available information and assumptions. They do not guarantee future opportunities, awards, revenue, profitability, successful partnerships, or business growth.
Marketplace features may process provider listings, service descriptions, customer inquiries, transaction information, reviews, dispute information, engagement, pricing observations, and other data needed to facilitate or analyze marketplace activity.
Marketplace providers and customers are independent parties. PrimeMatch AI may display profiles, ratings, Trust Score™, recommendations, or Marketplace Intelligence™, but does not guarantee provider identity, honesty, qualifications, licensing, insurance, financial stability, service quality, compatibility, performance, or legal compliance.
Payments may be processed by third-party payment providers. Those providers may collect payment-card, bank, identity-verification, tax, and fraud-prevention data under their own terms and privacy notices. PrimeMatch AI may receive transaction identifiers, payment status, limited billing details, and related information necessary to administer marketplace functions.
The Platform may enable users to send messages, match requests, invitations, referrals, proposal communications, workflow notifications, and other communications. PrimeMatch AI may process message metadata and, where necessary to provide the feature, message content.
AI Agents™ may draft or assist with emails, introductions, outreach, proposal text, follow-up messages, or other communications. Users are responsible for reviewing content, selecting recipients, ensuring accuracy, obtaining required consent, and complying with marketing, procurement-integrity, confidentiality, and communications laws before sending.
We may send transactional messages concerning accounts, security, subscriptions, policy updates, service changes, and requested support. Marketing communications may be sent where permitted by law and may be declined using provided unsubscribe mechanisms, except that service-related communications necessary to operate an account may continue.
PrimeMatch AI may power portals branded by an enterprise customer or partner. The branding, domain, or customer-facing name may differ from PrimeMatch AI even though PrimeMatch AI provides the underlying technology. The portal should identify the relevant privacy roles and provide notices appropriate to the deployment.
PrimeMatch AI uses logical access controls and other safeguards designed to separate customer tenants and restrict access according to roles and permissions. No cloud service can be guaranteed absolutely secure, and specific security commitments are governed by applicable agreements and security documentation.
Enterprise administrators may be able to invite or remove users, reset access, assign permissions, view organizational analytics, access business-unit information, review audit logs, export data, or configure integrations. Individuals using an employer or customer-sponsored tenant should consult that organization regarding its independent privacy practices.
Partner discovery, marketplace, benchmarking, or networking features may intentionally expose certain profile or listing information across tenants according to user settings, enterprise configuration, and feature design. PrimeMatch AI will not treat information intentionally designated for cross-tenant discovery as restricted to a single tenant for that purpose.
Customers may connect CRM systems, procurement sources, file repositories, identity providers, communication tools, analytics systems, or other services through APIs or integrations. PrimeMatch AI may receive data from and transmit data to those services according to the customer’s configuration and the permissions granted.
Third-party services are governed by their own terms, privacy notices, availability, and security practices. PrimeMatch AI is not responsible for a third party’s independent processing after data is transmitted to that third party at a customer’s direction.
We may process API keys, tokens, endpoint information, call metadata, payload diagnostics, rate-limit information, and security logs to operate, secure, and troubleshoot integrations. Customers must protect integration credentials and limit scopes to what is reasonably necessary.
Opportunity data obtained through public or government APIs may be cached, normalized, summarized, indexed, or combined with other information. Source systems remain authoritative for official solicitation terms, deadlines, amendments, and notices.
PrimeMatch AI may use cookies, local storage, software development kits, pixels, tags, and similar technologies to maintain sessions, remember settings, authenticate users, secure the Platform, measure performance, understand usage, and, where applicable, support marketing. Specific technologies in use should be reflected in the production cookie banner and cookie inventory.
Certain technologies are necessary for authentication, security, load balancing, fraud prevention, user preferences, and core platform functionality. Where applicable law permits, these may operate without opt-in consent because they are necessary to provide requested services.
Analytics or advertising technologies may require consent or opt-out mechanisms depending on jurisdiction and deployment. PrimeMatch AI will implement controls appropriate to the production configuration, including recognition of legally required opt-out preference signals where applicable.
Where required by applicable law, PrimeMatch AI will treat a recognized browser-based opt-out preference signal, such as Global Privacy Control, as a request to opt out of legally defined sale or sharing for the browser or device from which the signal is received, subject to applicable verification and technical requirements.
If PrimeMatch AI releases mobile applications, this Policy will apply to Personal Information processed through those applications. Mobile-specific notices may supplement this Policy if application functionality materially differs from web functionality.
Depending on enabled features, a mobile application may request device permissions for notifications, camera access, file access, microphone access, contacts, or location. PrimeMatch AI will request only permissions reasonably related to enabled features and will provide platform-level controls where supported by the device operating system.
PrimeMatch AI does not intend to collect precise geolocation unless a future feature specifically requires it and appropriate notice and consent are provided. Approximate location may be inferred from IP address for security, fraud prevention, localization, or analytics.
Certain laws define government identifiers, account credentials, precise geolocation, racial or ethnic origin, religious beliefs, health information, biometric information, union membership, sexual orientation, citizenship or immigration status, and other categories as sensitive. PrimeMatch AI does not require most categories of sensitive Personal Information for ordinary Platform use and asks users not to upload unnecessary sensitive information.
Authentication credentials, security questions, tokens, and similar information are used only for authorized security and account functions and should not be included in prompts, proposal drafts, public profiles, marketplace listings, or ordinary support messages.
Unless expressly authorized in a separate written agreement, users must not submit classified information, controlled cryptographic information, export-controlled technical data, protected health information subject to HIPAA, payment-card data beyond supported payment flows, consumer-report information regulated by the FCRA, or other specially regulated data requiring controls not expressly supported by the applicable service.
Customers subject to federal information-security obligations should not upload Controlled Unclassified Information (CUI), Federal Contract Information (FCI), or information subject to specific safeguarding clauses unless the applicable PrimeMatch AI deployment and written agreement expressly authorize that category of information and identify required controls. Availability of the Platform does not by itself establish FedRAMP authorization, CMMC status, NIST 800-171 compliance, or suitability for classified or CUI workloads.
PrimeMatch AI may process solicitations, notices, awards, agency information, procurement forecasts, public contract records, and other government information to support Opportunity Intelligence™ and Partner Intelligence™. Public sources may contain names and professional contact information of public officials or contractor personnel.
Customers are responsible for ensuring that information uploaded to or obtained through the Platform is lawfully possessed and may be used for the intended purpose. PrimeMatch AI does not authorize users to obtain, submit, solicit, or use contractor bid or proposal information, source-selection information, export-controlled information, classified information, or other protected procurement information in violation of law.
A government entity’s use of PrimeMatch AI may be governed by statutory restrictions, procurement clauses, records laws, security requirements, or agency-specific terms. Any legally required modifications should be addressed in a public-sector addendum or negotiated agreement rather than inferred from this Policy.
PrimeMatch AI may provide compliance-support information or organize public procurement data, but the Platform does not guarantee compliance with the FAR, DFARS, agency supplements, small-business rules, socioeconomic program requirements, procurement-integrity laws, cybersecurity clauses, or any solicitation-specific requirement.
We disclose information to other users, partners, integrations, marketplace participants, or third parties when a user or authorized customer administrator directs or configures the Platform to do so, including through partner discovery, team invitations, public or shared profiles, exports, APIs, or white-label workflows.
We may disclose information to cloud hosting providers, AI infrastructure providers, model providers, security vendors, analytics providers, support vendors, communication providers, payment processors, and professional advisors that process information to provide services to PrimeMatch AI. Such providers are subject to contractual and legal obligations appropriate to their role.
We may disclose information to corporate affiliates under appropriate safeguards and in connection with financing, merger, acquisition, reorganization, asset sale, due diligence, bankruptcy, or other corporate transaction, subject to applicable law and confidentiality protections.
We may disclose information if we reasonably believe disclosure is necessary to comply with law, subpoena, court order, governmental request, procurement obligation, or legal process; to investigate fraud, security incidents, or violations; to protect rights or safety; or to establish, exercise, or defend legal claims.
We may disclose information for other purposes disclosed at the time of collection or with the individual’s or customer’s valid consent.
PrimeMatch AI may rely on third parties for infrastructure hosting, database services, authentication, observability, logging, content delivery, email, customer support, analytics, payment processing, cybersecurity, search, vector processing, AI model inference, and other technical functions.
Certain AI-enabled features may transmit prompts, context, documents, or derived representations to approved model or infrastructure providers to generate or support requested outputs. PrimeMatch AI will configure such services in accordance with contractual terms and enterprise commitments applicable to the deployment. Customers should consult the applicable DPA or subprocessor list for production-specific information.
Where required by applicable law or contract, PrimeMatch AI will maintain contractual data-protection terms with subprocessors and provide notice or objection mechanisms for material subprocessor changes as described in the applicable DPA.
[COUNSEL / PRODUCT CONFIRMATION REQUIRED: As of the publication date, determine whether PrimeMatch AI “sells” or “shares” Personal Information, uses cross-context behavioral advertising, or discloses data in a manner treated as targeted advertising under any applicable U.S. state privacy law. The final published version must accurately reflect actual cookie, analytics, marketing, and data-partnership practices.]
PrimeMatch AI does not intend to sell Customer Data entrusted to the Platform for monetary consideration as a standalone data-broker business. However, some privacy laws define “sale” or “sharing” broadly to include certain disclosures for analytics, advertising, or other valuable consideration, so statutory characterizations must be assessed based on actual production practices.
If PrimeMatch AI engages in activity subject to statutory sale, sharing, or targeted-advertising opt-out rights, PrimeMatch AI will provide legally required methods to exercise those rights and will honor qualifying universal opt-out mechanisms where required.
PrimeMatch AI may create information that has been aggregated or de-identified so that it is not reasonably linkable to an identifiable individual, consistent with applicable law and contractual commitments. PrimeMatch AI may use and disclose such information for analytics, benchmarking, security, research, product development, and business operations.
Where required by law, PrimeMatch AI will maintain processes intended to prevent re-identification of information treated as de-identified and will contractually restrict recipients from attempting re-identification when applicable.
Enterprise dashboards or Marketplace Intelligence™ may present industry, market, usage, or performance benchmarks derived from aggregated information. PrimeMatch AI will design such outputs to avoid identifying another customer or individual unless disclosure is authorized.
Use of Customer Data for generalized AI or model training, if any, must be consistent with the applicable contract, DPA, customer settings, and law. PrimeMatch AI may use feedback, de-identified data, Usage Data, and other permitted information to evaluate and improve Platform performance. Enterprise agreements may impose stricter limitations.
PrimeMatch AI retains Personal Information for the period reasonably necessary to provide services, fulfill the purposes described in this Policy, comply with contractual and legal obligations, resolve disputes, enforce agreements, preserve security records, support legitimate business needs, and maintain required records. Retention periods vary by data type, customer configuration, legal obligations, and account status.
Return, export, deletion, and post-termination retention of enterprise Customer Data are governed by the applicable agreement and DPA. Some residual copies may persist for limited periods in backups, disaster-recovery systems, legal holds, or immutable security logs before deletion or overwrite in the ordinary course.
PrimeMatch AI may retain information beyond ordinary periods when required by law, court order, investigation, dispute, tax or accounting rule, public-sector obligation, litigation hold, or legitimate need to establish or defend legal claims.
When underlying Personal Information is deleted, associated derived information may also be deleted, de-linked, or retained in de-identified or aggregate form as permitted by law and contract. Certain generalized model parameters may not be technically capable of being traced back to an individual record; production practices should be reflected in applicable enterprise disclosures.
PrimeMatch AI uses administrative, technical, and physical safeguards designed to protect information against unauthorized access, acquisition, destruction, loss, misuse, alteration, or disclosure. Safeguards may include access controls, authentication, encryption in transit and at rest where appropriate, logging, monitoring, vulnerability management, tenant isolation, backups, and incident-response procedures.
No internet-connected service, cloud environment, AI system, or data transmission method can be guaranteed completely secure. PrimeMatch AI does not warrant that unauthorized parties will never defeat security measures or that information will never be lost, accessed, disclosed, altered, or destroyed.
PrimeMatch AI will investigate confirmed or reasonably suspected security incidents affecting information under its control and will provide notices to customers, individuals, regulators, or others when required by applicable law or contract. Enterprise incident-notification timing and procedures may be specified in a DPA or security addendum.
Customers are responsible for protecting credentials, configuring permissions, securing connected systems, managing endpoints, controlling exports, reviewing administrator access, using supported authentication controls, and promptly notifying PrimeMatch AI of suspected compromise.
PrimeMatch AI and its service providers may process information in the United States and other jurisdictions where they operate. Those jurisdictions may have data-protection laws different from the laws where an individual resides.
Where required, PrimeMatch AI may use approved transfer mechanisms such as standard contractual clauses, the UK International Data Transfer Addendum, adequacy decisions, or other legally recognized safeguards. Specific mechanisms will be identified in the applicable DPA or international transfer documentation.
Information processed in another jurisdiction may be subject to lawful access by courts, law-enforcement agencies, intelligence authorities, or regulators under that jurisdiction’s laws. PrimeMatch AI will respond to governmental requests in accordance with applicable law and its contractual commitments.
Depending on location and applicable law, individuals may have rights to request access, confirmation, correction, deletion, portability, restriction, objection, withdrawal of consent, information about categories or recipients, opt-out of certain processing, appeal a denied request, or lodge a complaint with a regulator. Some rights are subject to exceptions and verification requirements.
Requests may be submitted through [PRIVACY REQUEST WEBFORM], by email to [PRIVACY EMAIL], or through other methods identified in the production privacy center. PrimeMatch AI may ask for information reasonably necessary to verify identity, authority, account affiliation, or the scope of the request.
If PrimeMatch AI processes information solely for an enterprise customer, PrimeMatch AI may direct the requester to that customer because the customer controls the relevant records and determines how the request should be handled. PrimeMatch AI will assist the customer as required by law and contract.
Where applicable law permits an authorized agent to submit a request, PrimeMatch AI may require proof of authorization and may separately verify the individual’s identity unless prohibited by law.
PrimeMatch AI will not unlawfully discriminate or retaliate against an individual for exercising applicable privacy rights. Certain services may necessarily be unavailable if required information is deleted or processing essential to the requested service is restricted.
Where applicable state law provides an appeal right, instructions for appealing a denied privacy request will be provided with the response or through [PRIVACY APPEAL METHOD].
This Article supplements the rest of the Policy for California residents to the extent the California Consumer Privacy Act, as amended, applies to PrimeMatch AI’s processing. Statutory terms such as “consumer,” “personal information,” “sensitive personal information,” “sell,” and “share” have the meanings assigned by California law.
During the applicable reporting period, PrimeMatch AI may collect identifiers; customer records and commercial information; internet or electronic-network activity; professional or employment-related information; geolocation at an approximate level; audio or visual information if submitted; sensitive account credentials; and inferences drawn from other information. The precise categories depend on enabled features and customer use.
PrimeMatch AI uses these categories for the business and commercial purposes described in Articles 6 through 27 and retains them according to Article 26 and applicable contractual commitments. The production policy should be reviewed annually to confirm the categories, purposes, and retention disclosures remain accurate.
Subject to statutory exceptions, California residents may have rights to know, access, correct, and delete Personal Information; obtain information about categories collected, disclosed, sold, or shared; opt out of sale or sharing; limit certain uses or disclosures of sensitive Personal Information; and receive equal service and pricing without unlawful discrimination for exercising rights.
California requests may be submitted through [WEBFORM], [TOLL-FREE NUMBER IF REQUIRED], or [EMAIL / OTHER METHOD AS PERMITTED]. PrimeMatch AI will use reasonable verification procedures appropriate to the sensitivity of the requested information and may deny or limit requests when permitted by law.
Where PrimeMatch AI is legally required to honor an opt-out preference signal for sale or sharing, a qualifying Global Privacy Control or other recognized mechanism will be processed in accordance with applicable California requirements. [IMPLEMENTATION CONFIRMATION REQUIRED BEFORE PUBLICATION.]
PrimeMatch AI does not intend to use or disclose sensitive Personal Information for purposes that trigger a separate limitation right unless disclosed in the production privacy notice. If practices change, PrimeMatch AI will provide any legally required notice and mechanism.
PrimeMatch AI does not offer a financial incentive or price-or-service difference in exchange for Personal Information unless separately disclosed through a notice of financial incentive that satisfies applicable law.
Residents of states with comprehensive privacy laws may have rights similar to those described in Article 29, including rights of access, correction, deletion, portability, opt-out of targeted advertising, sale, or certain profiling, and appeal of denied requests. Rights vary by jurisdiction, scope, exemptions, and applicability thresholds.
Where required by applicable state law, PrimeMatch AI will recognize qualifying universal opt-out mechanisms for covered targeted advertising or sale activities. Technical implementation will reflect the jurisdictions and technologies applicable to the production service.
Where state law requires consent before processing sensitive data, PrimeMatch AI will obtain required consent or rely on another lawful basis where permitted. Customers must not configure the Platform to process sensitive data in a manner inconsistent with applicable requirements.
PrimeMatch AI’s partner matching, opportunity ranking, reputation indicators, and AI-assisted recommendations are designed for business decision support. To the extent any use constitutes regulated profiling producing legal or similarly significant effects concerning an individual, PrimeMatch AI and the customer will address applicable notice, assessment, opt-out, human-review, or other obligations based on their respective legal roles.
Where the GDPR, UK GDPR, or analogous Swiss law applies and PrimeMatch AI acts as controller, PrimeMatch AI may rely on performance of a contract, legitimate interests, compliance with legal obligations, consent, or another lawful basis appropriate to the processing. Legitimate interests may include securing the Platform, providing requested business functionality, improving services in a privacy-protective manner, managing customer relationships, and protecting legal rights.
Subject to applicable law, individuals may have rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and rights relating to certain automated decision-making. Individuals may also lodge a complaint with a competent supervisory authority.
PrimeMatch AI’s proprietary matching, scoring, and recommendation systems are intended to assist users rather than make solely automated decisions that produce legal or similarly significant effects concerning individuals. Customers are responsible for ensuring their own use of outputs does not create prohibited or noncompliant automated decision-making.
[IF APPLICABLE: EEA REPRESENTATIVE: ________. UK REPRESENTATIVE: ________. DATA PROTECTION OFFICER / PRIVACY LEAD: ________.] These fields should be completed only if legally required or operationally designated.
PrimeMatch AI is designed for organizations, professionals, contractors, and business users and is not directed to children. Individuals under the age of 18 should not create accounts unless the applicable service expressly permits it and all required organizational and parental authorizations have been obtained.
PrimeMatch AI does not knowingly solicit Personal Information from children under 13 through general Platform services. If PrimeMatch AI learns that it has collected such information without legally sufficient authorization, it will take reasonable steps to delete or otherwise address the information as required by law.
PrimeMatch AI may process professional contact information relating to customers, prospects, partners, government personnel, vendor representatives, and other business contacts for account management, business development, procurement, support, security, and relationship administration.
If PrimeMatch AI collects applicant or workforce information, that information may be governed by a separate employee or applicant privacy notice. This Privacy Policy is not intended to replace employment-specific disclosures where required.
Customers are responsible for ensuring they have a lawful basis, required notices, permissions, consents, contractual rights, and other authority to submit Customer Data and instruct PrimeMatch AI to process it. This includes information about employees, subcontractors, partners, applicants, marketplace providers, and third parties.
Customers should upload only information reasonably necessary for the intended use case and should avoid entering Social Security numbers, personal financial information, health information, classified data, sensitive government information, or other high-risk data unless expressly supported by the applicable service and agreement.
Enterprise customers may have independent privacy-notice obligations to their authorized users, partners, workforce, or other individuals. PrimeMatch AI’s publication of this Policy does not satisfy every customer’s separate legal obligations.
Customers must not use PrimeMatch AI proprietary scores, rankings, or AI Outputs as the sole basis for legally significant decisions about individuals unless the use is expressly authorized, independently validated, and implemented in compliance with applicable law, including required notices, assessments, human review, and appeal rights.
Enterprise customers may execute PrimeMatch AI’s then-current DPA where required by applicable data-protection law. The DPA may address processing instructions, confidentiality, security, subprocessors, international transfers, deletion, assistance with data-subject requests, and audit or information rights.
Government, defense, healthcare, financial-services, or other regulated deployments may require additional security, records, residency, incident, or data-use terms. Such commitments exist only if expressly included in a signed addendum, Order Form, or other written agreement.
If a DPA or other signed privacy addendum conflicts with this Policy regarding processing performed under that agreement, the signed agreement controls to the extent of the conflict.
The Platform may link to or integrate with government websites, commercial databases, social or professional networks, payment processors, marketplace providers, and other third parties. PrimeMatch AI does not control those third parties’ privacy or security practices.
Marketplace providers are responsible for their own collection, use, and protection of information obtained directly from customers or through a permitted Platform transaction. Users should review provider terms and privacy notices before disclosing information beyond what is necessary.
PrimeMatch AI may display or summarize publicly available business or professional information, but does not guarantee that third-party source data is current, accurate, complete, or lawfully reusable for every purpose. Users remain responsible for verifying source information when making material decisions.
PrimeMatch AI, including PrimeMatch Intelligence™, Partner Intelligence™, Opportunity Intelligence™, Proposal Intelligence™, Executive Intelligence™, Marketplace Intelligence™, Enterprise Intelligence™, PrimeMatch Confidence™, Trust Score™, Team Strength Index™, and outputs produced by AI Agents™ or any Intelligence Engine™, provides informational decision support only.
Processing information through the Platform does not create an attorney-client, accountant-client, broker, fiduciary, employment, procurement-advisor, contracting-officer, insurance, financial-adviser, or other professional relationship with PrimeMatch AI.
PrimeMatch AI does not guarantee contract awards, proposal success, business growth, profitability, successful partnerships, legal compliance, licensing, insurance, financial stability, vendor performance, marketplace quality, partner honesty, compatibility, or future outcomes. Users remain solely responsible for independent judgment, diligence, verification, and professional advice where appropriate.
PrimeMatch AI may update this Policy to reflect changes in technology, services, AI capabilities, data practices, laws, regulations, contracts, or business operations. The revised Policy will identify an updated effective or revision date.
Where required by law, PrimeMatch AI will provide additional notice of material changes and obtain consent when legally required. Continued use of the Platform does not override any consent requirement imposed by applicable privacy law.
PrimeMatch AI may retain prior versions of this Policy for compliance and recordkeeping. [PUBLIC ARCHIVE LOCATION, IF USED: ________.]
Questions, complaints, or privacy requests may be directed to: [PRIMEMATCH AI LEGAL ENTITY], Attn: Privacy, [POSTAL ADDRESS], [PRIVACY EMAIL], [PRIVACY WEBFORM], [TOLL-FREE NUMBER IF REQUIRED].
Individuals in jurisdictions that provide a right to complain to a privacy or data-protection authority may contact the authority with jurisdiction over their residence, workplace, or alleged infringement. PrimeMatch AI encourages individuals to contact us first so we can attempt to address concerns directly, but doing so does not waive a statutory right to complain to a regulator.
[COUNSEL REVIEW REQUIRED: confirm controller identity, state registration or data-broker implications, consumer-request channels, regional representatives, DPO requirements, cookie consent settings, U.S. state thresholds, automated-decision obligations, retention disclosures, and international transfer mechanisms before publication.]
APPENDIX A
DATA CATEGORY AND PURPOSE MATRIX
Data Category | Illustrative Purposes | Illustrative Sources | Illustrative Disclosures |
Identifiers and business contact data | Account creation; authentication; support; communications; organization administration | Customer/user; enterprise administrator; public/business sources | Customer-directed recipients; service providers; integrations |
Professional and organization data | Organization DNA™; Partner Intelligence™; team formation; opportunity fit; marketplace profiles | Customer/user; public procurement/business sources; licensed sources | Authorized users; potential partners where configured; service providers |
Opportunity and solicitation data | Opportunity DNA™; Opportunity Intelligence™; semantic search; forecasting; pipeline management | Government/public sources; customer uploads; integrations | Customer users; service providers; customer-directed integrations |
Proposal and pursuit data | Proposal DNA™; Proposal Intelligence™; AI-assisted drafting; requirement analysis | Customer uploads; authorized integrations | Customer users; AI/service providers as needed to provide requested functionality |
Relationship and reputation data | Relationship DNA™; Reputation Intelligence; Trust Score™; Partner Intelligence™ | User activity; customer input; public/licensed sources; marketplace interactions | Authorized users; cross-tenant recipients where feature settings permit |
Marketplace and transaction data | Listings; transactions; Marketplace Intelligence™; dispute administration | Users; providers; payment processors | Transaction counterparties; payment/service providers; legal recipients when required |
Usage, device, and audit data | Security; fraud prevention; analytics; service improvement; audit logging | Automatically collected | Security, hosting, analytics, and support providers |
AI inferences and scores | PrimeMatch Confidence™; Team Strength Index™; matching; ranking; recommendations | Derived from permitted inputs | Authorized users; service providers supporting AI functionality |
This matrix is illustrative and must be validated against the production data inventory, subprocessor list, cookie configuration, enterprise product tiers, and actual data flows before publication.
APPENDIX B
PROPRIETARY INTELLIGENCE DATA MAP
Data: May combine organization profile fields, qualifications, certifications, professional data, uploaded documents, public business information, and inferred capabilities or gaps.
Purpose: Supports organization representation, matching, readiness analysis, and decision support.
Data: May combine solicitation documents, requirements, deadlines, buyer information, customer notes, and extracted or inferred attributes.
Purpose: Supports opportunity search, comparison, requirements analysis, and fit evaluation.
Data: May combine information about multiple organizations or individuals, intended roles, complementary capabilities, gaps, and relationships.
Purpose: Supports team composition and capability-coverage analysis.
Data: May combine introductions, prior collaboration, saved relationships, interaction history, and related signals.
Purpose: Supports relationship visibility and partner-context analysis.
Data: May combine proposal drafts, solicitation requirements, source materials, compliance-support information, and generated analysis.
Purpose: Supports proposal organization, gap identification, and AI-assisted drafting.
Data: May combine market, pipeline, organization, opportunity, partner, and performance signals.
Purpose: Supports strategic growth and business-development decision support.
Data: May use relevance, data completeness, consistency, semantic similarity, and other proprietary factors.
Purpose: Communicates estimated confidence or data sufficiency; not a guarantee or probability of award.
Data: May use profile, reputation, verification, transaction, activity, and other permitted signals.
Purpose: Provides informational reputation support; not a background check, credit score, or guarantee.
Data: May combine team coverage, gaps, qualification indicators, relationships, and other factors.
Purpose: Provides a composite decision-support indicator for team evaluation.
Data: May map relationships among organizations, people, opportunities, capabilities, teams, and documents.
Purpose: Supports connected intelligence, search, relationship analysis, and retrieval.
Data: May create semantic or vector representations from text and structured fields.
Purpose: Supports similarity analysis, search, matching, and ranking.
Data: May process feedback, corrections, selections, outcome signals, and permitted usage information.
Purpose: Supports improvement of relevance, ranking, classification, and workflows subject to contract and law.
APPENDIX C
U.S. STATE PRIVACY RIGHTS SUMMARY
The following summary is intentionally generalized because comprehensive state privacy laws continue to evolve. The final published Policy should be confirmed against the jurisdictions in which PrimeMatch AI meets statutory applicability thresholds and the actual processing activities in production.
Many states provide a right to confirm whether Personal Information is processed and to access covered data.
Many states permit correction of inaccuracies, subject to statutory exceptions and the nature of the data.
Many states provide deletion rights, often subject to exceptions for security, legal obligations, transactions, and internal uses.
Many states provide a right to obtain certain information in a portable and, where technically feasible, readily usable format.
Certain states permit opt-out from targeted advertising, sale of Personal Information, or both; definitions differ by state.
Certain states provide rights relating to profiling in furtherance of decisions that produce legal or similarly significant effects.
Several states require consent or provide heightened rights for sensitive data processing.
Certain states require a process to appeal denial of a privacy request.
Certain states require recognition of qualifying browser- or device-based universal opt-out mechanisms for covered activities.
APPENDIX D
ENTERPRISE / GOVERNMENT DEPLOYMENT REVIEW CHECKLIST
☐ Identify the PrimeMatch AI legal entity acting as controller, business, service provider, contractor, or processor for each deployment.
☐ Complete a production data inventory and data-flow map covering web, APIs, white-label portals, marketplace functions, analytics, AI providers, and future mobile applications.
☐ Confirm whether customer prompts, documents, or outputs may be used for generalized model training and align that practice with contracts, DPA language, and customer controls.
☐ Publish and maintain an accurate subprocessor list and applicable notification mechanism for enterprise customers.
☐ Confirm cookie categories, consent configuration, analytics providers, advertising technologies, Global Privacy Control handling, and state universal opt-out support.
☐ Confirm California sale/sharing, sensitive-data, ADMT, risk-assessment, and cybersecurity-audit applicability based on actual processing and statutory thresholds.
☐ Confirm other U.S. state privacy-law applicability, profiling rules, appeal requirements, sensitive-data consent, and universal opt-out obligations.
☐ Confirm GDPR/UK GDPR legal bases, international transfer mechanisms, representative/DPO requirements, and data-subject request procedures if relevant.
☐ Document retention periods by major data category and ensure the published retention disclosure matches operational practice.
☐ Confirm enterprise administrator visibility, organization hierarchy, audit log retention, export controls, and cross-tenant discovery behavior.
☐ Confirm whether CUI, FCI, export-controlled data, ITAR data, PHI, payment-card data, or other regulated information is prohibited or supported under a specific deployment.
☐ For government customers, reconcile privacy terms with procurement clauses, records laws, agency security requirements, public-records obligations, and negotiated data rights.
☐ Confirm mobile permissions, SDKs, app-store privacy disclosures, and device-data collection before any mobile launch.
☐ Validate incident-response contacts, breach-notification workflow, security addendum, and DPA timing commitments.
☐ Ensure all AI scores, recommendations, rankings, forecasts, and generated outputs remain expressly characterized as informational decision-support tools and not guaranteed outcomes.
☐ Perform final attorney review of all bracketed placeholders and jurisdiction-specific provisions before publication.
END OF PRIVACY POLICY
Draft for attorney review; bracketed items require completion before publication.