Third-Party AI and Confidential Information Usage Policy (the “Policy”)

Scale Microgrid Solutions, LLC (“Company”)
Effective Date: May 15, 2026
1. Purpose and Intent. The proliferation of artificial intelligence (“AI”) tools presents unique risks to data security, confidentiality, and intellectual property. The purpose of this Policy is to protect the Company’s Confidential Information (CI) from unauthorized disclosure, retention, training, or exposure arising from the use of third-party AI systems.
2. Scope and Applicability. This Policy applies to all external parties who access, possess, or process the Company’s CI, including, but not limited to, vendors, service providers, customers, partners, consultants, and contractors (collectively, "Third Parties").
This Policy governs the use of any and all AI tools, including generative AI models (e.g., large language models), code assistants, predictive analytics tools, and any software where user input may be retained, logged, or used for model training or improvement by a third-party provider.
3. Definitions of Key Terms.
(a) AI Tool/System: Any computational system designed to simulate human cognitive functions, where user inputs are processed to generate outputs, summarize data, or train underlying models.
(b) Confidential Information (CI): any non-public information relating to the Company’s business, including without limitation, affiliates, operations, strategies, customers, opportunities, vendors, partners, products, contracts, software, marketing, technology, pricing, financial information and the information related to the relationship or transactions contemplated with the receiving party, which is identified as, or under the circumstances of disclosure would reasonably be understood to be, confidential or proprietary by the receiving party, as may be defined more fully in the governing contract or non-disclosure agreement with the receiving party.
(c) Enterprise Instance: premium, dedicated, and isolated version of an AI product specifically designed for the receiving party’s corporate use and compliant with the Required Technical Controls (as defined hereinafter).
(d) Public AI Tool: any AI tool/system offered on a non-enterprise, consumer, or publicly accessible platform (e.g., ChatGPT, Gemini, Copilot, Claude, Bard, etc.) where user’s inputs may be processed or stored by the provider for service improvement or analytics or otherwise used to train such models.
4. Prohibition on Inputting Confidential Information; Use of AI-generated Outputs
(a) General Prohibition: The receiving party is strictly prohibited from entering, uploading, pasting, or otherwise submitting any form of the Company’s CI into any Public AI Tool.
(b) No Training Data: Under no circumstances shall CI be used as input data for AI models where the input may be retained, logged, or utilized to train, improve, or update the AI model or its underlying services.
(c) Querying with CI: Using CI to formulate prompts, queries, or instructions for a Public AI Tool, even if not fully disclosed, is prohibited if the intent or effect is to leverage the CI for AI-generated output.
(d) AI-Generated Outputs: Third Parties shall not use AI-generated outputs that are based on or derived from CI for any purpose that could disclose, replicate, reverse engineer, or misrepresent the Company’s CI. Any AI-generated content derived from CI remains the Company’s CI and must be validated and approved by the Company prior to external use or disclosure.
5. Requirements for AI Tool Usage
(a) Permitted Use: Third Parties may only use AI Tools with Company CI if the specific AI Tool is an Enterprise Instance, which provides reasonable confidentiality protection for the Company’s CI that is at least the same level of protection as provided for the receiving party’s own CI.
(b) Required Technical Controls: AI Tools must be confirmed to offer, at minimum, the following contractual and technical safeguards (“Required Technical Controls”):
i) No Retention/Logging: At Company’s request, all input data (CI) is immediately purged and no longer retained, logged, or stored after processing .
ii)No Training: An explicit contractual clause confirming that input data will not be used for training or improving the AI model, including aggregated or anonymized training.
iii) Data Minimization: Third Parties must adhere to a strict CI minimization principle, ensuring that only the absolute minimum amount of CI necessary to complete a contractually defined task is exposed to any AI process, even with an approved tool.
iv) Security Controls: Third Parties use security controls such as encryption, multi-factor authentication and audit logs.
v) CI Data Residency / Cross-Border Transfer: Processing of CI must occur only in the U.S., Canada, or European Economic Area in compliance with applicable data protection laws. The Third Party must not allow CI to be transferred to or processed in restricted or sanctioned jurisdictions pursuant to applicable law.
(c) Personal Data: To the extent Company CI includes personally identifiable information or other personal data, the Third Party must comply with all applicable laws and regulations governing access, storage, processing, and use of such data.
(d) Compliance: Upon the Company’s request, the Third Party shall provide proof of compliance with this Policy and the Required Technical Controls. Third Parties shall maintain records of AI Tool usage involving CI for a minimum of 24 months.
6. Responsibility and Contractual Overlap
(a) No Waiver of Existing Agreements: This Policy is in addition to and does not supersede, amend, or waive any obligations under existing written agreement, including without limitation non-disclosure agreements or other binding contracts. In the event of a conflict, the more restrictive clause shall apply.
(b) Accountability for Personnel: The Third Party is fully responsible for ensuring strict compliance with this Policy by all of its employees, agents, subcontractors, and any other party acting on its behalf.
7. Incident Reporting and Breach Notification
(a) Immediate Notification: The Third Party must immediately notify the Company’s Legal Department (see Section 9) within twenty-four (24) hours of discovering any actual or suspected unauthorized use of an AI Tool involving Company CI. The notification must include, at minimum, a description of the incident, date/time of occurrence, affected data, systems involved, and remedial plan. Notification must be made via email to legal@scalemicrogrids.com.
(b) Cooperation and Remediation: The Third Party shall fully cooperate with the Company in investigating, mitigating, and remediating any AI-related data exposure, breach, or security incident, bearing all associated costs where the Third Party is found to be non-compliant.
8. Consequences of Non-Compliance. Any violation of this Policy shall constitute a material breach of the underlying contract (e.g., MSA, NDA). The Company reserves all rights and remedies available at law or equity.
9. Policy Review and Contact Information
(a) Policy Updates: This Policy will be reviewed and updated periodically. Third Parties are responsible for checking this website for the current version.
(b) Policy Contact: All questions regarding this Policy, or required notifications of a suspected violation, must be directed to: legal@scalemicrogrids.com.
10. Applicable Law. This Policy shall be governed by, and constructed in accordance with, the laws of State of New York.