Privacy Policy
ro2 Partners LLC
Effective Date: July 30, 2026 Last Updated: July 30, 2026
1. Overview
ro2 Partners LLC ("ro2 Partners," "we," "us," or "our") is a Virginia limited liability company providing consulting services in data strategy, AI enablement, and process automation. This Privacy Policy explains how we collect, use, disclose, and protect personal information through our website at [ro2partners.com] (the "Site") and in connection with our marketing and business development activities.
This policy applies to information we collect as a business acting on our own behalf — website visitors, prospective clients, newsletter subscribers, and job applicants.
This policy does not govern client data. When we process data on behalf of a client under a consulting engagement, we act as a service provider or processor. That processing is governed by the applicable Master Services Agreement, Statement of Work, Data Processing Agreement, or Non-Disclosure Agreement — not by this policy.
2. Information We Collect
2.1 Information You Provide Directly
Contact and inquiry information: name, business email address, telephone number, company name, job title, and the contents of any message you send through a Site form or to a published email address.
Meeting scheduling information: if you book time with us through a scheduling tool, the information you supply to that tool, including your name, email address, and selected time.
Subscription information: email address and any preferences you provide when subscribing to a newsletter or mailing list.
Applicant information: if you apply for a role or subcontract opportunity, your resume, work history, and any information you choose to include.
2.2 Information Collected Automatically
When you visit the Site, we and our service providers may automatically collect:
IP address (which may be truncated or anonymized)
Browser type, operating system, and device type
Referring URL and pages viewed
Date, time, and duration of visit
General geographic location inferred from IP address (typically at the city or region level)
2.3 Information from Third Parties
We may receive business contact information from publicly available sources, professional networking platforms, government contracting databases (such as SAM.gov), and business data providers, for the purpose of business development outreach.
2.4 What We Do Not Collect
We do not knowingly collect:
Payment card numbers through the Site (invoicing and payment occur through separate accounting and banking channels)
Social Security numbers, government-issued identification numbers, or financial account numbers
Sensitive personal information as defined under applicable state privacy laws, including precise geolocation, biometric data, health information, or information about racial or ethnic origin, religious beliefs, or sexual orientation
Personal information from children under the age of 16
3. Controlled and Sensitive Government Information
Do not submit classified information, Controlled Unclassified Information (CUI), export-controlled technical data, procurement-sensitive information, or any other restricted material through the Site.
Our Site forms and general email addresses are not accredited or authorized systems for handling such material. If you need to transmit sensitive or controlled information to us, contact us first and we will establish an appropriate transmission channel under the terms of an executed agreement.
4. How We Use Information
We use the information described above to:
PurposeExamplesRespond to inquiriesReplying to a contact form submission or scheduling a callDeliver servicesCommunicating during a proposal or engagementMarketing communicationsSending newsletters, updates, or thought leadership, where permittedBusiness developmentIdentifying and contacting prospective clients and teaming partnersSite operation and improvementUnderstanding traffic patterns, diagnosing errors, improving contentSecurityDetecting, preventing, and investigating fraud, abuse, or unauthorized accessLegal and contractual complianceMeeting recordkeeping, tax, audit, and government contracting obligations
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
5. Legal Bases for Processing (EEA and UK Visitors)
Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases:
Legitimate interests — operating and securing the Site, business-to-business marketing, and responding to inquiries
Consent — non-essential cookies and analytics, and email marketing where consent is required
Contract — steps taken at your request prior to entering into a contract, and performance of a contract
Legal obligation — compliance with applicable law
You may withdraw consent at any time; withdrawal does not affect processing carried out before withdrawal.
6. Cookies and Analytics
The Site uses cookies and similar technologies:
Strictly necessary cookies — required for the Site to function, including security and load balancing. These cannot be disabled through our Site.
Analytics cookies — used to measure traffic and understand how visitors use the Site. We use [ANALYTICS PROVIDER — e.g., Plausible Analytics, which is cookieless and does not track individuals across sites / Google Analytics 4 with IP anonymization enabled].
Preference cookies — remember settings such as your cookie consent choices.
You can control cookies through your browser settings. Disabling cookies may affect Site functionality.
Global Privacy Control: We honor the Global Privacy Control (GPC) signal where legally required. Because we do not sell personal information or share it for targeted advertising, receipt of a GPC signal generally results in no change to our practices.
7. Artificial Intelligence and Automated Processing
We use AI and large language model services in our internal operations, including for drafting, research, and analysis support. Where we process information you submit to us using a third-party AI service, we use enterprise or API-tier services that are configured so that submitted content is not used to train the provider's models.
We do not use automated decision-making that produces legal or similarly significant effects concerning you.
8. How We Share Information
We share personal information only in the following circumstances:
Service providers and subprocessors who perform functions on our behalf under contractual confidentiality and security obligations. Current categories include:
Website and application hosting [e.g., DigitalOcean]
Email, calendar, and productivity services [e.g., Google Workspace / Microsoft 365]
Email marketing and CRM platforms
Analytics providers
AI and language model API providers [e.g., Anthropic, OpenAI]
Accounting, billing, and professional services providers
Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy's protections.
Legal requirements — where required by law, subpoena, court order, or a lawful request from a government or regulatory authority, including in connection with federal contracting obligations.
Protection of rights — where necessary to enforce our agreements or protect the rights, property, or safety of ro2 Partners, our clients, or others.
We do not disclose personal information to third parties for their own independent marketing purposes.
9. Data Retention
We retain personal information only as long as necessary for the purposes described in this policy:
CategoryTypical RetentionInquiry and contact form submissions[24 months] from last contactNewsletter subscribersUntil unsubscribe, plus a suppression record retained indefinitely to honor the opt-outWebsite analytics[14 months]Applicant materials[12 months] unless a longer period is required by lawRecords related to executed contractsAs required by contract, tax, and federal contracting recordkeeping obligations (typically [6] years)
10. Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS), access controls and least-privilege permissions, multi-factor authentication on business systems, and periodic review of vendor security practices.
No system is completely secure. We cannot guarantee the security of information transmitted to us over the internet, and you transmit information at your own risk.
11. International Transfers
We are based in the United States and process information in the United States. If you access the Site from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction. Where required, we implement appropriate safeguards for such transfers, including Standard Contractual Clauses.
12. Your Privacy Rights
Depending on your location, you may have the right to:
Access the personal information we hold about you
Correct inaccurate personal information
Delete personal information
Obtain a portable copy of personal information you provided to us
Opt out of targeted advertising, sale of personal information, or profiling (note: we do not engage in these activities)
Appeal a denial of a rights request
Non-discrimination for exercising your rights
Virginia residents have rights under the Virginia Consumer Data Protection Act. California residents have rights under the California Consumer Privacy Act, as amended. Residents of other states with comprehensive privacy laws have comparable rights. Note that most state privacy laws exclude information collected in a business-to-business or employment context; we will nonetheless make reasonable efforts to honor requests.
To exercise a right, email [info@ro2partners.com] with the subject line "Privacy Rights Request." We will verify your identity using information already in our possession and respond within 45 days, with one 45-day extension where reasonably necessary. If we deny your request, you may appeal by replying to our response; we will respond to an appeal within 60 days.
Authorized agents may submit requests on your behalf with written proof of authorization.
EEA and UK residents additionally have the right to lodge a complaint with a supervisory authority.
13. Marketing Communications
You can unsubscribe from marketing email at any time using the link in any message or by emailing [info@ro2partners.com] . We will continue to send transactional and engagement-related communications necessary to provide services under an existing agreement.
14. Third-Party Links
The Site may link to third-party websites, including social media profiles and scheduling tools. We are not responsible for the privacy practices of those sites. Review their privacy policies before providing information.
15. Children's Privacy
The Site is directed to businesses and professionals and is not intended for individuals under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised policy with an updated "Last Updated" date. Material changes will be communicated by [posting a prominent notice on the Site / emailing subscribers] before the change takes effect. Continued use of the Site after the effective date constitutes acceptance.
17. Contact Us
ro2 Partners LLC [info@ro2partners.com]
For general inquiries: [info@ro2partners.com]
