Version 2026-09-04
PRIVACY POLICY
Beverlin Strategic Advisors LLC
Last updated: September 4, 2026
This Privacy Policy explains how Beverlin Strategic Advisors LLC, a Texas limited liability company ("BSA," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the BSA Platform and related Services (the "Services"). This Policy is incorporated by reference into the BSA Terms of Service and Terms of Use.
This Policy addresses BSA’s processing of information in a business-to-business (B2B) context. It is directed to Clients and to Business Contacts (defined in Section 1), meaning individuals who interact with BSA as employees, contractors, or other authorized representatives of a Client, acting in that capacity. It is not directed to, and is not designed on its own to satisfy, disclosure obligations BSA may owe to an individual acting in a purely personal, non-representative capacity. Section 11 separately addresses the state consumer-privacy statutes that may nonetheless extend rights to Business Contacts, or to other individuals whose information appears in Client Content or public records even though they are not Business Contacts.
Definitions
-
"AI Sub-Processor" means a third-party AI tool used to perform portions of the Services, as described in Section 4.
-
"Business" or "controller" means BSA acting with respect to its own direct account, billing, and website-visitor data, as described in Section 5.1.
-
"Business Contact" means an individual who interacts with BSA as an employee, contractor, or other authorized representative of a Client, acting in that capacity. Examples include a Client employee who creates a workspace account, submits Client Content, or communicates with BSA on the Client’s behalf. Most individuals whose information BSA processes under this Policy are Business Contacts.
-
"Client" means an organization that has engaged BSA for the Services.
-
"Client Content" means documents, data, communications, and other materials a Client or its representatives upload or submit to a workspace.
-
"Consumer" or "individual" means a natural person (not a Client organization) to whom personal information relates under a state consumer-privacy statute discussed in Section 11, whether a Business Contact or a person referenced in Client Content or public records who is not a Business Contact.
-
"Deliverables" means the reports, analyses, models, maps, and other work product BSA prepares and makes available to a Client through a Workspace as part of the Services.
-
"GIS" means a geographic information system, meaning the software and data used to capture, store, analyze, and display location-based and mapping data referenced in Section 2.
-
"Personal information" means information that identifies, relates to, or could reasonably be linked with a particular individual or household, as further defined under applicable state law.
-
"Platform," "Services," or "Analytical Services" means the BSA platform, Workspaces, and analytical tools, together with the related site, property, and real-estate research and analysis services BSA provides to Clients, as further described in the BSA Terms of Service and Terms of Use.
-
"Sell," "sale," and "share" have the meanings given under applicable state consumer-privacy law; see Section 11.
-
"Sensitive personal information" means categories of personal information subject to heightened protection under applicable state law; see Section 11.
-
"Service provider" or "processor" means BSA acting with respect to personal information embedded in Client Content, as described in Section 5.1.
-
"Workspace" means a secure, Client-specific environment within the Platform through which a Client and its Business Contacts submit Client Content, access the Services, and receive Deliverables.
Information We Collect
Information You Provide
-
Account and registration information (name, business email, employer, role, phone number).
-
Workspace content: Client communications, uploaded documents and notes, and any personal information those materials contain (which may include names, addresses, or other identifying information about property owners, tenants, or other individuals referenced in Client Content or public records).
-
Billing and payment information. Online payment functionality is not yet active on the Platform. When implemented, payment-card information will be processed by a third-party payment processor (currently anticipated to be Square), and BSA does not intend to store full payment-card numbers on the Platform.
-
Communications with BSA, including support requests and engagement correspondence.
Information Collected Automatically
-
Usage data (pages/features accessed, timestamps, session activity, audit/project history log entries).
-
Device and technical data (IP address, browser type, operating system).
-
Session cookies necessary to maintain an authenticated user’s session on the Platform; BSA’s public website does not set cookies for unauthenticated visitors (see Section 6).
Information From Third Parties and Public Sources
-
Public records and governmental data (parcel, zoning, jurisdictional, infrastructure, incentive-program, demographic, and market data) incorporated into the Services.
-
GIS and mapping data licensed from third-party providers.
Categories of Personal Information: Statutory Mapping
This table identifies, by statutory category, the information BSA collects, to the extent those categories are relevant under applicable law.
| Statutory Category | Collected by BSA? |
|---|---|
| Identifiers (name, email, IP address, online identifiers) | Yes: account, registration, and business-contact data; device and online identifiers (such as IP address) collected automatically; and identifiers appearing in Client Content or public records. |
| Commercial information (records of services obtained) | Yes: billing history and engagement records. |
| Internet or network activity | Yes: platform usage data collected within an authenticated Workspace. BSA does not use website analytics, advertising, or tracking technologies (see Section 6). |
| Geolocation data | Limited: property/parcel-level location data researched as part of the Services; not device-level geolocation of individuals, unless present in Client Content. |
| Professional or employment-related information | Yes: job titles, roles, and employer of Business Contacts. |
| Inferences drawn from other personal information | Limited: only in aggregated or de-identified form, as described in Section 3. |
| Biometric information | No. |
| Audio, visual, or sensory data | No. |
| Protected classification characteristics (race, religion, health, etc.) | No: not intentionally collected. |
| Financial account or payment card numbers | No: online payment processing is not yet active on the Platform. When implemented, payment-card data will be processed and held only by BSA’s third-party payment processor (currently anticipated to be Square), and BSA does not intend to store full payment-card numbers. |
| Education information | No. |
How We Use Information
-
To provide, maintain, and improve the Platform and the Services, including AI-assisted analysis (see Section 4).
-
To manage accounts, workspaces, and the audit/project history log.
-
To communicate with Clients about their engagements, and to provide customer support.
-
To process payments and maintain business records.
-
To detect, prevent, and address security incidents, fraud, and misuse.
-
To comply with legal obligations and enforce the Terms of Service.
-
To develop and improve BSA’s internal tools using aggregated or de-identified data that does not identify a Client or individual and that BSA will not attempt to re-identify.
AI Processing and Sub-Processors
-
Portions of the Services are performed using third-party AI tools ("AI Sub-Processors"), which currently include the Anthropic Claude API. AI-assisted processing of Client Content occurs only when a Client user affirmatively initiates an analysis within a Workspace. The information sent to an AI Sub-Processor for that purpose may include the text of documents selected for the analysis, relevant project context, and verified site or project facts needed to perform the requested analysis.
-
BSA does not permit its AI Sub-Processors to use Client Content to train, fine-tune, or otherwise improve their general-purpose or public models, and requires each AI Sub-Processor it engages to enter into enterprise-level data-processing terms requiring confidentiality and prohibiting any use of Client Content for model-training purposes other than generating the requested analysis for the applicable Client. Client-initiated analytical output, meaning output displayed when a Client user affirmatively initiates an analysis within a Workspace, is displayed directly within that Workspace without prior review by BSA and is accompanied by an in-product disclaimer identifying it as preliminary. AI-generated content that BSA incorporates into a formal Deliverable is, by contrast, part of BSA’s internal analytical workflow and is reviewed by a qualified member of BSA’s project team before the Deliverable is published or delivered to a Client.
-
A current list of AI Sub-Processors and other material service providers is available upon request.
Our Role, and How We Share Information
Our Role: Service Provider and Business
BSA’s role with respect to personal information depends on whose information it is. For account, billing, and user-registration information that Clients and website visitors provide directly to BSA, BSA acts as a "business" (or controller) in its own right. For personal information embedded in Client Content (for example, names or contact details of property owners, tenants, or other individuals appearing in documents or public records that a Client submits for analysis), BSA acts solely as a "service provider" (or processor) performing the Services on the Client’s instructions. In that service-provider capacity, BSA does not use that personal information for its own independent purposes, does not sell it or share it for cross-context behavioral advertising, and will delete or return it in accordance with the Client’s instructions and Section 7 (Data Retention). The Client that submitted the personal information remains responsible for having a lawful basis to do so and for providing any notice or obtaining any consent that applicable law requires from the individuals to whom it relates.
How We Share Information
-
Service providers and sub-processors who support hosting, database and file storage, authentication, payment processing (once implemented), and AI-assisted analysis, under confidentiality and data-protection obligations.
-
Third-party data and GIS providers — including, for example, the U.S. Census Bureau geocoder and American Community Survey (ACS), FEMA’s National Flood Hazard Layer (NFHL), HUD, the U.S. Small Business Administration’s HUBZone program, the Houston-Galveston Area Council (H-GAC), the Texas Commission on Environmental Quality (TCEQ), the Public Utility Commission of Texas, the Texas Geographic Information Office (TxGIO), the USGS, the Multi-Resolution Land Characteristics (MRLC) Consortium, the Harris County Appraisal District, the Texas Comptroller of Public Accounts, and CARTO/OpenStreetMap basemap infrastructure — only as necessary to perform the requested research. These queries generally involve site- or property-level information, such as an address or geographic coordinates, rather than the Client’s identity, and generally involve BSA querying those providers rather than sharing Client Content with them, except where a specific tool requires it.
-
Professional advisors (e.g., auditors, legal counsel) under confidentiality obligations.
-
As required by law, regulation, legal process, or governmental request.
-
In connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality protections.
BSA does not sell personal information and does not share personal information for cross-context behavioral advertising. See Section 11 for the state-law definitions of these terms and BSA’s related disclosures.
Cookies and Tracking Technologies
BSA’s Platform does not use analytics, advertising pixels, tag managers, session-recording software, A/B-testing tools, or other third-party behavioral tracking technologies. An unauthenticated visitor to BSA’s public website does not receive any cookies. After a user authenticates to a Workspace, the Platform uses session cookies, provided through BSA’s authentication provider (Supabase Auth), that are strictly necessary to maintain the user’s authenticated session; these cookies are not used for advertising or cross-context behavioral tracking. BSA’s Platform also loads two categories of third-party network resources in the ordinary course of providing the Services: (a) web fonts served from Google Fonts, which receive ordinary request information such as a visitor’s IP address and user-agent string when serving a font; and (b) basemap tile imagery served from CARTO/OpenStreetMap infrastructure on authenticated mapping pages, which receives ordinary request information such as the user’s IP address and the map tiles requested. Neither of these third parties is used by BSA for advertising or behavioral tracking, and neither receives Client Content. Accordingly, BSA does not sell or share personal information for advertising purposes.
See Section 11 for BSA’s recognition of opt-out preference signals (such as the Global Privacy Control) and other state consumer-privacy-law rights that may apply to information collected through cookies.
Data Retention
BSA retains information under the schedule below, as reasonably necessary for its recordkeeping, client-service, and legal-compliance needs and subject to applicable law, contractual requirements, legal holds, and Client deletion requests as described below. After the applicable period, information is deleted or de-identified, except where longer retention is required by law, necessary to establish, exercise, or defend legal claims, or otherwise agreed with Client. This retention schedule applies regardless of whether Client’s access to the Platform is active, suspended, or terminated; suspension or termination of access does not, by itself, shorten the retention periods described below or result in earlier deletion of the information they cover.
-
Client workspace/project records and final Deliverables: retained for seven (7) years following completion or termination of the applicable engagement.
-
Billing, tax, and business records: retained for seven (7) years, or longer where required by applicable law.
-
Operational and security logs: retained for a shorter period appropriate to their operational and security purpose.
-
Audit-trail and evidence records documenting material project and system actions: retained as part of BSA’s project-history and compliance record for the periods described above, even where a Client requests deletion of the underlying Client Content to which they relate, except as otherwise required by law or separately agreed with Client in writing.
-
Infrastructure backups: retained and allowed to age out in accordance with the applicable infrastructure provider’s standard backup-retention cycle.
Data Security
Safeguards
BSA maintains administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, or destruction, including: encryption of data in transit and at rest by BSA’s infrastructure providers; role-based access controls and database row-level security limiting internal access to workspace content on a need-to-know basis; malware and antivirus scanning of uploaded files; multi-factor authentication, available to users; and audit/event logging of material system and project events, which BSA reviews periodically (not every instance of staff access to Client Content is separately logged, and BSA does not currently provide continuous, real-time production monitoring or alerting). BSA has prepared a written incident-response plan, which is in the process of formal adoption and testing. No method of transmission or storage is completely secure, and BSA cannot guarantee absolute security.
Security Incident Notification
If BSA becomes aware of a confirmed unauthorized access to or acquisition of personal information that compromises its security, confidentiality, or integrity, BSA will notify affected Clients without undue delay and in any event within any period required by applicable law and will provide information reasonably available to BSA regarding the nature and scope of the incident and BSA’s remediation efforts, consistent with Section 16.4 of the Terms of Service. Where BSA is acting as a service provider with respect to the affected information (see Section 5.1), BSA’s notification is provided to the Client, and the Client, not BSA, remains responsible for any notification the Client is independently required to make to affected individuals or regulators.
Children’s Privacy
The Services are intended for business use by adults and are not directed to children. BSA does not knowingly collect personal information from children.
Changes to This Policy
BSA may update this Policy from time to time. Material changes will be reflected in the "Last updated" date above and, where required by law, communicated to Clients directly.
This Policy and State Consumer Privacy Statutes
Scope: Not a General Consumer Privacy Notice
This Policy is a B2B notice directed to Clients and Business Contacts, not a general consumer privacy notice. That said, the California Consumer Privacy Act (CCPA/CPRA) extends rights to a Business Contact acting in an employment or commercial capacity on a Client’s behalf, and BSA extends the same request-handling process described in this Section 11 to Business Contacts as a matter of policy, regardless of state of residency. Most of the other state consumer-privacy statutes referenced in this Section — including the Texas Data Privacy and Security Act (TDPSA) and the Virginia, Colorado, Connecticut, and Utah statutes — define "consumer" to exclude an individual acting in a commercial or employment context, and so do not independently require this treatment for a Business Contact acting in that capacity. Separately, and without regard to this distinction, an individual identified in Client Content or public records who is not a Business Contact at all (for example, a property owner named in a title record) may independently qualify as a "consumer" under one of these statutes. This Section 11 identifies the statutes most likely to apply and how BSA addresses each.
Applicable State Consumer Privacy Statutes
Depending on residency, an individual described in Section 11.1 may have rights under an applicable state consumer-privacy statute to: (a) confirm whether BSA processes their personal information; (b) access a copy of it; (c) correct inaccuracies; (d) delete it, subject to exceptions; (e) opt out of certain processing, such as targeted advertising, sale, or profiling producing legal or similarly significant effects; and (f) appeal a denied request.
The statutory references in this Section 11 are provided for general informational purposes only. They are not a complete or exhaustive summary of every state consumer-privacy statute that may apply, are current only as of this Policy’s "Last updated" date above, and do not constitute legal advice. State privacy law in this area continues to change quickly, and additional states may adopt new statutes, or amend existing ones, after that date. BSA disclaims any liability arising from a change in, or omission of, an applicable statute after this Policy’s "Last updated" date, and any individual seeking to exercise a specific statutory right should consult the applicable statute directly or seek independent legal advice.
Because BSA is domiciled in Texas, the Texas Data Privacy and Security Act (TDPSA), Tex. Bus. & Com. Code ch. 541, applies to BSA unless BSA qualifies for the TDPSA’s small-business exemption. Because BSA and its Clients may also process information about individuals located in other states, California’s CCPA/CPRA, Cal. Civ. Code § 1798.100 et seq., is likewise relevant. More than twenty other states, including Virginia, Colorado, Connecticut, Utah, and Nevada, have adopted comprehensive consumer-privacy statutes that are broadly similar in structure and impose comparable obligations, and additional states continue to adopt new statutes or amend existing ones. Whether a particular statute applies to a particular individual depends on that individual’s state of residency and on BSA’s own size and activities, and should be confirmed against the current text of the statute at the time a request is received rather than assumed from this Policy alone.
BSA’s Services are operated using infrastructure providers located in both the United States and Canada; Client Content and other information may accordingly be stored, processed, or transmitted in either country. Where an individual described in this Section 11 is located outside the United States, see the International Processing section of the BSA Terms of Service for BSA’s cross-border transfer disclosures and consent, which apply in addition to the state consumer-privacy rights described in this Section 11.
How to Submit a Request
An individual may designate an authorized agent to submit a request on their behalf. BSA may require proof of the agent’s written authorization and may separately verify the request directly with the individual before responding.
To exercise the rights described above, an individual may submit a request to BSA by emailing privacy@beverlindevelopment.com. BSA will verify the request using information reasonably available to it before responding, and will not discriminate against anyone for exercising these rights. BSA will confirm receipt of a verifiable request within ten (10) business days and will respond substantively within forty-five (45) calendar days, extendable by an additional forty-five (45) calendar days where reasonably necessary, with notice of the extension provided within the initial period.
If BSA denies a request in whole or in part, BSA will inform the individual of the denial and of the right to appeal. An individual may appeal a denial by submitting a written appeal to privacy@beverlindevelopment.com, and BSA will respond to the appeal in writing within sixty (60) days of receipt, extendable by an additional forty-five (45) days where reasonably necessary with notice of the extension. If BSA denies the appeal, BSA will provide the individual a means to submit a complaint to the Attorney General of the individual’s state of residence, to the extent that state’s consumer-privacy statute provides for such a complaint mechanism.
Where BSA processes sensitive personal information as that term is defined under an applicable state statute (for example, precise geolocation or government identifiers appearing in Client Content), an individual may also have the right to limit BSA’s use of that information to purposes necessary to provide the Services. BSA does not use sensitive personal information for any purpose beyond providing the Services and complying with applicable law.
Do Not Sell or Share Your Personal Information
BSA does not sell personal information and does not use tracking technologies on its public website to share personal information for cross-context behavioral advertising, in each case as those terms are defined under applicable state law.
Some state consumer-privacy statutes define "sale" and "share" broadly enough to include certain uses of standard advertising or analytics cookies, even without an exchange of money. To the extent BSA ever engages in an activity that constitutes a sale or share of personal information under applicable law, BSA will post a clear and conspicuous opt-out mechanism on its website and will honor opt-out requests submitted through that mechanism or through a recognized opt-out preference signal, such as the Global Privacy Control, consistent with the Texas Data Privacy and Security Act (TDPSA), Tex. Bus. & Com. Code universal opt-out-signal requirement (in effect since January 1, 2025) and comparable requirements in other states.
The Texas TDPSA requires the specific notice "NOTICE: We may sell your sensitive personal data" wherever a business does sell sensitive or biometric personal data. BSA does not sell sensitive or biometric personal data, and this statement is included only to confirm that fact.
Contact Us
Questions or requests regarding this Policy or BSA’s privacy practices—including requests to exercise the rights described in Section 11—may be directed to Beverlin Strategic Advisors LLC, Attn: Richard Beverlin, 5900 Balcones Dr, Ste 100, Austin, TX 78731, privacy@beverlindevelopment.com.