Privacy at Broadview

Effective date: January 2, 2026

1. Who we are and the scope of this Policy

This Privacy Policy describes how Broadview Capital (“we,” “us,” or “our”) collects, uses, discloses, and otherwise processes personal information in connection with www.broadviewcapital.com, related pages that link to this Policy, and the inquiries, communications, subscriptions, and business interactions described below (collectively, the “Services”). Personal information means information relating to an identified or reasonably identifiable individual, as defined by applicable law.

Broadview Capital is the parent business platform, and Broadview Real Estate is its real estate subsidiary. This Policy governs this website operator’s processing, not every group company’s operations. Broadview Real Estate’s website, www.broadviewre.com, has a separate privacy policy. References to the Broadview group describe affiliation, not a single combined legal entity.

This Policy covers individuals acting personally or for a business, including website visitors, prospective business partners, owners, investors, lenders, advisers, vendors, applicants, and other contacts, to the extent we process their information through the Services. Rights and exemptions depend on the law and the capacity in which an individual interacts with us. Describing a right does not represent that every privacy statute applies to every Broadview entity or interaction.

A property, portfolio company, employer, fund, lender, service provider, or other organization may have a separate privacy notice. Where a specific notice applies, it governs the processing it describes, subject to applicable law. This Policy does not replace legally required financial privacy notices, employment notices, tenant-screening disclosures, consumer-report authorizations, health-information notices, or notices for building security systems. It does not make us responsible for an independent organization’s processing merely because we link to it or have an investment or business relationship with it.

This Policy is a disclosure of our practices, not a request for blanket consent. Merely visiting the Services, receiving this Policy, or accepting website Terms of Use is not consent to processing for which applicable law requires a separate choice or authorization.

2. Categories of information we collect

The information involved depends on the interaction. We seek information relevant to the purposes below, not every category from every person. Information supplied voluntarily in a message may include categories beyond the fields we request.

Contact and identifier information. Name, business name, title, email address, telephone number, mailing address, communication identifiers, social-media or professional-network handles and publicly available profile information, and information identifying your employer, organization, representatives, or professional role.

Inquiry, relationship, and transaction information. Messages, interests, preferences, proposals, business relationships, correspondence, meeting arrangements, requested services, and information about opportunities or transactions you ask us to consider. This may include the names and business details of founders, owners, executives, investors, financing sources, and other representatives; investment or partnership preferences; and non-sensitive materials about an acquisition, operating business, or proposed relationship.

Website and device information. Internet protocol address, device and browser characteristics, operating system, referring and exit pages, page views, date and time of access, interactions with features, approximate location inferred from an internet protocol address, and security or diagnostic logs. Cookies or similar identifiers may be involved as described in Section 5. Approximate location is different from precise device geolocation.

Professional and recruiting information. Where you contact us about opportunities, we receive information you submit about employment, education, qualifications, references, professional experience, work authorization, and availability. A designated employer’s supplemental notice and separate authorizations govern additional recruiting or background-check activities where required. We do not ask you to send government identifiers or background reports through a general website inquiry.

Communication and preference records. Subscription status, email delivery and interaction information where tracking is enabled, event registration, privacy choices, consent and withdrawal records, complaints, and records of requests and our responses. If a call, meeting, or other interaction is recorded, any required notice and consent will be provided for that interaction; this Policy alone does not authorize a recording.

Limited inferences. We may infer the subject matter, region, property, sector, or type of business relationship that interests you from your communications and use of the Services, for routing, relevant follow-up, and service improvement. Uses for targeted advertising or legally significant automated decisions are addressed separately below, not implied by this paragraph.

Audio, visual, and event information. Photographs, video, or recordings taken at events we host, sponsor, or attend, with notice provided at the event; voicemail messages; visitor and sign-in records for our offices or properties; and, where you participate, recordings or automated transcripts and summaries of calls or video meetings, which are made only with the notice and consent applicable law requires.

Sensitive information. General website forms are not intended for Social Security numbers, payment-card details, account credentials, medical records, biometric identifiers, precise geolocation, immigration documents, or other sensitive information. Do not submit these materials unless we specifically request them through an appropriate channel and provide any required notice. When necessary for a separately initiated transaction, legal obligation, accommodation, or recruitment process, sensitive information is handled under the applicable notice, purpose limitations, security controls, and consent requirements.

3. Sources of information

We receive information directly from you when you use a form, send a message, subscribe, attend an event, or otherwise communicate with us. We also receive it from your employer or organization; authorized representatives; business partners, brokers, advisers, and referrers; public professional profiles, public records, registries, and public filings; business-contact, data-enrichment, identity-verification, and sanctions- or watch-list-screening providers, where permitted; recruiting sources where relevant; and providers operating our website, communications, and business systems. Automated sources include your browser or device and technologies described in Section 5.

When you provide another person’s information, provide only what you are authorized to disclose and give that person any notice required of you. This request does not transfer our own legal obligations to you. We may combine information from these sources when relevant to a disclosed purpose and permitted by law.

4. How we use information

Operate the Services. Deliver pages and requested features; route and answer inquiries; maintain contact records; provide requested materials; coordinate meetings; support accessibility; diagnose problems; and administer our website and communications.

Evaluate and manage relationships. Review business acquisitions, investments, financing proposals, partnerships, supplier relationships, and operating opportunities; conduct relevant business research; and coordinate discussions with the appropriate sector or regional team. We may check the identity and authority of a contact, perform appropriate due diligence, and manage relationships with advisers, lenders, vendors, and counterparties. A general inquiry does not authorize a consumer report, establish investment eligibility, or create a binding transaction.

Communicate and market. Send subscriptions, invitations, firm announcements, and information about relevant opportunities where permitted and consistent with your choices. A request for a response is distinct from permission for unrelated marketing. We obtain additional consent where required and honor applicable suppression and opt-out requirements.

Improve and analyze. Understand which information is useful, assess website performance, identify service issues, and develop aggregated or deidentified business insights. Identifiable information is not treated as deidentified merely because we remove a name.

Automated and AI-assisted tools. We may use automated tools, including AI-assisted software provided by us or our service providers, to transcribe, summarize, classify, route, translate, draft responses to, or detect fraud or security risks in communications and Website activity. These tools support, and do not replace, human review of any decision that produces legal or similarly significant effects concerning you. We contractually restrict our service providers from using personal information we provide to them to train generally available artificial-intelligence models, other than as permitted by applicable law. Any regulated automated decision-making is disclosed in Section 15 or 16 or in a specific notice.

Protect and comply. Detect and investigate fraud, misuse, unauthorized access, and security incidents; protect people, property, systems, and legal rights; meet applicable recordkeeping, sanctions-screening, regulatory, tax, and other legal obligations; resolve disputes; enforce valid agreements; and establish, exercise, or defend legal claims.

Administer recruiting and corporate activity. Consider inquiries about employment or professional opportunities; administer relevant communications; and evaluate or implement lawful financings, acquisitions, restructurings, asset transfers, or similar transactions, with safeguards appropriate to the information involved.

We may also use information for any other purpose disclosed to you at the time of collection, with your consent, or as otherwise permitted or required by applicable law. We do not treat this Policy as permission to collect unlimited information or use information for any purpose. A materially different or incompatible purpose will be addressed through updated notices, an appropriate legal basis, and additional consent when required. We process sensitive information only as permitted by applicable law.

5. Cookies, analytics, embedded content, and privacy signals

The Services may use cookies, local storage, pixels, tags, and comparable technologies. Essential technologies support functions such as security, navigation, load balancing, form submission, and saving privacy preferences. Optional technologies, when enabled, may support preferences, audience measurement, communications measurement, embedded media, or advertising. An embedded video, map, social feature, or similar third-party service may receive technical information when it loads or when you interact with it.

Current technology disclosure. The Services may use the following categories of technologies, operated by us or by third-party providers acting on our behalf or, as described in Section 6, for their own purposes: (1) strictly necessary technologies, including security, authentication, load balancing, bot and fraud detection, form submission, and storage of your privacy preferences, which do not require consent; (2) functional and preference technologies that remember your settings, language, region, and prior interactions with the Services; (3) analytics and performance technologies, including web-analytics, tag-management, session-replay or heat-mapping, and A/B-testing tools, that collect page views, clicks, scrolling, time on page, referring and exit pages, approximate location, and device and browser identifiers; (4) advertising, retargeting, conversion-measurement, and audience-measurement technologies, including pixels, tags, and software development kits provided by advertising networks, social-media platforms, and search engines, that may collect identifiers and browsing activity across websites and link them to accounts you hold with those platforms; (5) embedded third-party content, including videos, maps, social-media feeds, scheduling tools, chat or virtual-assistant widgets, document viewers, and data-room or application portals, which may set their own cookies and receive your IP address and interaction data under their own privacy policies; and (6) communications-tracking technologies, including open- and click-tracking pixels and links in emails and other messages we send. Durations range from the browser session to up to 24 months, or longer where a provider’s published policy so states, after which identifiers expire or are renewed on your next visit. Categories (2) through (6) are optional and, where active, may be managed through any cookie-preference tool offered on the Website, through the opt-out tools offered by the relevant providers (including industry opt-out pages at optout.aboutads.info and optout.networkadvertising.org), and through browser and device settings. Where a cookie-preference tool is offered, it identifies the specific providers active at that time, and a category that is not listed there is not in use.

We request consent before setting or accessing technologies when the law requires it. We do not infer that consent solely from scrolling, continued browsing, or acceptance of Terms of Use. Where a lawful exception applies, we provide any required information and objection mechanism. You may manage optional technologies through the provider-specific opt-out tools described above, through browser or device settings, and, where applicable to the request, through the privacy-request methods in Section 14. Blocking essential functions may affect the Services; rejecting optional tracking does not prevent you from exercising privacy rights.

Where applicable law requires, we process recognized universal opt-out signals, including Global Privacy Control, as requests to opt out of the covered sale, sharing, or targeted advertising for the browser or device and, where required and identifiable, the associated account. You do not have to provide identity-verification documents to make an advertising opt-out. We do not treat a generic browser “Do Not Track” setting as equivalent to every legally recognized opt-out signal; this distinction does not limit our duty to honor a recognized signal.

Choices may be browser- or device-specific, and clearing cookies may remove stored preferences, although a valid broadcast opt-out signal continues to apply where required. Opting out does not necessarily eliminate contextual advertising or disclosures necessary to operate the Services. You may exercise applicable privacy choices using the methods in Section 14 whether or not a separate on-site privacy-choice control is available.

6. Sale, sharing, targeted advertising, and sensitive data

Privacy laws may classify disclosures for valuable consideration as a “sale” and certain advertising disclosures as “sharing,” even where no money changes hands. The legal characterization depends on actual data flows, contracts, and recipient uses, not the label we or a provider gives the arrangement.

Current practices and preceding 12 months. Depending on the technologies active on the Services from time to time, we may “sell” or “share” personal information, or process it for targeted or cross-context behavioral advertising, as those terms are defined under the CCPA and comparable state laws, and we may have done so during the preceding 12 months to the extent such technologies were active. The categories of personal information potentially involved are identifiers (including cookie, device, and advertising identifiers, IP address, and, where you provide it, email address or a hashed form of it); internet or other electronic-network activity information (including pages viewed, links clicked, searches, and referring websites); commercial information (including the properties, sectors, opportunities, or services in which you have expressed interest); approximate geolocation; and inferences drawn from the foregoing. The categories of recipients are advertising networks and platforms, social-media platforms, search engines, analytics and audience-measurement providers, marketing-technology and data-analytics providers, and our affiliates where they use the information for their own marketing. The purposes are measuring, attributing, and improving our advertising and content; building and reaching audiences likely to be interested in our businesses, properties, or opportunities; and other cross-context behavioral advertising. We do not sell or share sensitive personal information, biometric information, or the personal information of individuals we know to be under 16. To exercise an applicable sale, sharing, or targeted-advertising opt-out, you may (i) email info@broadviewcapital.com with “Broadview Capital - Privacy Opt-Out” in the subject, (ii) use the contact form at www.broadviewcapital.com/contact and identify the request as a sale/sharing or targeted-advertising opt-out, (iii) call +1 (832) 476-3550 and ask for the privacy contact, or (iv) enable a recognized universal opt-out signal such as Global Privacy Control in your browser. Opt-outs are honored within the time applicable law requires, apply to the browser or device from which they are made (and, where we can reasonably associate it, to your account or other known identifiers), and do not require you to create an account or verify your identity beyond what is needed to apply the choice.

These methods are available directly under this Policy and do not depend on a footer link or separate privacy-choice page. For browser- or device-specific technologies, provider or browser controls or a recognized opt-out signal may be needed to apply a choice to a particular browser or device. We apply the scope and timing required by the relevant law. A newsletter unsubscribe is separate from an advertising or sale/sharing opt-out.

We do not knowingly sell or share the personal information of children under 16. We do not use this Policy to obtain permission to sell sensitive information or biometric data. Any activity requiring a sensitive-data notice, opt-in, limitation mechanism, or separate authorization must satisfy those requirements before it occurs. Required rights cannot be waived by accepting Terms of Use.

7. How we disclose information

We disclose information for the purposes described in this Policy, subject to applicable law, binding confidentiality obligations, and relevant privacy choices. A disclosure is not authorized merely because a recipient belongs to a listed category.

Service providers and contractors. Website and infrastructure hosts; cloud, storage, and information-technology providers; security providers; communications and email-delivery services; customer-relationship-management and workflow providers; analytics providers where enabled; event or recruiting support; and other vendors performing services for us. They receive information relevant to their work. We require the contractual privacy, security, purpose, and onward-disclosure restrictions applicable to the relationship. A provider acting for its own advertising purposes is not treated as a restricted service provider for that activity merely because it also supplies other services.

Affiliates. Relevant Broadview entities may receive contact, inquiry, professional, and business-relationship information to route an inquiry, provide shared administrative support, evaluate an opportunity, or carry out a requested relationship. For example, a property-related inquiry may be directed to Broadview Real Estate, and a sector-specific proposal may be reviewed by an appropriate operating affiliate. Common ownership does not authorize unrestricted sharing, override consent requirements, or make all group entities joint controllers.

Business counterparties and professional advisers. When relevant to a requested or prospective relationship, business contact, professional, and opportunity information may be shared with sellers, founders, management teams, co-investors, financing sources, due-diligence participants, and authorized representatives. We may also disclose relevant information to attorneys, accountants, auditors, insurers, consultants, and other professional advisers for legitimate business and legal purposes. We limit disclosures to what is appropriate for the purpose and use confidentiality arrangements where warranted.

Corporate transactions. Relevant information may be disclosed to prospective or actual buyers, investors, lenders, successors, and advisers in connection with a proposed or completed merger, financing, acquisition, reorganization, insolvency proceeding, or transfer of all or part of our business or assets. Appropriate diligence protections, existing privacy commitments, applicable notice requirements, and legal restrictions continue to apply; a transaction does not eliminate them.

Legal and protective disclosures. Information may be disclosed when required by law or valid legal process, or where legally permitted and reasonably necessary to prevent fraud or harm, investigate wrongdoing, secure systems, enforce agreements, protect our rights or property or the safety, rights, or property of our affiliates, personnel, visitors, counterparties, or the public, or respond to a request from law enforcement, a regulator, or another government authority. We evaluate the legal basis and scope rather than treating every third-party request as compulsory.

At your direction or with required consent. We disclose information where you ask us to make an introduction, share materials, or use an integrated feature, and for other purposes specifically disclosed when the required authorization is obtained.

Information may be disclosed in properly aggregated or deidentified form. Where we rely on statutory deidentification, we take reasonable measures to prevent association with an individual, commit not to reidentify except to test legally compliant deidentification, and impose required restrictions on recipients.

8. Communications choices

You may unsubscribe from marketing emails through the link in the message or contact us using Section 14. We honor email opt-outs within the legally required period, including within 10 business days where the U.S. CAN-SPAM Act applies. We may retain a limited suppression record so that the choice remains effective. We may still send genuinely transactional, security, legal, or directly requested communications that are not marketing.

Providing a telephone number in a general inquiry is not, by itself, consent to automated marketing calls, prerecorded messages, or marketing texts. Any program requiring prior express or written consent uses a separate, clear request identifying the sender and relevant terms. Participation is not required to purchase goods or services where the law prohibits such a condition. Any revocation will be honored through legally recognized methods and within applicable deadlines. This Policy is not an SMS-program agreement.

9. Retention

We retain personal information only for as long as reasonably necessary and proportionate for the disclosed purpose, a continuing relationship, or a lawful compliance, security, or legal need. The following criteria apply to the relevant categories; a legal hold, pending or threatened dispute, regulatory inquiry, audit, security investigation, or other legal requirement may require longer retention of particular records, and we may retain information longer where permitted by law for the purposes described in this Policy.

Contact, inquiry, and relationship records: the time needed to answer and follow up on the inquiry, evaluate or administer the relationship, and meet applicable recordkeeping and claims periods. We may retain information about opportunities that did not proceed for the period reasonably necessary to document our evaluation, avoid duplicative review, satisfy conflict-check and recordkeeping obligations, and consider future opportunities where you have not objected.

Technical, cookie, and analytics information: the operational life of the technology and a proportionate period needed for security, troubleshooting, or measurement, subject to consent settings, configured expiration, and any incident investigation. Cookie durations are addressed in the current disclosure under Section 5.

Marketing information: the relevant subscription or permitted relationship, followed by a limited record needed to honor opt-outs and document compliance. An unsubscribe does not require erasing the minimum information needed to avoid contacting you again.

Professional, recruiting, and sensitive information: the specific evaluation or transaction and any required or justified compliance period, under the applicable supplemental notice. Sensitive information is not retained merely because less sensitive relationship information remains useful.

Privacy, consent, security, and dispute records: the period needed to demonstrate compliance, protect rights, resolve the matter, and meet applicable legal requirements. When information is no longer needed, we delete, deidentify, or otherwise dispose of it appropriately. Where immediate deletion from isolated backups is impracticable, retained copies remain protected, are not restored for ordinary new uses, and are removed through the applicable retention cycle unless legally required otherwise.

10. Security

We maintain administrative, technical, and physical safeguards designed to protect information, taking account of its nature, volume, use, and risk. No website, network, communication channel, or storage system can be guaranteed completely secure. This limitation is not a waiver of our legal security duties, breach-notification duties, or your nonwaivable rights. You are responsible for maintaining the security of your own devices, networks, email accounts, and credentials, and for the accuracy of the contact information you provide.

Do not send passwords, payment instructions, financial-account credentials, protected medical information, or unnecessary sensitive documents through a general contact form. Use a separately approved secure channel when appropriate. Contact us promptly about suspected misuse of the Services or your information. Never rely only on an email or website message to verify a change in bank or payment instructions.

11. International processing

We are based in the United States, and information may be accessed or processed in the United States and other countries where the relevant Broadview entity, counterparty, or service provider operates. Data-protection laws may differ from those in your location. Where a transfer is restricted by applicable law, we use the required lawful mechanism and safeguards, which may include an adequacy decision, approved contractual clauses, a UK transfer addendum or agreement, and supplementary measures as appropriate. Contact us to request information about relevant safeguards, subject to lawful redactions.

We do not rely on your use of the Services as blanket consent to international transfers. We do not claim certification under a governmental transfer program merely by describing cross-border processing. Additional territorial rights are described in Section 16.

12. Children and young people

The Services are directed to adults and business audiences and are not intended for children under 18. We do not knowingly solicit children’s personal information through the general Services. If you believe a child provided information, contact us so we can investigate and take appropriate action, including deletion or obtaining legally required authorization. Recruiting or other lawful interactions with young people, if offered, require appropriate procedures and any additional notices rather than reliance on this general Policy.

13. External websites and separate systems

Links and embedded functions may take you to a property website, portfolio company, application platform, social network, data room, payment service, or other separately operated service. Review the notice and terms for that service before submitting information. This Policy continues to apply to information we receive and process within its scope, but it does not control an independent party’s own processing. Our legal responsibilities for our own selection, configuration, or disclosure decisions remain unaffected.

14. Privacy rights, requests, verification, and appeals

Depending on your residence, our activities, and the governing law, you may have rights to confirm whether we process your information; access it and obtain a portable copy; correct inaccuracies; request deletion; withdraw consent; limit or object to certain processing; and opt out of sale, sharing, targeted advertising, or qualifying profiling. Some laws also provide rights concerning specific third-party recipients, categories of recipients, or automated-decision information, explanation, and review. We provide those rights to the extent applicable rather than treating this summary as an exhaustive limitation.

Submit a request. Email info@broadviewcapital.com with “Broadview Capital - Privacy Request” in the subject; use the contact form at www.broadviewcapital.com/contact and identify it as a privacy request; or call +1 (832) 476-3550 and ask for the privacy contact. Mailing details are in Section 18. Tell us which website or entity is involved, your jurisdiction, how you interacted with us, and the request you wish to make. Please do not send sensitive identity documents unless we request them through a secure method. An accessible alternative format is available on request. These same methods may be used for any applicable sale, sharing, or targeted-advertising opt-out.

Verification and agents. For requests requiring verification, we use information reasonably necessary to confirm identity and authority, proportionate to the sensitivity of the request. An authorized agent may act where permitted, subject to reasonable proof of authority and any permitted direct confirmation. We do not require a new account. Sale/sharing and advertising opt-outs are not subject to the identity-verification standard used for disclosure of specific personal information, although information needed to apply the choice may be requested as permitted by law.

Timing and limitations. We respond within the applicable statutory period and explain a permitted extension or denial. Rights may be subject to lawful exceptions, including security, legal obligations, privilege, trade secrets, another person’s rights, recordkeeping, and establishing or defending claims, and we may decline, or charge a reasonable fee for, a request that is manifestly unfounded, excessive, or repetitive, as permitted by law. We will not deny a request solely because an available process is inconvenient or because you decline unrelated marketing consent. Requests are handled without charge unless the applicable law allows a reasonable fee or refusal in the particular circumstances. We explain the basis when required.

Appeal. Where an appeal right applies, email the same address with “Broadview Capital - Privacy Appeal,” or use the same phone or form channels, and identify the decision you are appealing. Submit the appeal within a reasonable period after the decision. We explain the result within the applicable deadline and provide the relevant regulator’s complaint mechanism when required. Privacy requests, appeals, and regulator complaints do not require a website-arbitration notice or completion of a contractual dispute process.

Texas. Where the Texas Data Privacy and Security Act applies, we respond to a rights request without undue delay and within 45 days, subject to a permitted additional 45 days with notice and reasons. We respond to an appeal within 60 days. If an appeal is denied, we provide the Texas Attorney General’s online complaint mechanism. Applicable access, correction, deletion, portability, opt-out, and non-discrimination rights are preserved, including recognized agent or technology-based opt-outs as required by law.

Other U.S. states. Where another U.S. state comprehensive privacy law applies (for example, in Virginia, Colorado, Connecticut, Utah, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, or Rhode Island), we honor the confirmation, access, correction, deletion, portability, opt-out, and appeal rights that law provides within the timelines it specifies, generally 45 days with one permitted 45-day extension, and we provide the applicable attorney general’s complaint channel when an appeal is denied. Many of these laws exclude individuals acting in a commercial or employment context from the definition of “consumer,” and we apply those exclusions as written.

We do not unlawfully discriminate or retaliate against you for exercising privacy rights. A lawful denial of a feature that cannot operate without requested information is different from a penalty for exercising a right. None of the website Terms of Use reduces a nonwaivable privacy right or our obligations under applicable law.

15. Additional California disclosures

This section applies where the California Consumer Privacy Act, as amended (“CCPA”), governs our processing of a California resident’s information. It does not assume an exemption merely because you contact us for a business or employment purpose. Exempt information and activities are treated according to the applicable law.

The categories potentially involved in the interactions described in Section 2 include identifiers; personal information described in California Civil Code Section 1798.80(e), such as contact and employment information; commercial information; internet or electronic-network activity; approximate geolocation; professional or employment-related information; and inferences. Other categories, such as protected-classification characteristics, audio or visual information, nonpublic education records, biometric information, and sensitive personal information, may be collected only when relevant to a specific interaction and as described below or in a transaction-specific notice. Listing a potential category is not a representation that all categories were collected.

Categories actually collected in the preceding 12 months: identifiers; personal information described in California Civil Code Section 1798.80(e), such as name, address, telephone number, and employment information; commercial information; internet or other electronic-network activity information; approximate geolocation data; audio, electronic, visual, or similar information, where calls or meetings are recorded or you attend an event we host, in each case with the required notice; professional or employment-related information; education information, where you provide it in a recruiting inquiry; inferences drawn from the foregoing; and sensitive personal information only to the extent you choose to include it in a message or it is required for a separately initiated transaction, accommodation, or recruiting process. We do not request protected-classification characteristics, biometric information, or precise geolocation through the Services, although you may volunteer such information in a communication.

Categories disclosed for a business purpose in the preceding 12 months, with recipient categories for each: each category listed above may have been disclosed to service providers and contractors (website hosting, cloud and information-technology, security, communications and email-delivery, customer-relationship-management and workflow, analytics, event-support, and recruiting-support providers); identifiers, Section 1798.80(e) information, commercial information, professional or employment-related information, and inferences may have been disclosed to our affiliates, business counterparties, and professional advisers; and any category may have been disclosed to courts, regulators, law-enforcement or other government authorities, insurers, or actual or prospective successors as described in Section 7.

The separate sale/sharing history, relevant categories, purposes, and recipients appear in Section 6. Sources are described in Section 3, collection and use purposes in Section 4, disclosure recipients in Section 7, and retention criteria in Section 9, as relevant to the categories actually processed. Required notice at collection is provided at or before collection; this Policy does not dispense with that notice.

California residents have applicable rights to know, access, correct, delete, opt out of sale or sharing, limit qualifying uses and disclosures of sensitive personal information, and receive equal treatment for exercising those rights. We use sensitive personal information only for purposes permitted without a right to limit, such as providing requested services, security, and legal compliance, unless we separately provide the required notice and limitation mechanism before another covered use. We do not operate a financial-incentive program involving personal information under this Policy; any such program would require its own notice and terms.

Use Section 14 to submit a request, including through an authorized agent as permitted. For access, correction, and deletion requests, we acknowledge receipt within 10 business days and generally respond within 45 calendar days, subject to the extensions and exceptions the CCPA permits. Applicable opt-outs and limitation requests are acted upon as soon as feasibly possible and no later than 15 business days where that deadline applies. We do not require you to create an account to exercise a right. A recognized Global Privacy Control signal is honored where the CCPA requires it. If we use automated decision making technology to make a significant decision about you within the meaning of the CCPA regulations, we will provide the required pre-use notice, opt-out, and access rights before doing so.

California residents may also contact us with “California Shine the Light” to request information concerning qualifying disclosures for third parties’ direct marketing under California Civil Code Section 1798.83, where applicable. This process is separate from, and does not replace, CCPA rights. We review and update the California disclosures at least annually while the CCPA requires them.

16. EEA, United Kingdom, Switzerland, and other territorial rights

Where the GDPR, UK GDPR, or applicable Swiss law governs our processing, the entity identified in Section 1 is the controller for its own processing unless a transaction-specific notice identifies another controller. You may contact that entity through Section 18. Any legally required local representative or data-protection contact is identified in the applicable territorial or transaction notice.

Purposes and legal bases. We rely on steps you request before a contract or performance of a contract where you are the contracting individual; legitimate interests, after the required balancing, for ordinary business-to-business relationships, inquiry routing, proportionate service improvement, fraud prevention, security, and legal claims; legal obligations for required compliance and recordkeeping; and consent for activities such as optional tracking or marketing where required. Our relevant legitimate interests are communicating with business contacts, evaluating and administering business opportunities, operating reliable Services, and protecting our business and others. We do not rely on legitimate interests where your rights override those interests. A separate legal condition is required for special-category or criminal-offence information where applicable.

Your choices and rights. Subject to the applicable law, you may request access, correction, erasure, restriction, portability, or relevant information about processing; object to processing based on legitimate interests; and withdraw consent without affecting earlier lawful processing. You may object to direct marketing at any time, including related profiling. You may complain to your competent supervisory authority without first contacting us. We generally respond within one month where the GDPR or UK GDPR applies, with a permitted extension and timely explanation when necessary.

Automated decisions. We do not use the Services to make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects concerning you. The automated and AI-assisted tools described in Section 4 support human review and do not replace it. If this changes, we will provide, before any such processing occurs, the information and rights applicable law requires, including meaningful information about the logic involved, the significance and expected consequences of the processing, and a means to obtain human review of or contest the decision.

Providing information. General browsing does not require submission of a business inquiry. Information specifically needed to answer your request, evaluate an opportunity, or meet a legal obligation may be necessary for that activity; without it, we may be unable to proceed. We identify mandatory information in the relevant process. Section 11 addresses international transfers. Where another jurisdiction grants mandatory rights, we address a request under that jurisdiction’s applicable requirements rather than asking you to waive them through a U.S. website contract.

17. Changes to this Policy

We may update this Policy to reflect changes in the Services, practices, or law. The effective date identifies the current version. We provide additional notice and obtain consent where legally required before a material change applies. New wording does not retroactively authorize a use that conflicts with binding promises made when information was collected. Continued use alone does not supply consent where a separate choice is required.

18. Contact

Broadview Capital - Privacy Contact
10500 Richmond Avenue, Suite 200, Houston, Texas 77042
Email: info@broadviewcapital.com
Telephone: +1 (832) 476-3550
Website contact form: www.broadviewcapital.com/contact

Please identify the relevant Broadview entity or property when writing. Where another entity is responsible, we will explain the appropriate route or forward the request when authorized and appropriate; this does not extend a statutory deadline that applies to us.