CBA Site Research
Privacy Notice
Last updated: August 31, 2026 (revised)
This Privacy Notice explains how Charlan, Brock & Associates, Inc. ("CBA", "we", "us", or "our") handles personal information in connection with CBA Site Research and service experiences branded CBA Land Intel (the "Service").
1. Scope and roles
The Service is a business application used through organization workspaces. Depending on the context, CBA may process personal information for an organization that controls Customer Content, or may act as an independent controller for its own account, security, support, marketing, and legal operations. A signed customer agreement controls if it provides different privacy or data-processing terms.
2. Information we collect
- Early-access and contact information: name, work email, company, market, communication preferences, and unsubscribe choices when you request access or contact us.
- Account and organization information: email address, display name, organization and workspace membership, role, authentication status, and administrator actions.
- Customer Content: project locations, parcel and site inputs, documents, research inputs, files, notes, and other information an authorized user adds to a workspace.
- Research-agent information: messages, conversation context, and outputs when an authorized user uses an AI-assisted feature.
- Usage, security, and support information: product activity, support requests, audit events, request identifiers, and technical diagnostics. Security logs use one-way hashes for network and browser identifiers where practicable.
- Public and third-party source information: property, mapping, regulatory, market, and other information obtained from public agencies and third-party research providers.
3. How we use information
We use information to provide, secure, maintain, and improve the Service; authenticate users; manage organization workspaces; perform requested research and AI-assisted functions; respond to support and privacy requests; prevent fraud and misuse; comply with law; and communicate about access requests. We send product, market, and early-access marketing messages only where you have opted in or another lawful basis applies. Transactional messages about a requested account or access request are not marketing messages.
4. AI-assisted features and research sources
When you use an AI-assisted feature, we may send the applicable prompt, conversation context, and authorized workspace context to providers that operate the feature for us. We provide the information needed to perform the requested function. Provider practices are governed by their applicable terms and any controlling customer agreement. Do not submit sensitive personal information or confidential material unless you have authority to do so and it is necessary for the intended use.
Research-source information may come from government agencies, mapping providers, and commercial data vendors. We use it to operate the Service, but do not control its completeness, timing, or accuracy. See the Terms of Service for important non-reliance and verification requirements.
5. How we share information
We share information only as reasonably necessary for the purposes above: with authorized users and administrators in your organization; with service providers that host, secure, monitor, email, map, research, or operate the Service; with professional advisers; to comply with law or a valid legal process; to protect people, rights, and systems; and in connection with a corporate transaction. Provider categories may include cloud hosting and database services, authentication and anti-abuse services, maps and geospatial services, AI and research providers, product analytics, error monitoring, and email delivery.
We do not sell personal information or use Customer Content for cross-context behavioral advertising. We do not knowingly allow a provider to use Customer Content for its own advertising purposes.
6. Cookies, local storage, and analytics
The Service uses essential cookies and similar technologies to keep a signed-in session secure and to protect forms from automated abuse. When product analytics is enabled for the Service, the authenticated application may use browser local storage and product analytics associated with internal account and workspace identifiers. Automatic interaction capture and session recording are disabled, and URL query strings and referrer information are removed before analytics data is sent. When error monitoring is enabled, it is configured to remove request bodies, cookies, request headers, and query strings; an error report may include an internal account identifier and technical error details so that we can diagnose the issue. You can manage browser storage through your browser settings; clearing it can affect the Service.
7. Marketing choices
An early-access request can be submitted without opting in to product and market updates. If you opt in, we record the consent version and time and provide an unsubscribe link in marketing emails. You may also request that we stop marketing communications through the contact method below. Withdrawing marketing consent does not prevent necessary transactional or security communications.
8. Retention
We retain information for as long as reasonably necessary to provide the Service, meet contractual obligations, resolve disputes, maintain security, and comply with law. Active account and project information is generally retained while the applicable customer relationship remains active. Our current application retention configuration is designed to retain security audit events for at least one year. Deleted project content is handled through the product’s deletion workflow, and timing can depend on technical, legal, and operational requirements.
9. Your privacy requests
Subject to applicable law, you may request access, correction, deletion, portability, restriction, or information about our handling of your personal information. An organization administrator may also make a request for its authorized users. We may need to verify your identity, authority, and request before responding. If we deny a request, you may ask for a review through the same contact channel. We may retain information where needed for security, legal, or contractual reasons.
10. Children and international processing
The Service is a business product and is not directed to children. Do not use it if you are under 18. The Service is operated from the United States, and information may be processed in the United States and other locations where our service providers operate, subject to applicable law and contractual safeguards.
11. Changes and contact
We may update this Notice as the Service or applicable law changes. We will post the updated version here and may provide additional notice for material changes. To make a privacy request or ask a question, email cristian@cbaarchitects.com, use the CBA contact page, or mail Charlan, Brock & Associates, Inc., 1770 Fennell Street, Maitland, Florida 32751. Authenticated users may also submit a Privacy request through Support.
CBA Site Research is a service of Charlan, Brock & Associates, Inc.