Privacy Policy
Effective August 1, 2026 · Chicago Business Intermediary LLC
1. Introduction and Scope
Chicago Business Intermediary LLC, an Illinois limited liability company ("Company," "we," "us," or "our"), is committed to protecting the privacy and security of personal information entrusted to us. This Privacy Policy ("Policy") describes how we collect, use, disclose, retain, and safeguard information when you:
- Visit our website at chicagobusinessintermediary.com, including any subdomains, successor URLs, or associated landing pages (collectively, the "Site");
- Communicate with us via telephone, email, text message, social media, or any other channel;
- Engage us for brokerage, valuation, advisory, exit planning, or any other professional services; or
- Interact with us in any other capacity, including as a referral source, professional contact, or event attendee.
This Policy applies to all individuals who interact with the Company (collectively, "you" or "your"). By accessing the Site or providing information to us through any channel, you acknowledge that you have read, understood, and agree to the practices described in this Policy. If you do not agree with this Policy, you must discontinue use of the Site and refrain from providing personal information to us.
Important Notice: This Privacy Policy is provided for informational purposes and does not constitute legal advice. This Policy does not create any contractual or other legal rights in or on behalf of any party. If you have questions about your rights under applicable privacy laws, consult a qualified attorney licensed in your jurisdiction.
2. Categories of Information We Collect
2.1 Information You Provide Directly
We collect personal information that you voluntarily provide, which may include:
- Identifiers: Full name, email address, telephone number, mailing address, and professional title
- Business Information: Business name, entity type, industry classification, approximate revenue and SDE/EBITDA, number of employees, years of operation, reason for selling or buying, asking price or acquisition budget, geographic preferences, and other information relevant to a potential transaction
- Financial Records: Income statements, tax returns, balance sheets, cash flow statements, debt schedules, proof of funds, lender pre-qualification letters, and other financial documentation provided in connection with a brokerage, valuation, or advisory engagement
- Professional Background: Professional experience, acquisition history, industry expertise, licensing and credentials, and references
- Self-Assessment Responses: Information provided through any self-assessment tools, readiness questionnaires, or other diagnostic instruments we may offer from time to time
- Communications Content: Content of emails, voicemail recordings, notes from telephone or in-person consultations, meeting summaries, and all other correspondence
2.2 Information Collected Automatically
When you visit the Site, we and our authorized third-party service providers may automatically collect certain technical and usage information through cookies, web beacons, server logs, and similar technologies, including:
- Device and Browser Data: IP address, browser type and version, operating system, device type and identifiers, screen resolution, and language preferences
- Usage Data: Pages viewed, links clicked, time and duration of visit, referring and exit URLs, search queries leading to the Site, and interaction patterns
- Location Data: Approximate geographic location derived from IP address (we do not collect precise geolocation data through the Site)
2.3 Information from Third-Party Sources
We may receive information about you from third-party sources, including: publicly available business databases and registries; business listing and transaction platforms; referral partners such as attorneys, certified public accountants, financial advisors, wealth managers, insurance professionals, and other intermediaries; analytics and advertising platforms; and social media platforms (only where you have chosen to interact with our social media presence). We may combine third-party information with information we collect directly.
2.4 Categories We Do Not Collect Through the Site
The Company does not intentionally collect the following categories of information through the Site: Social Security numbers or government-issued identification numbers; biometric identifiers or biometric information as defined under 740 ILCS 14/10 (the Illinois Biometric Information Privacy Act); protected health information governed by HIPAA; financial account numbers (bank accounts, credit/debit card numbers); information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership. If any such information becomes necessary in connection with a formal engagement, it will be collected under the terms of a separate written agreement with appropriate safeguards and, where required, your explicit written consent.
3. How We Use Your Information
We process personal information for the following business purposes:
- Service Delivery: To evaluate and respond to inquiries; assess suitability for potential engagements; facilitate business sale, acquisition, and transfer transactions; prepare valuations and market analyses; provide advisory and exit planning services; and administer ongoing client relationships
- Transaction Facilitation: To match prospective sellers with qualified buyers; present business opportunities (subject to NDA protections); coordinate due diligence processes; and support closing activities
- Communications: To respond to your inquiries; provide engagement updates and transaction status communications; deliver requested information and documents; and conduct follow-up consultations
- Marketing Communications: To send market insights, industry reports, newsletters, event invitations, or promotional materials only where you have affirmatively opted in to receive such communications or where otherwise permitted by applicable law
- Site Operations and Improvement: To operate, maintain, and improve the Site; analyze usage patterns and traffic sources; optimize content and user experience; test new features; and ensure technical functionality
- Security and Fraud Prevention: To detect, investigate, prevent, and respond to security incidents, unauthorized access, fraud, spam, and other malicious or illegal activity
- Legal and Regulatory Compliance: To comply with applicable federal, state, and local laws, regulations, industry standards, and professional obligations; respond to subpoenas, court orders, and other legal processes; and cooperate with regulatory authorities and law enforcement
- Internal Business Operations: For internal administration, record-keeping, auditing, quality assurance, training, dispute resolution, and enforcement of our agreements
- De-identified and Aggregated Analysis: To create de-identified or aggregated data sets that do not reasonably identify any individual, for purposes of market research, industry analysis, and business intelligence
4. Legal Bases for Processing
Where applicable law requires a legal basis for processing, we rely on one or more of the following:
- Your Consent: Where you have given explicit, informed consent (e.g., opting in to marketing emails). You may withdraw consent at any time without affecting the lawfulness of processing conducted prior to withdrawal.
- Performance of a Contract: Where processing is necessary to perform our obligations under an engagement agreement, NDA, or other contract with you, or to take pre-contractual steps at your request
- Legitimate Business Interests: Where processing is necessary for our legitimate interests (such as improving services, preventing fraud, ensuring network security, or conducting reasonable marketing), provided those interests do not override your fundamental rights and freedoms
- Legal Obligation: Where processing is necessary to comply with a legal obligation to which the Company is subject
- Vital Interests: In rare circumstances, where processing is necessary to protect your vital interests or those of another person
5. Confidentiality in Business Transactions
Confidentiality is foundational to our business and a core professional obligation. The Company recognizes that premature or unauthorized disclosure of a potential sale, acquisition, or valuation can cause material harm to business operations, employee relations, customer relationships, vendor arrangements, competitive positioning, and the transaction itself.
Accordingly, the Company maintains the following confidentiality practices:
- All information provided to the Company in connection with a potential or active engagement is treated as confidential, subject to the terms of any applicable engagement agreement, non-disclosure agreement ("NDA"), or other written confidentiality undertaking.
- We require all prospective buyers to execute an NDA satisfactory to the Company before we disclose any identifying business information, financial details, trade secrets, or proprietary data belonging to a seller client.
- We do not publicly disclose the identity of our clients, the existence or terms of any engagement, or the details of any transaction without the express prior written consent of the affected party, unless compelled by law, regulation, or legal process.
- Our employees, independent contractors, agents, and any third parties with authorized access to confidential engagement information are bound by written confidentiality obligations.
- Information sent to us through email or another communication channel is treated as confidential from the point of receipt. However, full contractual confidentiality protections, including remedies for breach, attach only upon execution of a formal NDA, engagement letter, or other written agreement between you and the Company.
- We maintain commercially reasonable administrative, technical, and physical safeguards to protect confidential information from unauthorized access, use, or disclosure.
Nothing in this Privacy Policy limits, modifies, waives, or supersedes any confidentiality obligations set forth in a separately executed NDA, engagement letter, listing agreement, buyer representation agreement, or any other agreement between you and the Company. In the event of a conflict between this Policy and the terms of such an agreement, the terms of the separately executed agreement shall control.
Partner Network Information Flow
Where a client asks Chicago Business Intermediary to identify a specialist through the Partner Network, we share only the information reasonably necessary to scope that specialist's work, and only after the client agrees to the introduction. The specialist is engaged directly by the client under the specialist's own engagement terms and privacy practices, and the specialist remains responsible for its own handling of client information.
Where a professional approaches us about joining the network, we collect the professional's name, business, discipline, licensing and credential information, insurance status, and conflict-check information, and retain it for the purpose of evaluating and administering that relationship.
Any referral compensation arrangement is disclosed in writing to the client before an introduction is made.
6. Information Sharing and Disclosure
The Company does not sell, rent, lease, or trade your personal information to third parties for their own independent marketing purposes. We may share your information only in the following limited and defined circumstances:
- With Your Authorization: When you have directed or authorized us to share information, including but not limited to: presenting a business opportunity to qualified, NDA-bound buyers; sharing your buyer profile with sellers or their representatives; or connecting you with transaction-related professionals (attorneys, CPAs, lenders, insurance brokers, landlords, or other parties reasonably necessary to facilitate a transaction)
- Service Providers and Processors: With trusted third-party vendors who perform services on our behalf and under our instruction, including website hosting and infrastructure, email delivery and marketing platforms, customer relationship management (CRM) systems, analytics services, cloud storage providers, and IT security vendors. These providers are bound by written agreements requiring them to process your information only for the purposes specified by the Company, maintain appropriate technical and organizational security measures, and refrain from using your information for their own purposes.
- Professional Advisors: With our own legal counsel, accountants, insurers, auditors, and other professional advisors, subject to applicable duties of professional confidentiality and privilege
- Legal Requirements and Protection of Rights: When we believe in good faith that disclosure is: (i) required by applicable federal, state, or local law, regulation, or ordinance; (ii) required in response to a subpoena, warrant, court order, discovery request, regulatory inquiry, or other compulsory legal process; (iii) necessary to protect the rights, property, or safety of the Company, our clients, our employees, or any third party; (iv) necessary to detect, prevent, or address fraud, security incidents, or technical issues; or (v) necessary to enforce our Terms of Service, engagement agreements, or other contractual rights
- Business Transfers: In connection with any actual or prospective merger, acquisition, asset sale, reorganization, dissolution, bankruptcy, or similar transaction involving all or a portion of the Company's business or assets, your personal information may be among the assets transferred or disclosed to the prospective acquirer or successor entity. Any successor entity will be required to honor the commitments made in this Policy or provide you notice and an opportunity to opt out.
- De-identified or Aggregated Data: We may share de-identified or aggregated information that cannot reasonably be used to identify any individual, for purposes including market research, industry benchmarking, and statistical analysis
7. Cookies, Tracking Technologies, and Online Analytics
7.1 Technologies We Use
The Site may use the following categories of cookies and tracking technologies:
- Strictly Necessary Cookies: Required for essential Site functions such as page navigation and security features. These cookies cannot be disabled without impairing core Site functionality.
- Analytics and Performance Cookies: Used to collect information about how visitors interact with the Site, including pages visited, traffic sources, bounce rates, and time on page. We may use third-party analytics platforms, including but not limited to Google Analytics, to collect and analyze this data.
- Functionality Cookies: Used to remember user preferences and settings across visits
- Web Beacons and Pixels: Small electronic files embedded in web pages or emails used to count visitors, track page views, monitor email open and click-through rates, and compile aggregate usage statistics
7.2 Your Cookie Choices
You may manage your cookie preferences through your browser settings. Most browsers allow you to refuse or delete cookies, set preferences for specific sites, and receive alerts when cookies are set. Note that disabling cookies may affect Site functionality. For more information, visit allaboutcookies.org.
7.3 Google Analytics
If we use Google Analytics, it may collect information about your use of the Site using cookies and report aggregate website trends without identifying individual visitors. Google's use of data collected through Google Analytics is governed by Google's own privacy policy and terms of service. You may opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
7.4 Do Not Track Signals
There is currently no universally accepted standard for interpreting "Do Not Track" (DNT) browser signals. The Site does not currently alter its data collection or use practices in response to DNT signals. If a uniform standard is adopted and we begin responding to DNT signals, we will update this Policy accordingly.
8. Data Retention
We retain personal information only for as long as reasonably necessary to fulfill the purposes for which it was collected, comply with our legal and regulatory obligations, resolve disputes, and enforce our agreements. Specific retention periods include:
- Active Client and Engagement Records: For the duration of the engagement plus a minimum of seven (7) years following completion or termination, or longer as required by applicable law, regulation, professional standards, statute of limitations, or contractual obligation
- Prospective Client and Inquiry Information: For a reasonable period following our most recent interaction, typically not to exceed three (3) years, unless you request earlier deletion or a longer period is warranted by ongoing discussions or legitimate business interest
- Transaction Records and Documentation: For a minimum of seven (7) years following the closing date of a transaction, or longer as required by the Illinois statute of limitations for contract, fraud, or fiduciary duty claims, applicable tax laws, or regulatory requirements
- Marketing and Communications Preferences: Until you opt out, unsubscribe, or request deletion of your contact information
- Website Analytics Data: In aggregated, de-identified form, retained indefinitely for trend analysis. Individual-level analytics data is retained for a maximum of twenty-six (26) months unless a shorter retention period is configured in our analytics platform.
- Legal Hold: Notwithstanding the above, we may retain information for longer periods when required to preserve evidence in connection with actual or reasonably anticipated litigation, regulatory investigation, or dispute
When personal information is no longer required for any purpose described above, we will securely delete or irreversibly anonymize it in accordance with our internal data retention and destruction procedures.
9. Data Security
The Company implements reasonable and appropriate administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, acquisition, use, alteration, disclosure, or destruction. These measures include, but are not limited to:
- Encryption of data in transit using industry-standard TLS/SSL protocols
- Access controls limiting personal information access to authorized personnel on a need-to-know basis
- Secure storage of physical documents containing personal information
- Employee and contractor training on data protection responsibilities and confidentiality obligations
- Regular review and updating of security practices in light of current risks and technology
No Guarantee of Security. Despite our efforts, no method of transmission over the Internet, method of electronic storage, or physical security measure is completely secure or impervious to breach. Accordingly, while we strive to protect your information using commercially reasonable means consistent with industry standards, we cannot and do not warrant or guarantee the absolute security of any information you transmit to us or that we store, and we expressly disclaim, to the fullest extent permitted by applicable law, any liability for unauthorized access to, acquisition of, or breach of personal information, except where such liability is imposed by applicable law and cannot be disclaimed.
10. Your Rights and Choices
10.1 General Rights
Depending on your jurisdiction, applicable law may provide you with certain rights regarding your personal information. These may include the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate, incomplete, or outdated personal information
- Deletion: Request deletion of your personal information, subject to applicable legal retention requirements, ongoing engagement obligations, and our legitimate business interests
- Restriction: Request that we restrict or limit certain processing activities
- Data Portability: Request that your personal information be provided in a structured, commonly used, machine-readable format
- Objection: Object to certain processing activities, including processing based on legitimate interests or for direct marketing
- Opt-Out of Marketing: Unsubscribe from marketing communications at any time using the unsubscribe mechanism in any marketing email, or by contacting us directly
- Non-Discrimination: Exercise your privacy rights without receiving discriminatory treatment
10.2 Illinois-Specific Provisions
Illinois Biometric Information Privacy Act (BIPA), 740 ILCS 14: The Company does not collect, capture, purchase, receive through trade, or otherwise obtain biometric identifiers (including retina or iris scans, fingerprints, voiceprints, or scans of hand or face geometry) or biometric information as defined under BIPA through the Site or in the ordinary course of its brokerage, valuation, or advisory services. We do not use facial recognition technology, fingerprint scanners, or other biometric collection devices. If our practices change in the future, we will update this Policy and obtain all consents and make all disclosures required under BIPA before collecting any biometric identifiers or biometric information.
Illinois Personal Information Protection Act (PIPA), 815 ILCS 530: In the event of a breach of the security of the system resulting in the unauthorized acquisition of personal information (as defined under PIPA) of an Illinois resident, the Company will provide notification in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Notification will be provided to affected individuals and to the Illinois Attorney General as required by PIPA.
Illinois Consumer Fraud and Deceptive Business Practices Act, 815 ILCS 505: The Company is committed to truthful and non-deceptive practices in all communications, including the representations made in this Policy. The practices described herein reflect our actual data collection, use, and disclosure activities.
Right of Publicity Act, 765 ILCS 1075: The Company will not use your name, photograph, likeness, or identity for commercial purposes (such as testimonials, case studies, or marketing materials) without your separate, express written consent.
10.3 Multi-State Privacy Law Compliance
The Company is committed to complying with applicable state privacy laws. If you are a resident of a state with a comprehensive consumer privacy statute (including but not limited to the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Texas Data Privacy and Security Act (TDPSA), or any successor or analogous state legislation enacted after the effective date of this Policy), you may have additional rights, including:
- The right to know what categories and specific pieces of personal information we have collected
- The right to know the categories of sources from which information is collected
- The right to know the business or commercial purposes for collection
- The right to know the categories of third parties to whom information is disclosed
- The right to delete personal information, subject to statutory exceptions
- The right to opt out of the sale or sharing of personal information
- The right to correct inaccurate personal information
- The right to limit the use of sensitive personal information
- The right to non-discrimination for exercising your rights
The Company does not sell personal information and does not share personal information for purposes of cross-context behavioral advertising, as those terms are defined under applicable state privacy laws. Because we do not engage in these activities, there is no need to submit an opt-out request for sale or sharing; however, if you wish to confirm our practices, you may contact us using the information in Section 16.
As new state and federal privacy legislation is enacted, we will evaluate our obligations and update this Policy and our practices as necessary to maintain compliance.
10.4 Exercising Your Rights
To exercise any rights available to you under applicable law, submit a verifiable request to us using the contact information in Section 16. We will acknowledge your request within ten (10) business days and provide a substantive response within the timeframes required by applicable law (typically 30 to 45 calendar days, with extensions as permitted). We may require you to verify your identity before processing your request by providing information sufficient to confirm you are the person (or authorized agent of the person) about whom we collected personal information. We will not charge a fee for processing your request unless the request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline the request as permitted by applicable law.
11. Children's Privacy
The Site and our services are directed exclusively to adults and business professionals. They are not intended for individuals under the age of eighteen (18). We do not knowingly collect, solicit, or maintain personal information from anyone under 18. If we learn that we have collected personal information from a child under 18, we will delete that information promptly. If you believe a child under 18 has provided personal information to us, please contact us immediately using the information in Section 16.
12. Third-Party Websites, Platforms, and Services
The Site may contain links to websites, platforms, applications, or services operated by third parties that are not owned or controlled by the Company. This Policy applies solely to information collected by the Company through the Site and our own services. We are not responsible for the privacy practices, data collection methods, content, accuracy, or security of any third-party websites or services. We strongly encourage you to review the privacy policy of any third-party site before providing personal information. The inclusion of any link on our Site does not constitute or imply endorsement, sponsorship, or recommendation of the linked site, its operator, or its content.
13. International Visitors
The Site is operated from, and our services are provided in, the United States. If you access the Site from outside the United States, be aware that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from, and may not provide the same level of protection as, the laws of your country or jurisdiction. By using the Site or providing information to us from outside the United States, you expressly consent to the transfer and processing of your information in the United States, subject to the protections described in this Policy.
14. Changes to This Policy
We reserve the right to modify, amend, or replace this Policy at any time in our sole discretion. Any changes will be effective immediately upon posting the revised Policy to the Site with an updated "Last Updated" date at the top of this page. If we make material changes that significantly affect our processing of your personal information, we will make reasonable efforts to provide prominent notice (such as a banner on the Site, notification via email to addresses in our records, or other appropriate communication). Your continued use of the Site or provision of personal information to us after the posting of any changes constitutes your acceptance of the revised Policy. We encourage you to review this Policy periodically. The version of the Policy in effect at the time your information is collected will govern our use of that information.
15. Dispute Resolution
Any dispute, claim, or controversy arising out of or relating to this Privacy Policy or the collection, use, or disclosure of your personal information by the Company shall be governed by and construed in accordance with the laws of the State of Illinois, without regard to its conflict of law provisions. You agree that any legal action or proceeding relating to this Policy shall be brought exclusively in the state or federal courts located in Cook County, Illinois, and you consent to the personal jurisdiction and venue of such courts. Nothing in this section limits the Company's right to seek injunctive or equitable relief in any court of competent jurisdiction.
16. Contact Information
If you have questions, concerns, complaints, or requests regarding this Privacy Policy or our data practices, please contact us:
Chicago Business Intermediary LLC
Attn: Privacy Inquiries
Chicago, IL
Phone: (312) 772-4998
Email: Info@chicagobusinessintermediary.com
If you are not satisfied with our response, you may have the right to lodge a complaint with the Illinois Attorney General's office (illinoisattorneygeneral.gov) or other applicable regulatory authority in your jurisdiction.
17. Severability
If any provision of this Privacy Policy is found by a court of competent jurisdiction to be invalid, illegal, or unenforceable, such finding shall not affect the validity, legality, or enforceability of the remaining provisions, which shall continue in full force and effect. The invalid or unenforceable provision shall be modified to the minimum extent necessary to make it valid and enforceable while preserving the original intent of the parties.