DFX Intelligence, Legal

Privacy Policy

Last updated: July 28, 2026

This Privacy Policy explains how Deal Flow Xchange Inc, a Delaware corporation that operates DFX Intelligence and The General ("DFX", "we", "us"), collects, uses, discloses, and protects information in connection with our websites, applications, the DFX browser extension, and our Services. It should be read together with our Terms of Service, with our Data Processing Addendum where you direct us to process personal data about other people, and, for the browser extension, with the dedicated extension privacy notice we publish at dfxintel.com/browser-extension-privacy.html.

By using the Services, you consent to the practices described here. If you connect accounts or provide or direct us to collect information about other people (for example, contacts in your CRM or inbox, prospects, recipients, donors, website visitors, callers, or counterparties), you represent that you have the authority and any required legal basis or consent to do so, and that you are the controller of that information as described below.

The Services are an AI operator. They read data you connect, generate content, learn from how you work, and, under settings you enable, act on your behalf. This Policy describes what that means for information about you, about your team, and about the people you contact.

  1. 1. Information we collect

    We collect information you provide, information from accounts you connect, information generated through your use of the Services, and information the Services collect or produce at your instruction:

    • +Account and contact data: name, email, company, role, team and workspace membership, plan, roles and permissions, and authentication details.
    • +Business context you provide: your goals, brand information, documents, pricing, notes, instructions, and rules.
    • +Connected-account data: when you connect email, calendar, CRM, telephony, messaging, social, file storage, payment, a sending domain, source-code repositories, or other tools, we access the data needed to perform the work you request, which may include the content of messages, contacts, calendar entries, files, and records, and the metadata and status of those connections.
    • +Communications content: where you connect a mailbox or sending channel, the content of inbound and outbound messages that the Services read, triage, classify, summarize, draft, or send on your behalf, threads you forward or hand to your General, and reply and outcome data such as whether a recipient replied, bounced, unsubscribed, or complained.
    • +Text-messaging data: where you enable SMS/MMS messaging, the mobile phone numbers you or your customers provide, the content of the text messages the Services send and receive on your behalf, delivery and reply data, and related opt-in, consent, and opt-out (such as STOP and HELP) records.
    • +Reviews and reputation data: where you enable review features, the customer contact details used to request reviews, the review-request messages sent, and the reviews and responses the Services draft or publish on the platforms you connect.
    • +Call and meeting data: where you use voice, telephony, or the meeting assistant, call and meeting audio, recordings, transcripts, notes, and summaries.
    • +Third-party and contact personal data: information about your contacts, prospects, leads, recipients, and other individuals that you provide, that we access in your connected accounts, that the Services collect from publicly available sources (such as company sites, news, public profiles, job boards, filings, and event pages) at your instruction, or that the Services obtain from third-party data-enrichment providers (such as contact-discovery and email-finding services) at your instruction for sourcing, research, enrichment, verification, and outreach. Where you trigger a lookup from a page you are viewing, the identifying details available at that moment, such as a person's name and company, are sent to those providers to perform the lookup.
    • +Website concierge and lead-capture data: where you deploy our website concierge widget, front desk, or a voice or chat assistant on your own site or phone line, the messages, questions, contact details, and other information your site visitors and callers provide, and the transcripts, summaries, and lead records generated from those interactions.
    • +In-app voice-assistant data: where you use an in-app or in-browser voice assistant or guide, the microphone audio captured while it is active and the transcripts, summaries, and instructions produced from it.
    • +Demo, tour, audit, business-read, and evaluation data: where you request or take part in a demonstration, guided product tour, trial, business audit, or an automated read of a business and its public web presence, the information you submit (such as a business name, website, or domain), the sources read and the understanding, observations, and sample results generated, your intake, persona, and interaction details, and any microphone or call audio, recordings, and transcripts from interactive, voice-guided, or phone-based demonstrations and demo bookings.
    • +Memory, learnings, and inferred preferences: what the Services record and infer about your business and how you work, including instructions and corrections you state, and inferences drawn from your behavior, such as the edits you make to a draft before sending it, the items you approve or reject, and the outcomes of your outreach. This is used to shape later work and may be scoped to you or to your whole workspace.
    • +Approval, autonomy, and decision records: the approvals, rejections, grants, scopes, and settings you configure, the precedent derived from them, and the record of what the Services decided to do without asking and why.
    • +Receipts, evidence, and activity records: the evidence records, screenshots, extracted content, step outcomes, work logs, timings, error details, and verification status attached to claims the Services make about work they performed.
    • +Product-usage and attention telemetry: which surfaces, items, briefs, deliverables, and decisions you open, when, for how long, what you do with them (for example send, download, edit, ignore, or resolve), funnel events such as connecting a browser or completing a first task, and aggregate measures of the attention the product costs you. We use this to measure and improve the product, not to profile you for advertising.
    • +CRM and connected-tool records: where you connect a CRM (such as HubSpot) or other tools via API keys or authorized connections, the records, notes, activities, and fields the Services read and write at your instruction, and the results of periodic read-only health checks on those connections.
    • +Google data: where you connect a Google account, the calendar, meeting, mail, or Drive data covered by the scopes you approve, including the work-log file the Services may maintain in your own Drive.
    • +Social media data: where you connect social accounts, the posts, drafts, and account information needed to publish or schedule content you direct.
    • +Browser extension and browser-operation data: where you install the DFX browser extension or otherwise connect a browser, the web addresses, page titles, visible page text, page markup, and screen images of the pages a task you approved is carried out on, the outcome, timing, and error details of each step, the address and title of the tab you are viewing when you send a message from the side panel, files you attach in the panel, microphone audio and transcripts while a voice session in the panel is active, and connection details such as a device label, the extension version, the capabilities that version supports, presence and pause state, and error categories used to diagnose failures. See the dedicated section below.
    • +Usage, deliverables, and activity: tasks, missions, autopilots, standing orders, conversations with The General, generated outputs and deliverables, and browser-action, local-command, software-build, and other automation logs where you use those features, together with device, browser, and network information, IP address, and analytics.
    • +Referral and partner data: where you take part in a referral, partner, or promotional program, the referral links and codes you use, the introductions and accounts attributed to you, reward and qualification status, and, for cash payouts, the legal name, entity type, country, address, and payout status we hold, together with the tax and bank details held by our payout provider rather than by us.
    • +Payment data: processed by our payment processor; we receive limited billing details and do not store full card numbers.
    • +Cookies and similar technologies used to operate the site, keep you signed in, and measure usage.
  2. 2. How we use information

    We use information to:

    • +provide, operate, secure, and maintain the Services and perform the work you request;
    • +enable The General to research, draft, communicate, and, where you connect accounts and configure the settings, act on your behalf, including on a recurring, proactive, or autonomous basis through autopilots, missions, standing orders, scheduled campaigns, triggers, and automatic inbox handling;
    • +decide, under the settings you enable, whether an action requires your approval, and to build the precedent that decision draws on from your own approvals, rejections, and corrections;
    • +learn from how you work, including from the edits you make to drafts, the items you reject, and the outcomes of your outreach, and apply what is learned to later work across the Services;
    • +build and maintain a working memory and an understanding of your business from your connected accounts, your website and public web presence, and the sources you connect, and present that understanding back to you for correction;
    • +carry out, verify, and show you evidence of the browser tasks you approve, where you install the DFX browser extension or connect a browser, including reading the page being worked on so the next step can be planned;
    • +read, triage, classify, and draft replies to email, take on threads you forward, send and receive text messages (SMS/MMS) on your behalf, request customer reviews and draft and publish review responses, source, enrich, and verify contact data from public sources and third-party data-enrichment providers, place and receive calls (including through a website or voice concierge and front desk that speaks with your customers and site visitors, and an in-app voice assistant that captures your microphone audio while active), transcribe calls, capture and summarize meetings, write to your CRM and connected tools and check that those connections still work, publish or schedule social content, maintain a work log in a Google Drive you connect, run approved commands on a computer you connect, and write code, open pull requests, and run builds on repositories you connect, where you enable those features;
    • +operate our websites, business audit tool, business reads, demonstrations, product tours, and trials, record and analyze interactive and voice demonstrations to run and improve them, and respond to inquiries and contact prospects about DFX and the Services, including sales and marketing follow-up, subject to your choices;
    • +process payments, manage subscriptions, credits, spend caps, seats, workspaces, and referral and partner rewards, meter usage and apply plan pricing, and prevent fraud and abuse of trials, credits, and reward programs;
    • +provide support, communicate with you, and send service and transactional messages;
    • +measure how the product is used, including which items you open and what you do with them, in order to debug, prioritize, and improve the Services and develop new features, using aggregated or de-identified data where practicable;
    • +enforce our Terms, comply with law, and protect the rights, safety, and property of DFX, our users, and others.

    We do not use your content, your communications, or your connected-account data to train generalized or third-party AI models, and we do not permit our model providers to do so under our arrangements with them. We may use aggregated and de-identified data, which does not identify you or any individual, to analyze and improve our products.

  3. 3. AI processing and service providers

    To provide the Services, we share information with sub-processors and service providers who process it on our behalf under contractual obligations. These include providers of AI language and voice models, payment processing, communications and email delivery, telephony, meeting capture, contact-data enrichment, cloud hosting and databases, authentication, and web analytics, and any third-party applications you connect. Representative sub-processors currently include Anthropic (primary AI language models), OpenAI (fallback AI language models used to maintain availability), ElevenLabs (synthetic voice), Twilio (telephony and messaging), a meeting-capture and transcription provider, Resend (email delivery), Apollo and Hunter (contact-data enrichment and email finding), Stripe (payment and payout processing), Google (calendar, Drive, and video-meeting scheduling for bookings, the work log, and the meeting assistant), Clerk (authentication), Supabase (cloud hosting and database), and Vercel (application hosting and storage). This list may change; we maintain a current list of sub-processors and provide it on request, and material changes are described in our Data Processing Addendum.

    When the Services generate outputs, take actions, or classify communications, relevant content (such as your instructions, business context, connected-account data, message content, page content and screenshots from browser work, and documents) is transmitted to third-party AI model providers, including Anthropic and OpenAI, to produce the result. We may route between providers, models, and versions to maintain availability, manage cost, or improve results. By using the Services you understand and agree that this content is sent to those providers. We use enterprise arrangements with our model providers under which your content is not used to train their general models. We do not control, and are not responsible for, the independent practices of these providers beyond our contractual arrangements with them.

  4. 4. Automated decisions, learning, and memory

    The Services make automated decisions in the course of doing the work you ask for. This includes classifying and prioritizing communications, grouping work for approval, scoring or ranking contacts and opportunities, generating content and recommendations, and, where you enable it, determining whether a given action may proceed without your approval based on factors such as reversibility, consequence, confidence, the scopes you granted, and precedent drawn from your own past approvals, rejections, and corrections.

    These decisions are made to operate the Services at your direction and under settings you control. They do not produce legal or similarly significant effects on you, and we do not use them to evaluate individuals for employment, credit, housing, insurance, education, or essential services, which is prohibited by our Terms. You can review what the Services have learned, correct or delete it, change or revoke autonomy and approval settings, and return to per-action approval at any time. Where applicable law gives you a right to obtain human review of an automated decision, contact us at hello@dfxintel.com.

    Learnings and corrections recorded at the company level apply to your whole workspace and may be visible to, and change work produced for, other members of that workspace. Learnings we derive from behavior (for example from an edit you made to a draft) are recorded with their provenance so you can see where they came from.

  5. 5. Communications, recordings, and meeting data

    Where you connect a mailbox, the Services may read, analyze, classify, triage, summarize, and draft replies to your email, take on threads you forward to your General, and send email as you, according to the settings you choose. Where you enable text messaging, the Services may send and receive text messages (SMS/MMS) on your behalf under your settings, and process the numbers, message content, and consent and opt-out records involved. Where you enable voice, telephony, or the meeting assistant, the Services may place and receive calls, including outbound calls that The General places on your behalf using an artificial, synthetic, or AI-generated voice, may capture your microphone audio through an in-app or in-browser voice assistant while it is active, and may join meetings and record, transcribe, and summarize calls, meetings, and interactive demonstrations.

    We process this communications, call, and meeting content to provide the Services and at your instruction. When you enable outbound calling, you are the caller and the party responsible for each call. You are responsible for providing all legally required notices to, and obtaining all legally required consents from, the individuals involved before any call, recording, transcription, or capture, and for directing outbound calls only to individuals who have opted in to being contacted by you and given the consent required by law (including, for calls using an artificial or AI-generated voice, the prior express written consent required by the TCPA and FCC rules), and for honoring do-not-call and opt-out requests, all as further described in our Terms of Service. We retain recordings, transcripts, and message content as described under Data retention.

  6. 6. Website concierge, front desk, and lead capture

    Where you deploy our website concierge widget, front desk, or a chat or voice assistant on your own website or phone line, the Services interact with your site visitors and callers, answer questions, and capture leads and the information those individuals choose to provide. This information is collected on your behalf and for your use. You are the controller or business with respect to that information and the deployer of that AI system, and you are responsible for providing your visitors and callers with any required notices (including notice that they are interacting with an automated or AI system and any recording notice) and for obtaining any required consents. We provide the functionality and process this information as your processor or service provider on your instructions.

  7. 7. The DFX browser extension and browser operation

    This section describes how information is handled when you install the DFX browser extension (the "Extension") or otherwise connect a browser so that The General can work in it. It applies in addition to the rest of this Policy. We also publish a dedicated privacy notice for the Extension at dfxintel.com/browser-extension-privacy.html, which is the notice referenced from the extension store listing; where the two describe the same practice, they are intended to be read together. That notice carries a revision number, and when our data handling changes we raise a notice inside the Extension to existing users rather than relying on a quiet edit to a web page.

    How the connection works. The Extension runs on your device and dials out to your own DFX workspace over HTTPS to ask whether you have approved any work. It does not open an inbound port and does not expose your browser to the public internet. It carries out approved work in a tab it creates and owns rather than in the tab you are using, using the browser's developer tooling interface. Your browser displays its own notice while that interface is attached.

    What is collected while a task runs. To carry out the work you approved and to show you evidence of what happened, the following is transmitted from your device to us: the web address and title of the page being worked on, the visible text of the page or of a selected element (currently truncated at approximately 200,000 characters), the page markup with scripts and styles removed (currently truncated at approximately 400,000 characters), images of the page captured as screenshots, the result or error of each step, and a short non-reversible fingerprint of the page used to prove the page changed. THIS MAY INCLUDE ANY INFORMATION PRESENT ON THOSE PAGES, INCLUDING PERSONAL INFORMATION, THIRD-PARTY DATA, AND CONFIDENTIAL BUSINESS INFORMATION. You choose which pages a task operates on and you are responsible for ensuring you are permitted to disclose what is on them. Do not direct browser work on pages containing information you may not lawfully or contractually share with us or with our sub-processors.

    What is collected from the side panel. When you send a message from the panel, we receive your message, the conversation it belongs to, and the web address and title of the tab you are currently viewing, so that instructions like "add this person" are complete. The content of that tab is not sent with a message; page content is read only while a task you asked for is running. Files you attach are transmitted with the message and processed to extract their text or, for images, to be read visually. Where you use a panel feature that requires it, the details that feature needs are transmitted for that purpose: for example, finding a contact's email address sends the person's name and company, taken from the page title or from what you type, to our contact-discovery providers, and subscribing sends the details our payment processor needs. If you use voice in the panel, your microphone audio is streamed while the session is active to our voice provider and to us, together with the resulting transcripts, and the call duration is recorded for metering and billing. Dictation, where offered, uses the browser's own speech recognition and is subject to your browser vendor's practices.

    Connection and health signals. The Extension reports the workspace it is registered to, a device label you choose, its version and the capabilities that version supports, its connection, presence, and pause state, and health signals used to tell when the Extension stops working for people: whether a connection or step succeeded or failed, and a general category for the failure such as network or timeout. These signals never include page content, addresses, titles, error messages, or anything you typed.

    What the Extension does not collect. It does not read or transmit your passwords, saved credentials, cookies, session tokens for other sites, autofill data, or browsing history. It does not monitor, log, or transmit the pages you visit outside a task you approved. It does not run script supplied by our servers in your pages, and it refuses navigation to a list of restricted financial, payroll, and personal-email domains. These are design characteristics, not guarantees; as described in our Terms of Service, such controls are aids that may fail or be circumvented, and no method of transmission or storage is completely secure.

    What is stored locally on your device. The Extension stores, in your browser's local extension storage and only on your device, the DFX address it connects to, the access token that identifies that browser to your workspace, short-lived session tokens, its connection and pause state, the identifier of its working tab, your recent panel conversation (retained for up to 24 hours so the panel survives being closed), and, if a step's result could not be delivered because the network or the browser interrupted it, a bounded queue of undelivered results, which may contain extracted page text or a screenshot until it is delivered. Anyone with access to that browser profile can access this data and use the connection. Disconnecting or uninstalling the Extension clears the connection; uninstalling removes its local storage.

    Where the information goes. Browser-operation content is transmitted to us and, to plan the next step and interpret what is on the page, to our AI model providers (currently Anthropic, with OpenAI as a failover) as described in the AI processing and service providers section; voice audio is transmitted to our voice provider; and details required by a panel feature you invoke are transmitted to the provider that feature uses. It is processed to deliver the Services you requested and to show you records and receipts of what your General did. We do not sell it, we do not share it for cross-context behavioral advertising, and we do not use it to build advertising profiles.

    Limited use commitment. Our use of information received from the extension platform, including any Google user data, adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements, and our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically: we use this data only to provide and improve the single, user-facing feature the Extension exists for, which is letting your DFX General carry out browser work you asked for and report what it did; we do not transfer this data except as necessary to provide or improve that feature, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you; we do not use it for advertising, retargeting, personalized advertising, or credit or lending decisions; we do not sell it; and we do not use it, or allow humans to read it, to train generalized or third-party AI or machine-learning models, except where required for security or to comply with law, where the data is aggregated or de-identified, or where you give us express consent for a specific purpose such as investigating a support issue you report.

    Retention and control. Browser-task records, including the addresses worked on, extracted content, screenshots, and step outcomes, are retained as part of your workspace activity so that you can review what your General did, subject to the Data retention section below. You can pause browser work, disconnect the browser from the Extension or from your portal at any time, revoke a connection so its token stops working, uninstall the Extension, and request deletion of your data by contacting us at hello@dfxintel.com.

  8. 8. Information we collect directly, demonstrations, and marketing

    When you visit our own websites, use our business audit tool, request an automated read of a business, request or take part in a demonstration, guided product tour, or trial, book a demo or call, sign up, install the Extension, or contact us, we collect the information you provide and generate, and with respect to that information we act as the controller. This includes your name, email, company, role, the business, website, or domain you submit, the sources read and the results generated, your intake, persona, and interaction details, demo bookings, and any microphone or call audio, recordings, and transcripts from interactive, voice-guided, or phone-based demonstrations. Interactive demonstrations, tours, and demo calls may be recorded, transcribed, and analyzed.

    We use this information to operate, secure, and improve these experiences and the Services, to respond to you, and to contact you about DFX and the Services, including sales and marketing follow-up. You can opt out of marketing communications at any time using the unsubscribe link in our messages or by contacting us at hello@dfxintel.com; we may still send necessary service and transactional messages. Please do not submit confidential, regulated, or sensitive information, or personal information about other people, into a demonstration, tour, trial, audit, or business read. Demonstration and tour workspaces use sample data and may be reset or wiped.

    Where an unauthenticated business read is run against a company domain, we read publicly available sources about that business at the moment of the request in order to show what the Services can do. That read may include information about individuals connected with the business that is published on the public web.

  9. 9. Personal data about third parties

    When you provide, or direct the Services to collect, source, enrich, store, profile, or contact, personal data about third parties, you are the controller or business and we act as your processor or service provider, processing that data only on your documented instructions to provide the Services. You are responsible for having a lawful basis and providing any required notices for that processing, including for sourcing, enrichment, profiling, automated processing, and outreach. Our Data Processing Addendum sets out the terms that govern that processing.

    We source third-party information from publicly available sources and from data-enrichment providers at your instruction. If you are an individual whose information was processed through the Services on behalf of one of our customers, the customer is the controller of that information; please direct your request to that customer, and we will assist them in responding as required by applicable law. If you contact us directly, we will refer you to the relevant customer where we are able to identify them.

  10. 10. How we share information

    We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only: (a) with sub-processors and service providers as described above; (b) at your direction, including with connected accounts, recipients of communications you send, participants of calls and meetings, and other members of your workspace; (c) with our professional advisers, auditors, and insurers under duties of confidentiality; (d) to comply with law, legal process, or lawful requests, or to establish, exercise, or defend legal claims, or to protect rights, safety, and security, including investigating fraud, abuse, or violations of our Terms; and (e) in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to this Policy and with notice to you where required.

    Mobile numbers and messaging consent. We do not sell, rent, or share the mobile phone numbers, text-messaging opt-in, or SMS consent of you or your customers with any third parties or affiliates for their own marketing or promotional purposes. Text-message consent and phone numbers are used only to operate the messaging you enable and are not shared for third-party marketing. This does not restrict our use of the messaging sub-processors (such as our telephony provider) that transmit messages on your behalf, or disclosures required by law.

  11. 11. Tenant isolation and security

    We design the Services for per-client isolation: your data and your General operate within your own tenant, and we apply technical and organizational measures to keep clients separated, including access controls, row-level database policies, per-member request scoping, and logging.

    Sensitive credentials you provide (such as connected-account passwords, app passwords, OAuth tokens, and API keys) are encrypted before storage using strong industry-standard encryption (AES-256-GCM), are never returned to your browser, and are decrypted only server-side when needed to perform the work you request. We log access to such credentials. Extension connection tokens are stored as hashes rather than in plain text. Notwithstanding these measures, no product, method of transmission, or method of storage is completely secure, and we do not warrant or guarantee that your information or credentials will be free from unauthorized access, loss, or misuse. You provide credentials and data at your own risk.

    If we become aware of a security incident affecting your personal data that requires notification under applicable law, we will notify you without undue delay and provide the information reasonably available to us so that you can meet your own notification obligations.

  12. 12. Data retention

    We retain information for as long as your account is active and as needed to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. This includes message content, recordings, transcripts, deliverables, contact and outreach records, memory and learnings, receipts and evidence records, browser-task records, and activity logs, each of which is retained as part of your workspace so that you and your team can review what was done.

    Records we are required to keep for financial, tax, audit, or legal-defense purposes (such as billing records, consent and opt-out records, security and access logs, and records relevant to a dispute) are retained for longer, generally for the period required by the applicable law or limitation period. Panel conversation data stored locally in the Extension is kept on your device for up to 24 hours.

    Upon termination, and after the export window described in our Terms of Service, we may delete or de-identify your data, subject to legal retention requirements and to routine backups that expire on their own cycle. You may request deletion earlier as described under Your rights and choices.

  13. 13. Your rights and choices

    Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, to object to certain processing, to opt out of the sale or sharing of personal information or of profiling with legal or similarly significant effects (we do not sell or share personal information, and we do not conduct such profiling), to obtain human review of certain automated decisions, and to withdraw consent. You can also disconnect connected accounts, revoke browser and device connections, change send, approval, and autonomy settings, correct or delete memory and learnings, pause activity, and manage cookie preferences in your browser at any time.

    To exercise a right, contact us at hello@dfxintel.com. We will respond as required by applicable law and may need to verify your identity. You may use an authorized agent where the law permits, and we may ask for proof of authorization. If we decline a request, you may appeal by replying to our response with the word "Appeal"; we will respond to appeals within the time the law requires. We do not discriminate against you for exercising your rights. Where we act as a processor of personal information you provide or direct us to collect about others, the customer is the controller and we will assist them in responding to such requests.

    For residents of California and other U.S. states with comprehensive privacy laws: the categories of personal information we collect, the sources, purposes, and categories of recipients are described in the sections above; we disclose personal information to service providers and processors for the business purposes described; we do not sell personal information and do not share it for cross-context behavioral advertising, including with respect to anyone under 16; and we honor opt-out preference signals such as Global Privacy Control where our systems receive them. Where we offer credits or rewards through a referral or partner program, participation is voluntary, is not conditioned on your privacy choices, and any difference in value relates directly to the value of the referral rather than to your personal information.

    For individuals in the European Economic Area, the United Kingdom, and Switzerland: where we act as a controller, we rely on the legal bases of contract (to provide the Services you request), legitimate interests (to secure, operate, measure, and improve the Services and for direct business-to-business marketing), consent (where required, for example for certain cookies, recordings, or marketing), and legal obligation. You may object to processing based on legitimate interests, withdraw consent at any time without affecting prior processing, and lodge a complaint with your local supervisory authority.

  14. 14. International data transfers

    We and our service providers process information in the United States and may process it in other countries whose data-protection laws differ from those where you live. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK Addendum, together with supplementary measures where appropriate. A copy of the relevant transfer mechanism is available on request at hello@dfxintel.com. By using the Services, you understand your information may be transferred to and processed in those locations.

  15. 15. Analytics and cookies

    We use cookies and similar technologies that are strictly necessary to operate the site, keep you signed in, secure your session, and remember your preferences, and analytics cookies to understand and improve how the Services are used. We do not use advertising or cross-site tracking cookies for behavioral advertising. You can control cookies through your browser settings, though some features may not function properly without them, and we honor recognized opt-out preference signals where our systems receive them.

  16. 16. Children

    The Services are for business use and are not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.

  17. 17. Changes to this Policy

    We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by posting the updated Policy with a new date, by email, or by other reasonable means, and, for changes to how the browser extension handles data, by raising a notice inside the Extension itself. Your continued use of the Services after the changes take effect constitutes acceptance.

  18. 18. Contact us

    If you have questions about this Privacy Policy or our data practices, or wish to exercise a right, contact us at hello@dfxintel.com, or write to Deal Flow Xchange Inc, Delaware, United States. If you are a customer and need data processing terms, see our Data Processing Addendum.