DFX Intelligence, Legal

Privacy Policy

Last updated: July 12, 2026

This Privacy Policy explains how Deal Flow Xchange Inc, a Delaware corporation that operates DFX Intelligence and The General ("DFX", "we", "us"), collects, uses, discloses, and protects information in connection with our websites, applications, and Services. It should be read together with our Terms of Service.

By using the Services, you consent to the practices described here. If you connect accounts or provide or direct us to collect information about other people (for example, contacts in your CRM or inbox, prospects, recipients, donors, or counterparties), you represent that you have the authority and any required legal basis or consent to do so, and that you are the controller of that information as described below.

  1. 1. Information we collect

    We collect information you provide, information from accounts you connect, information generated through your use of the Services, and information the Services collect or produce at your instruction:

    • +Account and contact data: name, email, company, role, team membership, and authentication details.
    • +Business context you provide: your goals, brand information, documents, pricing, notes, instructions, and rules.
    • +Connected-account data: when you connect email, calendar, CRM, telephony, social, a sending domain, or other tools, we access the data needed to perform the work you request, which may include the content of messages, contacts, calendar entries, and records.
    • +Communications content: where you connect a mailbox or sending channel, the content of inbound and outbound messages that the Services read, triage, classify, summarize, draft, or send on your behalf, and reply and outcome data such as whether a recipient replied.
    • +Text-messaging data: where you enable SMS/MMS messaging, the mobile phone numbers you or your customers provide, the content of the text messages the Services send and receive on your behalf, delivery and reply data, and related opt-in, consent, and opt-out (such as STOP and HELP) records.
    • +Reviews and reputation data: where you enable review features, the customer contact details used to request reviews, the review-request messages sent, and the reviews and responses the Services draft or publish on the platforms you connect.
    • +Call and meeting data: where you use voice, telephony, or the meeting assistant, call and meeting audio, recordings, transcripts, notes, and summaries.
    • +Third-party and contact personal data: information about your contacts, prospects, leads, recipients, and other individuals that you provide, that we access in your connected accounts, that the Services collect from publicly available sources (such as company sites, news, public profiles, job boards, and event pages) at your instruction, or that the Services obtain from third-party data-enrichment providers (such as contact-discovery and email-finding services) at your instruction for sourcing, research, enrichment, and outreach.
    • +Website concierge and lead-capture data: where you deploy our website concierge widget, front desk, or a voice or chat assistant on your own site or phone line, the messages, questions, contact details, and other information your site visitors and callers provide, and the transcripts, summaries, and lead records generated from those interactions.
    • +In-app voice-assistant data: where you use an in-app or in-browser voice assistant or guide, the microphone audio captured while it is active and the transcripts, summaries, and instructions produced from it.
    • +Demo, tour, audit, and evaluation data: where you request or take part in a demonstration, guided product tour, trial, or our website business audit, the information you submit (such as a business name, website, or domain), the audit or sample results generated, your intake, persona, and interaction details, and any microphone or call audio, recordings, and transcripts from interactive, voice-guided, or phone-based demonstrations and demo bookings.
    • +CRM and connected-tool records: where you connect a CRM (such as HubSpot) or other tools via API keys or authorized connections, the records, notes, activities, and fields the Services read and write at your instruction.
    • +Social media data: where you connect social accounts, the posts, drafts, and account information needed to publish or schedule content you direct.
    • +Usage, deliverables, and activity: tasks, missions, autopilots, conversations with The General, generated outputs, and browser-action, local-command, software-build, and other automation logs where you use those features, together with device and browser information and analytics.
    • +Payment data: processed by our payment processor; we receive limited billing details and do not store full card numbers.
    • +Cookies and similar technologies used to operate the site, keep you signed in, and measure usage.
  2. 2. How we use information

    We use information to:

    • +provide, operate, secure, and maintain the Services and perform the work you request;
    • +enable The General to research, draft, communicate, and, where you connect accounts and configure the settings, act on your behalf, including on a recurring or autonomous basis through autopilots, missions, scheduled campaigns, and automatic inbox handling;
    • +read, triage, classify, and draft replies to email, send and receive text messages (SMS/MMS) on your behalf, request customer reviews and draft and publish review responses, source and enrich contact data from public sources and third-party data-enrichment providers, place and receive calls (including through a website or voice concierge and front desk that speaks with your customers and site visitors, and an in-app voice assistant that captures your microphone audio while active), transcribe calls, capture and summarize meetings, write to your CRM and connected tools, publish or schedule social content, run approved commands on a computer you connect, and write code, open pull requests, and run builds on repositories you connect, where you enable those features;
    • +operate our websites, business audit tool, demonstrations, product tours, and trials, record and analyze interactive and voice demonstrations to run and improve them, and respond to inquiries and contact prospects about DFX and the Services, including sales and marketing follow-up, subject to your choices;
    • +process payments, manage subscriptions, credits, spend caps, seats, and multiple workspaces, and prevent fraud;
    • +provide support, communicate with you, and send service and transactional messages;
    • +monitor, analyze, debug, and improve the Services and develop new features, using aggregated or de-identified data where practicable;
    • +enforce our Terms, comply with law, and protect the rights, safety, and property of DFX, our users, and others.
  3. 3. AI processing and service providers

    To provide the Services, we share information with sub-processors and service providers who process it on our behalf under contractual obligations. These include providers of AI language and voice models, payment processing, communications and email delivery, telephony, meeting capture, contact-data enrichment, cloud hosting and databases, authentication, web analytics, and any third-party applications you connect. Representative sub-processors currently include Anthropic (primary AI language models), OpenAI (fallback AI language models used to maintain availability), ElevenLabs (synthetic voice), Twilio (telephony), a meeting-capture and transcription provider, Resend (email delivery), Apollo and Hunter (contact-data enrichment and email finding), Stripe (payment and payout processing), Google (calendar and video-meeting scheduling for bookings and the meeting assistant), and Supabase (cloud hosting and database). This list may change; we may maintain a current list of sub-processors and provide it on request. When you connect third-party tools of your own (such as your email provider, calendar, CRM, or social accounts), those providers also process your data under their own terms.

    When the Services generate outputs, take actions, or classify communications, relevant content (such as your instructions, business context, connected-account data, message content, and documents) is transmitted to third-party AI model providers, including Anthropic and OpenAI, to produce the result. By using the Services you understand and agree that this content is sent to those providers. We use enterprise arrangements with our model providers under which your content is not used to train their general models, except as permitted by your settings or applicable agreements. We do not control, and are not responsible for, the independent practices of these providers beyond our contractual arrangements with them.

  4. 4. Communications, recordings, and meeting data

    Where you connect a mailbox, the Services may read, analyze, classify, triage, summarize, and draft replies to your email, and send email as you, according to the settings you choose. Where you enable text messaging, the Services may send and receive text messages (SMS/MMS) on your behalf under your settings, and process the numbers, message content, and consent and opt-out records involved. Where you enable voice, telephony, or the meeting assistant, the Services may place and receive calls, including outbound calls that The General places on your behalf using an artificial, synthetic, or AI-generated voice, may capture your microphone audio through an in-app or in-browser voice assistant while it is active, and may join meetings and record, transcribe, and summarize calls, meetings, and interactive demonstrations.

    We process this communications, call, and meeting content to provide the Services and at your instruction. When you enable outbound calling, you are the caller and the party responsible for each call. You are responsible for providing all legally required notices to, and obtaining all legally required consents from, the individuals involved before any call, recording, transcription, or capture, and for directing outbound calls only to individuals who have opted in to being contacted by you and given the consent required by law (including, for calls using an artificial or AI-generated voice, the prior express written consent required by the TCPA and FCC rules), and for honoring do-not-call and opt-out requests, all as further described in our Terms of Service. We retain recordings, transcripts, and message content as described under Data retention.

  5. 5. Website concierge, front desk, and lead capture

    Where you deploy our website concierge widget, front desk, or a chat or voice assistant on your own website or phone line, the Services interact with your site visitors and callers, answer questions, and capture leads and the information those individuals choose to provide. This information is collected on your behalf and for your use. You are the controller or business with respect to that information, and you are responsible for providing your visitors and callers with any required notices (including notice that they are interacting with an automated or AI system and any recording notice) and for obtaining any required consents. We provide the functionality and process this information as your processor or service provider on your instructions.

  6. 6. Information we collect directly, demonstrations, and marketing

    When you visit our own websites, use our business audit tool, request or take part in a demonstration, guided product tour, or trial, book a demo or call, sign up, or contact us, we collect the information you provide and generate, and with respect to that information we act as the controller. This includes your name, email, company, role, the business, website, or domain you submit, audit inputs and the results generated, your intake, persona, and interaction details, demo bookings, and any microphone or call audio, recordings, and transcripts from interactive, voice-guided, or phone-based demonstrations. Interactive demonstrations, tours, and demo calls may be recorded, transcribed, and analyzed.

    We use this information to operate, secure, and improve these experiences and the Services, to respond to you, and to contact you about DFX and the Services, including sales and marketing follow-up. You can opt out of marketing communications at any time using the unsubscribe link in our messages or by contacting us at hello@dfxintel.com; we may still send necessary service and transactional messages. Please do not submit confidential, regulated, or sensitive information, or personal information about other people, into a demonstration, tour, trial, or audit. Demonstration and tour workspaces use sample data and may be reset or wiped.

  7. 7. Personal data about third parties

    When you provide, or direct the Services to collect, source, enrich, store, or contact, personal data about third parties, you are the controller or business and we act as your processor or service provider, processing that data only on your documented instructions to provide the Services. You are responsible for having a lawful basis and providing any required notices for that processing, including for sourcing, profiling, and outreach.

    We source third-party information from publicly available sources at your instruction. If you are an individual whose information was processed through the Services on behalf of one of our customers, the customer is the controller of that information; please direct your request to that customer, and we will assist them in responding as required by applicable law.

  8. 8. How we share information

    We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only: (a) with sub-processors and service providers as described above; (b) at your direction, including with connected accounts, recipients of communications you send, and participants of calls and meetings; (c) to comply with law, legal process, or lawful requests, or to protect rights, safety, and security; and (d) in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

    Mobile numbers and messaging consent. We do not sell, rent, or share the mobile phone numbers, text-messaging opt-in, or SMS consent of you or your customers with any third parties or affiliates for their own marketing or promotional purposes. Text-message consent and phone numbers are used only to operate the messaging you enable and are not shared for third-party marketing. This does not restrict our use of the messaging sub-processors (such as our telephony provider) that transmit messages on your behalf, or disclosures required by law.

  9. 9. Tenant isolation and security

    We design the Services for per-client isolation: your data and your General operate within your own tenant, and we apply technical and organizational measures to keep clients separated.

    Sensitive credentials you provide (such as connected-account passwords, app passwords, OAuth tokens, and API keys) are encrypted before storage using strong industry-standard encryption (AES-256-GCM), are never returned to your browser, and are decrypted only server-side when needed to perform the work you request. We log access to such credentials. Notwithstanding these measures, no product, method of transmission, or method of storage is completely secure, and we do not warrant or guarantee that your information or credentials will be free from unauthorized access, loss, or misuse. You provide credentials and data at your own risk.

  10. 10. Data retention

    We retain information for as long as your account is active and as needed to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. This includes message content, recordings, transcripts, deliverables, contact and outreach records, and activity logs. We retain certain records (such as billing and audit logs) for longer where required. Upon termination, we may delete or de-identify your data after a reasonable period, subject to legal retention requirements and backups.

  11. 11. Your rights and choices

    Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, to object to certain processing, and to withdraw consent. You can also disconnect connected accounts, change send and automation settings, pause activity, and manage cookie preferences in your browser at any time.

    To exercise a right, contact us at hello@dfxintel.com. We will respond as required by applicable law and may need to verify your identity. Where we act as a processor of personal information you provide or direct us to collect about others, the customer is the controller and we will assist them in responding to such requests. We do not discriminate against you for exercising your rights.

  12. 12. International data transfers

    We and our service providers may process information in the United States and other countries that may have different data-protection laws than your own. Where required, we use appropriate safeguards for cross-border transfers. By using the Services, you understand your information may be transferred to and processed in those locations.

  13. 13. Analytics and cookies

    We use cookies and analytics tools to understand and improve how the Services are used and to keep you signed in. You can control cookies through your browser settings, though some features may not function properly without them.

  14. 14. Children

    The Services are for business use and are not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.

  15. 15. Changes to this Policy

    We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by posting the updated Policy with a new date or by other reasonable means. Your continued use of the Services after the changes take effect constitutes acceptance.

  16. 16. Contact us

    If you have questions about this Privacy Policy or our data practices, contact us at hello@dfxintel.com.