MLX is in limited private release and access is granted individually. This document states our current practice in full. It has not yet been reviewed by outside counsel, and it will be re-issued before MLX is offered to the public.
Privacy

Privacy Policy

This policy explains what MLX collects, why we collect it, who we share it with, how long we keep it, and the choices available to you and to the people who appear in your network.

Last updated 25 July 2026

Who this applies to

This policy covers MLX, the acquisition intelligence service, and applies to two groups of people: members, who hold an MLX account, and third parties, who appear in a member’s workspace as a contact, an intermediary, or a decision-maker at a target company without having an account themselves. The rights described below belong to both.

What we collect

From members:

  • Account information: name, work email, organization, and the identity provider you sign in with. MLX never receives or stores your password.
  • Access request details: the name, work email, phone number and description of what you are working toward that you submit when you ask for access.
  • Workspace content: the deal criteria, notes, drafts and pipeline records you create.
  • Connected source data: message and calendar metadata and professional network connections from accounts you explicitly connect. See the Security page for the read and do-not-read boundary.
  • Usage and device data: pages viewed, features used, approximate location derived from IP address, browser and device type, and error diagnostics.

About third parties:

  • Business contact information: name, employer, role, and business contact details.
  • Professional relationship data: that a working relationship exists between two people, how it arose, and how recent it is.
  • Publicly available and licensed business information about companies and the people who run them: filings, press coverage, job postings, company websites and trade publications.

Information about third parties is business information, gathered in a business context, for the purpose of a business introduction. MLX does not seek out special category data, and does not build profiles of people in their personal capacity.

Why we use it

  • To provide the service: to surface signals, rank opportunities, find a warm path, and draft outreach for your approval.
  • To authenticate you and secure your account.
  • To respond to an access request and determine the right engagement.
  • To support you, and to diagnose and fix faults.
  • To improve the service, using aggregate and de-identified patterns only. One member's workspace is never exposed to another. See the Security page.
  • To meet legal obligations and to enforce our terms.

Where the law requires a legal basis, we rely on our legitimate interest in operating a business intelligence service and in facilitating business introductions, on performance of a contract with our members, on consent where you connect a data source, and on legal obligation where one applies. Where we rely on consent, you may withdraw it at any time by disconnecting the source.

What we never do

  • We do not sell personal information, and we do not share it for cross-context behavioral advertising.
  • We do not make one member’s workspace visible to another.
  • We do not send outreach on your behalf without your explicit approval of each message.
  • We do not contact a person who has been marked do-not-contact, or allow a member to do so through MLX.

Who we share it with

We share personal information only in these circumstances:

  • Service providers who process data on our behalf for hosting, storage, monitoring and authentication, under contract, limited to what they need, and prohibited from using it for their own purposes.
  • Recipients you choose. When you approve a message, its content goes to the person you send it to.
  • Legal and safety: where we are required by law, or to establish, exercise or defend a legal claim.
  • A corporate transaction: if MLX is involved in a merger, acquisition or sale of assets, in which case we will give notice before your information becomes subject to a different policy.

How long we keep it

We keep member account and workspace data for as long as the account is active, and delete it within 30 days of a verified deletion request, other than records we must retain for legal or accounting reasons. Usage and diagnostic logs are kept for a limited period and then discarded.

Do-not-contact records are the exception. Where someone has asked not to be contacted, we keep the minimum information needed to keep honoring that request, for as long as we operate the service. Deleting it would allow the contact to resume, which is the opposite of what was asked.

Your rights and choices

Depending on where you live, you may have the right to access a copy of your information, correct it, delete it, object to or restrict how we use it, withdraw consent, and receive it in a portable format. You also have the right to complain to your data protection authority.

These rights apply whether or not you are an MLX member. If you appear in someone’s workspace and want to know what we hold, correct it, have it deleted, or object to its use, write to privacy@mlx.com and we will act on it. We do not require you to create an account to exercise a right, and we will not treat you differently for exercising one.

Asking not to be contacted

Anyone can ask not to be contacted through MLX, at any time, by writing to donotcontact@mlx.com or by replying to a message you received. We apply the request across every workspace on the service, not only the one that reached you, and it is enforced at the point where a draft is assembled. You do not need to explain why, and you do not need an account.

Security

We protect information with single sign-on, least-privilege access to production systems, encryption in transit and at rest, scoped and revocable source connections, and logged administrative access. The Security page describes this in full, including an honest statement of where our security program currently stands. No service can promise perfect security, and we do not.

International transfers

MLX is operated from the United States and information is processed there. If you are outside the United States, transferring your information there means it is handled under privacy laws that differ from your own. Where required, we use appropriate safeguards, including standard contractual clauses, for those transfers.

Children

MLX is a professional tool for business use. It is not directed to anyone under 18, and we do not knowingly collect information from children. If you believe a child has provided us information, write to us and we will delete it.

Changes to this policy

We will update this policy as the service changes. When a change is material, we will give notice to members before it takes effect. The date at the top of this page always reflects the current version.

Contact

For any privacy question or to exercise a right, write to privacy@mlx.com. To ask not to be contacted, write to donotcontact@mlx.com. To report a security issue, write to security@mlx.com. We answer privacy requests within 30 days, and sooner where the law requires it.