1. Scope
This Privacy Policy explains how MindLab collects, uses, shares, retains, and protects information when you visit our website, request a demo, communicate with us, or use a MindLab workspace.
MindLab is a business and institutional software service for investment research, monitoring, source-backed reporting, review, approval, and reusable firm memory. Customer agreements, order forms, data processing terms, or implementation scopes may provide additional terms for a specific deployment.
2. Information We Collect
The information we collect depends on how you interact with MindLab.
- Contact and business information: name, business email, firm name, role, firm type, workflow priorities, and messages submitted through our website or sales process.
- Workspace and account information: authorized users, authentication data, workspace settings, permissions, dashboard configuration, source categories, reviewer rules, and support requests.
- Customer workspace content: materials a customer chooses to upload, connect, or generate in MindLab, which may include data-room exports, decks, models, notes, research, call summaries, prior memos, advisor responses, portfolio updates, report drafts, reviewer comments, approvals, company records, and source metadata.
- Usage and technical information: log data, IP address, browser and device information, page views, feature use, performance data, error reports, security events, and diagnostics needed to operate and protect the service.
- Cookies and similar technologies: our website may use necessary cookies and, where enabled, analytics or similar tools to understand site performance and improve the visitor experience.
3. How We Use Information
- Provide, secure, administer, and improve MindLab.
- Respond to demo requests, support requests, legal notices, security inquiries, and customer communications.
- Configure customer workspaces around source systems, research intake, monitoring needs, dashboards, rubrics, reviewer rules, approval states, permissions, and memory rules.
- Operate AI-assisted workflows such as source review, discrepancy checks, radar monitoring, analyst workbench activity, report drafting, review, approval, and reusable firm memory.
- Maintain service reliability, troubleshoot issues, prevent abuse, detect security events, and enforce agreements.
- Analyze aggregated or de-identified usage patterns to improve product quality, reliability, and customer support.
- Meet legal, compliance, accounting, tax, security, and contractual obligations.
4. AI Processing and Model Training
MindLab uses AI systems to support research, analysis, summarization, report drafting, discrepancy checks, monitoring workflows, and firm memory features. AI output is assistive and should be reviewed by qualified humans before it is used for decisions or external communication.
- Customer confidential data is used to operate the customer workspace and agreed workflows.
- Customer documents, deal flow, proprietary outputs, and firm records are not used to train public models by default.
- MindLab may use third-party infrastructure, model, hosting, analytics, or support providers to operate the service under appropriate commercial, technical, and contractual controls.
- Specific model providers, deployment boundaries, data residency, retention rules, and enterprise commitments may be defined in the applicable agreement.
5. How We Share Information
We do not sell customer confidential data. We do not sell personal information in the ordinary meaning of selling data for money.
- Service providers and subprocessors that help us operate hosting, infrastructure, AI processing, analytics, email, support, security, payments, or administration.
- Customer-directed integrations, connectors, or third-party tools that a customer chooses to use with MindLab.
- Professional advisors, auditors, insurers, accountants, or legal counsel where needed to operate the business or protect legal rights.
- Authorities or third parties when required by law, legal process, security investigation, or to protect MindLab, customers, users, or the public.
- A successor entity in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections.
6. Customer Control, Retention, and Deletion
Customers control the materials they choose to provide to MindLab and are responsible for ensuring they have the rights and authority to upload, connect, or process those materials.
We retain information for as long as needed to provide the service, support agreed workflows, maintain firm memory, comply with legal obligations, resolve disputes, enforce agreements, and protect security. Customer agreements may define more specific retention, deletion, export, backup, and termination procedures.
- Workspace content may remain available while the customer maintains an active workspace or as otherwise agreed.
- Deleted data may persist for a limited period in backups, logs, or security records before it is removed through ordinary retention cycles.
- Certain records may be retained where required for legal, compliance, tax, billing, security, fraud prevention, or dispute-resolution purposes.
7. Security
MindLab uses commercially reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, and disclosure. No system is perfectly secure, and specific security commitments are governed by the applicable agreement.
- Access controls, workspace permissions, logging, monitoring, and operational safeguards are applied according to the deployment scope.
- Customers are responsible for managing authorized users, account access, source permissions, and the sensitivity of materials they provide to MindLab.
- If you believe there is a security issue involving MindLab, contact contact@mindlab.io with "Security" in the subject line.
8. Privacy Rights and Choices
Depending on your location and relationship with MindLab, you may have rights to access, correct, delete, restrict, object to, or receive a copy of certain personal information. Business users should contact their organization administrator for workspace-specific requests where appropriate.
To make a privacy request, contact contact@mindlab.io with "Privacy" in the subject line. We may need to verify your identity and authority before fulfilling a request.
9. International Transfers
MindLab may process information in the United States and other jurisdictions where we or our service providers operate. Where required, we use appropriate safeguards for cross-border processing. Enterprise data residency or dedicated deployment requirements can be scoped in a written agreement.
10. Children
MindLab is not directed to children and is intended for business and institutional use. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through reasonable means, such as updating this page, emailing designated customer contacts, or notifying users through the service.
12. Contact
For privacy questions, security reports, or legal notices, contact contact@mindlab.io and identify the request in the subject line.
