MIA is an AI-native Deal Operating System for M&A and private-markets teams. This policy explains how MIA processes information when you visit the public site, create an account, use a workspace or connect Google services.
One principle guides the product: personal account data is private to its owner unless that person takes an explicit action to share an approved item or privacy-safe signal.Scope and roles
This policy applies to inviertepedia.com and the MIA application. A workspace controls the deal information its members place in that workspace. Each user controls the personal Google account they connect. Depending on the context, MIA operates the service as provider and processes data according to the user's and workspace's instructions.
Questions or privacy requests may be submitted through the public request form on the MIA home page or through the support contact displayed in the application and Google consent screen.
Data we process
Account and workspace data
Name, work email, profile photo, authentication identifiers, workspace membership, security and audit events. MIA stores the deals, documents, counterparties, decisions, tasks and approvals that authorized users add to their workspace.
Service and diagnostic data
Limited request, security, job and error information used to operate, protect and troubleshoot the service. Public demo requests are reviewed by a person and do not trigger automatic outreach.
AI-assisted processing
MIA can structure documents and relationship evidence, recommend next actions and draft material. External communication and governed outputs remain subject to the approval controls shown in the product. Personal Google data is used only to provide the user-facing features described below, not to train a general-purpose advertising model.
Google user data
Google sign-in first requests only basic identity information: OpenID identifier, email and profile. Access to Contacts, Gmail and Calendar is a separate, explicit consent step. MIA uses the minimum scopes required by the features the user chooses.
Names, email addresses, phone numbers, organizations, resource identifiers and synchronization metadata. Used to show the user's private address book, avoid suggesting an already-saved person, and create, edit or delete a contact when the user explicitly submits that action.
Message identifiers, threads, labels, sender, recipients, dates, subject and message body. Used to provide a private inbox, search and relationship context, and to send, reply, mark, archive, restore or move a message to trash when the user explicitly requests it. Attachments and remote tracking images are not imported by this integration.
Selected calendar identifiers, event identifiers, timing, status, organizer and attendees. Used to display and synchronize meetings and to create, edit, move or cancel an event after an explicit user action. Private/confidential imported events are minimized according to the user's settings.
Limited Use
MIA's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, used for advertising or shared with data brokers. It is not exposed to another workspace member unless the connected user deliberately shares a governed output or privacy-safe relationship signal.
Retention and deletion
Workspace information is retained while the workspace is active and as required for legitimate security, audit and legal obligations. Google synchronization history defaults to a configurable period and is incrementally refreshed. Users can disconnect Google at any time; MIA then revokes the token when Google accepts the request and stops synchronization.
“Remove imported data” deletes the private imported mailbox copies, personal Google-contact records, calendar source records and imported relationship activity in scope. It does not delete information in Google. An item a user explicitly converted into governed Deal evidence may be retained in that Deal's audit context. Users may also revoke MIA from their Google Account permissions page.
Security
OAuth client secrets and refresh/access tokens are encrypted in MIA's credential vault and excluded from logs and user-facing responses. MIA uses HTTPS, role-based access, workspace isolation, CSRF protection, session-bound OAuth state, PKCE for sign-in, audit records and human approval boundaries. No method of storage or transmission is completely risk-free; security is monitored and improved continuously.
Your choices and rights
Users can review connected-account status, select import destinations and calendars, synchronize, disconnect and remove imported data. Depending on applicable law, a person may request access, correction, deletion, restriction, portability or objection. We may need to verify identity before fulfilling a request.
Material changes will be reflected on this page with a revised effective date. If a change materially affects connected Google data, MIA may request consent again.