Amafi Limited and its affiliated group entities (“Amafi,” “we,” “us,” or “our”) operate an editorial directory and research library covering AI, M&A, and finance tools. We also communicate with providers, readers, partners, and counterparties through this website and related channels.
01 What this policy covers
This policy applies to information processed through the amafi.ai website, verified intelligence portal, MCP endpoint, contact forms, tool-submission and correction forms, and related communications. It also applies to information we receive while evaluating directory submissions, editorial corrections, provider claims, deployment notes, uploaded materials, research enquiries, and partnerships.
02 Information we collect
- Identity and contact details such as name, email, phone number, company, and role.
- Submission details such as product information, provider role, target users, pricing and access information, public demo or documentation links, optional fundraising signals, pilot interest, and requested corrections.
- Account and verification details such as email-link or optional Google authentication records, company domain, profile verification status, and provider claims.
- Structured deployment notes, conflict disclosures, uploaded product materials, document visibility choices, and moderation records.
- Security and access records such as hashed API-token identifiers, MCP usage, document-access logs, and IP address.
- Communications and correspondence you send us directly.
- Technical information such as browser type, device information, IP address, and website interaction data.
03 How we use information
- Responding to enquiries and evaluating tool submissions, corrections, and partnership requests.
- Verifying submitted product information and preparing, correcting, or maintaining editorial profiles.
- Authenticating users, verifying work identities, moderating contributions, issuing short-lived document links, and operating read-only MCP access.
- Operating, securing, and improving our website, directory, research, and internal workflow systems.
- Managing relationships with providers, readers, partners, and service providers.
- Monitoring site performance and preventing abuse, fraud, or misuse.
- Complying with legal obligations and enforcing our rights.
04 Publication and AI-assisted processing
Information submitted as product information may be checked against public sources and used to prepare or update a public editorial profile. Approved deployment notes may identify the verified contributor by name, company, and role on the website; those identity fields are excluded from MCP results. Provider facts, public materials, and fundraising signals publish only after moderation. Fundraising signals expire after 90 days unless reconfirmed.
Files marked for verified users remain in private storage and are released through short-lived, logged links only after work verification. They are excluded from public search and MCP. Public files also remain private until moderation, then use expiring links rather than a permanently public storage bucket.
Amafi uses internal software, automation, and AI-assisted systems as part of its research and operating model. We may use third-party technology providers to help power parts of our workflow, communication, and website stack.
We use appropriate technical and contractual measures where available, including limiting access, restricting unnecessary sharing, and using service providers that support commercial confidentiality and security requirements.
05 Disclosure
We may disclose information to affiliated group entities, infrastructure providers, analytics providers, professional advisers, and other service providers where reasonably necessary for the purposes described above.
We may also disclose information where required by law, regulation, court order, or valid governmental request.
06 International processing
Amafi operates across multiple jurisdictions. Information you provide may be processed by group entities or service providers in Hong Kong, Australia, or other locations where our providers and infrastructure operate.
07 Security and retention
We use administrative, technical, and organisational safeguards designed to protect information against unauthorised access, disclosure, alteration, or destruction. Browser clients do not receive database service credentials; access tokens are hashed at rest; controlled files use private storage and short-lived links.
We retain personal information only for as long as reasonably necessary for the relevant purpose, to maintain moderation and security records, or to satisfy legal and compliance obligations. MCP tokens expire after 180 days unless revoked earlier.
08 Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal information, or ask questions about how it is handled. To do so, contact us at contact@amafi.ai.
09 Changes
We may update this policy from time to time. If we make material changes, we will update the effective date on this page and publish the revised version here.