Privacy Policy
What we collect, why we collect it, and what you can do about it. Written in plain English.
The short version
We collect the information you give us when you fill in a form, enrol in a course, ask about a service, or sign in to one of our workspaces. We use it to deliver the service you signed up for, to keep the platform secure, and — only with your permission — to send you updates that are actually useful. We do not sell your data. We share it with a small, named list of sub-processors (hosting, payment, AI) that you can read in full on our sub-processor register (available on request from legal@mindarchitecturegroup.com).
You can ask us to show you what we hold, correct it, delete it, or hand it back to you in a portable format. The contact is at the bottom of this page.
Who we are
Mind Architecture Group is the operating brand for the Mind Architecture consultancy, learning platform, and AI tools. The legal entity that controls your personal data depends on how you interact with us:
- mindarchitecturegroup.com visitors and ICI respondents: Mind Architecture Group, the operating entity registered in St. Lucia / Wyoming.
- Course learners and client portal users: Mind Architecture Group, in its capacity as the platform operator. Where you are a learner or client of a partner (Felaris, TASC, NAGICO, and similar), the partner is the business customer and we act as their data processor under a written agreement.
For the rest of this policy, "we", "us", and "our" refer to whichever entity is the controller in your case.
What personal data we collect
We collect personal data in three ways.
- You give it to us directly when you fill in a form, enrol in a course, sign in, or email us. Typical items: name, work email, phone number, job title, organisation, country, and the content of your answers to our assessments.
- We generate it as you use the platform: course progress, assessment scores, time on lesson, learning-engine activity logs, and the output of our AI consulting reports.
- We receive it from your browser for basic operation: IP address, user agent, referrer, and (if you accept them) cookies. We do not use third-party advertising cookies.
Special categories. Some of our assessments (mental wellness, sports psychology, certain emotional-intelligence instruments) may collect data that is treated as special-category data under GDPR Article 9 (health, philosophical beliefs about self). Where we do, we ask for explicit consent at the point of collection, and you can withdraw that consent at any time.
Why we use it (lawful basis)
Under GDPR we need a lawful basis for each use. The main ones we rely on:
- Contract. To deliver the service you signed up for — running the course, generating the consulting report, hosting your workspace.
- Legitimate interest. To keep the platform secure, prevent abuse, debug issues, and improve the product. We balance this against your rights and offer an opt-out where the balance tips.
- Consent. For marketing emails, for special-category data, for non-essential cookies, and for any processing that an explicit opt-in is the right way to do.
- Legal obligation. For tax, accounting, and any other obligation the law puts on us.
AI and automated decision-making
Parts of the platform use third-party large-language-model providers (currently MiniMax, with OpenAI as an optional fallback) to generate ICI consulting reports and power the in-product chat assistant. The full list of AI providers, their regions, and what data we send them is on the sub-processor register (available on request).
The AI report is reviewed by a human operator before it is shown to a client. You always have the right to ask for human review of any decision that was substantially influenced by an AI output (GDPR Article 22).
How long we keep it
We keep personal data only as long as we need it for the purpose it was collected, plus whatever retention window the law requires (typically 6–7 years for tax-relevant records). Operational defaults:
- ICI assessment responses: 24 months from last interaction, then deleted.
- Course progress and certificates: for the life of the account, then 12 months after closure.
- AI consulting reports: 24 months, then archived (or deleted on request).
- Server logs: 30 days, then aggregated and deleted.
International data transfers
The platform is hosted in the United States (Render) and uses a US-region Supabase project. Where we transfer personal data outside the UK / EEA, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or other lawful transfer mechanisms.
Our AI providers may process prompts in their own regions. We have configured the default provider to the global endpoint (api.minimax.io) and you can find the regional decision in our sub-processors register.
Your rights
You have the right to:
- Access the personal data we hold about you (Article 15).
- Correct inaccurate or incomplete data (Article 16).
- Request deletion of your data (Article 17).
- Restrict or object to certain processing (Articles 18, 21).
- Receive a portable copy of your data (Article 20).
- Withdraw consent at any time, where consent is the lawful basis.
- Lodge a complaint with your local data protection authority.
To exercise any of these, email legal@mindarchitecturegroup.com. We respond within 30 days. There is no fee.
How we protect it
We protect personal data with a defence-in-depth approach: encryption in transit (TLS 1.2+), encryption at rest (Supabase-managed), role-based access control with row-level security on every data table, hashed access tokens, signed service-role keys, environment-driven secret management, and continuous dependency vulnerability scanning.
The current security posture and roadmap to certification is published in our internal compliance baseline (Phase 1 of our three-phase programme).
Children
The platform is not directed at children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We will post material changes on this page and bump the version number and last-updated date. Where the change is significant, we will email active users and (where required) ask for renewed consent.
Contact
Data protection questions: legal@mindarchitecturegroup.com
Postal address and registered entity details are on our about page.
