Privacy Policy
Effective from 1 September 2026 · Last updated 1 September 2026
This Privacy Policy explains how MindMillers Foundation handles personal data on the MindMillers platform. It is written to meet the requirements of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), the UK GDPR and Data Protection Act 2018 where they apply, and India's Digital Personal Data Protection Act, 2023 (the “DPDP Act”) together with the rules made under it. Where the two regimes use different words for the same idea, both are given.
On this page
- Who we are
- Scope of this policy
- Key terms
- Personal data we collect
- How and why we use it
- Consent and how to withdraw it
- Cookies and local storage
- Who we share data with
- International transfers
- How long we keep data
- Security
- Personal data breaches
- Your rights
- Exercising your rights
- Your duties under the DPDP Act
- Automated processing and AI
- Children and guardianship
- Data about other members
- Grievances and complaints
- Changes to this policy
- Contact
1. Who we are
MindMillers Foundation (“MindMillers”, “we”, “us”, “our”) operates the invitation-only mentorship platform at portal.mindmillers.com and its companion mobile and desktop applications (together, the “Platform”).
For the personal data described in this policy, MindMillers Foundation is the Data Controller under the GDPR and the Data Fiduciary under the DPDP Act. That means we decide why and how your personal data is processed, and we are accountable for it.
Our identity and contact details, as required by Article 13(1) GDPR and section 5 of the DPDP Act.
- Legal entity
- MindMillers Foundation
- Registered office
- [Registered office address, city, state, PIN — India]
- Registration no.
- [CIN / Society or Trust registration number]
- Platform
- portal.mindmillers.com
- General enquiries
- hello@mindmillers.com
- Privacy & data protection
- privacy@mindmillers.com
- Legal notices
- legal@mindmillers.com
- Grievance Officer
- [Name of Grievance Officer]
grievance@mindmillers.com
Any question about this policy, any request to exercise your rights, and any complaint may be sent to privacy@mindmillers.com. We do not currently meet the thresholds that would require us to appoint a statutory Data Protection Officer under Article 37 GDPR, or to be designated a Significant Data Fiduciary under section 10 of the DPDP Act. If either changes, this policy will be updated with the appointed officer's contact details.
2. Scope of this policy
This policy applies to personal data we process about:
- Visitors to our public pages, including anyone who submits an invitation request or a contact message.
- Members — founders, entrepreneurs and other invited participants with a Platform account.
- Mentors and other experts who offer sessions, publish content or run groups on the Platform.
- Correspondents who write to us about the Platform.
It does not cover third-party websites we link to, or the separate processing carried out by a video-meeting provider you choose to use for a mentorship session. Those are governed by their own privacy notices.
3. Key terms
- Personal data
- Any information relating to an identified or identifiable individual. The DPDP Act uses the term in substantially the same sense.
- Processing
- Anything done with personal data — collecting, storing, using, sharing, altering or erasing it.
- Data Subject / Data Principal
- The individual the personal data is about. That is you.
- Data Controller / Data Fiduciary
- The organisation that determines the purposes and means of processing. That is MindMillers Foundation.
- Data Processor
- A service provider that processes personal data on our documented instructions and for no purpose of its own.
- Supervisory Authority / Data Protection Board
- The regulator you can complain to — a national supervisory authority in the EEA, the ICO in the UK, and the Data Protection Board of India under the DPDP Act.
4. Personal data we collect
We collect only what the Platform needs. The table below lists every category we hold and where it comes from.
| Category | What it includes | Source |
|---|---|---|
| Invitation request data | Name, email address, LinkedIn profile URL, and the answers you give in the invitation form; the identity of the member who nominated you, where applicable. | You, or the member who nominated you |
| Account credentials | Username, email address, a cryptographic hash of your password (never the password itself), and multi-factor authentication settings and recovery codes if you enable them. | You |
| Profile data | Full name, pronouns, date of birth, job title, employer, education, location and country, industry, biography, profile and cover images, time zone, and any social or website links you choose to add. | You |
| Contact details | Email address and, if you provide one, a phone number. | You |
| Content you publish | Posts, comments, ideas, opportunities, group posts and memberships, event listings and registrations, job posts, saved items, and any images or files attached to them. | You |
| Private communications | Direct messages between members, and any files attached to them (ZIP, PDF, TXT, PNG, JPG). | You and the members you correspond with |
| Mentorship session data | Mentor availability, bookings, the message you send when requesting a session, the meeting method and link, session status, reminder records, and the ratings, reviews and written feedback exchanged after a session. | You and the other participant |
| MMSpace session data | Records of the audio and video rooms you join, who was present, and when. We do not record the audio or video content of a session unless participants are told in advance and consent within the session. | Generated by the Platform |
| Documents you upload | CVs and similar documents you submit for the job-match feature, and the text extracted from them. | You |
| AI assistant conversations | The prompts you send to the in-Platform assistant and the responses generated for you. | You |
| Preferences | Your notification settings for email and in-app alerts, digest frequency, and newsletter subscription state. | You |
| Device and push data | Push notification tokens, device platform, device name, application version, and a last-seen timestamp for each device you register. | Your device, when you enable notifications |
| Usage and technical data | IP address, browser type and user agent, pages requested, timestamps, referring page, and error diagnostics recorded in server logs; searches you run on the Platform. | Collected automatically |
| Correspondence | Contact messages, support requests, feedback and grievances you send us, and our replies. | You |
| Moderation records | Reports you make or that are made about you, and the outcome of any moderation decision. | You, other members, and our review |
4.1 Data we do not collect
We do not knowingly collect special categories of personal data under Article 9 GDPR — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation. Please do not put such information in your profile, posts or messages. If you choose to, you do so on your own initiative and, in the EEA and UK, on the basis of your explicit consent under Article 9(2)(a) GDPR, which you may withdraw at any time by deleting the content or asking us to.
We do not collect financial account numbers, card details or payment credentials. Membership of the Platform does not involve payment to us.
5. How and why we use it
Under the GDPR we must have a lawful basis for every processing activity. Under the DPDP Act we must process personal data either with your consent or for a permitted “legitimate use”. Both are set out below.
| Purpose | Data used | GDPR lawful basis | DPDP basis |
|---|---|---|---|
| Assessing an invitation request and deciding whether to admit you | Invitation request data | Art. 6(1)(b) — steps taken at your request before entering a contract | Consent, given at the point of submission |
| Creating and running your account and providing the Platform's features | Account, profile, content, messaging, session and preference data | Art. 6(1)(b) — performance of our contract with you | Consent for the specified purpose |
| Displaying your profile and content to other members | Profile data and content you publish | Art. 6(1)(b) — performance of our contract with you | Consent for the specified purpose |
| Arranging, reminding about and following up mentorship sessions | Session data, contact details, time zone | Art. 6(1)(b) — performance of our contract with you | Consent for the specified purpose |
| Sending service and transactional messages — security alerts, booking confirmations, account notices | Contact details, device data, preferences | Art. 6(1)(b), and Art. 6(1)(f) for our interest in keeping you informed about your account | Consent for the specified purpose |
| Sending optional newsletters, digests and community updates | Contact details, preferences | Art. 6(1)(a) — your consent | Consent, withdrawable at any time |
| Search, recommendations, and matching you with mentors, groups, opportunities and jobs | Profile data, search queries, uploaded CVs | Art. 6(1)(f) — our legitimate interest in making the Platform useful | Consent for the specified purpose |
| Operating the AI assistant and CV-to-job matching | Your prompts, uploaded document text, relevant Platform content | Art. 6(1)(a) — your consent, given by choosing to use the feature | Consent, withdrawable by ceasing to use the feature |
| Keeping the Platform secure; preventing fraud, abuse and unauthorised access | Usage and technical data, account data, moderation records | Art. 6(1)(f) — our legitimate interest in security | Legitimate use under s.7 — compliance with law and protection of the service |
| Moderating content and enforcing our Terms & Conditions | Content and messages reported to us, moderation records | Art. 6(1)(f) — our legitimate interest in a safe community | Legitimate use under s.7 — performance of our obligations as an intermediary |
| Diagnosing faults, maintaining and improving the Platform | Usage and technical data, error logs | Art. 6(1)(f) — our legitimate interest in a working service | Legitimate use under s.7 — the purpose for which the data was voluntarily provided |
| Complying with law; responding to lawful requests; establishing or defending legal claims | Any category, as strictly necessary | Art. 6(1)(c) — legal obligation; Art. 6(1)(f) — legal claims | Legitimate use under s.7(b) and s.7(i) |
Our legitimate interests. Where we rely on Article 6(1)(f), we have assessed that our interest in operating a curated, safe and useful professional community does not override your rights and freedoms. You can ask us for a summary of that assessment, and you can object to the processing — see section 13.
We do not sell your personal data. We do not rent or share it with third parties for their own marketing, we do not carry out behavioural advertising, and we do not build advertising profiles.
6. Consent and how to withdraw it
Where we rely on consent, section 6 of the DPDP Act and Articles 4(11) and 7 GDPR require it to be free, specific, informed, unconditional and unambiguous, and given by a clear affirmative action. We ask for it separately from other terms, in plain language, and we keep a record of when and how it was given. Under section 5 of the DPDP Act you are entitled to receive this notice in English or in any language listed in the Eighth Schedule to the Constitution of India; write to us and we will provide it.
You may withdraw consent at any time, and it must be as easy to withdraw as it was to give. You can do this by changing the relevant setting in your account, unsubscribing from an email, deleting the content concerned, or writing to privacy@mindmillers.com. Withdrawal does not affect the lawfulness of processing carried out before you withdrew, and it does not affect processing that rests on a different basis — for example, records we must keep by law. Where withdrawing consent means we can no longer provide part of the Platform, we will tell you the consequences before acting on the withdrawal.
We do not currently use a Consent Manager registered with the Data Protection Board of India. If we adopt one, we will update this policy and explain how to use it.
7. Cookies and local storage
We use only strictly necessary cookies. We do not use advertising, profiling or cross-site tracking cookies, and we do not embed third-party analytics or advertising trackers in the Platform. The one third-party embed we do use — the introduction video on our public home page — is described in section 7.1 and loads nothing until you choose to play it.
| Cookie | Purpose | Duration |
|---|---|---|
sessionid | Keeps you signed in and links your requests to your session. | Session, or until you sign out |
csrftoken | Protects forms against cross-site request forgery. A security requirement. | Up to 12 months |
| Authentication cookies | Remember your sign-in and multi-factor state between visits, if you ask us to. | The length of the session you chose |
Because these cookies are strictly necessary to deliver a service you have asked for, they fall within the exemption in Article 5(3) of the ePrivacy Directive and its national implementations, so we do not ask for consent to set them. If we ever introduce a non-essential cookie, we will ask for your consent first through a cookie banner and update this section.
The Platform also uses your browser's local storage for interface preferences such as collapsed panels and unsent drafts. That data stays on your device and is not sent to us. You can clear it through your browser settings.
7.1 The introduction video on our home page
Our public home page carries an introduction video hosted on YouTube. It is embedded as a click-to-play preview: until you press play, nothing is requested from YouTube and no YouTube cookie is set. Only the still preview image is loaded, from Google's image server.
When you press play, the player loads from youtube-nocookie.com, Google's privacy-enhanced embed domain. At that point Google receives your IP address and device information and may set storage on your device, and it acts as an independent controller for that processing under its own privacy policy. We receive nothing about who watched or for how long. If you would rather not involve YouTube at all, simply do not press play.
8. Who we share data with
8.1 Other members
The Platform is a community. Your profile, the content you publish, your group memberships and your session reviews are visible to other signed-in members according to the visibility of the space you post in. Direct messages are visible to the participants in that conversation. Nothing on the Platform is published to the open internet unless you place it on a page that is public by design, and we will tell you when that is the case.
8.2 Service providers (Data Processors)
We use a small number of vendors to run the Platform. Each processes personal data only on our documented instructions, under a written contract meeting Article 28 GDPR and section 8(2) of the DPDP Act, and none is permitted to use your data for its own purposes.
| Provider | What it does for us | Data involved |
|---|---|---|
| Cloud hosting and database provider [Provider name and hosting region] | Hosts the Platform, its database, file storage and backups. | All categories |
| Postmark | Delivers transactional and notification email. | Name, email address, message content |
| Google Firebase Cloud Messaging, and Apple Push Notification service on iOS | Delivers push notifications to your registered devices. | Push token, device identifiers, notification content |
| OpenAI | Generates responses for the in-Platform AI assistant and the CV-to-job match. | Your prompts, uploaded document text, and the Platform context needed to answer |
Content sent to our AI provider is processed under an API agreement that excludes its use for training that provider's models. We keep this list current; if we add a processor that handles personal data, we will update this table.
8.3 Meeting providers you choose
Mentorship sessions may take place over Zoom or Google Meet, using a link supplied by the participants. When you join such a meeting, the meeting provider processes your data as its own controller under its own privacy notice. We hold only the link and the fact that a session was scheduled.
8.4 Legal and corporate disclosures
We may disclose personal data:
- Where required by law, by court order, or by a lawful request from a public authority — after checking that the request is valid and limiting the disclosure to what is strictly necessary.
- To establish, exercise or defend legal claims, or to protect the rights, safety or property of MindMillers, our members or the public.
- To professional advisers — lawyers, auditors, insurers — who are bound by duties of confidentiality.
- To a successor entity in a merger, restructuring or transfer of the Platform. We will tell you before your data becomes subject to a different privacy policy, and your rights will not be reduced without notice.
9. International transfers
MindMillers Foundation is established in India, and the Platform is hosted in [hosting region]. Some of our service providers are located in the United States and elsewhere. Personal data may therefore be transferred outside the country you live in.
Under the GDPR, where we transfer personal data of individuals in the EEA or the UK to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) under Article 46(2)(c) GDPR, supported by a transfer impact assessment and, where needed, additional technical measures such as encryption in transit and at rest. You can request a copy of the safeguards in place by writing to privacy@mindmillers.com.
Under the DPDP Act, section 16 permits transfer of personal data outside India except to territories the Central Government notifies as restricted. We monitor that list and will stop transfers to any territory that is notified. Where a sectoral law imposes a stricter localisation requirement on data we hold, that stricter requirement applies.
10. How long we keep data
We keep personal data only for as long as the purpose it was collected for requires, and then erase it — the standard set by Article 5(1)(e) GDPR and section 8(7) of the DPDP Act.
| Data | Retention period |
|---|---|
| Unsuccessful or withdrawn invitation requests | 12 months from the decision, then deleted |
| Account, profile and preference data | For as long as your account is open |
| Accounts you have asked us to delete | A 15-day recovery window during which you can reverse the request, after which the account and its personal data are permanently deleted |
| Content you published in shared spaces | Removed when your account is deleted, except where another member's copy of a conversation must be preserved, or where an anonymised record is needed for the integrity of a discussion |
| Direct messages | Until deleted by a participant, or until account deletion |
| Mentorship session records and reviews | 3 years from the session, for dispute resolution and community quality |
| AI assistant conversations | 90 days, then deleted |
| Uploaded CVs | Until you delete them, or 12 months after your last use of the job-match feature |
| Server and security logs | 90 days, unless held longer for an active security investigation |
| Contact and support correspondence | 24 months from the last message |
| Moderation and enforcement records | 3 years from the decision, to keep enforcement consistent and to defend appeals |
| Consent records | For the life of the consent, plus 3 years, as evidence of compliance |
| Records we are required to keep by law | For the period the relevant law requires |
Backups follow their own rotation and may hold a copy of deleted data for a short further period. Data in backups is not used for any live purpose and is overwritten in the ordinary course.
11. Security
We take reasonable security safeguards to prevent a personal data breach, as required by Article 32 GDPR and section 8(5) of the DPDP Act. These include:
- Encryption of traffic in transit using TLS, and encryption of data at rest in our hosting environment.
- Passwords stored only as salted Argon2 hashes — we never hold your password itself.
- Optional multi-factor authentication on your account, which we recommend you enable.
- Role-based access control, so staff can reach only the data their role requires, with access reviewed periodically.
- Cross-site request forgery, clickjacking and session-fixation protections on every form and session.
- Validation and file-type restrictions on uploads.
- Logging and monitoring of administrative access, and regular patching of the application and its dependencies.
- Contractual security obligations on every service provider, and periodic review of them.
No system is perfectly secure. You play a part too: use a strong and unique password, enable multi-factor authentication, keep your devices patched, and tell us immediately at privacy@mindmillers.com if you think your account has been compromised.
12. Personal data breaches
If a personal data breach occurs, we will investigate it promptly and record it.
- Under the GDPR, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach unless it is unlikely to result in a risk to your rights and freedoms (Article 33), and we will notify you without undue delay where the breach is likely to result in a high risk to you (Article 34).
- Under the DPDP Act, we will give intimation of the breach to the Data Protection Board of India and to each affected Data Principal, in the form and manner prescribed under section 8(6).
Our notification will describe what happened, the categories and approximate number of records affected, the likely consequences, the measures we have taken, and what you can do to protect yourself.
13. Your rights
13.1 If the GDPR applies to you
You have the right to:
- Access — obtain confirmation that we process your data and a copy of it, with information about how and why (Art. 15).
- Rectification — have inaccurate data corrected and incomplete data completed (Art. 16).
- Erasure — have your data deleted where it is no longer needed, where you withdraw consent and no other basis applies, or where it has been processed unlawfully (Art. 17).
- Restriction — have processing paused while a dispute about accuracy or lawfulness is resolved (Art. 18).
- Portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible (Art. 20).
- Object — object at any time to processing based on our legitimate interests, and absolutely to any processing for direct marketing (Art. 21).
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22). See section 16.
- Withdraw consent at any time, where consent is the basis (Art. 7(3)).
- Complain to a supervisory authority in the EEA state where you live or work, or where the alleged infringement occurred; or, in the UK, to the Information Commissioner's Office at ico.org.uk (Art. 77).
13.2 If the DPDP Act applies to you
As a Data Principal you have the right to:
- Access information about the personal data we process, a summary of the processing, and the identities of other Data Fiduciaries and Processors with whom it has been shared (s.11).
- Correction, completion, updating and erasure of your personal data (s.12). We will erase it unless retention is necessary for the specified purpose or for compliance with a law in force.
- Grievance redressal — a readily available means of raising a grievance with us, which we must respond to within the prescribed period (s.13). See section 19.
- Nominate another individual to exercise your rights on your behalf in the event of your death or incapacity (s.14). Write to privacy@mindmillers.com to register a nominee.
You may also complain to the Data Protection Board of India if you are not satisfied with how we have handled your grievance.
14. Exercising your rights
Write to privacy@mindmillers.com, or use the controls in your account settings. Some things — correcting your profile, changing notification preferences, deleting your content, deleting your account — you can do yourself at any time without asking us.
- Verification. We will take reasonable steps to confirm your identity before acting, usually by asking you to make the request from your registered email address. We will not ask for more information than that check needs.
- Timing. We respond within one month of receiving a GDPR request, extendable by two further months for complex or numerous requests — in which case we will tell you within the first month and explain why. Grievances under the DPDP Act are acknowledged within 24 hours and resolved within 15 days.
- Cost. Free of charge. We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive — and we will explain our reasoning and your right to complain.
- Limits. Some rights are qualified. We may be unable to erase data we must keep by law, data needed to defend a legal claim, or content that forms part of another member's record of a conversation. If we decline any part of a request, we will tell you which part and why.
15. Your duties under the DPDP Act
Section 15 of the DPDP Act places duties on Data Principals. In dealing with us, you must:
- Comply with applicable law when exercising your rights.
- Not impersonate another person when providing personal data for a specified purpose.
- Not suppress material information when providing personal data for any document, identifier, or proof of identity or address.
- Not register a false or frivolous grievance or complaint.
- Furnish only information that is verifiably authentic when seeking correction or erasure.
The Act provides for a penalty where these duties are breached.
16. Automated processing and AI features
The Platform uses automated processing to rank search results; to suggest mentors, groups, opportunities and jobs; to generate assistant responses; and to score the fit between an uploaded CV and a job listing.
None of these produces a legal or similarly significant effect on you, and none of them decides anything about you on its own. Suggestions are suggestions. A person decides whether to admit a member, whether to accept a session request, and whether to act on a moderation report. Article 22 GDPR is therefore not engaged. If that ever changes, we will tell you first, explain the logic involved and the consequences, and give you a route to human review, to express your point of view, and to contest the decision.
Output from the AI assistant is generated by a language model and can be incomplete or wrong. It is not advice. Please verify anything you intend to rely on.
17. Children and guardianship
The Platform is for adults. You must be at least 18 years old to hold an account, and we do not knowingly collect personal data from anyone under 18.
Section 9 of the DPDP Act requires verifiable consent from a parent or lawful guardian before processing the personal data of a child, or of a person with a disability who has a lawful guardian, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. We meet this by not admitting minors and by not carrying out behavioural tracking or advertising at all. Article 8 GDPR is addressed the same way.
If you believe a person under 18 has given us personal data, write to privacy@mindmillers.com and we will delete the account and its data.
18. Data about other members
When you use the Platform you will see personal data about other members. You may use it only to take part in the community — to connect, converse and arrange mentorship. You must not scrape it, copy it into another system, add it to a marketing list, or disclose another member's private messages or session content without their consent. Doing so breaches our Terms & Conditions and may make you a controller or Data Fiduciary in your own right, with your own legal obligations.
If you nominate someone for an invitation, you confirm that you have a genuine professional relationship with them and that you are entitled to give us their contact details. We will tell them where their details came from.
19. Grievances and complaints
If you are unhappy with how we have handled your personal data, tell us first — it is usually the fastest route to a fix.
- Step one. Write to our Grievance Officer at grievance@mindmillers.com with enough detail to identify the issue. We acknowledge within 24 hours and aim to resolve within 15 days, in line with the IT Rules 2021 and section 13 of the DPDP Act.
- Step two. If you remain dissatisfied, you may complain to the Data Protection Board of India, or — if you are in the EEA or the UK — to your national supervisory authority or the Information Commissioner's Office.
Complaining to us does not affect your right to go to a regulator or to a court.
20. Changes to this policy
We may update this policy as the Platform or the law changes. The “last updated” date at the top always reflects the current version. For material changes — a new purpose, a new category of data, a new recipient, or a change to your rights — we will give notice by email or a prominent notice on the Platform before the change takes effect, and where the change requires it we will ask for your consent again rather than assume it.
21. Contact
For anything in this policy, including requests to exercise your rights, write to privacy@mindmillers.com or to the registered office address above.