Privacy Policy
Last updated: July 2026
Data controller
The data controller responsible for your personal data is:
What we collect
When you interact with our platform we may collect:
- Your name and email address when you complete the self-diagnosis or sign up
- Answers you provide inside the tools portal, used only to personalise your experience
- Usage data such as pages visited and time spent, via our own analytics and not third-party ad trackers
- Payment information processed securely by Stripe or PayPal (we never store card numbers)
- Technical data including browser type, device type, and approximate location at country level
- IP address and session identifiers for security and fraud prevention
Legal basis for processing (GDPR)
Under the GDPR we are required to identify a lawful basis for each processing activity. We rely on the following:
Processing your name, email, and tool data is necessary to provide the platform you signed up for.
We analyse anonymised usage patterns to improve the product. This does not override your rights.
We send marketing emails on the basis of your consent. You can withdraw consent at any time by unsubscribing.
We retain billing records as required by Dutch tax and accounting law (typically 7 years).
How we use your data
- Deliver and personalise the Mind Minutes Method platform
- Send transactional emails such as your magic-link login and receipts
- Send marketing updates and offers. You can unsubscribe at any time
- Improve the product based on aggregated, anonymised usage patterns
- Comply with legal obligations including tax record-keeping
Cookies
We use a small number of strictly necessary cookies to keep you signed in and remember your session. We do not use advertising cookies, tracking pixels, or profiling cookies. No cookie consent banner is shown because we do not set any non-essential cookies.
You can clear cookies at any time in your browser settings. Clearing session cookies will sign you out of the platform.
Third-party sub-processors
We share your data with the following processors only to the extent necessary to deliver the service. Each operates under a data processing agreement and appropriate safeguards.
Transactional and marketing emails
Payment processing
Payment processing
Application hosting and database
Where data is transferred outside the European Economic Area, we rely on Standard Contractual Clauses (EU SCCs) approved by the European Commission to ensure adequate protection.
Your rights under GDPR
If you are in the EU or UK, you have the following rights. You can exercise any of them by emailing hello@mindminutesmethod.com. We will respond within 30 days.
Request a copy of all personal data we hold about you.
Ask us to correct inaccurate or incomplete data.
Request deletion of your data, also known as the right to be forgotten. We will comply unless we are required to retain data by law.
Ask us to pause processing your data while a dispute is resolved.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests, including profiling. You can also object to direct marketing at any time.
Where processing is based on consent (such as marketing emails), you can withdraw at any time by clicking unsubscribe or emailing us.
You have the right to complain to the Dutch data protection authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or your local supervisory authority.
California residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- The right to know what personal information we collect, use, disclose, or sell
- The right to delete personal information we have collected from you
- The right to opt out of the sale of personal information. We do not sell personal information.
- The right to non-discrimination for exercising your CCPA rights
To submit a CCPA request, email hello@mindminutesmethod.com. We will respond within 45 days.
Data retention
We retain your personal data for as long as your account is active. If you request deletion, we will remove your personal information within 30 days. Financial and billing records are retained for 7 years as required by Dutch law (Belastingdienst). Anonymised, aggregated analytics data may be retained indefinitely as it cannot identify you.
Data security
We implement appropriate technical and organisational measures to protect your data including encrypted connections (TLS), hashed authentication tokens, and access controls. In the event of a personal data breach that poses a risk to your rights, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Art. 33 and 34.
Automated decision-making
We do not use fully automated decision-making or profiling that produces legal or similarly significant effects on you. Your diagnostic results are shown to you for your own use and are not used to make automated decisions about you.
Children's privacy
Our platform is intended for education business owners and professionals. We do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us with their data, contact us and we will delete it promptly.
Changes to this policy
We may update this policy from time to time. We will notify active users by email if we make material changes. The date at the top of this page reflects the most recent update. Continued use of the platform after changes means you accept the updated policy.
Contact and complaints
For any privacy-related questions or to exercise your rights, contact us at hello@mindminutesmethod.com.
If you are not satisfied with our response, you have the right to lodge a complaint with the Dutch supervisory authority: Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl.