LEGAL
Privacy Policy
This policy explains what personal data MindPolar collects, why, and what you can do about it. It is written to describe what MindPolar's systems actually do — where something is not yet built, this policy says so plainly rather than describing it as done.
Document status
This document is a draft prepared to describe MindPolar's systems accurately. It is not legal advice, and it requires review by qualified legal counsel before it governs any account, transaction, or data processing.
1
Who is responsible for your data
| Legal entity | MindPolar Pvt Ltd |
|---|---|
| Corporate Identification Number | U62099OD2025PTC047911 |
| Registered address | [TO BE SUPPLIED BY OWNER] |
| Privacy contact | hello@mindpolarai.com (interim — a dedicated privacy/DPO address should replace this before publication) |
MindPolar is two different things to two different kinds of personal data, and the distinction below governs the rest of this policy. This is not a stylistic choice — GDPR Art. 28 and the DPDP Act 2023 impose materially different duties on a controller than on a processor.
1.1
Where MindPolar is the controller, and where it is the processor
Your own MindPolar account — your name, login email, profile photo, sessions, authentication records, and your own security-activity history — is data MindPolar controls: you are the data subject, and MindPolar decides why and how it is processed.
If you are added to MindPolar as an employee, contractor, or other person inside a customer organization's directory — your work email, employee number, department, job position, employment dates, or reporting line — the organization that added you is the controller of that data, and MindPolar processes it only on that organization's documented instructions, under a Data Processing Agreement. If you have a question about that data, your employer's own privacy notice governs it, and MindPolar will direct your request back to them.
2
What personal data MindPolar processes
| Category | Data | Source |
|---|---|---|
| Account identity | Full name, email address, profile photo | You, at sign-up or in account settings |
| Authentication | Password (hashed, never stored in plain text), session tokens, email-verification and password-reset tokens | Generated by the system when you sign up, sign in, or request a reset |
| Preferences | Timezone, formatting locale, light/dark theme | You, in account settings |
| Security activity | Login events, password changes, email changes, deactivation/erasure requests, plus the IP address and user agent for each | Captured automatically by the system |
| Organization membership | Which organizations you belong to, your role, your job title in each | You (creating/joining) or an organization admin (inviting you) |
| Category | Data |
|---|---|
| Identity | Display name, given name, family name, employee number, work email |
| Employment | Employment status (active / former), start date, end date |
| Structure | Department, team, work location, job position, who they report to |
This data is entered by a customer organization's own administrators. MindPolar does not collect it directly from the individual it describes, and does not decide what is collected, for how long, or for what purpose. If you are an employee whose data appears here and you are not a MindPolar account holder yourself, direct your data-protection questions to your employer.
| Category | Data | Purpose |
|---|---|---|
| Rate-limiting signal | A one-way cryptographic hash (HMAC) of your IP address plus the action attempted | Prevent credential-stuffing and abuse of authentication endpoints — the raw IP is never stored, only an irreversible pseudonym |
| Cookies | See the Cookie Policy | Keep you signed in; remember your last-used workspace |
3
Purpose and legal basis for each use
Stated per purpose for identity data only. Employee-directory data is processed solely on the controlling organization's instructions under the DPA, which is itself the legal basis between MindPolar and that organization.
| Purpose | Legal basis (GDPR) | Legal basis (DPDP Act 2023) |
|---|---|---|
| Create and operate your account | Art. 6(1)(b) — necessary to perform the contract you enter at sign-up | §4(a) — consent, accompanying the §5 notice |
| Verify your email address | Art. 6(1)(b) | §4(a) |
| Keep you signed in / detect suspicious activity | Art. 6(1)(f) — legitimate interest in account security | §4(a) |
| Prevent abuse of authentication endpoints | Art. 6(1)(f) | §4(a) |
| Let an organization invite or add you as a member | Art. 6(1)(b) | §4(a) |
| Respond to a data-subject rights request | Art. 6(1)(c) — legal obligation | §4(a) read with §11–14 |
| Send a transactional email (verification, reset, invitation) | Art. 6(1)(b) | §4(a) |
No marketing email exists in this product
There is no mailing list, newsletter, or marketing-consent flow today. If one is added, it needs its own opt-in consent basis (GDPR Art. 6(1)(a)) and its own row here before it ships.
5
International data transfers
| Region | Provider | What's processed there |
|---|---|---|
| ap-south-1 — Mumbai, India | Amazon Web Services | All personal data MindPolar processes today. The platform runs from this single region; there is no second region and no data stored outside it as part of normal operation. |
CloudFront, the content-delivery layer in front of the web and API applications, may route a request in transit through an edge location outside India as part of ordinary internet routing. This does not mean data is stored there, and CloudFront edge caching is not used for personal data responses.
India does not currently hold an EU adequacy decision (GDPR Art. 45)
The moment MindPolar processes an EU or EEA resident's personal data, that transfer becomes a GDPR Chapter V restricted transfer, requiring a transfer mechanism (Standard Contractual Clauses) plus a documented Transfer Impact Assessment — disclosure alone does not make it lawful. No EU-resident customer has been onboarded yet, so this has not arisen in practice. No SCCs have been executed and no Transfer Impact Assessment has been performed. Both must be in place before, not after, the first EU customer's data starts flowing. No EU-region deployment exists or is scheduled in the current infrastructure configuration. This section gains a row in the table above the day any of that changes — it is not rewritten.
6
How long MindPolar keeps your data
| Data | Retention |
|---|---|
| Your account, while active | Indefinitely, until you deactivate or erase it |
| Deactivated account | Indefinitely — deactivation is reversible; signing back in restores it |
| Erased account | 14-day grace window, fully reversible; irreversibly purged after, enforced in the database itself |
| Deleted infrastructure backups | Up to 7 days, disaster-recovery only, never reachable as a self-service restore |
| Organization deletion | Currently a reversible administrative action; an organization's records are retained until erasure is carried out. An automated purge window is not yet in operation — to request erasure of an organization's records, contact privacy@mindpolarai.com |
| Your own security-activity history | Deleted together with your account, with no independent retention |
| An organization's shared audit trail (who invited whom, who changed what) | Survives the acting person's own erasure — only their identifying link is removed, a non-identifying label remains, because the audience is the organization's other members |
| Employee-directory data after someone leaves an organization | Retained indefinitely as a terminal record; identifiers are scrubbed on that person's own account erasure, but employee number, department, position, dates, and reporting position are retained for the organization's audit history |
There is no retention-expiry mechanism in this system
No job, schedule, or policy currently deletes or anonymises data because it has aged past a defined period — the only deletions that happen are the ones a person or organization explicitly triggers. A former employee's non-identifying directory record, and the pseudonymised rate-limit signal, can persist indefinitely today. This is stated plainly because claiming a retention period this system does not enforce would be a false statement to a regulator.
7
Your rights
- Access (GDPR Art. 15) — a copy of the personal data MindPolar holds about you.
- Rectification (Art. 16) — correct inaccurate data. For identity data this is self-service today: name, email, and password are all correctable in-product.
- Erasure (Art. 17) — see the 14-day grace-window process above.
- Restriction of processing (Art. 18).
- Data portability (Art. 20).
- Objection (Art. 21), including to processing based on legitimate interest.
- Withdraw consent at any time, without affecting processing already carried out (Art. 7(3)).
- Lodge a complaint with a supervisory authority — your own country's data protection authority.
- Right to access information about your personal data and its processing (DPDP Act 2023 §11).
- Right to correction and erasure (§12).
- Right to grievance redressal, and to approach the Data Protection Board of India if unresolved (§13).
- Right to nominate another individual to exercise these rights on your behalf in the event of death or incapacity (§14).
Most of the above are self-service today inside your account settings. For anything not self-service — an access request, a portability request, an objection — contact privacy@mindpolarai.com.
If your request is about employee-directory data
MindPolar is the processor, not the controller, of that data. If you contact MindPolar directly, MindPolar will tell you who the controller is and forward your request to them — MindPolar does not independently rectify or erase employee-directory data outside the controlling organization's instruction.
8
The Data Processing Agreement
If you are a customer organization, your relationship with MindPolar for employee-directory data is additionally governed by a Data Processing Agreement, which sets out MindPolar's obligations as processor, the sub-processor list, and the safeguard for any future cross-border transfer.
9
Security
Measures applied to the data MindPolar controls and processes:
- Encryption in transit (TLS) for every connection to the web application and API.
- Encryption at rest for the database (AWS Aurora) and object storage (AWS S3).
- Tenant isolation enforced in the database itself — Postgres Row-Level Security, forced on every organization-scoped table, so an application bug cannot leak one organization's data into another's query.
- Least-privilege AWS IAM roles per function; no long-lived AWS access keys used by the application at runtime.
- Passwords are hashed, never stored or logged in plain text.
- Pseudonymisation of IP addresses used for rate-limiting.
No system is unbreakable, and this section is not a guarantee.
10
Data breach notification
Where a breach of personal data creates a risk to individuals, MindPolar will notify affected customer organizations, and — where MindPolar is the controller — affected individuals, without undue delay, consistent with GDPR Art. 33/34 and DPDP Act 2023 §8(6).
11
Automated decision-making
MindPolar does not perform automated decision-making that produces legal or similarly significant effects on an individual. The product's organizational maturity diagnostic produces a score about the organization as a whole, from answers the organization's own people submit — it does not profile or score an individual, and no output is used to make an automated decision about any specific person.
12
Children's data
No age-verification mechanism exists
MindPolar is a B2B product not directed at children, and does not knowingly collect data from anyone under the age of legal majority in their jurisdiction. No age-gating mechanism exists in the product today — stated as a gap, not a control.
13
Changes to this policy
MindPolar will update this policy as the product, its sub-processors, or its data-residency footprint change, posting the new version and effective date at the top of this page and in the changelog below.
Version acceptance is not yet recorded
MindPolar does not currently record which version of this policy a given user accepted at sign-up — only that a policy was accepted, not which one. Until that changes, the version in force for any past acceptance cannot be reconstructed from system data alone.
Version history
- v1.0.0Pending — not yet published
Initial draft, pending legal review.