Legal
Privacy Policy
Effective date: 1 January 2025
1. About this policy
Mindacks Global Pvt Ltd ("MHCAI", "we", "us", or "our") operates the website mhcai.org and provides AI education programmes, certifications, and related services (collectively, the "Services"). This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our Services.
By accessing our website or enrolling in any of our programmes, you agree to the practices described in this policy. If you do not agree, please discontinue use of our Services.
2. Information we collect
2.1 Information you provide directly
- Account information: name, email address, password when you register.
- Enrolment information: billing address, payment details (processed by our payment provider — we do not store full card numbers), organisation name, and job title.
- Contact forms: any information you submit when contacting us, including enquiry type and message content.
- Assessment data: responses to AI readiness assessments, learning progress, quiz results, and certification submissions.
- Communications: emails, support tickets, and other correspondence you send us.
2.2 Information collected automatically
- Usage data: pages visited, time on site, click events, and navigation paths via analytics tools.
- Device data: browser type, operating system, screen resolution, and IP address.
- Cookies and similar technologies: see Section 6 for details.
2.3 Information from third parties
If you sign in via LinkedIn or Google, we receive your name, email address, and profile picture from those platforms subject to their privacy policies. We do not receive your password.
3. How we use your information
We use personal information to:
- Create and manage your account and learning profile
- Deliver, personalise, and improve our programmes and certifications
- Process enrolments and payments
- Send administrative communications (receipts, certificates, programme updates)
- Send marketing communications where you have opted in (you can unsubscribe at any time)
- Respond to enquiries and provide customer support
- Analyse usage patterns to improve our Services
- Comply with legal obligations and enforce our terms
- Detect and prevent fraud or abuse
Legal basis (GDPR / UK GDPR): We rely on contract performance (delivering your enrolment), legitimate interests (analytics, fraud prevention, direct marketing to existing customers), consent (where required, e.g. newsletter sign-up), and legal obligation as applicable grounds for processing.
4. How we share your information
We do not sell your personal information. We share it only in these circumstances:
- Service providers: payment processors, email delivery platforms, hosting providers, and analytics tools acting as data processors under contract.
- Certification bodies: where required to issue, verify, or register your certification with relevant standards bodies (e.g. ISO-aligned credential registries).
- Corporate clients: if your employer sponsored your enrolment, we may share your completion status and assessment outcomes with your employer as agreed in the corporate contract.
- Legal requirements: where required by law, court order, or to protect our rights or the safety of others.
- Business transfers: in connection with a merger, acquisition, or sale of assets, with appropriate notice to you.
5. Data retention
We retain personal data for as long as necessary to provide our Services and comply with legal obligations:
- Account data: retained for the life of your account plus 3 years after closure.
- Certification records: retained for 7 years to support credential verification.
- Financial records: retained for 7 years to meet accounting obligations.
- Marketing consent: retained until you withdraw consent or unsubscribe.
- Support communications: retained for 2 years.
6. Cookies
We use the following types of cookies:
- Strictly necessary: authentication session, CSRF protection. These cannot be disabled.
- Analytics: anonymous usage tracking to understand how people use our site. You may opt out via our cookie banner.
- Preferences: storing your language or display settings.
You can manage cookies through your browser settings. Disabling certain cookies may affect site functionality.
7. Your rights
Depending on your location, you may have the following rights:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate data.
- Erasure: request deletion of your data (subject to legal retention obligations).
- Portability: receive your data in a machine-readable format.
- Objection: object to processing based on legitimate interests.
- Restriction: request we limit processing in certain circumstances.
- Withdraw consent: where processing is based on consent, withdraw it at any time.
To exercise any right, email privacy@mindacks.com. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.
8. International transfers
MHCAI operates globally. Your data may be transferred to and processed in countries outside your own. Where we transfer data from the EEA or UK to countries without an adequacy decision, we use Standard Contractual Clauses approved by the relevant authority.
9. Security
We implement appropriate technical and organisational measures to protect your personal data, including TLS encryption in transit, encrypted storage, access controls, and regular security reviews. No system is entirely secure; we encourage you to use strong, unique passwords and to notify us immediately if you suspect unauthorised access to your account.
10. Children
Our Services are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, please contact us and we will promptly delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or a prominent notice on our website at least 14 days before they take effect. Your continued use of the Services after that date constitutes acceptance of the updated policy.
12. Contact us
For privacy enquiries or to exercise your rights, contact our Data Protection team:
Mindacks Global Pvt LtdEmail: privacy@mindacks.com
General: info@mindacks.com
Website: mindacks.com