1. Who We Are and How to Contact Us
Mind University (mdu.lt) is an online educational platform offering courses, memberships, digital products and an educational community. Platform operations are carried out by three data controllers, each of which processes certain personal data about you within its area of responsibility.
Multiverse LTD
Trust Company Complex, Ajeltake Road, Ajeltake Island, Majuro, P.O. Box 1405, Marshall Islands
Area of responsibility: platform operations, user accounts, access rights administration, community content.
BIOMIND BY PROFESSIONALS Sp. z o.o.
ul. Chmielna 2/31, 00-020 Warsaw, Poland
NIP: PL1182307005 · REGON: 541902732
Area of responsibility: order processing, invoicing, payments, delivery, customer service.
Asociacija Firmus Medicus
Code: 305168407
T. Masiulio g. 21B, LT-52436 Kaunas, Lithuania
Area of responsibility: administration of educational initiatives funded by donations and contributions, and the cultural revival project of Lentvaris Manor.
General contact: we@mind.university. We respond within 30 calendar days of receiving your request.
2. What Data We Collect
We collect only the data necessary to achieve a specific purpose.
2.1 Account Data
First name, last name, email address, chosen username (display name), password hash (we do not store the original), profile picture (optional), account creation date, last login timestamp.
2.2 Technical Data
IP address, browser type and version, operating system, device identifier, page view logs, session duration, error reports. This data is collected automatically each time you visit the platform.
2.3 Community Content
Comments, community space posts, feedback forms, Q&A material, course completion certificates, progress data. Processing of this content is described in more detail in Section 11.
2.4 Purchase and Payment Data
Order number, purchased products or courses, payment amount and currency, payment method (card type, last 4 digits), invoice data, transaction date and status. Full payment card data is processed only within the payment processor's (Stripe) infrastructure — we do not store or have access to it.
2.5 Communication Data
Emails and requests you send us; automated system notifications (registration confirmation, password recovery, order confirmation); marketing newsletters if you have given consent.
2.6 Cookie and Tracking Data
Described in detail in Section 9 (Cookie Policy).
We deliberately do not collect special category data (e.g. health, religious beliefs or biometric data) unless you voluntarily submit it in community content. Such data is processed only with your explicit consent (GDPR Art. 9(2)(a)).
3. Why We Process Data and the Legal Basis
Each processing purpose has a clear legal basis under the GDPR (2016/679).
Where processing is based on legitimate interest, we carry out a balancing test. You may request a summary by email at we@mind.university.
4. Recipients and Data Sharing
We do not sell or exchange your data for commercial purposes. Data is transferred only in the following cases:
- Between the three controllers — only data necessary for coordinated service delivery (e.g. a purchase confirmation linked to granting access to a course).
- To data processors (see Section 5) — service providers acting on our behalf under written agreements.
- To public authorities — competent authorities (courts, pre-trial investigation bodies, tax authorities) only upon receipt of a lawful request or obligation.
- Business transfers — if a merger or restructuring occurs, data may be transferred to a new controller with a commitment to comply with this policy.
5. Data Processors
We enter into a GDPR-compliant Data Processing Agreement (DPA) with each data processor.
6. International Data Transfers
Some processors operate outside the European Economic Area (EEA). Such transfers are subject to GDPR Chapter V safeguards:
- EU–US Data Privacy Framework (DPF) — applies to Stripe, Meta and Google.
- Standard Contractual Clauses (SCCs) — where DPF does not apply; we use the 2021 European Commission-approved SCCs.
- Additional technical measures — data encryption (TLS 1.2+), access restrictions, regular security audits.
You may request copies of the specific SCCs by email at we@mind.university.
7. Data Retention Periods
8. Your Rights Under the GDPR
As a data subject you have the following rights, which you may exercise at any time:
- Right of access (GDPR Art. 15) — to receive confirmation and a copy of your data.
- Right to rectification (GDPR Art. 16) — to correct inaccurate or supplement incomplete data.
- Right to erasure (GDPR Art. 17) — the "right to be forgotten"; does not apply where we are legally required to retain data.
- Right to restriction of processing (GDPR Art. 18) — to suspend active processing in certain circumstances.
- Right to data portability (GDPR Art. 20) — to receive your data in JSON or CSV format.
- Right to object (GDPR Art. 21) — to processing based on legitimate interest or direct marketing.
- Right to withdraw consent (GDPR Art. 7(3)) — at any time; this does not affect prior processing.
Submit requests by email to we@mind.university. We respond within 30 days (in complex cases within 90 days with advance notice). You also have the right to lodge a complaint with a supervisory authority — see Section 17.
9. Cookie Policy
Cookies are small text files stored on your device. We use them to ensure platform functionality, your convenience and analytics.
Essential cookies (always active) — technically necessary for the platform to function. Without them you cannot log in, make a payment or use course materials.
Analytical cookies (consent required) — collect anonymous information about how users interact with the platform.
Marketing cookies (consent required) — used for targeted advertising on social networks and Google platforms.
On your first visit you will see a cookie consent banner. You can change your preferences at any time via the "Cookie Settings" link at the bottom of the page. You can opt out of Google Analytics via this tool; Meta advertising via Facebook Ad Preferences.
10. Platform Security
To ensure data security we apply technical and organisational measures in accordance with GDPR Art. 32:
- Encryption — all data is transmitted via TLS 1.2+ (HTTPS); passwords are stored using bcrypt hashing.
- Access control — sensitive data is accessible only to authorised personnel (principle of least privilege).
- Regular backups — performed daily and stored in a separate geographic location.
- Data breach management — if a breach could pose a risk to your rights, we will notify you within 72 hours (GDPR Art. 33–34).
We recommend using strong, unique passwords and enabling two-factor authentication.
11. Community Content Policy
By publishing content on the platform (comments, questions, reviews) you retain copyright in your creations. However, you grant Multiverse LTD a non-exclusive licence to display that content for platform operating purposes.
Multiverse LTD reserves the right to remove without prior notice any content that infringes intellectual property rights, is defamatory, discriminatory or otherwise unlawful. If you see content that violates your rights, contact us at we@mind.university — we respond within 5 business days.
12. Membership and Subscription
When you purchase a membership or subscription, the following data is processed: chosen membership plan, subscription start and end date, auto-renewal status, tokenised payment card identifier (Stripe Token — not the card number), payment history.
If you have chosen auto-renewal, you will receive a reminder by email at least 3 days before each payment (in case of price or terms changes). You may cancel your subscription at any time via account settings.
13. Children's Data
The platform is intended for persons aged 16 and over. We do not knowingly collect data from younger individuals. If we learn that a person under 16 has created an account, we will delete that account without delay. If you are a parent or guardian and believe your child has created an account, please contact us: we@mind.university.
14. Automated Decision-Making
We currently do not carry out automated decision-making as defined in GDPR Art. 22 that would have legal or similarly significant effects on you. We use limited profiling for content personalisation (course recommendations) and newsletter segmentation — this can be disabled at any time via account settings.
15. Links to Third-Party Websites
The platform may contain links to external websites. This privacy policy applies only to the mdu.lt platform. Third-party privacy practices are solely their own responsibility — we recommend reviewing their policies before submitting personal data.
16. Policy Updates
Minor changes (spelling, formatting, clarifications) — take effect immediately; the date at the top of the document is updated.
Material changes (new data categories, new controllers, new purposes) — we notify all active account holders by email at least 30 days before the effective date.
Previous versions are retained and provided on request. Your continued use of the platform after changes take effect confirms that you have read the new version.
17. Contacts and Supervisory Authority
General data protection contact:
we@mind.university
Response time: 30 days from receipt of request.
Multiverse LTD
Trust Company Complex, Ajeltake Road, Ajeltake Island, Majuro, P.O. Box 1405
BIOMIND BY PROFESSIONALS Sp. z o.o.
ul. Chmielna 2/31, 00-020 Warsaw, Poland
Asociacija Firmus Medicus
T. Masiulio g. 21B, LT-52436 Kaunas, Lithuania
Supervisory authorities:
State Data Protection Inspectorate (Lithuania) — vdai.lt · ada@vdai.lt
Urząd Ochrony Danych Osobowych (Poland) — uodo.gov.pl