Wed · 7 OctMoon 12%Field Kp 3 · unsettledQuote · Alan WattsRiddle of the daySky tonightHow today feels →

Privacy Policy

1. Who we are and how to contact us

Mind University (mdu.lt) is an online education platform offering courses, memberships, digital products and an educational community. The platform is run by three data controllers, each responsible for your personal data within their own area of activity.

Multiverse LTD
Trust Company Complex, Ajeltake Road, Ajeltake Island, Majuro, P.O. Box 1405, Marshall Islands
Area of responsibility: platform operation, user accounts, access-rights administration, community content. Multiverse LTD is also the owner and manufacturer of physical products under the "Biomind" brand.

3T Media FZE
M1 Floor, Twin Towers, PO Box 4422, Fujairah, United Arab Emirates
Reg./licence no. 20352/2026 (not VAT-registered)
Area of responsibility: order processing, invoicing, payments, delivery, customer support.

General contact: we@mind.university. We reply within 30 calendar days of receiving your request.

2. What data we collect

We only collect the data that is necessary for a specific purpose.

2.1 Account data
First and last name, email address, chosen username, password hash (we never store the original password), account creation date, last login timestamp.

2.2 Technical data
IP address, browser type and version, operating system, device identifier, page-view logs, session length, error reports. This data is collected automatically every time you visit the platform.

2.3 Community content
Comments, posts in the community area, review forms, Q&A material, course-completion records, progress data. Handling of this content is described in more detail in Section 11.

2.4 Purchase and payment data
Order number, products or courses purchased, payment amount and currency, payment method (card type, last 4 digits), invoice data, transaction date and status. Full card details are only ever handled inside the payment processor's (Stripe) own infrastructure — we never store them and have no access to them.

2.5 Communication data
Emails and enquiries you send us; automatic system messages (registration confirmation, password reset, order confirmation); marketing newsletters, if you consented.

2.6 Cookie and tracking data
Described in full in Section 9 (Cookie Policy).

We deliberately do not collect special-category data (e.g. health, religious belief or biometric data), unless you voluntarily provide it in community content. Such data is only processed with your explicit consent (GDPR Art. 9(2)(a)).

Every processing purpose has a clear legal basis under the GDPR (2016/679).

Processing purposeLegal basis (GDPR)Responsible controller
Creating and administering accountsArt. 6(1)(b) – Performance of a contractMultiverse LTD
Providing courses and contentArt. 6(1)(b) – Performance of a contractMultiverse LTD
Payment processingArt. 6(1)(b) – Performance of a contract3T Media FZE
Invoicing and accountingArt. 6(1)(c) – Legal obligation3T Media FZE
Warehousing and shipping of goodsArt. 6(1)(b) – Performance of a contract3T Media FZE
Platform security and fraud preventionArt. 6(1)(f) – Legitimate interestMultiverse LTD
Technical logs and fault diagnosticsArt. 6(1)(f) – Legitimate interestMultiverse LTD
Marketing newslettersArt. 6(1)(a) – ConsentMultiverse LTD / 3T Media FZE
Analytics and statistics (aggregated)Art. 6(1)(f) – Legitimate interestMultiverse LTD
Cookies — analytics and marketingArt. 6(1)(a) – ConsentMultiverse LTD
Defence of legal claimsArt. 6(1)(f) – Legitimate interestAll three controllers

Where processing relies on legitimate interest, we carry out a balancing test. You may request a summary of it by emailing we@mind.university.

4. Data recipients and sharing

We never sell your data or exchange it for commercial purposes. We only share data in the following cases:

  • Between the three controllers — only the data necessary for coordinated service delivery (e.g. matching a purchase confirmation with course access).
  • With data processors (see Section 5) — service providers acting on our behalf under written contracts.
  • With public authorities — competent bodies (courts, pre-trial investigation authorities, tax authorities) only on receipt of a lawful request or order.
  • Business transfers — if the company merges or restructures, data may be transferred to a new controller bound by this policy.

5. Data processors

We sign a GDPR-compliant data processing agreement (DPA) with every processor.

ProcessorPurposeData locationSafeguards
Stripe, Inc.Payment processing, fraud prevention (via the mr.lt platform)US / EUEU–US DPF; PCI DSS Level 1
Hetzner Online GmbHWebsite and database hostingEU (Germany)SCC, physical security
Brevo (Sendinblue)Email deliveryEU (Paris)GDPR DPA; data stays in the EU
Meta Platforms Ireland Ltd.Meta Pixel — conversion tracking, retargetingEU / USEU–US DPF; SCC; Meta GDPR DPA
Google Ireland Ltd.Google Analytics 4 — traffic statisticsEU / USEU–US DPF; IP anonymisation enabled
mr.lt (Rezervuok), UAB Elektroniniai SprendimaiOrder, booking and payment-processing platformEU (Lithuania)GDPR DPA

6. International data transfers

Some processors operate outside the European Economic Area (EEA). Such transfers are protected under Chapter V of the GDPR:

  • EU–US Data Privacy Framework (DPF) — applies to Stripe, Meta and Google.
  • Standard Contractual Clauses (SCC) — wherever the DPF does not apply; we use the SCC approved by the European Commission in 2021.
  • Additional technical measures — data encryption (TLS 1.2+), access restriction, regular security audits.

You may request copies of the specific SCCs by emailing we@mind.university.

7. Data retention periods

Data categoryRetention periodBasis
Account dataLength of the account + 3 yearsLegitimate interest
Purchase and payment data10 yearsAccounting law
Invoices10 yearsTax law (LT, UAE)
Technical logs12 monthsSecurity diagnostics
Marketing consentsUntil withdrawn + 3 years (as evidence)GDPR Art. 7(1)
Cookie data (analytics)13 monthsConsent
Deleted account30 days, then permanently erasedRight to be forgotten (GDPR Art. 17)

8. Your rights under the GDPR

As a data subject, you have the following rights, which you may exercise at any time:

  • Right of access (GDPR Art. 15) — obtain confirmation and a copy of your data.
  • Right to rectification (GDPR Art. 16) — correct inaccurate or complete incomplete data.
  • Right to erasure (GDPR Art. 17) — the "right to be forgotten"; does not apply where we are required by law to retain data.
  • Right to restriction of processing (GDPR Art. 18) — suspend active processing in certain cases.
  • Right to data portability (GDPR Art. 20) — receive your data in JSON or CSV format.
  • Right to object (GDPR Art. 21) — to processing based on legitimate interest or direct marketing.
  • Right to withdraw consent (GDPR Art. 7(3)) — at any time; this does not affect processing carried out before withdrawal.

Send requests by email to we@mind.university. We reply within 30 days (up to 90 days for complex cases, with advance notice). You also have the right to lodge a complaint with a supervisory authority — see Section 17.

Cookies are small text files stored on your device. We use them to keep the platform running, for your convenience, and for analytics.

Essential cookies (always on) — technically necessary for the platform to work. Without them you cannot log in, pay, or access course material.

CookiePurposeDuration
mdu_sessionKeeps you logged inSession, or up to 30 days if "Remember me" is checked
mdu_anonAnonymous visitor identity — guest cart and free-lesson progress12 months
mdu_localeRemembers your chosen language30 days
mdu_consentRemembers your cookie choice (see this section)6 months

Analytics cookies (consent required) — collect anonymous information about how visitors use the platform.

CookieSourceDuration
_ga, _ga_*Google Analytics 42 years
_gidGoogle Analytics24 hours

Marketing cookies (consent required) — used for targeted advertising on social networks and Google platforms.

CookieSourceDuration
_fbp, _fbcMeta Pixel3 months

On your first visit you will see a cookie consent banner. You can change your choice at any time via the "Cookie settings" link at the bottom of the page. You can opt out of Google Analytics via this tool; opt out of Meta advertising via Facebook's ad settings.

10. Platform security

We apply technical and organisational measures under GDPR Art. 32 to keep data secure:

  • Encryption — all data is transmitted over TLS 1.2+ (HTTPS); passwords are stored as a bcrypt hash.
  • Access control — only authorised staff can access sensitive data (least-privilege principle).
  • Regular backups — taken daily and stored in a separate geographic location.
  • Data breach management — if a breach could pose a risk to your rights, we will notify you within 72 hours (GDPR Art. 33–34).

We recommend using strong, unique passwords and enabling two-factor authentication.

11. Community content provisions

By publishing content on the platform (comments, questions, reviews), you retain copyright in your own work. However, you grant Multiverse LTD a non-exclusive licence to display that content for the operation of the platform.

Multiverse LTD may remove, without prior notice, content that infringes intellectual property rights, is defamatory, discriminatory or otherwise unlawful. If you see content that infringes your rights, contact we@mind.university — we respond within 5 business days.

12. Membership and subscriptions

When you purchase a membership or subscription, we process: the membership plan chosen, subscription start and end dates, auto-renewal status, a tokenised payment card identifier (a Stripe Token — never the card number), and payment history.

If you chose auto-renewal, we send an email reminder at least 3 days before each payment where the price or terms have changed. You may cancel your subscription at any time via your account settings.

13. Children's data

The platform is intended for people aged 16 and over. We do not knowingly collect data from younger individuals. If we learn that someone under 16 has created an account, we will delete it without delay. If you are a parent or guardian and believe your child has created an account, contact us: we@mind.university.

14. Automated decision-making

We do not currently carry out automated decisions as defined in GDPR Art. 22 that would produce legal or similarly significant effects for you. We use limited profiling for content personalisation (course recommendations) and newsletter segmentation — you can turn this off at any time via your account settings.

The platform may contain links to external websites. This privacy policy only applies to the mdu.lt platform. Third parties are solely responsible for their own privacy practices — we recommend reviewing their policies before submitting any personal data.

16. Updates to this policy

Minor changes (spelling, formatting, clarifications) — take effect immediately; the date at the top of the document is updated.

Material changes (new data categories, new controllers, new purposes) — we notify every active account holder by email at least 30 days before the effective date.

Older versions are archived and available on request. By continuing to use the platform after a change takes effect, you confirm that you have reviewed the new version.

17. Contacts and supervisory authority

General data protection contact:
we@mind.university
Response time: 30 days from receipt of your request.

Multiverse LTD
Trust Company Complex, Ajeltake Road, Ajeltake Island, Majuro, P.O. Box 1405

3T Media FZE
M1 Floor, Twin Towers, PO Box 4422, Fujairah, United Arab Emirates

Supervisory authority:
State Data Protection Inspectorate of Lithuania — vdai.lt · ada@vdai.lt

Journal

What you should know, before others do

Weekly insights. One article. One practice. No noise.