1. Who we are and how to contact us
Mind University (mdu.lt) is an online education platform offering courses, memberships, digital products and an educational community. The platform is run by three data controllers, each responsible for your personal data within their own area of activity.
Multiverse LTD
Trust Company Complex, Ajeltake Road, Ajeltake Island, Majuro, P.O. Box 1405, Marshall Islands
Area of responsibility: platform operation, user accounts, access-rights administration, community content. Multiverse LTD is also the owner and manufacturer of physical products under the "Biomind" brand.
3T Media FZE
M1 Floor, Twin Towers, PO Box 4422, Fujairah, United Arab Emirates
Reg./licence no. 20352/2026 (not VAT-registered)
Area of responsibility: order processing, invoicing, payments, delivery, customer support.
General contact: we@mind.university. We reply within 30 calendar days of receiving your request.
2. What data we collect
We only collect the data that is necessary for a specific purpose.
2.1 Account data
First and last name, email address, chosen username, password hash (we never store the original password), account creation date, last login timestamp.
2.2 Technical data
IP address, browser type and version, operating system, device identifier, page-view logs, session length, error reports. This data is collected automatically every time you visit the platform.
2.3 Community content
Comments, posts in the community area, review forms, Q&A material, course-completion records, progress data. Handling of this content is described in more detail in Section 11.
2.4 Purchase and payment data
Order number, products or courses purchased, payment amount and currency, payment method (card type, last 4 digits), invoice data, transaction date and status. Full card details are only ever handled inside the payment processor's (Stripe) own infrastructure — we never store them and have no access to them.
2.5 Communication data
Emails and enquiries you send us; automatic system messages (registration confirmation, password reset, order confirmation); marketing newsletters, if you consented.
2.6 Cookie and tracking data
Described in full in Section 9 (Cookie Policy).
We deliberately do not collect special-category data (e.g. health, religious belief or biometric data), unless you voluntarily provide it in community content. Such data is only processed with your explicit consent (GDPR Art. 9(2)(a)).
3. Why we process data and the legal basis
Every processing purpose has a clear legal basis under the GDPR (2016/679).
| Processing purpose | Legal basis (GDPR) | Responsible controller |
|---|---|---|
| Creating and administering accounts | Art. 6(1)(b) – Performance of a contract | Multiverse LTD |
| Providing courses and content | Art. 6(1)(b) – Performance of a contract | Multiverse LTD |
| Payment processing | Art. 6(1)(b) – Performance of a contract | 3T Media FZE |
| Invoicing and accounting | Art. 6(1)(c) – Legal obligation | 3T Media FZE |
| Warehousing and shipping of goods | Art. 6(1)(b) – Performance of a contract | 3T Media FZE |
| Platform security and fraud prevention | Art. 6(1)(f) – Legitimate interest | Multiverse LTD |
| Technical logs and fault diagnostics | Art. 6(1)(f) – Legitimate interest | Multiverse LTD |
| Marketing newsletters | Art. 6(1)(a) – Consent | Multiverse LTD / 3T Media FZE |
| Analytics and statistics (aggregated) | Art. 6(1)(f) – Legitimate interest | Multiverse LTD |
| Cookies — analytics and marketing | Art. 6(1)(a) – Consent | Multiverse LTD |
| Defence of legal claims | Art. 6(1)(f) – Legitimate interest | All three controllers |
Where processing relies on legitimate interest, we carry out a balancing test. You may request a summary of it by emailing we@mind.university.
4. Data recipients and sharing
We never sell your data or exchange it for commercial purposes. We only share data in the following cases:
- Between the three controllers — only the data necessary for coordinated service delivery (e.g. matching a purchase confirmation with course access).
- With data processors (see Section 5) — service providers acting on our behalf under written contracts.
- With public authorities — competent bodies (courts, pre-trial investigation authorities, tax authorities) only on receipt of a lawful request or order.
- Business transfers — if the company merges or restructures, data may be transferred to a new controller bound by this policy.
5. Data processors
We sign a GDPR-compliant data processing agreement (DPA) with every processor.
| Processor | Purpose | Data location | Safeguards |
|---|---|---|---|
| Stripe, Inc. | Payment processing, fraud prevention (via the mr.lt platform) | US / EU | EU–US DPF; PCI DSS Level 1 |
| Hetzner Online GmbH | Website and database hosting | EU (Germany) | SCC, physical security |
| Brevo (Sendinblue) | Email delivery | EU (Paris) | GDPR DPA; data stays in the EU |
| Meta Platforms Ireland Ltd. | Meta Pixel — conversion tracking, retargeting | EU / US | EU–US DPF; SCC; Meta GDPR DPA |
| Google Ireland Ltd. | Google Analytics 4 — traffic statistics | EU / US | EU–US DPF; IP anonymisation enabled |
| mr.lt (Rezervuok), UAB Elektroniniai Sprendimai | Order, booking and payment-processing platform | EU (Lithuania) | GDPR DPA |
6. International data transfers
Some processors operate outside the European Economic Area (EEA). Such transfers are protected under Chapter V of the GDPR:
- EU–US Data Privacy Framework (DPF) — applies to Stripe, Meta and Google.
- Standard Contractual Clauses (SCC) — wherever the DPF does not apply; we use the SCC approved by the European Commission in 2021.
- Additional technical measures — data encryption (TLS 1.2+), access restriction, regular security audits.
You may request copies of the specific SCCs by emailing we@mind.university.
7. Data retention periods
| Data category | Retention period | Basis |
|---|---|---|
| Account data | Length of the account + 3 years | Legitimate interest |
| Purchase and payment data | 10 years | Accounting law |
| Invoices | 10 years | Tax law (LT, UAE) |
| Technical logs | 12 months | Security diagnostics |
| Marketing consents | Until withdrawn + 3 years (as evidence) | GDPR Art. 7(1) |
| Cookie data (analytics) | 13 months | Consent |
| Deleted account | 30 days, then permanently erased | Right to be forgotten (GDPR Art. 17) |
8. Your rights under the GDPR
As a data subject, you have the following rights, which you may exercise at any time:
- Right of access (GDPR Art. 15) — obtain confirmation and a copy of your data.
- Right to rectification (GDPR Art. 16) — correct inaccurate or complete incomplete data.
- Right to erasure (GDPR Art. 17) — the "right to be forgotten"; does not apply where we are required by law to retain data.
- Right to restriction of processing (GDPR Art. 18) — suspend active processing in certain cases.
- Right to data portability (GDPR Art. 20) — receive your data in JSON or CSV format.
- Right to object (GDPR Art. 21) — to processing based on legitimate interest or direct marketing.
- Right to withdraw consent (GDPR Art. 7(3)) — at any time; this does not affect processing carried out before withdrawal.
Send requests by email to we@mind.university. We reply within 30 days (up to 90 days for complex cases, with advance notice). You also have the right to lodge a complaint with a supervisory authority — see Section 17.
9. Cookie policy
Cookies are small text files stored on your device. We use them to keep the platform running, for your convenience, and for analytics.
Essential cookies (always on) — technically necessary for the platform to work. Without them you cannot log in, pay, or access course material.
| Cookie | Purpose | Duration |
|---|---|---|
| mdu_session | Keeps you logged in | Session, or up to 30 days if "Remember me" is checked |
| mdu_anon | Anonymous visitor identity — guest cart and free-lesson progress | 12 months |
| mdu_locale | Remembers your chosen language | 30 days |
| mdu_consent | Remembers your cookie choice (see this section) | 6 months |
Analytics cookies (consent required) — collect anonymous information about how visitors use the platform.
| Cookie | Source | Duration |
|---|---|---|
| _ga, _ga_* | Google Analytics 4 | 2 years |
| _gid | Google Analytics | 24 hours |
Marketing cookies (consent required) — used for targeted advertising on social networks and Google platforms.
| Cookie | Source | Duration |
|---|---|---|
| _fbp, _fbc | Meta Pixel | 3 months |
On your first visit you will see a cookie consent banner. You can change your choice at any time via the "Cookie settings" link at the bottom of the page. You can opt out of Google Analytics via this tool; opt out of Meta advertising via Facebook's ad settings.
10. Platform security
We apply technical and organisational measures under GDPR Art. 32 to keep data secure:
- Encryption — all data is transmitted over TLS 1.2+ (HTTPS); passwords are stored as a bcrypt hash.
- Access control — only authorised staff can access sensitive data (least-privilege principle).
- Regular backups — taken daily and stored in a separate geographic location.
- Data breach management — if a breach could pose a risk to your rights, we will notify you within 72 hours (GDPR Art. 33–34).
We recommend using strong, unique passwords and enabling two-factor authentication.
11. Community content provisions
By publishing content on the platform (comments, questions, reviews), you retain copyright in your own work. However, you grant Multiverse LTD a non-exclusive licence to display that content for the operation of the platform.
Multiverse LTD may remove, without prior notice, content that infringes intellectual property rights, is defamatory, discriminatory or otherwise unlawful. If you see content that infringes your rights, contact we@mind.university — we respond within 5 business days.
12. Membership and subscriptions
When you purchase a membership or subscription, we process: the membership plan chosen, subscription start and end dates, auto-renewal status, a tokenised payment card identifier (a Stripe Token — never the card number), and payment history.
If you chose auto-renewal, we send an email reminder at least 3 days before each payment where the price or terms have changed. You may cancel your subscription at any time via your account settings.
13. Children's data
The platform is intended for people aged 16 and over. We do not knowingly collect data from younger individuals. If we learn that someone under 16 has created an account, we will delete it without delay. If you are a parent or guardian and believe your child has created an account, contact us: we@mind.university.
14. Automated decision-making
We do not currently carry out automated decisions as defined in GDPR Art. 22 that would produce legal or similarly significant effects for you. We use limited profiling for content personalisation (course recommendations) and newsletter segmentation — you can turn this off at any time via your account settings.
15. Links to third-party websites
The platform may contain links to external websites. This privacy policy only applies to the mdu.lt platform. Third parties are solely responsible for their own privacy practices — we recommend reviewing their policies before submitting any personal data.
16. Updates to this policy
Minor changes (spelling, formatting, clarifications) — take effect immediately; the date at the top of the document is updated.
Material changes (new data categories, new controllers, new purposes) — we notify every active account holder by email at least 30 days before the effective date.
Older versions are archived and available on request. By continuing to use the platform after a change takes effect, you confirm that you have reviewed the new version.
17. Contacts and supervisory authority
General data protection contact:
we@mind.university
Response time: 30 days from receipt of your request.
Multiverse LTD
Trust Company Complex, Ajeltake Road, Ajeltake Island, Majuro, P.O. Box 1405
3T Media FZE
M1 Floor, Twin Towers, PO Box 4422, Fujairah, United Arab Emirates
Supervisory authority:
State Data Protection Inspectorate of Lithuania — vdai.lt · ada@vdai.lt