MINDKODEX · Privacy Notice
Privacy Notice
This notice explains exactly what personal data we use, why, who receives it, how long it is needed and how you can exercise your rights.
Controller and contact
The controller for the MINDKODEX platform and content is SEVK s. r. o., Palárikova 193/26, 018 41 Dubnica nad Váhom, Slovak Republic, Company ID 56 122 292. Send data-protection requests to mindkodex@mindkodex.com.
For Stripe Managed Payments, the relevant Stripe entity acts as a separate Merchant of Record and controller for payment, tax, invoicing, refunds and transaction support, as described in Checkout.
Data categories and sources
- Account: email, internal user ID, language, session data and security events.
- Membership and course: access, order and subscription status, progress, verification answers, highlights and local notes; we do not see full card data.
- Support and withdrawal: email, subject, messages, reference, order and data needed to handle the request.
- Video story: optional title, text, email, consents, attachments, review status, working Slovak translation and admin notes.
- Optional AI cases: text, response settings and user-selected screenshots only if the feature is active and knowingly used.
- Traffic and performance: Cloudflare Web Analytics provides aggregate page views, referrers, approximate country, browser and device type, and performance metrics. Our API additionally counts unique visitors using a monthly rotating, non-reversible HMAC pseudonym derived server-side from the IP address. The raw IP is not stored in the analytics database. We use no analytics cookie, advertising identifier or cross-site tracking.
- Technical data: IP in transit, time, request path, device, error and security logs. For daily support/story limits we store a separate daily HMAC pseudonym, not the raw IP.
We obtain data from you, your use of the service and payment or infrastructure providers as needed for the selected function.
Purposes and legal bases
- Contract and pre-contract steps: registration, access, course, progress, support, withdrawal and membership management.
- Legal obligation: accounting, tax, consumer duties, rights requests and lawful authority requests.
- Legitimate interests: service protection, abuse prevention, diagnostics, aggregate traffic and performance measurement, audit of admin access and legal claims. You can object to this processing.
- Consent: possible anonymised publication of a submitted story, voluntary attachments and future marketing or measurement that stores a non-essential identifier on a device. Consent can be withdrawn for the future.
Data needed for an account, payment or legal request are required for that purpose. Optional fields are marked and do not prevent basic membership.
Stories, support, translations and AI
A story is first stored in private admin. Submission does not guarantee selection or publication. Human review and anonymisation of names and identifiers occur before publication. Attachments stay private and are used only for review. You may withdraw publication consent before publication by emailing the reference.
Support and story messages in EN/DE/ES may be translated server-side into Slovak with Cloudflare Workers AI so the owner can handle them. The translation is an aid; a human decides replies, selection and publication. We do not use private messages, case names or attachments for advertising audiences.
If the optional AI guide is activated, we will disclose its exact route, provider and retention settings before first use. Merely visiting the website does not send a personal AI case to OpenAI.
Recipients and providers
| Recipient | Role | When |
|---|---|---|
| Cloudflare | Website, API, security, technical logs, cookie-free Web Analytics and approved server-side translations. | On a visit or API use. |
| Supabase | Authentication, database and private storage. | When using an account, course, support or story. |
| Bunny Stream | Protected video playback. | After starting a video. |
| Resend | Operational, support and transactional email. | For email communication. |
| Stripe Managed Payments | Checkout, payment, tax, invoices, subscriptions, refunds and transaction support. | After opening Checkout and for the transaction. |
| OpenAI API | Optional AI-guide responses if that feature is activated. | Only after expressly sending an AI request. |
Professional advisers or authorities receive data only where legally necessary. We do not sell personal data.
Transfers outside the EEA
Some providers or subprocessors may process data outside the European Economic Area. GDPR transfer mechanisms are used, including an adequacy decision, the EU–US Data Privacy Framework for eligible recipients, or Standard Contractual Clauses with appropriate supplementary measures. Current details are available from each provider or from us on request.
Retention
- account, progress and private notes while the account exists and then until secure deletion, except data needed for law or claims;
- orders, receipts and transactions for statutory accounting, tax and complaint periods;
- support, withdrawals and complaints until handled and then for a proportionate follow-up and claims period; an email thread moved to trash is permanently deleted after 30 days;
- stories and attachments until selection, consent withdrawal or as needed to document publication and rights; unnecessary attachments are removed;
- monthly analytics pseudonyms for a proportionate period needed to compare traffic; they cannot be linked across calendar months;
- daily rate-limit pseudonyms only for the short anti-abuse period;
- security and audit logs proportionate to risk and proof of authorised action.
Data may be restricted for longer during a dispute, suspected fraud, legal duty or preservation hold. It is deleted or irreversibly anonymised when that reason ends.
Your rights
Subject to the GDPR, you can request access, a copy, correction, erasure, restriction and portability, and object to legitimate-interest processing. You can withdraw consent at any time without affecting prior lawful processing. We normally respond within one month and may reasonably verify identity.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects. You can complain to the Office for Personal Data Protection of the Slovak Republic or the competent authority where you habitually reside.
Security, children and changes
The service is for adults aged 18 or over. We use encrypted transport, role separation, private storage, short-lived attachment links, rate limits and audits of sensitive admin access. No internet system is absolutely secure.
We publish material changes on the website and, depending on impact, notify them by email. The date above identifies the current version.