Use the minimum information needed for identity, payment, licensing, service delivery, lawful analytics and governance.
Sell personal data, store full card details, collect broker passwords or use profile photos for facial recognition.
Optional profile data, marketing and measurement choices, and requests to access, correct or delete eligible data.
This declaration reflects the UK GDPR and Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, together with applicable Privacy and Electronic Communications rules. The 2025 Act updates the UK framework; it does not replace the UK GDPR or Data Protection Act 2018.
Who controls your data
DPMINDS INTERNATIONAL LIMITED is the data controller for personal data described in this declaration. We are registered in England and Wales (company number 11739636), with a registered address at 10 Thompson Road, Tidworth, SP9 7GT, United Kingdom.
This declaration covers the My DPMINDS iOS application, www.dpminds.com, DPMINDS Academy, customer accounts, telephone and online support, licences, purchases, live learning and connected read-only decision-intelligence services. A third party may be a separate controller for information you provide directly to it—for example, Apple or PayPal under its own privacy terms.
Personal data we collect
| Category | Examples | When collected |
|---|---|---|
| Account and contact | Name, email, generated username, country and verified phone number where you choose phone access | Account creation, sign-in, profile and support |
| Authentication and security | Account identifiers, authentication factors, session data, security events and limited device or country-change risk signals | Email or phone codes, Sign in with Apple, Authenticator MFA and fraud prevention |
| Optional profile data | Professional headline, biography, profile photograph and voluntary accountability pledge | Only when you choose to complete a member profile |
| Purchases and fulfilment | Customer and billing details, country, order and payment references, product, price, licence, platform, terminal account number and broker-server name | Checkout, invoicing, refunds, licensing and support |
| Academy and coaching | Entitlements, lesson and video progress, quiz and examination results, notes, certificates, bookings and accessibility-feature events | When you use protected learning or coaching services |
| Live learning media | Room and attendance identifiers, participant display name, connection diagnostics, and camera, microphone or screen content you intentionally share | Only when you enter an enabled Live Intelligence Room |
| Support and communications | Support requests, feature suggestions, correspondence, notification delivery state and communication preferences | When you request help, contribute an idea or receive service messages |
| Telephone and callback | Caller number where presented, last four digits, call time, duration, destination, outcome, triage category, department, callback preference, number-prefix country estimate, operational notes and unusual-pattern flags | When you call, request a verified callback or an authorised administrator records a verified call outcome |
| Decision intelligence | Approved read-only market snapshots, risk geometry, chart evidence and limited account-sizing information you connect | When you enable an entitled intelligence connection |
| Referral and campaign attribution | Referral code, campaign labels, landing path, pseudonymous session hash and linked commercial outcome | When you follow a tracked DPMINDS or approved affiliate link and optional measurement is enabled |
| Usage and diagnostics | Feature use, service events, sanitized route and error state, incident frequency and aggregate country-level public page counts | When you use the app or site |
DPMINDS does not store full payment-card details. Public geography measurement is aggregated and does not retain GPS, city, raw IP address, a device fingerprint or a named visitor. Connected intelligence is read-only: DPMINDS does not collect broker passwords, place trades or control your broker account. Sanitized incident records exclude passwords, tokens, email addresses, query credentials and stack traces.
Where personal data comes from
Most information comes directly from you. We may also receive or generate limited information from:
- Apple or another approved authentication provider when you choose that sign-in method;
- PayPal or an app marketplace when it confirms a payment, refund or purchase status;
- your entitled MT4 or MT5 read-only bridge when you deliberately enable a connection;
- telephone network information and information you provide during a call or callback request;
- an approved DPMINDS referral link, limited to the attribution information described above; and
- our own security, service, learning, support and administrative records.
How and why we use personal data
| Purpose | Typical UK lawful basis |
|---|---|
| Create and secure your account; authenticate access; investigate abuse | Contract and legitimate interests in account and service security |
| Process purchases, invoices, licences, downloads, refunds and customer support | Contract and legal obligations |
| Provide Academy, coaching, certificates, account services and read-only decision intelligence | Contract |
| Triage calls, return verified callbacks, assign responsibility and protect staff and services from abusive or unusual calling patterns | Contract where support forms part of the service; legitimate interests in customer care, allocation, safety and abuse prevention |
| Maintain financial, tax, fraud-prevention and security records | Legal obligation and legitimate interests |
| Operate, troubleshoot and improve service reliability and accessibility | Legitimate interests, balanced against your rights |
| Measure anonymous public demand, referral effectiveness and service improvement where optional measurement is enabled | Legitimate interests and applicable storage-access rules; you can switch this off below |
| Send optional news or promotional communications | Consent, which you may withdraw at any time |
Automated rules may prioritize operational errors, flag unusual call patterns or support triage, but a flag is not proof of abuse. Material action requires authorised human review. We do not use personal data to make solely automated decisions that produce legal or similarly significant effects.
Telephone support and verified callbacks
Telephone records help DPMINDS identify missed calls, route enquiries, manage callbacks, allocate departmental responsibility and protect staff and services. Caller numbers are masked in the management dashboard by default. An authorised reveal for operational follow-up is audit-recorded. Country and time-zone hints are inferred only from a telephone country code and are not precise location tracking.
DPMINDS does not infer that a caller is abusive from a flag alone. Blocking requires recorded evidence, explicit administrator action and review. We do not record the audio content of ordinary telephone calls through this dashboard. If call recording is introduced, callers will receive appropriate notice and this declaration will be updated.
Who receives personal data
We disclose only what is reasonably necessary to vetted providers supporting the service:
- Supabase — customer authentication, account security and related hosted services.
- Apple — Sign in with Apple, iOS distribution, App Store services and Apple-managed purchases where used.
- PayPal — hosted payment processing, payment confirmation, fraud controls and refunds.
- Postmark — transactional email delivery and delivery-status events.
- Cloudflare and OpenAI Sites — hosting, storage, availability and security for DPMINDS web services.
- Daily — private, short-lived live-video, audio and screen-sharing rooms when enabled. DPMINDS recording is off by default.
- Voipfone — business telephone connectivity, call routing and related network records for customer-care operations.
- Professional advisers and authorities — only when required for legal, tax, audit, claims or regulatory purposes.
We do not sell or rent personal data. We do not share it for third-party cross-app advertising or data-broker profiling.
International transfers
Some providers may process data outside the United Kingdom. Where UK adequacy regulations do not apply, DPMINDS uses appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful transfer mechanism, together with proportionate transfer assessment, security and access controls.
Cookies, browser storage and audience measurement
DPMINDS uses essential cookies or similar storage for sign-in, session security, purchases, service continuity and remembering settings. Optional public-site measurement uses browser session markers, a pseudonymous referral session and aggregate country-level counts. It does not store raw IP addresses, GPS, city or a device fingerprint in the DPMINDS visitor-intelligence ledger.
Account security and service storage remain active. This control covers anonymous public-page, country-level and referral measurement on this browser.
Switching optional measurement off removes its DPMINDS browser markers and referral cookie from this browser and prevents future optional audience/referral events here. It does not remove essential security storage or alter anonymous aggregate counts already recorded, which cannot be linked back to a named visitor.
How long we keep data
We keep personal data only for as long as needed for the purpose collected, including:
- active account, entitlement, learning and support records while the service or relationship continues;
- live-room access, invitation and administrator-audit records for safeguarding and service security; DPMINDS does not record room audio, video or screen content in the free pilot;
- security and diagnostic records for a limited period appropriate to investigation and service protection;
- telephone, callback, triage and blocking records only while reasonably needed for follow-up, service management, safety, disputes or legal claims, with block decisions subject to review;
- pseudonymous referral and campaign records while needed to validate attribution, prevent abuse and administer commission, with financial records retained as required by law;
- order, payment, invoice, refund, licence and tax records for the period required by UK law, normally six years after the relevant accounting period or transaction;
- optional profile content until you remove it, close your account or ask us to delete eligible information; and
- marketing preferences until withdrawal, plus a minimal suppression record where needed to respect that choice.
We may retain limited information longer where necessary to establish, exercise or defend legal claims, prevent fraud or comply with law. Data is then deleted, anonymised or securely restricted.
Your UK data-protection rights
Depending on the circumstances, you may ask us to:
- confirm whether we process your data and provide a copy;
- correct inaccurate or incomplete data;
- erase eligible data or restrict its processing;
- provide certain data in a portable format;
- object to processing based on legitimate interests or to direct marketing; and
- withdraw consent without affecting earlier lawful processing.
To exercise a right or request account deletion, email admin@team.dpminds.com from your registered address with the subject Privacy request. We may need to verify your identity and will conduct reasonable and proportionate searches for relevant information. Account deletion does not require us to erase records retained for tax, payment, security or legal purposes; those records will be restricted.
Your right to object: you may object at any time to direct marketing. You may also object to processing based on legitimate interests; we will stop unless we demonstrate compelling lawful grounds or the processing is needed for legal claims.
Children and financial suitability
My DPMINDS is a financial education and analytical service for people capable of making informed financial decisions. It is not directed to children. We do not knowingly solicit personal data from children under 13. A parent or guardian who believes a child has provided data should contact us so we can review and take appropriate action. Nothing in DPMINDS constitutes personal investment advice.
Security and your responsibilities
We use measures appropriate to the risk, including encrypted connections, access controls, least-privilege administration, one-time codes, optional or required multi-factor authentication, protected storage, masked telephone details, event monitoring and signed or time-limited links. No online system is entirely risk-free. Keep authentication codes and credentials private and notify us promptly of suspected misuse.
Data-protection complaints
To make a data-protection complaint, email admin@team.dpminds.com with the subject Data protection complaint. Describe what happened, the DPMINDS service involved and the outcome you seek. Do not send passwords, authentication codes, full payment-card details or broker credentials.
We will acknowledge a data-protection complaint within 30 days, take appropriate steps to investigate it and communicate the outcome without undue delay. We may ask for proportionate information to verify identity or locate relevant records. You may complain to the UK Information Commissioner's Office at any time at ico.org.uk/make-a-complaint.
Contact and policy changes
DPMINDS INTERNATIONAL LIMITED10 Thompson Road, Tidworth, SP9 7GT, United Kingdom
Privacy email: admin@team.dpminds.com
We may update this declaration when services, providers or law change. Material changes will be clearly posted, and the effective date above will be updated.
