Use the minimum information needed for identity, payment, licensing, service delivery, lawful analytics and governance.
Sell personal data, store full card details, collect broker passwords or use profile photos for facial recognition.
Optional profile data, marketing and measurement choices, and requests to access, correct or delete eligible data.
This declaration reflects the UK GDPR and Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, together with applicable Privacy and Electronic Communications rules. The 2025 Act updates the UK framework; it does not replace the UK GDPR or Data Protection Act 2018.
Who controls your data
ICO registration: ZC237952. Registered 3 September 2026; certificate expires 2 September 2027. Download ICO registration certificate (PDF). Registration is not a certification of GDPR compliance or a product endorsement.
DPMINDS INTERNATIONAL LIMITED is the data controller for personal data described in this declaration. We are registered in England and Wales (company number 11739636), with a registered address at 10 Thompson Road, Tidworth, SP9 7GT, United Kingdom.
This declaration covers the My DPMINDS iOS application, www.dpminds.com, DPMINDS Academy, customer accounts, telephone and online support, licences, purchases, live learning and connected read-only decision-intelligence services. A third party may be a separate controller for information you provide directly to it—for example, Apple, Stripe or PayPal under its own privacy terms.
Personal data we collect
| Category | Examples | When collected |
|---|---|---|
| Account and contact | Name, email, generated username, country and verified phone number where you choose phone access | Account creation, sign-in, profile and support |
| Authentication and security | Account identifiers, authentication factors, My DPMINDS login time, recent authenticated heartbeat, session duration, sign-out or timeout time, Academy channel and short lease timing, security events and limited device or country-change risk signals. The member-presence register does not collect an IP address, authentication token, password, device fingerprint or precise location. | Email or phone codes, Sign in with Apple, Authenticator MFA, protected-platform presence, single-channel Academy enforcement and fraud prevention |
| Optional profile data | Professional headline, biography, profile photograph and voluntary accountability pledge | Only when you choose to complete a member profile |
| Purchases and fulfilment | Customer and billing details, country, order and payment references, product, price, licence, platform, terminal account number and broker-server name | Checkout, invoicing, refunds, licensing and support |
| Installer authorisation | Platform, linked entitlement, device and network hashes, authorisation expiry and use status | Secure browser authorisation and licence activation for Core and Edge |
| Protected package delivery | Linked order or entitlement, first successful download time, download count and channel, and package integrity fingerprint | When an authenticated customer downloads an entitled licence package from My DPMINDS, an order page or a protected email link |
| Academy and coaching | Entitlements, active web or iOS channel, short lease and attributable administrator release, lesson position, watched duration, qualifying progress, offline reconciliation events, quiz and examination results, notes, certificates, bookings, attendance and accessibility-feature events | When you use protected learning or coaching services |
| Mobile content protection | Learner-specific watermark, streaming-only delivery state and limited session or progress-integrity evidence; the current iOS release does not collect screenshot-attempt or screen-recording events | When you open protected Academy content in the iOS app |
| Live learning media | Room and attendance identifiers, participant display name, connection diagnostics, and camera, microphone or screen content you intentionally share | Only when you enter an enabled Live Intelligence Room |
| Support and communications | Support requests, feature suggestions, correspondence, notification delivery state and communication preferences | When you request help, contribute an idea or receive service messages |
| My DPMINDS member updates | Publisher display name and protected account identity, update text, general or selected-recipient audience, recipient account emails where a message is directed, publication and expiry times, optional video/voice/PDF metadata and integrity hashes, and archive events. For PDFs, visible rendered-page data is recognised locally in the authorised publisher's browser, corrected and confirmed by that person, and placed into a professional landscape member report. A market-opportunity PDF also contains publisher-confirmed symbol, timeframe, market time, entry, stop-loss and 1R/2R/3R profit-target values. PNG, JPG, JPEG and GIF screenshots are converted locally into a one-page PDF source before the same recognition and review. The authorised member copy includes the reviewed professional report followed by the original source pages as an audit evidence appendix. The extracted text is not retained as a separate database record; source and prepared-copy hashes are recorded, and successful publication requires temporary source chunks to be removed before the protected audit package is stored. Incomplete staging uploads cannot be completed after 30 minutes and are removed during subsequent protected-upload maintenance. | When an authorised administrator or approved trainer publishes a general or account-directed member update; ordinary member reading is not recorded as a content-view history, and neither is printing |
| Telephone and callback | Caller number where presented, last four digits, call time, duration, destination, outcome, triage category, department, callback preference, number-prefix country estimate, operational notes and unusual-pattern flags | When you call, request a verified callback or an authorised administrator records a verified call outcome |
| Decision intelligence | Approved read-only market snapshots, risk geometry, chart evidence and limited account-sizing information you connect | When you enable an entitled intelligence connection |
| Referral and campaign attribution | Referral code, campaign labels, landing path, pseudonymous session hash and linked commercial outcome | When you follow a tracked DPMINDS or approved affiliate link and optional measurement is enabled |
| Usage and diagnostics | Feature use, service events, sanitized route and error state, incident frequency and aggregate country-level public page counts | When you use the app or site |
| Internal traffic exclusion | A keyed one-way network token and administrator label; the source network address is used transiently to create the token and is not stored in the visitor-intelligence ledger | When the Principal Administrator elects to exclude a current DPMINDS-operated network from future public visitor counts |
DPMINDS does not store full payment-card details. Public geography measurement is aggregated and does not retain GPS, city, raw IP address, a device fingerprint or a named visitor. The website intelligence feed is read-only and does not place trades or control your broker account. Installed Core/Edge software may have separately enabled execution features; DPMINDS does not collect broker passwords through the website feed. Sanitized incident records exclude passwords, tokens, email addresses, query credentials and stack traces.
Software installation and licensing
Our Windows installers require explicit acceptance of the software terms before installation. An acceptance receipt is stored locally on your computer with the agreement identifier and hash, acceptance time, platform, installer version and acceptance method. A copy accompanies the installation receipt. This is separate from marketing consent and trading permissions. Preview mode does not write an acceptance receipt or perform installation. Local receipts remain until removed by you or through an authorised support process; they are not automatically uploaded as proof of identity.
Core (MT4) and Edge (MT5) installers contact DPMINDS to authorise an entitled installation. This uses the selected platform, linked order and customer identity, short-lived authorisation information and a device identifier derived from the computer name, Windows user name and operating-system version. The identifier is received for verification and stored as a hash. A hash derived from the connection address also supports secure matching and abuse prevention. Hashes are pseudonymous information, not anonymous data.
Authorisation expires after a short validity period. Expiry prevents reuse; it does not mean every related licensing or security record has been deleted. Records are managed under the retention purposes below. These functions support fulfilment of your licence and our legitimate interests in preventing unauthorised installation. They are separate from optional audience measurement and marketing.
The website intelligence connection is read-only and uses MT5. Retirement of the MT4 market-data bridge does not disconnect Core licensing. Any order-execution capability in installed software depends on the purchased feature and your terminal permissions; the website feed does not place orders.
Where personal data comes from
Most information comes directly from you. We may also receive or generate limited information from:
- Apple or another approved authentication provider when you choose that sign-in method;
- Stripe, PayPal or an app marketplace when it confirms a payment, refund or purchase status;
- your entitled MT5 read-only bridge when you deliberately enable a market-data connection; the MT4 website market-data bridge is retired, while Core licensing, activation and support connections continue;
- telephone network information and information you provide during a call or callback request;
- an approved DPMINDS referral link, limited to the attribution information described above; and
- our own security, service, learning, support and administrative records.
How and why we use personal data
| Purpose | Typical UK lawful basis |
|---|---|
| Create and secure your account; authenticate access; investigate abuse | Contract and legitimate interests in account and service security |
| Process purchases, invoices, licences, downloads, refunds and customer support | Contract and legal obligations |
| Confirm protected package delivery, prevent duplicate trial use and measure conversion only after a trial package is actually downloaded | Contract and legitimate interests in entitlement security and accurate service measurement |
| Consolidate records linked to your verified My DPMINDS identity for refunds, support, licensing, account security and lawful customer administration | Contract, legal obligations and legitimate interests in secure and accountable customer service |
| Provide Academy, synchronize web and iOS progress, validate offline learning, operate assessments and issue certificates | Contract |
| Protect Academy content, investigate capture-security events and preserve assessment integrity | Legitimate interests in content, service and assessment security, balanced against learner rights; contract where necessary to enforce the protected service |
| Triage calls, return verified callbacks, assign responsibility and protect staff and services from abusive or unusual calling patterns | Contract where support forms part of the service; legitimate interests in customer care, allocation, safety and abuse prevention |
| Maintain financial, tax, fraud-prevention and security records | Legal obligation and legitimate interests |
| Operate, troubleshoot and improve service reliability and accessibility | Legitimate interests, balanced against your rights |
| Deliver current My DPMINDS news, learning resources and service information; remove expired items from members; and preserve accountable publisher evidence | Contract for service delivery and legitimate interests in useful, secure and accountable member communications |
| Measure anonymous public demand, referral effectiveness and service improvement where optional measurement is enabled | Legitimate interests and applicable storage-access rules; you can switch this off below |
| Send optional news or promotional communications | Consent, which you may withdraw at any time |
Automated rules may prioritize operational errors, flag unusual call patterns or support triage, but a flag is not proof of abuse. Material action requires authorised human review. We do not use personal data to make solely automated decisions that produce legal or similarly significant effects.
Telephone support and verified callbacks
Telephone records help DPMINDS identify missed calls, route enquiries, manage callbacks, allocate departmental responsibility and protect staff and services. Caller numbers are masked in the management dashboard by default. An authorised reveal for operational follow-up is audit-recorded. Country and time-zone hints are inferred only from a telephone country code and are not precise location tracking.
DPMINDS does not infer that a caller is abusive from a flag alone. Blocking requires recorded evidence, explicit administrator action and review. We do not record the audio content of ordinary telephone calls through this dashboard. If call recording is introduced, callers will receive appropriate notice and this declaration will be updated.
Who receives personal data
We disclose only what is reasonably necessary to vetted providers supporting the service:
- Supabase — customer authentication, account security and related hosted services.
- Apple — Sign in with Apple, iOS distribution, App Store services and Apple-managed purchases where used.
- YouTube and Google — hosted Academy video playback and related technical delivery data. Their services may receive IP address, device and playback information under their own terms.
- Stripe — hosted checkout, Managed Payments, subscription administration, payment confirmation, fraud controls, tax handling and refunds where used.
- PayPal — hosted payment processing, payment confirmation, fraud controls and refunds.
- Postmark — transactional email delivery and delivery-status events.
- Cloudflare and OpenAI Sites — hosting, storage, availability and security for DPMINDS web services.
- Daily — private, short-lived live-video, audio and screen-sharing rooms when enabled. DPMINDS recording is off by default.
- Voipfone — business telephone connectivity, call routing and related network records for customer-care operations.
- Professional advisers and authorities — only when required for legal, tax, audit, claims or regulatory purposes.
We do not sell or rent personal data. We do not share it for third-party cross-app advertising or data-broker profiling.
International transfers
Some providers may process data outside the United Kingdom. Where UK adequacy regulations do not apply, DPMINDS uses appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful transfer mechanism, together with proportionate transfer assessment, security and access controls.
Cookies, browser storage and audience measurement
DPMINDS uses essential cookies or similar storage for sign-in, session security, purchases, service continuity and remembering settings. Optional public-site measurement uses browser session markers, a pseudonymous referral session and aggregate country-level counts. It does not store raw IP addresses, GPS, city or a device fingerprint in the DPMINDS visitor-intelligence ledger.
To keep operational reporting free from DPMINDS's own activity, the Principal Administrator may exclude a current company-operated network. DPMINDS derives a keyed one-way token from the request network address, stores only that token and an administrative audit record, and suppresses future visitor-intelligence events from the excluded network. The source network address is not retained in the exclusion register.
A device-local trial identifier supports proportionate duplicate-trial protection. It is an essential matching signal, not advertising storage and not proof that a trial was used. Trial consumption is recorded only after an authenticated customer successfully downloads the protected licence package.
Account security and service storage remain active. This control covers anonymous public-page, country-level and referral measurement on this browser.
Switching optional measurement off removes its DPMINDS browser markers and referral cookie from this browser and prevents future optional audience/referral events here. It does not remove essential security storage or alter anonymous aggregate counts already recorded, which cannot be linked back to a named visitor.
Mobile Academy continuity and protected learning
My DPMINDS uses one verified Academy record across the protected website and iOS app. We process lesson position, watched duration, qualifying progress, completion, assessment and certificate evidence so a learner can continue from the latest server-accepted point without losing valid credit. Where offline learning is available, the app keeps encrypted local state and queues events for validation when connectivity returns.
Protected views may display a learner-specific watermark and lesson video is streaming-only in the iOS app. The current App Review-compatible release does not claim to block screenshots or screen recording and does not collect screenshot-attempt or screen-recording events. DPMINDS does not activate the camera or microphone to monitor learners. No application can prevent a separate external camera filming a screen; recording and redistribution remain prohibited by the Academy rules and Customer Terms.
For assessment integrity, learner access is limited to one active Academy channel at a time: website or iOS. DPMINDS processes the active channel, last heartbeat, short lease expiry, concurrent-use denial and any attributable administrator release. Principal and delegated administrators are exempt only for authorised support, assurance and incident-response duties.
Full operating rules, learner safeguards and the review process are set out in the Mobile Academy, Progress, Assessment and Content Protection Policy.
How long we keep data
We keep personal data only for as long as needed for the purpose collected, including:
- active account, entitlement, learning and support records while the service or relationship continues;
- live-room access, invitation and administrator-audit records for safeguarding and service security; DPMINDS does not record room audio, video or screen content in the free pilot;
- security and diagnostic records for a limited period appropriate to investigation and service protection;
- My DPMINDS login, heartbeat, duration, sign-out and timeout evidence only while reasonably needed for account security, service administration, investigation or legal claims;
- protected package-download evidence while needed for entitlement delivery, customer support, proportionate abuse prevention, conversion accuracy or legal claims;
- telephone, callback, triage and blocking records only while reasonably needed for follow-up, service management, safety, disputes or legal claims, with block decisions subject to review;
- pseudonymous referral and campaign records while needed to validate attribution, prevent abuse and administer commission, with financial records retained as required by law;
- order, payment, invoice, refund, licence and tax records for the period required by UK law, normally six years after the relevant accounting period or transaction;
- optional profile content until you remove it, close your account or ask us to delete eligible information; and
- ordinary My DPMINDS updates, including selected-recipient details where used, in the member space until their publisher-set expiry; after expiry, the active database copy is removed and a restricted audit snapshot and any protected asset are retained only while reasonably needed for governance, disputes, security, legal claims or an applicable hold. The Principal Administrator may securely dispose of an archive and its stored media when no continuing retention need or hold applies; a minimal non-content disposal record is retained;
- certified Decision Intelligence reports under a strict latest-per-platform rule: one current MT4 report and one current MT5 report. When a replacement is accepted, the superseded platform report and its PIN become inaccessible immediately, its data is held for one hour, and then its report content and stored evidence are securely deleted unless preservation is legally required. Only a minimal non-content deletion receipt is retained;
- marketing preferences until withdrawal, plus a minimal suppression record where needed to respect that choice.
We may retain limited information longer where necessary to establish, exercise or defend legal claims, prevent fraud or comply with law. Data is then deleted, anonymised or securely restricted.
Your UK data-protection rights
Depending on the circumstances, you may ask us to:
- confirm whether we process your data and provide a copy;
- correct inaccurate or incomplete data;
- erase eligible data or restrict its processing;
- provide certain data in a portable format;
- object to processing based on legitimate interests or to direct marketing; and
- withdraw consent without affecting earlier lawful processing.
To exercise a right or request account deletion, email admin@team.dpminds.com from your registered address with the subject Privacy request. We may need to verify your identity and will conduct reasonable and proportionate searches for relevant information. Account deletion does not require us to erase records retained for tax, payment, security or legal purposes; those records will be restricted.
Your right to object: you may object at any time to direct marketing. You may also object to processing based on legitimate interests; we will stop unless we demonstrate compelling lawful grounds or the processing is needed for legal claims.
Children and financial suitability
My DPMINDS is a financial education and analytical service for people capable of making informed financial decisions. It is not directed to children. We do not knowingly solicit personal data from children under 13. A parent or guardian who believes a child has provided data should contact us so we can review and take appropriate action. Nothing in DPMINDS constitutes personal investment advice.
Security and your responsibilities
We use measures appropriate to the risk, including encrypted connections, access controls, least-privilege administration, one-time codes, optional or required multi-factor authentication, protected storage, masked telephone details, event monitoring and signed or time-limited links. No online system is entirely risk-free. Keep authentication codes and credentials private and notify us promptly of suspected misuse.
The cross-system Customer Master is restricted to the Principal Administrator using verified MFA and an administrator session. Every list, search and customer-record view is audit-recorded. It excludes payment-card numbers, passwords, authentication tokens, private anti-abuse hashes and protected package object keys.
Data-protection complaints
To make a data-protection complaint, email admin@team.dpminds.com with the subject Data protection complaint. Describe what happened, the DPMINDS service involved and the outcome you seek. Do not send passwords, authentication codes, full payment-card details or broker credentials.
We will acknowledge a data-protection complaint within 30 days, take appropriate steps to investigate it and communicate the outcome without undue delay. We may ask for proportionate information to verify identity or locate relevant records. You may complain to the UK Information Commissioner's Office at any time at ico.org.uk/make-a-complaint.
Contact and policy changes
DPMINDS INTERNATIONAL LIMITED10 Thompson Road, Tidworth, SP9 7GT, United Kingdom
Privacy email: admin@team.dpminds.com
We may update this declaration when services, providers or law change. Material changes will be clearly posted, and the effective date above will be updated.
