1. Who Is the Data Controller?
NEXAPHAZE LTD, company number 15607406, registered at Flat 15, Chancery House, Lowood Street, London, England, E1 0BU (trading as Mindgrads) is the data controller for all personal data processed through the Mindgrads platform.
For all privacy enquiries, contact: privacy@mindgrads.com.
2. What Data We Collect
We collect and process the following categories of personal data:
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email, password hash | You, at registration |
| Usage data | Login times, features accessed, credit usage | Automatic collection |
| Document content | Assignment briefs, uploaded PDFs, notes, drafts | You, during workspace use |
| Billing data | Payment method tokens, subscription status | Stripe (we do not store card numbers) |
| Communications | Support emails, contact form messages | You, via contact channels |
| Technical data | IP address, browser type, device info, cookies | Automatic collection |
3. Lawful Basis for Processing
Under UK GDPR Article 6, we process your data on the following lawful bases:
| Processing Activity | Lawful Basis | Reference |
|---|---|---|
| Account registration and service delivery | Performance of a contract | Article 6(1)(b) |
| AI feature processing (document analysis, generation) | Performance of a contract | Article 6(1)(b) |
| Billing and payment processing | Performance of a contract | Article 6(1)(b) |
| Service improvement and analytics | Legitimate interests | Article 6(1)(f) |
| Marketing communications (opt-in only) | Consent | Article 6(1)(a) |
| Legal compliance and fraud prevention | Legal obligation | Article 6(1)(c) |
| Support and complaint handling | Legitimate interests | Article 6(1)(f) |
4. AI Data Processing and Third-Party Providers
When you use AI-powered features on Mindgrads, your document content and prompts are transmitted to third-party AI providers for processing. We currently use:
- Anthropic (Claude models) — anthropic.com
- OpenAI (GPT models) — openai.com
- Google (Gemini models and search APIs) — google.com
- Perplexity (Sonar web research / topic source discovery) — perplexity.ai. Used only when you explicitly opt in to topic web discovery or related research features.
AI requests are routed through the Vercel AI Gateway where configured. Mindgrads does not use your content to train, fine-tune, or improve any model of our own. For the third-party providers listed above, the provider, model, region, retention and model-training settings are reviewed before that provider is enabled, and the transfer mechanism and data processing agreement for each are recorded in our subprocessor register. We do not represent a provider as contractually restricted from training on your content unless we hold current contractual and configuration evidence for it — see our AI Transparency Notice. If you would like the evidence held for a specific provider, ask us at privacy@mindgrads.com.
Grounded assignment Q&A uses only sources you attach to the project (uploaded documents and imported URLs). It does not perform open-web search. Optional topic web discovery sends your topic query to Perplexity solely to suggest HTTPS source URLs for you to review and import.
5. International Data Transfers
Your account data and uploaded files are stored in the European Union (Frankfurt). The application servers that read and write that data run in the United States (Northern Virginia), so a transfer outside the UK and EEA takes place whenever you use the platform — not only when an AI feature is used. Our hosting provider is certified under the EU–US Data Privacy Framework and its UK Extension, and we additionally rely on the Standard Contractual Clauses set out below.
Anthropic, OpenAI, Google, and Perplexity are US-based companies. Processing your data through these services involves transferring personal data outside the UK. Depending on the provider, we rely on one of the following mechanisms recognised under UK GDPR Chapter V:
- The UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses
- EU Standard Contractual Clauses (SCCs) where a provider offers these rather than an IDTA
- An adequacy regulation, where the recipient is covered by one — including the UK Extension to the EU–US Data Privacy Framework for providers certified under it
The mechanism relied on for each provider, together with the data processing agreement and the region in which processing takes place, is recorded in our subprocessor register. A provider whose transfer mechanism has not been verified against that register is not enabled for your data.
You may request the specific mechanism and supporting documentation for any named provider, and a copy of our transfer risk assessment, by contacting privacy@mindgrads.com.
7. Data Retention
We retain your personal data for as long as necessary to provide the service and comply with our legal obligations:
| Data Category | Retention Period |
|---|---|
| Account data (active) | Retained for the duration of your account |
| Document content and workspaces | Retained while your account is active. Deleted when you delete the project, or immediately when you delete your account |
| Uploaded files | Given an automatic expiry set by your plan — 7 days (Free), 30 days (Pro Student), 90 days (Pro Plus Research). Access ends at expiry and the stored file is removed by a scheduled sweep shortly after |
| Billing records | 7 years from transaction (UK tax law obligation) |
| Support communications | Target of 3 years from resolution |
| Analytics and usage data | Target of 24 months, then aggregated anonymously |
| Sign-in and security records | Sign-in history 12 months. Records of administrative actions on an account — a role change, an MFA reset, a plan change made by staff — 6 years, so they remain available for as long as a related claim could be brought. Routine internal change logs 90 days |
| Deleted account data | Erased from our live systems at the point of your request, not on a delay |
When you delete your account, your documents, workspaces, AI conversation history and uploaded files are erased from our live systems as part of that request rather than queued for later deletion, and your profile record is anonymised. Your email address is retained only where we are required to keep it — principally on billing records we must hold for seven years under UK tax law.
One honest caveat: an operational backup or export taken before you deleted your account may still contain a copy until that backup is rotated out. We do not restore deleted accounts from backups, and we will act on an erasure request against retained backups where it is technically feasible to do so. Ask us at privacy@mindgrads.com if you need this confirmed for your own data.
8. Your Rights Under UK GDPR
You have the following rights in relation to your personal data:
- Right of Access — request a copy of your personal data (Subject Access Request)
- Right to Rectification — ask us to correct inaccurate or incomplete data
- Right to Erasure — request deletion of your data ("right to be forgotten"), subject to legal retention obligations
- Right to Restriction — ask us to restrict processing of your data in certain circumstances
- Right to Data Portability — receive your data in a structured, machine-readable format
- Right to Object — object to processing based on legitimate interests or for direct marketing
- Rights relating to automated decision-making — we do not use fully automated decision-making that produces legal or similarly significant effects without human oversight
To exercise any of these rights, contact privacy@mindgrads.com. We will respond within 30 days (extendable to 90 days for complex requests, with notice).
9. Children and Younger Students
Mindgrads supports students across a range of education levels, including pre-university study. We want to be straightforward about what that means for younger users.
- We rely on performance of a contract rather than consent as the lawful basis for providing the core service, so the age at which a child can consent for themselves to an information society service (13 in the UK, under section 9 of the Data Protection Act 2018) is not what gates ordinary use of the workspace. It does gate optional, consent-based processing — marketing emails and analytics cookies — which we do not target at children.
- Where a user is below the age at which they can enter into a contract for themselves, the account should be set up and supervised by a parent, guardian, teacher, or school.
- We do not currently operate an age-verification mechanism. We do not ask for a date of birth at registration, so we cannot confirm a user's age, and the education level a user selects is not treated as proof of age.
- We do not knowingly use a child's personal data for profiling, behavioural advertising, or any purpose beyond delivering the academic features they are using.
If you are a parent, guardian, or school and you believe a child's personal data has been provided to us without an appropriate basis, contact privacy@mindgrads.com and we will delete the account and its content. You do not need to hold the account to make that request.
We are actively reviewing our position on age assurance and children's data, including against the ICO's Age Appropriate Design Code. This section will be updated as that review concludes, and material changes will be notified as set out in section 12.
11. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include:
- Encrypted storage and transmission (TLS/HTTPS)
- Row-level access controls and role-based permissions
- Regular security assessments and monitoring
- A data processing agreement with each provider before it is enabled for your data, recorded in our subprocessor register
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform affected users without undue delay, as required by UK GDPR Articles 33–34.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice at least 14 days before they take effect. The effective date at the top of this document will be updated accordingly.
For privacy questions or data subject requests, email privacy@mindgrads.com. For general support, email support@mindgrads.com.
© 2026 NEXAPHAZE LTD. All rights reserved.
