Privacy Policy

Mindmux CIC · Last updated: March 2026

Mindmux CIC (“we”, “us”, “our”) operates the mindmux platform, a WhatsApp-based support tool for parents of young people with Pathological Demand Avoidance (PDA), a profile of autism. This policy explains what personal data we collect, why we collect it, and your rights under UK and EU law.

1. Who We Are

Mindmux CIC is a Community Interest Company registered in England and Wales. We are the data controller for personal data processed through the mindmux platform.

Contact: info@mindmux.io

2. What Data We Collect

3. How We Use Your Data

Our lawful basis for processing is legitimate interests (Article 6(1)(f) UK GDPR) for service delivery, and explicit consent (Article 9(2)(a)) where we process sensitive data relating to a child’s health or autism profile.

4. Data Minimisation & Retention

5. Children’s Data

Our platform is designed to support young people with PDA. A parent or guardian sets the service up and provides consent on their young person's behalf.

Young people do send us data directly. They answer check-in questions and quizzes on WhatsApp, and those answers are stored so that progress can be shown to their parent. What they cannot do is hold an open conversation with our AI: free-text messages from a young person are not sent to any AI provider. That is enforced in our software and it fails safe, meaning that if we cannot tell who is writing, we do not send the message.

6. Care Group Members

Names of people outside your care group that appear in your messages are removed before the message is stored.

We do not currently operate an automated process for asking other adults to consent to being added to a care group. If we introduce one, we will update this policy first and tell you about it.

7. Who We Share Data With

We do not sell your data. We share it only with:

For generating activities and stories we send only short structured labels, such as interests and goals. No names, and no message text.

A young person's own messages are never sent to an AI provider. That is enforced in our software and it fails safe: if we cannot tell who is writing, we do not send the message.

We are also preparing a second use of AI, to find and remove personal details from messages before they are stored. This is not switched on at present. When we turn it on we will tell you first, because it works differently from the above and we want to be clear about it: to remove personal details from a message, we have to send the message. It would arrive complete and unedited, and it may contain your own words about your young person, including their name. We will not turn this on until the provider has confirmed in writing that they do not keep what we send.

8. Your Rights

Under UK GDPR and the UK Data Protection Act 2018, you have the right to:

To exercise any of these rights, contact us at info@mindmux.io. We will respond within 30 days.

9. Security

All data is encrypted in transit (TLS) and at rest. Flow tokens and sensitive payloads are encrypted end-to-end. We conduct regular security reviews and follow OWASP best practices.

10. Cookies

Our WhatsApp-based platform does not use cookies. If you visit our website (mindmux.io), only essential cookies required for site functionality are used.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via WhatsApp message to registered users. The “last updated” date at the top of this page will always reflect the current version.

12. Contact & Complaints

For any privacy-related questions, contact us at info@mindmux.io.

If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Website: ico.org.uk
Phone: 0303 123 1113