Mindmux CIC (“we”, “us”, “our”) operates the mindmux platform, a WhatsApp-based support tool for parents of young people with Pathological Demand Avoidance (PDA), a profile of autism. This policy explains what personal data we collect, why we collect it, and your rights under UK and EU law.
Mindmux CIC is a Community Interest Company registered in England and Wales. We are the data controller for personal data processed through the mindmux platform.
Contact: info@mindmux.io
Our lawful basis for processing is legitimate interests (Article 6(1)(f) UK GDPR) for service delivery, and explicit consent (Article 9(2)(a)) where we process sensitive data relating to a child’s health or autism profile.
Our platform is designed to support young people with PDA. A parent or guardian sets the service up and provides consent on their young person's behalf.
Young people do send us data directly. They answer check-in questions and quizzes on WhatsApp, and those answers are stored so that progress can be shown to their parent. What they cannot do is hold an open conversation with our AI: free-text messages from a young person are not sent to any AI provider. That is enforced in our software and it fails safe, meaning that if we cannot tell who is writing, we do not send the message.
Names of people outside your care group that appear in your messages are removed before the message is stored.
We do not currently operate an automated process for asking other adults to consent to being added to a care group. If we introduce one, we will update this policy first and tell you about it.
We do not sell your data. We share it only with:
For generating activities and stories we send only short structured labels, such as interests and goals. No names, and no message text.
A young person's own messages are never sent to an AI provider. That is enforced in our software and it fails safe: if we cannot tell who is writing, we do not send the message.
We are also preparing a second use of AI, to find and remove personal details from messages before they are stored. This is not switched on at present. When we turn it on we will tell you first, because it works differently from the above and we want to be clear about it: to remove personal details from a message, we have to send the message. It would arrive complete and unedited, and it may contain your own words about your young person, including their name. We will not turn this on until the provider has confirmed in writing that they do not keep what we send.
Under UK GDPR and the UK Data Protection Act 2018, you have the right to:
To exercise any of these rights, contact us at info@mindmux.io. We will respond within 30 days.
All data is encrypted in transit (TLS) and at rest. Flow tokens and sensitive payloads are encrypted end-to-end. We conduct regular security reviews and follow OWASP best practices.
Our WhatsApp-based platform does not use cookies. If you visit our website (mindmux.io), only essential cookies required for site functionality are used.
We may update this policy from time to time. Material changes will be communicated via WhatsApp message to registered users. The “last updated” date at the top of this page will always reflect the current version.
For any privacy-related questions, contact us at info@mindmux.io.
If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Website: ico.org.uk
Phone: 0303 123 1113