Legal
Privacy Policy
How Mentivox collects, uses, protects, and shares personal data
Version 1.0 • Last updated 26 July 2026 • Effective 26 July 2026
Recitals
Mentivox Ltd (“Mentivox”, “we”, “us”, or “our”) provides a proactive, culturally-intelligent AI companion application (the “Service”) designed to support young adults navigating loneliness, emotional stress, and cultural displacement, through scheduled proactive check-in notifications and persistent, cross-session conversation memory. Mentivox is not a therapy replacement, not a clinical tool, and does not diagnose, treat, or prescribe. We understand that the nature of our Service means users may share personal, sensitive, and at times emotionally vulnerable information with us, and we have written this Privacy Policy to explain, in plain and precise terms, how we collect, use, store, share, and protect that information, and what rights you have over it.
We take the trust our users place in us seriously. We do not sell your personal data. We do not share your conversation content with third parties for commercial purposes. We do not monetise emotional vulnerability. These commitments are foundational to how Mentivox is built and operated, and they inform every provision that follows in this Privacy Policy.
This Privacy Policy should be read alongside our Terms of Service, AI Safety & Responsible Use Policy, Acceptable Use Policy, Cookie Policy, and Data Retention Policy, each of which is cross-referenced where relevant below.
1. Introduction & Controller Identity
1.1 This Privacy Policy explains how Mentivox Ltd collects, uses, discloses, and safeguards personal data in connection with the Service, whether accessed via our website, mobile application, or any other means we make available.
1.2 Data controller. Mentivox Ltd is the data controller responsible for your personal data for the purposes of the UK General Data Protection Regulation (as retained and amended in UK law, “UK GDPR”), the Data Protection Act 2018, and, where applicable, Regulation (EU) 2016/679 (“EU GDPR”) and the Nigeria Data Protection Act 2023 (“NDPA”). Our corporate and registration details are as follows:
Legal name: Mentivox Ltd
Company number: 17271375 (incorporated 9 June 2026 under the Companies Act 2006, England and Wales)
Registered office: 3 Manchester Road, Thornton-Heath, CR7 8HH, United Kingdom
ICO registration reference: ZC154942 (registered 3 June 2026; renewal due 2 July 2027)
1.3 Mentivox Ltd is registered with the UK Information Commissioner’s Office (“ICO”) as a data controller and is subject to the ICO’s supervisory jurisdiction in respect of its UK data protection obligations. Details of our registration can be verified on the ICO’s public register.
1.4 References in this Privacy Policy to “you” or “your” mean the individual using or registering for the Service, including, where applicable, a parent or guardian acting on behalf of a child user aged 13–17 in accordance with Section 4 below.
1.5 This Privacy Policy forms part of, and should be read together with, our Terms of Service. Capitalised terms not otherwise defined in this Privacy Policy have the meanings given to them in our Terms of Service.
2. Scope
2.1 This Privacy Policy applies to all personal data processed by Mentivox in connection with:
your registration for, and use of, the Service, including our mobile application and any associated website;
your communications with us, including support enquiries, feedback, and correspondence relating to the exercise of your data protection rights;
our proactive outreach features, including scheduled check-in notifications; and
any institutional or business-to-business arrangements we may enter into in the future (for example, with universities, employers, or non-governmental organisations), to the extent such arrangements involve personal data — noting that, as at the date of this Privacy Policy, no such institutional product is live, and any future institutional offering is anticipated to involve only anonymised, aggregate data as described in Section 9.6.
2.2 This Privacy Policy applies to users in the United Kingdom, the European Union and European Economic Area (“EEA”), the Federal Republic of Nigeria, and any other jurisdiction from which the Service is accessed, subject to the jurisdiction-specific provisions set out in Section 13.
2.3 This Privacy Policy does not apply to third-party websites, applications, or services that may be linked from within the Service. We encourage you to review the privacy policies of any third-party service you access.
2.4 The Service is currently offered on a free-of-charge basis only. No paid subscription tier is currently live. If and when a paid tier is introduced, this Privacy Policy will be updated to describe any additional data processing (for example, payment processing) associated with it, and we will notify users in accordance with Section 16.
3. What Data We Collect
3.1 We collect and process the following categories of personal data.
3.1.1 Account data
Information you provide when you register for and maintain an account, including: your name or display name, email address, date of birth or age confirmation, password (stored in hashed form), account preferences and settings, and, where applicable to users aged 13–17, parental or guardian contact details captured for the purpose of parental consent under Section 4.
3.1.2 Conversation content
The content of your interactions with the Mentivox AI companion, including messages you send, information you choose to share about your circumstances, relationships, feelings, cultural background, and daily life, and the AI-generated responses you receive. Because the Service is built around persistent, cross-session conversation memory, we retain relevant context from past conversations to inform future interactions, so that the companion can respond in a manner that is consistent with, and informed by, your prior conversations. We describe this only in terms of function and outcome; we do not disclose, and this Privacy Policy should not be read as disclosing, the internal technical architecture, system design, or engineering methods by which this is achieved, which remain confidential and, in part, the subject of pending patent applications.
3.1.3 Special category data
Conversation content may reveal, directly or by inference, information about your mental or emotional health, wellbeing, or state of mind (for example, references to stress, anxiety, low mood, loneliness, or similar matters), and may also reveal other special category data such as information about your racial or ethnic origin, religious beliefs, or sexual orientation where you choose to disclose it in conversation (for example, in the context of discussing cultural displacement or identity). This information constitutes “special category data” under Article 9 of the UK GDPR. We treat any conversation content that reveals or reasonably suggests information about your mental or emotional health state as special category data, and we process it only on the basis of your explicit consent, as further described in Section 6. We do not require you to disclose special category data to use the Service, and you should be aware that anything you choose to share in conversation may be processed as set out in this Privacy Policy.
3.1.4 Device and usage data
Technical information generated by your use of the Service, including device type and operating system, application version, IP address, general location inferred from your IP address (country/region level only, and not precise geolocation unless separately and explicitly enabled by you), log data (timestamps, feature usage, crash reports, error logs), and interaction metadata (for example, the frequency and timing of your engagement with proactive check-ins, to the extent necessary to schedule and deliver those check-ins appropriately).
3.1.5 Communications data
Records of correspondence between you and us, including support requests, feedback, complaints, and any communications relating to the exercise of your data protection rights.
3.1.6 Data we do not currently collect
We do not currently collect payment or billing information (as no paid tier is live), precise real-time geolocation data (location services beyond country/region-level inference are not enabled by default for any user, and are disabled by default and not offered at all for child accounts, as described in Section 4), or biometric data. If this changes in the future, we will update this Privacy Policy and, where required, obtain your consent before doing so.
3.2 We collect personal data (a) directly from you, when you register, use the Service, or contact us; (b) automatically, through your use of the Service (for example, device and usage data); and (c) in the case of users aged 13–17, from a parent or guardian who provides consent and contact details on the child’s behalf.
3.3 We do not currently collect personal data from third-party sources (for example, social media log-in providers, data brokers, or public databases) in connection with the Service. If this changes, we will update this Privacy Policy accordingly.
4. Children’s Data & Parental Consent
4.1 Age policy. The Service is intended for use by individuals aged 13 and above. Users aged 18 and above may register and use the Service without parental or guardian involvement. Users aged 13 to 17 (“child users”) may only register and use the Service with verifiable parental or guardian consent, obtained in accordance with this Section 4.
4.2 A deliberate, more protective policy choice. Under the UK GDPR and the Data Protection Act 2018, a child aged 13 or above may, as a matter of law, validly consent on their own behalf to the processing of their personal data in connection with information society services (below age 13, parental consent is legally required for consent-based processing). Notwithstanding that legal minimum, Mentivox has made a deliberate policy decision to require verifiable parental or guardian consent for all users aged 13 to 17, going beyond what UK data protection law strictly requires. We have adopted this more protective standard because of the emotionally sensitive nature of our Service and the potential for young people to share vulnerable personal information with an AI companion, and because we consider it to be in keeping with the best-interests-of-the-child standard referenced throughout this Section.
4.3 Age assurance at signup. At registration, all prospective users are required to self-declare their date of birth or confirm they meet the minimum age requirement via an age gate. Any user who indicates they are under 13 will be refused registration. Any user who indicates they are aged 13–17 will be directed into the parental consent flow described below before being permitted to access the Service’s substantive features.
4.4 Parental consent mechanism. Where a prospective user self-declares as aged 13–17:
we require the prospective child user to provide a parent or guardian’s contact details (name and email address, and, where available, telephone number);
we send a consent request directly to the parent or guardian, explaining the nature of the Service, the categories of personal data (including special category data, where applicable) that may be processed, the purposes of processing, and the parent’s or guardian’s rights, including the right to review, restrict, or require deletion of the child’s data;
the child user’s account remains restricted, and full functionality (including proactive check-ins and persistent conversation memory) is not enabled, until affirmative parental or guardian consent is received and verified;
we take reasonable steps, proportionate to the risk involved, to verify that the person providing consent is in fact the child’s parent or guardian, recognising that no verification method is perfect and that we apply a risk-based, proportionate approach consistent with ICO guidance on age assurance; and
consent, once given, may be withdrawn by the parent or guardian at any time, with the effect described in Section 4.8.
4.5 Alignment with the ICO Children’s Code. We design and operate child accounts in accordance with the standards set out in the ICO’s Age Appropriate Design Code (the “Children’s Code”), including in particular the following commitments:
High privacy by default. Child accounts are configured, by default, to the most privacy-protective settings the Service offers. Any setting that would reduce privacy protection (for example, enabling optional data sharing features, where such features exist) must be actively and separately opted into, and, where the change is material, may require renewed parental consent.
Data minimisation. We collect and process only the personal data reasonably necessary to provide the Service to child users, and we do not request or encourage child users to provide more personal data than is needed for the features they are using.
No profiling of children for marketing purposes. We do not use child users’ personal data, including conversation content or usage patterns, to build profiles for marketing or advertising purposes, and we do not serve targeted advertising to child accounts. Mentivox does not currently serve advertising to any user, but we make this commitment explicit and binding in respect of children regardless of any future change to our approach for adult users.
No nudge techniques. We do not design features intended to encourage child users to weaken their privacy settings, provide unnecessary personal data, or extend their engagement with the Service beyond what is healthy or intended. Our proactive check-in feature for child accounts is designed to be supportive rather than engagement-maximising, and is subject to parental visibility as described below.
Geolocation off by default. Precise geolocation functionality, to the extent it exists or is introduced within the Service, is switched off by default for all users and is not offered at all for child accounts unless and until we determine, following a specific children’s-focused data protection impact assessment, that a geolocation feature can be safely and appropriately offered to child users with parental control.
Parental controls. Parents and guardians who have provided consent under this Section may, on request to privacy@mentivox.app, (i) review the categories of personal data we hold about their child, (ii) request correction of inaccurate data, (iii) request deletion of their child’s conversation history or entire account, and (iv) withdraw consent for their child’s continued use of the Service.
Best-interests-of-the-child standard. In designing, operating, and making decisions about features that affect child users, we treat the best interests of the child as a primary consideration, consistent with the approach required by the Children’s Code.
4.6 Special category data and children. Where a child user’s conversation content reveals information about their mental or emotional health state or other special category data, the explicit consent basis described in Section 6 applies with equal force, and parental consent obtained under this Section 4 is treated as encompassing consent to this category of processing; a parent or guardian may withdraw this consent at any time with the effects described in Section 4.8.
4.7 No solely-automated decisions about children. We do not subject child users to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects concerning them.
4.8 Effect of withdrawal of parental consent. If a parent or guardian withdraws consent, we will suspend the child’s account, cease active processing of the child’s personal data for ongoing service provision, and delete the child’s account and associated conversation data within the timeframes set out in our Data Retention Policy, save to the extent limited retention is necessary for legal or safeguarding reasons.
4.9 Transition to adulthood. Where a child user who registered under this Section 4 reaches the age of 18, we will treat them as an adult user going forward, and parental consent and parental controls will cease to apply, save that we may retain a record that parental consent was obtained during the period it was legally and contractually required.
4.10 Reporting concerns. Any concern that a user under the age of 13 has registered for or is using the Service, or that a child user’s account is being used inappropriately, should be reported to privacy@mentivox.app, and we will investigate and take appropriate action, including suspension or deletion of the relevant account, as a matter of priority.
5. Special Category Data — Article 9 Treatment
5.1 As described in Section 3.1.3, conversation content shared with the Mentivox AI companion may reveal information falling within the special categories of personal data listed in Article 9(1) of the UK GDPR, most commonly data concerning your mental or emotional health or state of mind, and potentially also data concerning racial or ethnic origin, religious or philosophical beliefs, or sexual orientation, depending on what you choose to share.
5.2 We process special category data revealed in conversation content on the basis of your explicit consent, obtained at account registration and reaffirmed through your continued, informed use of the Service. Explicit consent is the Article 9(2)(a) condition we rely upon for this processing, and we consider it the most appropriate and rights-protective basis given the sensitive and voluntarily-disclosed nature of this information.
5.3 Prior to or at the point of first substantive use of the Service, we present a clear, standalone explanation that: (a) the Service may involve you sharing information about your mental or emotional wellbeing; (b) this constitutes special category data; (c) we will process it only with your explicit consent; and (d) you may withdraw that consent at any time, with the effect that we will cease using special category data for ongoing conversation personalisation and will delete it in accordance with Section 8 and our Data Retention Policy, subject to any residual data embedded in aggregate or anonymised records that can no longer be linked to you.
5.4 You are never required to disclose special category data to use core features of the Service, and we do not design the Service to actively solicit disclosure of special category data beyond what naturally arises from open-ended, supportive conversation.
5.5 We do not use special category data for any purpose other than providing and personalising the Service to you as described in Section 7, and, in particular, we do not use special category data to make decisions about your eligibility for any product, service, insurance, employment, or credit, and we do not disclose special category data to third parties for commercial purposes.
5.6 Withdrawal of explicit consent to special category data processing may materially affect our ability to provide certain features of the Service (in particular, persistent conversation memory and check-in personalisation), and we will explain this clearly to you if you seek to withdraw consent.
6. Lawful Bases for Processing
6.1 UK GDPR Article 6 requires that all processing of personal data have a lawful basis. Where special category data is involved, an Article 9 condition must also apply. The table below sets out, for each principal purpose of processing, the lawful basis (and, where relevant, Article 9 condition) we rely upon.
Creating and administering your account
Category of data: Account data
Article 6 lawful basis: Contract (Art. 6(1)(b)) — necessary to perform our contract with you (the Terms of Service)
Article 9 condition (if applicable): N/A
Verifying age and obtaining parental consent (users 13–17)
Category of data: Account data, parent/guardian contact details
Article 6 lawful basis: Legal obligation (Art. 6(1)(c)) and consent (Art. 6(1)(a))
Article 9 condition (if applicable): Not applicable to this purpose; see below for special category data disclosed by child users
Delivering conversational responses and maintaining persistent conversation memory
Category of data: Conversation content
Article 6 lawful basis: Contract (Art. 6(1)(b)) — necessary to provide the core functionality you have signed up for
Article 9 condition (if applicable): Explicit consent (Art. 9(2)(a)) where conversation content constitutes special category data
Delivering proactive check-in notifications
Category of data: Account data, conversation content, usage data
Article 6 lawful basis: Consent (Art. 6(1)(a)) — you may opt in or out of proactive check-ins at any time
Article 9 condition (if applicable): Explicit consent (Art. 9(2)(a)) where check-in personalisation draws on special category data
Ensuring platform security, preventing fraud and abuse
Category of data: Account data, device/usage data
Article 6 lawful basis: Legitimate interests (Art. 6(1)(f)) — our legitimate interest in maintaining a safe and secure Service, balanced against your rights and freedoms
Article 9 condition (if applicable): N/A
Responding to support enquiries and complaints
Category of data: Communications data, account data
Article 6 lawful basis: Contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f))
Article 9 condition (if applicable): Explicit consent (Art. 9(2)(a)) if the enquiry discloses special category data
Complying with legal and regulatory obligations (e.g. ICO reporting, law enforcement requests)
Category of data: Account data, conversation content (where legally compelled)
Article 6 lawful basis: Legal obligation (Art. 6(1)(c))
Article 9 condition (if applicable): Substantial public interest / legal claims conditions (Art. 9(2)(f)/(g)) as applicable, assessed case by case
Improving and maintaining the Service (bug fixing, quality assurance, aggregate analytics)
Category of data: Device/usage data, anonymised or aggregated conversation insights
Article 6 lawful basis: Legitimate interests (Art. 6(1)(f))
Article 9 condition (if applicable): Explicit consent, where any underlying special category data has not been fully anonymised prior to use for this purpose
Safeguarding children and responding to safeguarding concerns
Category of data: Account data, conversation content, parental consent records
Article 6 lawful basis: Legal obligation (Art. 6(1)(c)) and vital interests (Art. 6(1)(d)) in exceptional cases
Article 9 condition (if applicable): Substantial public interest conditions (Art. 9(2)(g)) as applicable
Exercising or defending legal claims
Category of data: Any relevant category
Article 6 lawful basis: Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f))
Article 9 condition (if applicable): Legal claims condition (Art. 9(2)(f))
Potential future institutional/B2B reporting (anonymised aggregate data only)
Category of data: Anonymised, aggregated data (not personal data once effectively anonymised)
Article 6 lawful basis: Not applicable once data is genuinely anonymised; legitimate interests (Art. 6(1)(f)) for any interim identifiable processing
Article 9 condition (if applicable): Not applicable, subject to genuine anonymisation prior to sharing
6.2 Where we rely on consent (including explicit consent for special category data), you have the right to withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal. You may withdraw consent via your in-app privacy settings or by contacting privacy@mentivox.app.
6.3 Where we rely on legitimate interests, we have carried out an assessment to satisfy ourselves that our interests are not overridden by your interests or fundamental rights and freedoms, and we are able to provide further information about this balancing assessment on request.
6.4 We do not rely on legitimate interests as a basis for processing any child user’s personal data where that would be inconsistent with the best-interests-of-the-child standard described in Section 4.5(g).
7. How We Use Data
7.1 We use the personal data described in Section 3 for the following purposes:
Providing the Service, including creating and maintaining your account, enabling you to converse with the Mentivox AI companion, and retaining relevant context from past conversations so that the companion can respond in a manner informed by your history with the Service.
Proactive check-ins. Scheduling and delivering AI-initiated outreach messages, calibrated to information you have shared and your engagement patterns, where you have not opted out of this feature.
Cultural intelligence and personalisation. Tailoring responses to reflect the cultural context and background you share with us, consistent with Mentivox’s mission to support users navigating cultural displacement — described here only as a functional outcome, not as a technical mechanism.
Account administration and communication, including sending service-related notices, responding to support requests, and administering parental consent workflows for child users.
Safety, security, and fraud prevention, including detecting and preventing misuse of the Service, unauthorised access, and abuse, consistent with our Acceptable Use Policy.
Legal and regulatory compliance, including responding to lawful requests from regulators or law enforcement as described in our Law Enforcement Requests Policy, and meeting our obligations under UK GDPR, EU GDPR, and the NDPA.
Service improvement, including bug fixing, quality assurance, and understanding aggregate usage patterns, which we carry out using anonymised or aggregated data wherever feasible, and which does not involve routing your personal conversation content to third-party artificial intelligence model providers (see Section 10).
Safeguarding, including identifying and appropriately handling situations that may indicate risk to a user’s welfare, within the honest limits of our current capability as described in our AI Safety & Responsible Use Policy (Mentivox does not currently provide automated crisis intervention or escalation to emergency services; see Section 11.5 below and our AI Safety & Responsible Use Policy for further detail).
Potential future institutional/B2B reporting. If Mentivox launches institutional products for universities, employers, or NGOs, we intend that such institutions would receive only anonymised, aggregate data (for example, aggregate wellbeing trend statistics across a cohort), and not identifiable conversation content or personal data about any individual user. As at the date of this Privacy Policy, no such institutional product is live; this paragraph describes a forward-looking possibility only.
7.2 We do not use your personal data, and in particular we do not use your conversation content, to sell to or share with third parties for their commercial or marketing purposes. We do not operate a data-broker style business model, and monetising emotional vulnerability disclosed through the Service is expressly contrary to our company values and to this Privacy Policy.
7.3 We do not use your personal data for purposes materially different from those described in this Section 7 without notifying you and, where required by law, obtaining your consent.
8. How Long We Keep Data
8.1 We retain personal data only for as long as is necessary for the purposes described in this Privacy Policy, in accordance with the UK GDPR storage limitation principle (Article 5(1)(e)).
8.2 The detailed retention periods applicable to each category of personal data are set out in our Data Retention Policy, which forms part of our data protection compliance framework and is available on request or via our website. In summary:
Account registration data is retained for the duration of your account plus six years following account closure, reflecting statutory record-keeping expectations under the Companies Act 2006 and applicable limitation periods under the Limitation Act 1980.
Conversation content and memory data is retained for the duration of your active account and is deleted within 30 days of a verified account deletion request, save where retained in anonymised, aggregated form for analytics purposes as described in Section 7.1(g), which can no longer be linked back to you.
Special category data disclosed in conversation is retained on the same basis as conversation content generally, is deletable by you on request at any time (independent of any wider account deletion request), and is deleted or irreversibly anonymised on withdrawal of consent as described in Section 5.6.
Support and complaints correspondence is retained for three years from resolution, reflecting the ordinary limitation period for contractual claims.
Security and access logs are retained for 12 months, balancing security investigation needs against data minimisation.
Data subject rights request records are retained for three years, to demonstrate accountability under UK GDPR Article 5(2).
Law enforcement disclosure records are retained for six years, for legal defensibility and audit purposes.
Parental consent records for child users are retained for the duration of the child’s account and for a reasonable period thereafter, sufficient to demonstrate that valid consent was obtained, after which they are deleted or anonymised.
8.3 On expiry of the applicable retention period, data is securely deleted or irreversibly anonymised such that it can no longer be linked to an identifiable individual. Backups containing personal data are subject to the same retention limits and are purged or overwritten on a rolling cycle, as further described in our Data Retention Policy.
8.4 You may request deletion of your account, or of specific conversation memories, at any time via in-app tools or by contacting privacy@mentivox.app, subject to limited retention necessary for fraud prevention, legal compliance, safeguarding, or dispute resolution, which we will minimise and explain to you on request.
10. Data Security
10.1 We take the security of your personal data seriously and apply technical and organisational measures designed to protect it against unauthorised access, alteration, disclosure, or destruction, proportionate to the sensitivity of the data involved.
10.2 Measures we apply include, without limitation:
Encryption at rest. Personal data, including conversation content, is encrypted at rest using AES-256 encryption.
Encryption in transit. Data transmitted between your device and our infrastructure is protected using industry-standard transport encryption.
Access controls. Access to personal data is restricted to personnel and systems that require it to provide or support the Service, on a need-to-know basis, with authentication controls in place to prevent unauthorised access.
On-device processing where possible. Certain processing is performed on-device where feasible, reducing the amount of personal data transmitted to or retained on our infrastructure.
Self-hosted processing infrastructure. Conversation processing occurs on Mentivox-operated infrastructure, rather than being routed to third-party artificial intelligence model providers. We consider this a privacy-positive design choice, because it reduces the number of parties with potential access to your conversation content and gives us direct control over the security measures applied to it. We describe this as an infrastructure fact only; the technical design and architecture of our systems are confidential and, in part, the subject of pending patent applications, and are not disclosed in this Privacy Policy or elsewhere.
Data storage location controls. Your data is stored using Supabase’s infrastructure in the EU (Ireland) region, a jurisdiction that maintains a robust and legally binding data protection framework under the EU GDPR.
Security testing and monitoring. We maintain logging and monitoring practices designed to detect and respond to potential security incidents, and we review our security measures periodically as the Service and associated risks evolve.
10.3 No method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. We will, however, notify you and the relevant supervisory authorities of any personal data breach in accordance with Section 14 and applicable law.
10.4 You also play a role in protecting your own data: you should use a strong, unique password for your account, avoid sharing your login credentials, and notify us immediately at privacy@mentivox.app if you suspect unauthorised access to your account.
11. Your Rights
11.1 UK GDPR rights
If you are in the United Kingdom, you have the following rights under the UK GDPR and the Data Protection Act 2018, subject to certain exemptions:
Right of access — to obtain confirmation that we are processing your personal data and to receive a copy of it, together with supplementary information.
Right to rectification — to have inaccurate personal data corrected, or incomplete personal data completed.
Right to erasure (“right to be forgotten”) — to have your personal data deleted in certain circumstances, including where it is no longer necessary for the purpose for which it was collected, or where you withdraw consent and no other lawful basis applies.
Right to restrict processing — to limit the way we use your personal data in certain circumstances, for example while the accuracy of the data is contested.
Right to data portability — to receive personal data you have provided to us, in a structured, commonly used, machine-readable format, and to have it transmitted to another controller, where processing is based on consent or contract and carried out by automated means.
Right to object — to object to processing based on legitimate interests, and to object at any time to processing for direct marketing purposes (noting that Mentivox does not currently carry out direct marketing based on your personal data).
Rights related to automated decision-making, including profiling, as described in Section 12.
Right to withdraw consent — at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
Right to lodge a complaint with the Information Commissioner’s Office, details of which are set out in Section 15.
11.2 EU GDPR rights
If you are a resident of the European Union or European Economic Area, you have equivalent rights under the EU GDPR, as described in Section 13.2, and may lodge a complaint with the supervisory authority of your habitual residence, place of work, or the place of the alleged infringement.
11.3 Nigeria Data Protection Act rights
If you are in Nigeria, you have rights under the Nigeria Data Protection Act 2023, as described in Section 13.3, including the right to be informed, the right of access, the right to rectification, the right to object, the right to restriction, the right to data portability, the right to erasure, and the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
11.4 How to exercise your rights
To exercise any of the rights described in this Section 11, please contact us at privacy@mentivox.app, or via the in-app privacy settings tools where available. We may need to verify your identity before responding to a request, and, in the case of a parent or guardian exercising rights on behalf of a child user, we may need to verify the parental or guardian relationship.
11.5 Response timelines
We will respond to requests to exercise your rights without undue delay and, in any event, within one calendar month of receipt (extendable by a further two months for complex or numerous requests, in which case we will explain the reason for the delay within the initial one-month period), consistent with UK GDPR Article 12(3) and the equivalent EU GDPR provision. Where we are unable to comply with a request (for example, because an exemption applies, or because we need to retain data to comply with a legal obligation), we will explain our reasons to you.
11.6 We do not charge a fee for handling a data subject rights request, save where a request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or decline to act on the request, and will explain our reasoning if we do so.
12. Automated Decision-Making
12.1 Solely automated decisions. We do not currently subject any user to a decision based solely on automated processing, including profiling, which produces legal effects concerning that user or similarly significantly affects them. In particular, we do not use automated processing to make decisions about a user’s access to the Service, eligibility for any product, or any matter with legal or similarly significant consequence.
12.2 Check-in personalisation and content personalisation. We recognise that our proactive check-in feature — which determines the timing and general content orientation of AI-initiated outreach based on information you have shared and your engagement history — and our broader personalisation of conversational responses could be characterised as a form of profiling within the meaning of Article 4(4) of the UK GDPR, in that it involves evaluating certain personal aspects relating to you in order to tailor how and when the Service interacts with you. We address this plainly rather than seeking to minimise its characterisation:
this personalisation does not produce a legal effect or similarly significant effect on you of the kind addressed by Article 22 of the UK GDPR — it does not determine your access to the Service, your rights, or any material entitlement, benefit, or opportunity; it only affects the manner and timing in which supportive conversational content and check-in prompts are delivered to you;
nonetheless, in the interests of transparency, we confirm that this personalisation occurs, that it draws on conversation content and usage data (and, where you have provided explicit consent under Section 5, on special category data), and that we do not use it to build advertising profiles or to make decisions about your eligibility for anything;
you may opt out of proactive check-in notifications entirely at any time via your in-app settings, in which case you will not receive AI-initiated outreach, while retaining full ability to initiate conversations yourself; and
you may contact privacy@mentivox.app to request human review of, or further information about, how personalisation of your experience operates, and we will respond consistent with the response timelines in Section 11.5.
12.3 No profiling of children for marketing. As stated in Section 4.5(c), we do not use any child user’s personal data to build profiles for marketing or advertising purposes, and this prohibition is absolute and not subject to opt-in.
12.4 Future automated decision-making. If we introduce any solely automated decision-making producing legal or similarly significant effects in the future (for example, in connection with the planned crisis detection and escalation protocol referenced in our AI Safety & Responsible Use Policy, which is a roadmap item and not a currently live feature), we will update this Privacy Policy, ensure a lawful basis under Article 22 UK GDPR is identified, and put in place appropriate safeguards, including the right to obtain human intervention, to express a point of view, and to contest the decision.
13. International Data Transfers and International Users
13.1 Overview
13.1 Mentivox has real, active users in the United Kingdom, the European Union, and Nigeria, and this Section addresses the multi-jurisdictional nature of our data processing directly and specifically, rather than treating any one framework as a formality.
13.2 United Kingdom — UK GDPR (primary framework)
13.2.1 As a company registered in England and Wales with its registered office in the United Kingdom, Mentivox Ltd is directly subject to the UK GDPR and the Data Protection Act 2018 as its primary data protection framework, and the ICO is our lead supervisory authority.
13.2.2 All UK users’ rights are as set out in Section 11.1 above, and complaints may be directed to the ICO as described in Section 15.
13.3 European Union — EU GDPR (extraterritorial application)
13.3.1 Mentivox has users who are resident in the European Union. Although Mentivox Ltd does not have an establishment in the EU, the EU GDPR applies to our processing of EU residents’ personal data on an extraterritorial basis under Article 3(2) of Regulation (EU) 2016/679, because we offer the Service to individuals in the EU.
13.3.2 Article 27 EU representative. Where a controller without an EU establishment processes the personal data of more than an incidental number of EU data subjects, Article 27 of the EU GDPR generally requires the appointment of a representative established in the EU. Mentivox has identified the appointment of an Article 27 EU representative as a recommended near-term action, and this is presently a planned rather than completed step. As at the date of this Privacy Policy, Mentivox has not yet confirmed the appointment of an Article 27 EU representative. We are actively assessing our EU user base against the “incidental” threshold and intend to appoint a representative promptly if and when appropriate, and we will update this Privacy Policy, including with contact details for that representative, once an appointment is made. In the interim, EU users may direct any enquiry regarding our processing of their personal data to privacy@mentivox.app, and we will respond in accordance with the response timelines described in Section 11.5.
13.3.3 EU residents have rights under the EU GDPR that are substantively equivalent to those described in Section 11.1, including the rights of access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making, and the right to lodge a complaint with the supervisory authority of their member state of habitual residence, place of work, or place of alleged infringement.
13.4 Nigeria — Nigeria Data Protection Act 2023 (NDPA)
13.4.1 Mentivox has real, active users in Nigeria, and we recognise our obligations under the Nigeria Data Protection Act 2023, which repealed and absorbed the prior Nigeria Data Protection Regulation framework, and is enforced by the Nigeria Data Protection Commission (“NDPC”).
13.4.2 Data protection principles. We process the personal data of Nigerian users in accordance with the six data protection principles under the NDPA: that processing be (i) carried out in a fair, lawful, and transparent manner; (ii) collected for specified, legitimate purposes; (iii) adequate, relevant, and limited to what is necessary; (iv) accurate and kept up to date; (v) retained no longer than necessary; and (vi) processed in a manner that ensures appropriate security.
13.4.3 Data subject rights under the NDPA. Nigerian users have the right: to be informed about the processing of their personal data; to access their personal data; to rectification of inaccurate data; to object to processing; to restriction of processing; to data portability; to erasure of their personal data; and not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. These rights may be exercised in the manner described in Section 11.4, and we will respond within the timelines described in Section 11.5, or such shorter period as the NDPA may require.
13.4.4 Breach notification. In the event of a personal data breach affecting Nigerian users that is likely to result in a risk to their rights and freedoms, we commit to notifying the NDPC within 72 hours of becoming aware of the breach, consistent with the NDPA’s breach notification requirement, and to notifying affected Nigerian users without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
13.4.5 Registration as a data controller/processor of major importance. Under the NDPA, a data controller or processor that meets specified thresholds (including, broadly, processing the personal data of more than 200 data subjects within a six-month period, or operating in specified sectors) is required to register with the NDPC as a “data controller or processor of major importance.” Mentivox actively monitors its Nigerian user numbers and processing activities against this threshold and will register with the NDPC promptly if and when the threshold is met or is reasonably anticipated to be met. As at the date of this Privacy Policy, we do not represent that such registration is currently required or has been completed, and this paragraph should be read as a statement of an active monitoring commitment rather than a claim of current registration.
13.4.6 Cross-border transfers from Nigeria. As described in Section 13.5, personal data of Nigerian users is transferred to and stored in the EU (Ireland). We address the lawfulness of this transfer under the NDPA’s cross-border transfer rules in Section 13.5.3 below.
13.5 International transfer mechanisms
13.5.1 Our data storage infrastructure, provided by our sub-processor Supabase, is located in the EU (Ireland). This means that personal data of all our users — including users based in the United Kingdom and users based in Nigeria — is transferred to, and stored in, the European Union.
13.5.2 UK to EU (Ireland) transfers. The transfer of personal data from the United Kingdom to the EU (Ireland) is a “restricted transfer” as a technical matter under the UK GDPR, but is subject to a low-friction transfer mechanism because the United Kingdom Government has formally recognised the European Union (including Ireland) as offering an adequate level of data protection for the purposes of UK GDPR Article 45 (an “adequacy regulation” applicable to EU/EEA member states). This adequacy recognition means that data may flow from the UK to Ireland without the need for additional transfer safeguards such as Standard Contractual Clauses, and we rely on this UK adequacy recognition as our transfer mechanism for UK users’ data stored in the EU (Ireland).
13.5.3 Nigeria to EU (Ireland) transfers. For our Nigerian users, the transfer of personal data to and storage in the EU (Ireland) is a cross-border transfer for the purposes of the NDPA’s data localisation and cross-border transfer provisions. The NDPA permits cross-border transfer of personal data where, among other mechanisms, the destination jurisdiction is recognised as having an adequate level of data protection, appropriate safeguards such as standard contractual clauses are in place, or the data subject has given specific consent to the transfer after being informed of the possible risks. The European Union, including Ireland, is generally regarded internationally as maintaining a robust and comprehensive statutory data protection framework under the EU GDPR, and we consider this relevant to the adequacy of protection afforded to Nigerian users’ data once transferred there. Without prejudice to that assessment, and as an additional and independent safeguard, Mentivox obtains the informed consent of Nigerian users to the transfer and storage of their personal data in the EU (Ireland) as part of the registration process, and we are documenting our transfer impact assessment and transfer mechanism on an ongoing basis as part of our compliance programme, consistent with our obligation under the NDPA to maintain an appropriate and documented basis for cross-border transfers.
13.5.4 EU (Ireland) as the storage jurisdiction generally. Because our infrastructure sub-processor is based in the EU (Ireland), personal data collected from users in any jurisdiction, including the UK and the EEA itself, is processed and stored within the EU. This means EU-resident users’ personal data does not leave the EU/EEA in the course of ordinary Service provision, and, for UK and Nigerian users, the international transfer analysis in Sections 13.5.2 and 13.5.3 applies.
13.5.5 We keep our international transfer arrangements under review and will update this Section 13.5 if our infrastructure or sub-processor arrangements change in a manner that affects the location of data processing or the applicable transfer mechanism.
13.6 General position on international users
13.6.1 Where obligations under the UK GDPR, EU GDPR, and NDPA differ in respect of a particular user, we apply the framework(s) applicable to that user’s location and circumstances, and, where our practices already meet a higher standard under one framework, we do not reduce protection for users subject to a framework with a lower baseline requirement.
14. Data Breach Notification
14.1 We maintain internal procedures to detect, investigate, and respond to personal data breaches.
14.2 Notification to the ICO. In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of UK data subjects, we will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 of the UK GDPR.
14.3 Notification to affected individuals. Where a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, describing in clear and plain language the nature of the breach, its likely consequences, and the measures we have taken or propose to take to address it, in accordance with Article 34 of the UK GDPR.
14.4 Notification to the NDPC. As described in Section 13.4.4, we commit to notifying the Nigeria Data Protection Commission within 72 hours of becoming aware of a personal data breach affecting Nigerian users that is likely to result in a risk to their rights and freedoms, and to notifying affected Nigerian users without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
14.5 Notification to EU supervisory authorities. Where a personal data breach is likely to result in a risk to the rights and freedoms of EU data subjects, we will assess our notification obligations under the EU GDPR, including notification to the relevant EU supervisory authority and, once appointed, coordination through our Article 27 EU representative referenced in Section 13.3.2.
14.6 We maintain a record of all personal data breaches, including their effects and the remedial action taken, regardless of whether notification to a supervisory authority or affected individuals was required, in order to demonstrate compliance with our accountability obligations.
16. Changes to This Policy
16.1 We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. The “Last Updated” date at the top of this Privacy Policy indicates when it was last revised.
16.2 Where we make material changes — including any change that would reduce your rights, expand the categories of data we collect or the purposes for which we use it, or introduce a new category of sub-processor or international transfer — we will provide prominent notice within the Service and, where appropriate and where we hold a valid contact address for you, by email, in advance of the change taking effect, and, where required by applicable law (for example, changes affecting the basis on which we rely on your consent), we will seek your renewed consent.
16.3 For child users, we will additionally notify the relevant parent or guardian of any material change affecting the processing of their child’s personal data, and, where the change would reduce the protections applicable to the child’s account, we will treat continued use of the Service as requiring renewed parental consent.
16.4 We encourage you to review this Privacy Policy periodically. Your continued use of the Service after a change takes effect constitutes your acknowledgement of the updated Privacy Policy, save where renewed consent is separately required as described above.
17. Contact Us
17.1 If you have any questions, concerns, or requests relating to this Privacy Policy or our processing of your personal data, please contact us at:
Mentivox Ltd 3 Manchester Road Thornton-Heath CR7 8HH United Kingdom
Privacy contact: privacy@mentivox.app
17.2 Mentivox has not currently appointed a statutory Data Protection Officer, as this is not presently a mandatory requirement under UK GDPR Article 37 given the nature, scale, and current volume of our processing activities. We do, however, maintain a dedicated privacy contact function (privacy@mentivox.app) responsible for handling data protection enquiries and requests, and we will appoint a formal Data Protection Officer if our processing activities grow to the point where such an appointment becomes mandatory or otherwise advisable, and we will update this Privacy Policy accordingly.
17.3 Parents and guardians of child users may also use the above contact details to exercise parental rights described in Section 4.
Legal Framework
This Privacy Policy has been prepared with reference to the following legal and regulatory sources:
UK General Data Protection Regulation (Retained Regulation (EU) 2016/679, as amended) and the Data Protection Act 2018
Information Commissioner’s Office (ICO) — ico.org.uk; public register entry ZC154942 — ICO register search
ICO Age Appropriate Design Code (Children’s Code) — ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/
Regulation (EU) 2016/679 (EU General Data Protection Regulation), in particular Article 3(2) (extraterritorial application) and Article 27 (representatives of controllers not established in the Union)
Nigeria Data Protection Act 2023, and the Nigeria Data Protection Commission (NDPC)
Companies Act 2006 (England and Wales company registration and record-keeping framework)
Consumer Rights Act 2015 (fairness and transparency of consumer contract terms, referenced in relation to this Privacy Policy’s plain-language drafting standard)
Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013 (referenced for consistency with our Terms of Service pre-contract information framework, applicable once any paid tier is introduced)
This Privacy Policy should be read together with Mentivox’s Terms of Service, AI Safety & Responsible Use Policy, Acceptable Use Policy, Cookie Policy, and Data Retention Policy, each available on our website or on request from privacy@mentivox.app.
Questions about this policy? Contact support@mentivox.com.
