GDPR Compliance
General Data Protection Regulation Information
Our Commitment to Data Protection
MindRise is committed to protecting the privacy and security of your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
This page outlines how we comply with GDPR requirements and explains your rights as a data subject.
Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: You have given clear consent for us to process your personal data for specific purposes (e.g., receiving newsletters, marketing communications)
- Contract: Processing is necessary for the performance of a contract with you (e.g., providing coaching services you have booked)
- Legal Obligation: Processing is necessary for compliance with a legal obligation
- Legitimate Interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, provided those interests are not overridden by your rights and interests
Data Controller Information
MindRise acts as the data controller for the personal information we collect. Our contact details are:
MindRise Transformation Centre
45 Martin Road, #08-12 Aspen Heights
Singapore 239065
Email: [email protected]
Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
1. Right to Access
You have the right to request access to the personal data we hold about you. You can request a copy of your personal data, which we will provide in a commonly used electronic format.
2. Right to Rectification
If you believe the information we hold about you is inaccurate or incomplete, you have the right to request correction or completion of your personal data.
3. Right to Erasure (Right to be Forgotten)
You have the right to request deletion of your personal data in certain circumstances, such as:
- The data is no longer necessary for the purposes it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
Please note that we may be required to retain certain information for legal or professional obligations.
4. Right to Restriction of Processing
You have the right to request that we restrict processing of your personal data in certain situations, such as:
- You contest the accuracy of the data
- Processing is unlawful but you don't want the data erased
- We no longer need the data but you need it for legal claims
- You have objected to processing while we verify legitimate grounds
5. Right to Data Portability
Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
6. Right to Object
You have the right to object to processing of your personal data where we are relying on legitimate interests. You also have the right to object to processing for direct marketing purposes at any time.
7. Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. MindRise does not currently use automated decision-making processes.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us:
- Email: [email protected]
- Include "GDPR Request" in the subject line
- Provide sufficient information to verify your identity
- Clearly state which right(s) you wish to exercise
We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of any such extension.
Data Protection Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Regular security assessments and audits
- Staff training on data protection and confidentiality
- Access controls limiting data access to authorized personnel only
- Secure backup and disaster recovery procedures
- Incident response procedures for data breaches
Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.
International Data Transfers
If we transfer your personal data outside the European Economic Area (EEA), we will ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Transfers to countries with adequate data protection as determined by the European Commission
- Other legally recognized transfer mechanisms
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Our retention periods are based on:
- The nature of the data and the purpose of processing
- Legal and regulatory requirements
- Professional standards and best practices
- Potential legal claims
Children's Data
Our services are not intended for individuals under 16 years of age. We do not knowingly process personal data of children under 16 without parental consent. If you believe we have collected data from a child, please contact us immediately.
Updates to This Policy
We may update this GDPR compliance information from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated information on our website.
Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority, particularly in the EU member state where you reside, work, or where the alleged infringement occurred.
For Singapore residents, you may contact the Personal Data Protection Commission (PDPC).
Contact Our Data Protection Officer
For questions specifically related to data protection and GDPR compliance, you can contact us at:
Email: [email protected]
Subject: Data Protection Inquiry