Privacy Policy

Version 2  Last updated 23/04/2026 

1. Introduction

This Privacy Policy explains how Mindtools Kineo collects, uses, and protects personal data globally. 

Mindtools Kineo is the trading name of Mind Tools Ltd (SC202102) and its current and future wholly owned subsidiaries and affiliates operating under the Mindtools Kineo brand. 

We are committed to: 

  • transparency  
  • data protection  
  • global regulatory compliance  

2. Who We Are

Mindtools Kineo is the trading name of Mind Tools Ltd (SC202102) and its current and future wholly owned subsidiaries and affiliates operating under the Mindtools Kineo brand (together, “Mindtools Kineo”, “we”, “us” or “our”). 

This Privacy Policy applies to all personal data processed by Mindtools Kineo entities in connection with our websites, platforms, and services. 

Mind Tools Ltd
21 Young Street, Edinburgh EH2 4HU, UK 

dpt@kineo.com 

We may act as: 

  • Controller (website users, direct relationships)  
  • Processor (enterprise services)  

3. Scope

This policy applies to: 

  • website users  
  • customers and end users  
  • business contacts  
  • individuals interacting with us globally  

4. Personal Data We Collect

Provided by you:
  • name, email, job role  
  • organisation  
  • contact details  
  • account credentials  
Automatically collected: 
  • IP address  
  • browser/device data  
  • usage behaviour  
  • cookies  
From third parties:
  • employers / training providers  
  • partners  
  • service providers  

5. How We Use Personal Data

We use data to: 

  • provide and manage services  
  • communicate and support users  
  • improve services and performance  
  • conduct analytics and marketing  
  • comply with legal obligations  

6. Legal Basis

We rely on: 

  • contract  
  • legitimate interests  
  • consent  
  • legal obligation  

7. AI and Automated Processing

We may use AI technologies to enhance our services. 

We: 

  • apply human oversight where appropriate  
  • avoid solely automated decision-making with legal impact  
  • limit use of personal data in AI systems  

AI outputs should not be relied upon without independent verification. 

We align with emerging global frameworks (including EU AI Act principles). 

8. Sharing Personal Data

We may share personal data with: 

  • Mindtools Kineo group entities  
  • service providers (hosting, CRM, analytics, marketing)  
  • professional advisers  
  • regulators and authorities  

All sharing is subject to: 

  • contractual safeguards  
  • confidentiality obligations  

9. Third-Party Service Providers

We use trusted third-party providers, including: 

  • cloud infrastructure providers  
  • analytics platforms  
  • marketing tools  
  • payment processors  

We ensure: 

  • due diligence and vendor selection processes  
  • contractual protections  
  • compliance with applicable data protection laws  

A current list of key service providers is available upon request. 

10. International Data Transfers

We operate globally and may transfer data across: 

  • UK / EU  
  • US  
  • Australia / New Zealand  
  • Latin America  
  • South Africa 

We implement safeguards including: 

  • Standard Contractual Clauses  
  • contractual protections  
  • local compliance measures  

11. Data Retention

We retain data only as long as necessary to: 

  • fulfil contractual obligations  
  • comply with legal requirements  
  • support business operations  

Data is securely deleted or anonymised when no longer required. 

12. Your Rights

You may have rights to: 

  • access  
  • correction  
  • deletion  
  • restriction  
  • objection  
  • portability  

Contact: dpt@kineo.com 

13. Regional Regulators

You may have the right to lodge a complaint with a relevant data protection authority in your jurisdiction, including: 

  • United Kingdom / European Union  

  Information Commissioner’s Office (ICO)   

  https://ico.org.uk   

  • Australia  

  Office of the Australian Information Commissioner (OAIC)   

  https://www.oaic.gov.au   

  • New Zealand  

  Office of the Privacy Commissioner   

  https://www.privacy.org.nz   

  • United States  

  You may contact your relevant state regulator or Attorney General’s office   

  • Mexico  

  National Institute for Transparency, Access to Information and Personal Data Protection (INAI)   

https://home.inai.org.mx/

  • Argentina  

  Agency for Access to Public Information (AAIP)   

  https://www.argentina.gob.ar/aaip   

  • Other Latin American jurisdictions 

  You may contact the relevant data protection authority in your country of residence. 

We encourage contacting us first. 

14. Marketing

You may opt out at any time. 

We comply with applicable marketing laws globally. 

15. Cookies

See our Cookies Policy. 

16. Security

We take the security of personal data seriously and implement appropriate technical and organisational measures to protect it. 

These include: 

  • secure infrastructure and hosting environments  
  • encryption and network security controls  
  • access controls and authentication  
  • monitoring and security updates  
  • staff training and internal policies  

We maintain practices aligned with recognised standards.
Certifications: Certifications | Mindtools Kineo 

Account Security

You are responsible for maintaining login credentials. 

Payment Security 

Payments are processed via trusted third-party providers. 

Data Breach Response 

We have procedures to detect and respond to breaches and will notify where required. 

Limitations of Internet Security 

Internet transmission is not fully secure; however, we apply safeguards once data is received. 

User Responsibility 

You should: 

  • protect credentials  
  • log out on shared devices  
  • report incidents  

17. Complaints

dpt@kineo.com 

We aim to respond promptly. 

18. Updates

We may update this policy periodically.