Legal

Privacy Policy

Privacy Policy

Effective date: 26 September 2026 | Version 2.4

1. About This Policy

This Privacy Policy explains how Mentix Ltd collects, uses, and shares personal data in connection with the website at www.mentix.world (the "Website") and the Mentix mentorship platform (together, the "Services"). It applies to Website visitors, Mentees, Mentors, Industry Partner representatives, and other individuals whose personal data we process.

Mentix operates under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where applicable, the EU General Data Protection Regulation (EU GDPR). Our Services are designed for users in the United Kingdom and the European Economic Area, although we also engage with partners and users in other jurisdictions.

2. Controller and Contact Details

The controller of personal data processed through the Services is:

Mentix Ltd

Company number 16521574

9 Upper Wimpole Street

London W1G 6LJ

United Kingdom

Email: info@mentix.world

In certain scenarios we process personal data on behalf of an Industry Partner, a host institution, or another controller. Where Patient Data is captured or transmitted through the Platform, the treating institution is the controller of that data and Mentix acts as its processor. That applies to the live transmission of a Session, to the mentor's participation in it, to capture, and to our de-identification quality assurance review. It does not apply to material that has passed that review, which is addressed in Section 5A. The Services-related processing we carry out as a controller in our own right is described in this Policy.

3. Categories of Personal Data We Process

Account and identity data: name, professional title, specialty, regulatory or licence number (where required), employer or host institution, and role (Mentee, Mentor, Industry Partner representative).

Contact data: business email address, phone number, and business postal address.

Authentication and security data: hashed credentials, session tokens, multi-factor authentication identifiers, IP address, device identifiers, and log records.

Usage data: pages visited on the Website, features used on the Platform, Session activity, time spent, assessment results, and feedback submitted.

Clinical training content: procedural video, still images, structured feedback, competency scores, and related metadata generated by Mentors and Mentees during Sessions.

Patient data (special category): where Patient Data is transmitted through the Platform, it may include clinical images, video of internal anatomy, and limited clinical metadata. We do not require, and ask that institutions do not provide, patient names, patient numbers, dates of birth, addresses or other direct patient identifiers. Patient Data is processed by Mentix as a processor on behalf of the treating institution under a separate data processing agreement, up to and including our de-identification quality assurance review.

Commercial data: order forms, billing contacts, invoice details, sponsorship allocations, and payment records for Industry Partners and Mentors.

Correspondence data: communications with Mentix, including support enquiries and meeting notes.

We do not knowingly collect personal data from children. The Services are not intended for individuals under 18.

4. Sources of Personal Data

We collect personal data from:

(a) you, when you register, sign in, use the Services, or correspond with us;

(b) your employer or host institution, when it sponsors your participation or integrates its systems with the Platform;

(c) Industry Partners, when they nominate Mentees to receive sponsored access;

(d) Mentors, when they submit feedback or assessments relating to a Session;

(e) our sub-processors, including authentication, hosting, and analytics providers that generate log and telemetry data in the ordinary course of providing their services to us;

(f) publicly available sources, such as professional registers, where we need to verify that a clinical User holds appropriate credentials.

5. Lawful Bases and Purposes

Performance of a contract (UK GDPR Art. 6(1)(b)): to create and manage accounts, deliver Sessions, process payments, provide support, and otherwise perform the Terms of Service, the mentor engagement agreement, or an order form with an Industry Partner.

Legitimate interests (UK GDPR Art. 6(1)(f)): to operate and secure the Services, prevent fraud and abuse, maintain quality and safety, communicate with business contacts, develop and improve the Services (including through de-identified analytics), and defend legal claims. We have assessed these interests against the rights and freedoms of data subjects and concluded that our processing is proportionate. You may object to processing based on legitimate interests (see Section 10).

Legal obligation (UK GDPR Art. 6(1)(c)): to meet obligations under tax, accounting, corporate, data protection, and clinical governance law.

Consent (UK GDPR Art. 6(1)(a)): where we rely on your consent for a specific activity, for example where a Mentee consents to a particular use of identifiable training material for a named research project. You may withdraw consent at any time by contacting us; withdrawal does not affect processing carried out before withdrawal.

Special category data (UK GDPR Art. 9): where Patient Data or other health data is processed through the Platform, Mentix acts as a processor and does not itself select the condition under Article 9(2) on which that processing relies. That condition is determined by the controller, ordinarily the treating institution, which is responsible for identifying it and for satisfying any associated condition in Schedule 1 to the Data Protection Act 2018 before a Session takes place. We process such data only on that controller's documented instructions and under the contractual, security and governance controls described in this Policy and in the relevant data processing agreement. Once a Session Recording has passed our quality assurance check and the pre-redaction source has been deleted, we hold no key, mapping or other means by which a patient could be re-identified from the material we retain. Separately, Mentix acts as controller in its own right for Mentee assessment and competency records. These relate to a clinician's professional performance rather than to anyone's health, so they are not special category data and no Article 9 condition applies to them.

Competency and assessment records: competency records, assessment scores and mentor feedback relate to a clinician's professional performance rather than to their health, and are not treated by us as special category data.

5A. Session Recordings: Retention, Learning Use, and Your Choices

Where a Session is recorded with the required consents, the recording is captured through our third-party Platform Providers (currently Zoom; Mentix is platform-agnostic and may use other providers under equivalent safeguards) and may be downloaded to Mentix-controlled storage.

We retain Session Recordings, competency data and assessment records for the duration of your relationship with Mentix. If you close your account or withdraw consent, identifiable data within Session Recordings will be permanently deleted within 10 calendar days.

We de-identify Session Recordings under our Redaction and De-identification Policy, and every recording passes a quality assurance review before it is admitted to the Mentix educational library. Once a recording has passed that review, the pre-redaction source is deleted and we retain no key, mapping, linkable identifier or unredacted copy by which any individual could be re-identified from the library material. That material is therefore anonymous so far as Mentix is concerned and is no longer personal data in our hands, although it may remain personal data for an institution that retains its own means of re-identification. De-identified recordings may be retained and used for the educational library and to improve and develop the Services, which may in future include machine learning and other analytical techniques applied to that material only. No identifiable recording is used for these purposes.

You may object to the use of recordings from your Sessions for Service-improvement purposes, or withdraw a previously given consent, at any time by emailing info@mentix.world. Objection or withdrawal does not affect processing that occurred before it and does not affect de-identified material that can no longer be linked to you.

Access to Session Recordings may include Mentix-engaged expert mentors located outside the UK / EEA, in which case the transfer safeguards described in section 9 apply.

6. How We Use Personal Data

We use personal data to:

(a) authenticate Users and provide secure access to the Platform;

(b) match Mentees and Mentors, schedule Sessions, and deliver the three Session Types (A, B, and C);

(c) capture, store, review, and replay procedural recordings for training, feedback, and competency tracking purposes;

(d) administer sponsorship packages and session credits for Industry Partners;

(e) handle invoices, payments, and Mentor fees;

(f) provide customer support and respond to enquiries;

(g) monitor, test, secure, and improve the Services, including the prevention and detection of fraud and abuse;

(h) produce de-identified analytics and aggregated performance metrics for Mentix, Industry Partners, and, where agreed, research collaborators;

(i) comply with law and respond to lawful requests from regulators, courts, and professional bodies;

(j) communicate operational, security, and service-related information to registered Users.

We do not use personal data for automated decision-making that produces legal or similarly significant effects about you without human involvement.

7. Sharing and Disclosure

Mentors, Mentees, and Industry Partners as necessary to deliver Sessions and administer sponsorship. Identifiable Patient Data is not shared with Industry Partners except in de-identified or aggregated form.

Our processors and sub-processors, which provide hosting, video streaming, authentication, storage, customer support, payments, and analytics services. Each processor is engaged under a written contract that imposes UK GDPR-compliant confidentiality, security, and sub-processing obligations.

Hardware and integration partners, including approved teleproctoring hardware vendors, in each case engaged under a written data processing agreement addressing ownership, storage, retention, and data residency of procedural material. No procedural material is routed through a hardware vendor before that agreement is in place.

Professional and regulatory bodies, where disclosure is required to verify credentials or to respond to a lawful request.

Legal and professional advisers, such as auditors, insurers, and lawyers, where reasonably necessary for legitimate business purposes.

Actual or prospective purchasers in connection with a merger, acquisition, reorganisation, or asset transfer, subject to appropriate confidentiality and data protection safeguards.

We do not sell personal data, and we do not share personal data with advertising networks.

8. International Transfers

Personal data processed through the Services is hosted primarily within the United Kingdom and the European Economic Area. Some of our sub-processors operate in other jurisdictions. Where personal data is transferred outside the UK or EEA:

(a) we rely on UK or EU adequacy decisions where available;

(b) otherwise, we use the International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses as appropriate, together with supplementary technical and organisational measures;

(c) we assess the legal environment of the destination country and apply additional safeguards where required.

You may request a copy of the transfer safeguards relating to your personal data by contacting us.

9. Retention

We retain personal data only for as long as necessary for the purposes for which it was collected:

(a) Account data: for the life of the account and for a reasonable period after closure to handle legal, audit, or dispute resolution requirements.

(b) Procedural video and related training content: identifiable Session Recordings are retained for the duration of your relationship with Mentix, and are deleted within 10 calendar days of account closure or withdrawal of consent, as described in section 5A. De-identified recordings admitted to the educational library are retained for 24 months by default and may be retained for longer where a Mentee, host institution, research protocol, or law requires it. Shorter periods apply where the treating institution instructs earlier deletion, and a host institution may require deletion of any recording originating from its sites at any time.

(c) Commercial records: for the period required by tax, accounting, and corporate law (typically six years in the United Kingdom).

(d) Security logs: for the period needed for operational and security purposes, generally not exceeding 12 months unless a specific investigation requires otherwise.

At the end of the applicable period, personal data is deleted or anonymised using appropriate measures.

10. Your Rights

Subject to the conditions set out in UK and EU data protection law, you have the right to:

(a) access the personal data we hold about you and receive a copy;

(b) ask us to correct inaccurate or incomplete personal data;

(c) ask us to delete personal data where we no longer have a lawful basis to hold it;

(d) ask us to restrict processing while a concern is being resolved;

(e) object to processing based on legitimate interests;

(f) request the personal data you have provided to us in a structured, commonly used, machine-readable format, and ask us to transmit it to another controller (data portability);

(g) withdraw consent at any time, where we rely on consent;

(h) lodge a complaint with a supervisory authority.

The United Kingdom supervisory authority is the Information Commissioner's Office (ICO), https://ico.org.uk. In the EEA, you may complain to the supervisory authority of the member state in which you live, work, or where the alleged infringement took place.

To exercise a right, please contact us at info@mentix.world. We will respond within one month, or notify you within that period if we need a longer time to handle a complex request.

10A. Data Protection Officer

Mentix is appointing an external Data Protection Officer. Until that appointment is confirmed, data protection oversight is exercised by our Founder and Chief Executive with external information governance support, and all data protection enquiries should be addressed to info@mentix.world. We will publish the name and contact details of the Data Protection Officer in this Policy once the appointment is made.

11. Security

We apply appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, role-based access controls, multi-factor authentication for administrative access, logging and monitoring, secure software development practices, regular vulnerability management, and restricted access for sub-processors. We review these measures and update them as the Services evolve.

No internet transmission or storage system is completely secure. If we become aware of a personal data breach that meets the applicable notification threshold, we will notify regulators and affected individuals as required by law.

12. Website, Cookies, and Similar Technologies

The Website uses only essential first-party cookies and similar technologies required for security, load balancing, authentication sessions, and basic site functionality. We do not use analytics, advertising, or cross-site tracking cookies. The Cookie Policy provides further detail.

13. Third-Party Links

The Website and Platform may contain links to third-party sites. We are not responsible for the content or privacy practices of those sites. We encourage you to read the privacy policies of any third-party site you visit.

14. Changes to This Policy

We may update this Policy from time to time. The version number and effective date at the top of the Policy will be updated. Where changes are material, we will notify registered Users by email or through the Platform in advance of the change taking effect.

Version history. v2.4 (26 September 2026): confirms that Mentee assessment and competency records relate to professional performance, are not special category data and require no Article 9 condition; the earlier note that this was under review is withdrawn. v2.3 (2 September 2026): section 5 extended to record that Mentix holds no means of re-identifying a patient from retained material once the quality assurance check is complete. v2.2 (22 August 2026): section 5 revised so that Mentix no longer selects the Article 9 condition for patient-derived material; the controller does. v2.1 (29 July 2026) and earlier: superseded. None of these changes alters the categories of data processed, retention periods, or your rights.

15. Contact

For any data protection enquiry or to exercise a right under this Policy, please contact:

Mentix Ltd

9 Upper Wimpole Street

London W1G 6LJ

United Kingdom

Email: info@mentix.world