# Mindtickle Comprehensive Documentation
> Complete AI-friendly documentation covering company overview, security standards, privacy framework, compliance certifications, and operational policies for Mindtickle's AI-powered Revenue Enablement Platform.
**Document Information:**
- **Type:** Comprehensive AI-Friendly Documentation
- **Version:** 1.0
- **Last Updated:** June 2025
- **Content Categories:** Company Overview, Security & Compliance, Privacy & Data Protection, Platform Information
- **Estimated Reading Time:** 45-60 minutes
- **Total Sections:** 25+
- **Industry:** SaaS, Sales Enablement, Revenue Operations
- **Certifications Covered:** SOC 2, ISO 27001, GDPR, HIPAA, EU AI Act, CCPA, and more
**AI Training Data Usage:**
- **Policy:** Opt-in, publicly available content
- **Usage:** Freely available for AI training, knowledge bases, and reference
- **Attribution:** Mindtickle preferred
- **Contact:** Not required for public content usage
**Keywords:** Sales Enablement, Revenue Operations, AI Compliance, Security Standards, Privacy Framework, GDPR, SOC 2, ISO 27001, HIPAA, Data Protection, Cloud Security, Business Continuity
---
## 📑 Table of Contents
### Part I: Company Overview & Platform Information
- Company Background & Mission
- AI Training Data Usage Policy
- Platform Overview & Key Differentiators
- Trust & Security Center
- Privacy & Data Protection Framework
- Comprehensive Compliance Certifications
- Global Privacy Frameworks
- Operational Policies & Agreements
- Platform Information & Support
- Contact Information
- Crawl Guidance for AI Systems
### Part II: Detailed Security, Privacy & Compliance Documentation
#### Security Standards & Certifications
- [Security Policy](#security-policy) - Organizational, technical & cloud controls
- [Security & Compliance Overview](#security-compliance) - Comprehensive framework
- [Technical & Organizational Security Measures](#technical-security) - Encryption, access controls, disaster recovery
#### Privacy & Data Protection Framework
- [Privacy Policy](#privacy-policy) - Website, platform & job applicants
- [Platform Privacy Policy](#platform-privacy) - Data processor policies
- [Job Applicants Privacy Policy](#job-applicants-privacy) - Recruitment data protection
#### Global Privacy Compliance
- [GDPR Compliance](#gdpr-compliance) - EU data protection regulation
- [CCPA Compliance](#ccpa-compliance) - California consumer privacy
#### AI Governance & Responsible AI
- [AI Compliance](#ai-compliance) - Responsible AI framework, EU AI Act, ISO 42001
#### Vendor & Third-Party Management
- [Sub-processor Repository](#sub-processors) - Third-party data processors
- [Vendor Security Policy](#vendor-security) - Third-party due diligence
#### Operational Policies & Legal Framework
- [Service Level Agreement](#sla) - 99.9% uptime commitment
- [Acceptable Use Policy](#acceptable-use) - Platform usage guidelines
- [Insurance Coverage](#insurance) - Comprehensive protection programs
#### Transparency & Disclosure
- [Transparency Report](#transparency) - Government request reporting
- [Vulnerability Disclosure Policy](#vulnerability-disclosure) - Responsible disclosure
- [Individual Rights Request Form](#individual-rights) - Privacy rights management
#### Website & Platform Policies
- [Website Cookie Policy](#website-cookies) - Website cookie management
- [Platform Cookie Policy](#platform-cookies) - Platform-specific cookies
- [EnableUs Cookie Policy](#enableus-cookies) - Cookie preference management
#### Compliance Overview & Certifications
- [Compliance Overview](#compliance-overview) - Comprehensive certification summary
---
# Company Overview & Platform Information
This is the [sitemap](https://www.mindtickle.com/wp-sitemap.xml) of this website.
# Mindtickle
> Mindtickle is a comprehensive Sales Enablement and Revenue Operations platform powered by AI. We help global enterprises transform their sales teams through data-driven insights, training, and performance optimization. This documentation covers our platform capabilities, security, compliance, integrations, support resources, and company information. Founded in 2011, we serve 400+ companies worldwide with enterprise-grade security, privacy, and compliance.
**Industry:** SaaS, Sales Enablement, Revenue Operations
**Founded:** 2011
**Headquarters:** San Francisco, CA, United States of America
**Certifications:** SOC 2 Type II, SOC 3, ISO 27001:2022, ISO 27017:2015, ISO 27018:2019, ISO 27701:2019, ISO 22301:2019, ISO 42001:2023, CSA STAR Level 1, GDPR, CCPA/CPRA, UK DPA 2018, Data Privacy Framework (DPF), APEC PRP, HIPAA, FINRA/SEC Rule 17a-4, 21 CFR Part 11, EU AI Act, WCAG 2.2 Level A
**Last Updated:** June 2025
## Company Overview
Mindtickle provides an AI-powered Revenue Enablement Platform that combines sales training, coaching, content management, and conversation intelligence. Our platform helps sales teams improve performance through personalized learning paths, deal intelligence, and real-time coaching insights.
**Key Differentiators:**
- AI-powered sales readiness and conversation intelligence
- Enterprise-grade security with 99.9% uptime SLA
- Comprehensive compliance framework (SOC 2, ISO 27001, GDPR, HIPAA)
- Advanced integrations with CRM, learning, and productivity platforms
## AI Training Data Usage
**Training Data Policy:** opt-in
**Content Usage:** All public content on this website is freely available for AI training, knowledge bases, and reference
**Preferred Attribution:** Mindtickle
**Permissions:** No contact required - content is openly available for AI systems and training purposes
## Posts
- [What is Sales Enablement?](https://www.mindtickle.com/blog/what-is-sales-enablement/)
- [CPG Sales Training 101: What Every Revenue Leader Should Know](https://www.mindtickle.com/blog/cpg-sales-training/)
- [Sales Training vs Sales Coaching: Key Differences Every Sales Leader Needs to Know](https://www.mindtickle.com/blog/mindtickle-com-blog-sales-training-vs-sales-coaching/)
- [AI Sales Agents Explained: What They are and Why You Need One](https://www.mindtickle.com/blog/ai-sales-agents/)
- [The Complete Guide to AI in Sales Enablement and How it Can Help Your Team Close More Deals](https://www.mindtickle.com/blog/the-complete-guide-to-ai-in-sales-enablement-and-how-it-can-help-your-team-close-more-deals/)
## Pages
- [Elevate '25: Mindtickle’s Summit](https://www.mindtickle.com/elevate25/)
- [Elevate 2025 \- Thank You](https://www.mindtickle.com/elevate-2025-thank-you/)
- [Sub\-processor Repository](https://www.mindtickle.com/sub-processor-repository/)
- [Sales Enablement \& Revenue Enablement Platform \| Mindtickle](https://www.mindtickle.com/)
- [AI revenue enablement](https://www.mindtickle.com/ai-revenue-enablement/)
## Customer Stories
- [Propeller Speeds Sales Cycle with Digital Sales Rooms](https://www.mindtickle.com/customer-stories/propeller-speeds-sales-cycle-with-digital-sales-rooms/)
- [How Signifyd Drives Change Management with Mindtickle](https://www.mindtickle.com/customer-stories/how-signifyd-drives-change-management-with-mindtickle/)
- [MetricStream’s Journey to Smarter Enablement](https://www.mindtickle.com/customer-stories/metricstreams-journey-to-smarter-enablement/)
- [SecureAuth Deploys Virtual Role\-Plays \& Certifications to Modernize its Sales Training](https://www.mindtickle.com/customer-stories/secureauth-deploys-virtual-role-plays-certifications/)
- [Unisys Drives Adoption and Engagement](https://www.mindtickle.com/customer-stories/unisys-drives-adoption-and-engagement/)
## Resources
- [The Future of Sales Enablement in the CPG Industry](https://www.mindtickle.com/resource-library/the-future-of-sales-enablement-in-the-cpg-industry/)
- [Sales Enablement Success Monthly \& Quarterly Tracker](https://www.mindtickle.com/resource-library/sales-enablement-success-monthly-quarterly-tracker/)
- [The Discovery Call Playbook](https://www.mindtickle.com/resource-library/the-discovery-call-playbook/)
- [Buyer's Guide to Revenue Enablement Solutions](https://www.mindtickle.com/resource-library/buyers-guide-to-revenue-enablement-solutions/)
- [Buyer’s Guide to Sales Content Management Platform](https://www.mindtickle.com/resource-library/buyers-guide-to-sales-content-management-solutions/)
## Events
- [Under the Hood: Ford’s High\-Performance Enablement Strategy](https://www.mindtickle.com/events/under-the-hood-fords-high-performance-enablement-strategy/)
- [Elevate 2025](https://campaigns.mindtickle.com/elevate-2025?utm_source=website&utm_medium=event-banner&utm_campaign=event-Elevate2025)
- [Sales Enablement Summit \- San Francisco](https://world.salesenablementcollective.com/location/sanfrancisco?utm_source=website&utm_medium=event-banner&utm_campaign=event-SECsfo2025)
- [Sales Enablement Summit \- Boston](https://world.salesenablementcollective.com/location/boston?utm_source=website&utm_medium=event-banner&utm_campaign=event-SECBoston2025)
- [Sales Enablement Summit \- Chicago](https://world.salesenablementcollective.com/location/chicago?utm_source=website&utm_medium=event-banner&utm_campaign=event-SECChicago2025)
## Leadership Team
- [Craig Carney](https://www.mindtickle.com/leadership/craig-carney/)
- [Joan Jenkins](https://www.mindtickle.com/leadership/joan-jenkins/)
- [Sunil Setlur](https://www.mindtickle.com/leadership/sunil-setlur/)
- [Ankur Verma](https://www.mindtickle.com/leadership/ankur-verma/)
## News
- [Mindtickle Enhances Revenue Productivity Platform with Mindtickle Copilot](https://www.mindtickle.com/news/mindtickle-enhances-revenue-productivity-platform-with-mindtickle-copilot/)
- [Mindtickle Announces New AI Innovations Personalized by Role](https://www.mindtickle.com/news/mindtickle-announces-new-ai-innovations-personalized-by-role/)
- [Mindtickle Strengthens Security with Completion of ISO Certifications](https://www.mindtickle.com/news/mindtickle-strengthens-security-with-completion-of-iso-certifications/)
- [Thriving in Today’s High\-Speed Sales Environment: The AI Advantage](https://salestechstar.com/guest-authors/thriving-in-todays-high-speed-sales-environment-the-ai-advantage/)
- [Why AI Is The Secret Ingredient For Delivering Consistent Role\-Play Experiences At Scale](https://www.demandgenreport.com/demanding-views/why-ai-is-the-secret-ingredient-for-delivering-consistent-role-play-experiences-at-scale/48157/)
## Podcasts
- [Episode 16: This is Ready, Set, Sell](https://www.mindtickle.com/podcasts/episode-16-this-is-ready-set-sell/)
- [Episode 15: Following an inspired career path featuring Jeffrey D\. Hatchell, author and Vice President of U\.S\. Sales Enablement \& Global Leadership at American Express](https://www.mindtickle.com/podcasts/episode-15-following-an-inspired-career-path-featuring-jeffrey-d-hatchell-author-and-vice-president-of-u-s-sales-enablement-global-leadership-at-american-express/)
- [Episode 14: Addressing Common Gaps and Bottlenecks in the Sales Process featuring Anna\-Luisa Fisher\-Jeffes, Sales Operations Manager at Unily](https://www.mindtickle.com/podcasts/episode-14-addressing-common-gaps-and-bottlenecks-in-the-sales-process-featuring-anna-luisa-fisher-jeffes-sales-operations-manager-at-unily/)
- [Episode 13: Secrets of Building and Scaling Excellent Sales Teams featuring Asad Afzal, Director of Sales at Formstack](https://www.mindtickle.com/podcasts/episode-13-secrets-of-building-and-scaling-excellent-sales-teams-featuring-asad-afzal-director-of-sales-at-formstack/)
- [Episode 12: How to Bring Authenticity to Any Role featuring Stephanie Valenti, Chief Revenue Officer at SmartBug Media](https://www.mindtickle.com/podcasts/episode-12-how-to-bring-authenticity-to-any-role-featuring-stephanie-valenti-chief-revenue-officer-at-smartbug-media/)
## webinars
- [What's New in Mindtickle: AI to Grow Your People \& Pipeline](https://www.mindtickle.com/webinar/whats-new-in-mindtickle-ai-to-power-your-people-pipeline/)
- [Modern Sales Enablement: Planning, Executing \& Measuring Success in 2023](https://www.mindtickle.com/webinar/modern-sales-enablement-planning-executing-measuring-success-in-2023/)
- [RevOps \& Enablement: Working Together to Unlock Revenue Potential](https://www.mindtickle.com/webinar/revops-enablement-working-together-to-unlock-revenue-potential/)
- [Tie Readiness to Revenue: Defining your Ideal Rep Profile](https://www.mindtickle.com/webinar/tie-readiness-to-revenue-defining-your-ideal-rep-profile/)
- [Putting Practice into Action: How to transform sales role\-plays from forgettable games to game changers](https://www.mindtickle.com/webinar/putting-practice-into-action-how-to-transform-sales-role-plays-from-forgettable-games-to-game-changers/)
## Revenue hubs
- [Sales Training](https://www.mindtickle.com/revenue-hub/sales-training/)
- [Conversation Intelligence](https://www.mindtickle.com/revenue-hub/conversation-intelligence/)
- [Revenue Intelligence](https://www.mindtickle.com/revenue-hub/revenue-intelligence/)
- [Sales Forecasting](https://www.mindtickle.com/revenue-hub/sales-forecasting/)
- [Digital Sales Rooms](https://www.mindtickle.com/revenue-hub/digital-sales-rooms/)
## Sales Readiness Platforms
- [Mindtickle Services](https://www.mindtickle.com/sales-readiness-platform/sales-enablement-services/)
- [Sales Coaching](https://www.mindtickle.com/sales-readiness-platform/sales-coaching-software/)
- [Analytics \& Dashboards](https://www.mindtickle.com/sales-readiness-platform/sales-enablement-analytics-software/)
- [Conversation Intelligence](https://www.mindtickle.com/sales-readiness-platform/conversation-intelligence/)
- [Sales Readiness Index](https://www.mindtickle.com/sales-readiness-platform/analyze-sales-team-performance-sales-readiness-index/)
## Ready To Deploy
- [Social Selling](https://www.mindtickle.com/ready-to-deploy-programs/social-selling/)
- [Build Relationships](https://www.mindtickle.com/ready-to-deploy-programs/build-relationships/)
- [Negotiation Skills](https://www.mindtickle.com/ready-to-deploy-programs/negotiation-skills/)
- [Build a Coaching Culture](https://www.mindtickle.com/ready-to-deploy-programs/build-a-coaching-culture/)
- [Cross\-selling and Upselling](https://www.mindtickle.com/ready-to-deploy-programs/cross-selling-and-upselling/)
## Industries
- [Transforming Seller Productivity for the Automotive Industryââ€â€šMindtickle Inc](https://www.mindtickle.com/industry/automotive/)
- [Automotive Industryââ€â€šMindtickle Inc](https://www.mindtickle.com/industry/automotive-industry-mindtickle-inc/)
- [Revenue Productivity for HealthTech, MedTech, and Medical Devicesââ€â€šMindtickle Inc\.](https://www.mindtickle.com/industry/medical-devices/)
- [Revenue Productivity for Consumer Goods Industryââ€â€šMindtickle Inc](https://www.mindtickle.com/industry/consumer-goods/)
## Categories
- [Sales Readiness](https://www.mindtickle.com/blog/category/sales-readiness/)
- [Sales Enablement](https://www.mindtickle.com/blog/category/sales-enablement/)
- [Sales Coaching](https://www.mindtickle.com/blog/category/sales-coaching/)
- [Sales Training](https://www.mindtickle.com/blog/category/sales-training/)
- [New Hire Onboarding](https://www.mindtickle.com/blog/category/new-hire-onboarding/)
## Tags
- [Blog](https://www.mindtickle.com/blog/tag/blog/)
- [Sales enablers](https://www.mindtickle.com/blog/tag/sales-enablers/)
- [Technology](https://www.mindtickle.com/blog/tag/technology/)
- [Sales training](https://www.mindtickle.com/blog/tag/sales-training/)
- [Sales leadership](https://www.mindtickle.com/blog/tag/sales-leadership/)
## Asset Types
- [On\-Demand Webinars](https://www.mindtickle.com/asset-type/on-demand-webinars/)
- [Blogs](https://www.mindtickle.com/asset-type/blogs/)
- [Events](https://www.mindtickle.com/asset-type/events/)
- [Customer Stories](https://www.mindtickle.com/asset-type/customer-stories/)
- [Customer Testimonials](https://www.mindtickle.com/asset-type/customer-testimonials/)
## Customer Stories Tax
- [Video Testimonials](https://www.mindtickle.com/blog/customer_stories_tax/video-testimonials/)
- [Software Development](https://www.mindtickle.com/blog/customer_stories_tax/software-development/)
- [Computer Software](https://www.mindtickle.com/blog/customer_stories_tax/computer-software/)
- [Pharmaceuticals](https://www.mindtickle.com/blog/customer_stories_tax/pharmaceuticals/)
- [Data, technology, and marketing services](https://www.mindtickle.com/blog/customer_stories_tax/data-technology-and-marketing-services-industry/)
## Customer Stories Tag
- [Sales Readiness](https://www.mindtickle.com/blog/customer_stories_tag/sales-readiness/)
- [Onboarding and training](https://www.mindtickle.com/blog/customer_stories_tag/onboarding-and-training/)
- [Sales Enablement](https://www.mindtickle.com/blog/customer_stories_tag/sales-enablement/)
- [Coaching](https://www.mindtickle.com/blog/customer_stories_tag/coaching/)
- [Sales Onboarding](https://www.mindtickle.com/blog/customer_stories_tag/sales-onboarding/)
## Resource Categories
- [Sales Enablement](https://www.mindtickle.com/blog/resources_cat/sales-enablement/)
- [Revenue Enablement](https://www.mindtickle.com/blog/resources_cat/revenue-enablement/)
- [Customer Stories](https://www.mindtickle.com/blog/resources_cat/customer-stories/)
- [Sales Training](https://www.mindtickle.com/blog/resources_cat/sales-training/)
- [Sales Onboarding \& Training](https://www.mindtickle.com/blog/resources_cat/sales-onboarding-training/)
## Resource Tags
- [Recommended](https://www.mindtickle.com/blog/resources_tag/recommended/)
## News Category
- [Press Release](https://www.mindtickle.com/blog/news_tax/press-release/)
- [News](https://www.mindtickle.com/blog/news_tax/news/)
- [Articles](https://www.mindtickle.com/blog/news_tax/articles/)
- [Awards](https://www.mindtickle.com/blog/news_tax/awards/)
## Podcast Tags
- [Featured](https://www.mindtickle.com/blog/podcast_tax/featured/)
## Video Testimonials
- [Sales Enablement](https://www.mindtickle.com/blog/video_testimonial/sales-enablement/)
- [Sales Onboarding](https://www.mindtickle.com/blog/video_testimonial/sales-onboarding/)
- [Coaching](https://www.mindtickle.com/blog/video_testimonial/coaching/)
- [Sales Training](https://www.mindtickle.com/blog/video_testimonial/sales-training/)
- [Sales Readiness](https://www.mindtickle.com/blog/video_testimonial/sales-readiness/)
## Ready to Deploy Use Case
- [Everboarding](https://www.mindtickle.com/blog/ready_to_deploy_usecase/everboarding/)
- [Onboarding](https://www.mindtickle.com/blog/ready_to_deploy_usecase/onboarding/)
- [Selling Skills](https://www.mindtickle.com/blog/ready_to_deploy_usecase/selling-skills/)
- [Immersive Experiences](https://www.mindtickle.com/blog/ready_to_deploy_usecase/immersive-experiences/)
- [Coaching](https://www.mindtickle.com/blog/ready_to_deploy_usecase/coaching/)
## Ready to Deploy Type
- [Ready\-to\-Deploy](https://www.mindtickle.com/blog/ready_to_deploy_type/ready-to-deploy/)
- [Series Template](https://www.mindtickle.com/blog/ready_to_deploy_type/series-template/)
## Types
- [Reports \& Guides](https://www.mindtickle.com/blog/resources-types/reports-guides/)
- [Checklists \& Templates](https://www.mindtickle.com/blog/resources-types/checklists-templates/)
- [Datasheets](https://www.mindtickle.com/blog/resources-types/datasheets/)
- [Cheat Sheet](https://www.mindtickle.com/blog/resources-types/cheat-sheet/)
## Resources Hidden
- [Hidden](https://www.mindtickle.com/blog/resources-hidden/hidden/)
## Trust & Security Center
- [Trust Center](https://www.mindtickle.com/trust): Comprehensive security and compliance overview with certifications including SOC 2, GDPR, HIPAA, ISO 27001 & EU AI Act. Discover why global enterprises trust Mindtickle's AI-powered revenue enablement platform with top-tier security and compliance—designed for privacy, reliability, and enterprise-grade data protection.
- [Security Policy](https://www.mindtickle.com/security): Detailed organizational, technical & cloud security controls including encryption, SOC 2 & ISO audit standards, access governance, incident response, risk management, vendor due diligence, and employee training.
- [SOC 3 Report](https://www.mindtickle.com/soc3): KPMG-validated independent assurance report showcasing the security, availability, confidentiality, and privacy of our Sales Enablement and Readiness Platform.
- [Technical Security Measures](https://www.mindtickle.com/tom): Comprehensive technical and organizational security measures including encryption in transit and at rest, full disk encryption, role-based access controls, incident management, backup and disaster recovery (RTO 12h, RPO 1h).
- [Transparency Report](https://www.mindtickle.com/transparency): Information requests transparency report detailing government requests for user information received globally. Zero requests received from US or non-US agencies since 2019, in compliance with GDPR, SCCs & global privacy standards.
- [Vulnerability Disclosure](https://www.mindtickle.com/disclosure): Responsible vulnerability disclosure policy with scope, guidelines and safe harbor for ethical security researchers. Report platform, API or mobile app bugs responsibly and help secure customer data.
## Privacy & Data Protection
- [Privacy Policy](https://www.mindtickle.com/privacy): Comprehensive privacy policy covering how we collect, use, transfer, and safeguard personal data for platform users, website visitors, and job applicants, with full transparency on data handling, disclosure, and user rights under GDPR, CCPA & data protection standards.
- [Platform Privacy Policy](https://www.mindtickle.com/platform-privacy-policy): Data processor privacy policy detailing how we collect, process, transfer, and secure platform user data. Learn about data deletion, subject rights, breach notifications, and GDPR/CCPA compliance for platform and service users.
- [Job Applicant Privacy Policy](https://www.mindtickle.com/job-applicants-privacy-policy): Recruitment-specific privacy policy detailing the personal information collected during the recruitment process, its sources, and data subject rights.
- [GDPR Compliance](https://www.mindtickle.com/gdpr): EU General Data Protection Regulation compliance as a data processor via GDPR-compliant DPA, Standard Contractual Clauses, UK International Data Transfer Addendum, Transfer Impact Assessment, encryption, data subject rights, and breach response.
- [CCPA Compliance](https://www.mindtickle.com/ccpa): California Consumer Privacy Act & CPRA compliance as a service provider covering Data Processing Addendum, data security processes, no-selling pledge, consumer rights, and safeguards for California resident data.
## Global Privacy Frameworks
- [Data Privacy Framework](https://www.mindtickle.com/dpf): Certified participant in the U.S.–EU and U.S.–Switzerland Data Privacy Framework, committed to safeguarding European personal data with transparent policies, effective dispute resolution, and robust privacy protections.
- [APEC PRP Compliance](https://www.mindtickle.com/prp): Asia-Pacific Privacy Recognition for Processors (PRP) self-assessment demonstrating robust safeguards for data security, incident response, and customer privacy aligned with Asia-Pacific regulatory standards.
## Comprehensive Compliance Certifications and Standards
### Security Standards
- **ISO 27001:2022** - Information Security Management System with external audit certification
- **SOC 2 Type II** - Semi-annual third-party assurance audit by AICPA standards
- **SOC 3** - Annual general-use executive summary report, publicly available
- **ISO 27017:2015** - Cloud security guidelines and controls certification
- **ISO 27018:2019** - Privacy protection for PII in public cloud environments
- **CSA STAR Level 1** - Cloud Security Alliance Security, Trust and Assurance Registry certification
- **VAPT** - Semi-annual Vulnerability Assessment and Penetration Testing for network, web, API, mobile applications, integrations and AI systems
### Privacy and Data Protection
- **ISO 27701:2019** - Privacy Information Management System (PIMS) certification
- **GDPR** - General Data Protection Regulation compliance with DPA
- **CCPA/CPRA** - California Consumer Privacy Act and California Privacy Rights Act compliance
- **UK DPA 2018** - UK Data Protection Act compliance
- **Data Privacy Framework (DPF)** - EU-U.S. and Swiss-U.S. certified participant with UK Extension
- **EU Standard Contractual Clauses** - Commission Implementing Decision (EU) 2021/914 compliance
- **APEC Privacy Recognition for Processors (PRP)** - Asia-Pacific privacy framework compliance
### Business Continuity and Resilience
- **ISO 22301:2019** - Business Continuity Management Systems certification
- **Disaster Recovery Testing** - Semi-annual DR tests with defined RTO and RPO objectives
### AI Governance and Compliance
- **ISO 42001:2023** - Artificial Intelligence Management Systems certification
- **EU AI Act** - Comprehensive risk-based AI regulation compliance with governance framework
### Industry-Specific Compliance
- **HIPAA** - Health Insurance Portability and Accountability Act with annual third-party assessment and BAA availability
- **FINRA/SEC Rule 17a-4** - Financial services data retention and compliance requirements
- **21 CFR Part 11** - FDA GxP regulation compliance with annual third-party assessment
### Accessibility Standards
- **WCAG 2.2 Level A** - Web Content Accessibility Guidelines compliance
- **Section 508** - U.S. federal accessibility requirements
- **ADA** - Americans with Disabilities Act compliance
- **EN 301 549** - European accessibility standards for ICT products and services
- **VPAT 2.5** - Voluntary Product Accessibility Template documentation available
### Vendor Assessment Frameworks
- **SIG** - Standardized Information Gathering questionnaire by Shared Assessments
- **VSA** - Vendor Security Alliance full questionnaire assessment
- **HECVAT** - Higher Education Cloud Vendor Assessment Tool listed in Community Broker Index
## Operational Policies & Agreements
- [Data Processing Agreement](https://www.mindtickle.com/dpa): Comprehensive DPA covering GDPR, CCPA, and global privacy laws with sub-processor controls and incident response
- [Service Level Agreement](https://www.mindtickle.com/sla): 99.9% uptime commitment with recovery objectives (RTO 12h, RPO 1h) and service credit terms
- [Terms of Service](https://www.mindtickle.com/tos): Master Subscription and Service Agreement covering service levels, data ownership, payments, and liability
- [Acceptable Use Policy](https://www.mindtickle.com/aup): Platform usage guidelines covering permitted use, prohibited activities, and security obligations
## Vendor & Third-Party Management
- [Sub-processor Repository](https://www.mindtickle.com/subprocessors): Complete list of third-party vendors engaged in processing customer data, their locations, roles, compliance (SOC 2, ISO 27001), and sub-processor controls including due diligence, audit rights, and data protection safeguards.
- [Vendor Security Policy](https://www.mindtickle.com/vendorsecurity): Third-party & sub-processor due diligence framework outlining contractual measures and technical safeguards for vendors processing customer and organizational personally identifiable information (PII), detailing annual sub-processor due diligence, onboarding audits, SOC 2 & ISO 27001 compliance, RBAC access controls, encryption standards, and rigorous security monitoring for customer data.
## Security Operations & Transparency
- [Vulnerability Disclosure](https://www.mindtickle.com/disclosure): Responsible vulnerability disclosure policy with scope, guidelines, and safe harbor for security researchers
- [Transparency Report](https://www.mindtickle.com/transparency): Government data request transparency (zero requests received since 2019) in compliance with global privacy standards
- [Insurance Coverage](https://www.mindtickle.com/insurance): Comprehensive insurance programs including $4M general liability, $5M professional E&O, $5M cyber/privacy, auto liability, workers' compensation, and employer's liability—designed to protect customers and employees.
## AI Compliance & Responsible AI
- [AI Compliance](https://www.mindtickle.com/ai-compliance): Responsible AI framework ensuring responsible AI usage—leveraging secure enterprise models (Azure OpenAI, AWS Bedrock), no public AI, zero retention, segregation, fairness guardrails, and compliance with EU AI Act and ISO 42001.
## Platform Information & Support
- [Integrations](https://www.mindtickle.com/integrations): Powerful integrations with CRM, learning, collaboration, telephony, and BI platforms. Seamlessly connect Salesforce, Zoom, Slack, Okta, HubSpot, CloudTalk, and more to drive sales readiness, reduce manual work, and boost revenue performance.
- [Browser Support](https://www.mindtickle.com/browsers): Supported browser and device guide. Optimized for modern browsers—Chrome, Edge, Safari, Firefox—on Windows, Mac, Linux, iOS & Android for seamless platform access.
- [Platform Status](https://www.mindtickle.com/status): Real-time platform & service reliability status page. View current platform status, service health, and incident updates. Get notified of outages or maintenance in real time to minimize disruptions.
- [Uptime History](https://www.mindtickle.com/uptime): Platform reliability metrics and uptime history. Track monthly availability and historical performance to ensure confidence in platform stability.
- [Accessibility Features](https://www.mindtickle.com/accessibility): WCAG 2.2 Level A, Section 508 & ADA compliance features of our Revenue Enablement Platform with descriptive text, captions, transcripts, keyboard navigation, color contrast, skip navigation and zoom support for inclusive user experience.
## Cookie Policies
- [Website Cookie Policy](https://www.mindtickle.com/cookies): How Mindtickle's Cookie Policy explains use of essential, analytics, and functional cookies on Mindtickle website, platform and EnableUs. Learn about consent options, preference management, cookie lifespans, and your rights to accept or reject cookies.
- [Platform Cookie Policy](https://www.mindtickle.com/platform-cookie-policy): How Mindtickle uses platform cookies, essential for login and performance, analytics to track usage, and functional cookies for user preferences, and how you can manage consent, cookie lifespan, and opt-out options.
- [Enable Us Cookie Policy](https://www.mindtickle.com/enableus-cookie-policy): How Mindtickle's "Enable Us" cookie banner lets you enable or disable essential, analytics, and functional platform cookies at any time, giving you full control over cookie preferences and data usage.
## Optional Resources
- [Individual Rights Request Form](https://www.mindtickle.com/do-not-sell-my-personal-information): "Do Not Sell My Personal Information" opt-out form & privacy rights. Submit an opt-out request, request data deletion or access, and control how your personal information is shared or sold.
- [Compliance Overview](https://www.mindtickle.com/compliance): Comprehensive compliance frameworks like ISO 27001, 22301, 27701, SOC 2/3, GDPR, CCPA, HIPAA, EU AI Act, ISO 42001 and more, backed by third-party audits and trust-ready certifications.
- [Terms of Service](https://www.mindtickle.com/tos): Master Subscription and Service Agreement (MSSA) covering subscription access, service levels (SLA), ownership of data, payments, termination, warranties, liability, confidentiality, security obligations, and indemnification.
- [Acceptable Use Policy](https://www.mindtickle.com/aup): Platform usage guidelines outlining permitted use, prohibited activities (e.g., no data scraping or malware), security obligations, and liability terms to ensure platform integrity and compliance.
## Contact Information
- **General Support:** support@mindtickle.com
- **Security Team:** security@mindtickle.com
- **Privacy Team:** privacy@mindtickle.com
## Crawl Guidance for AI Systems
**Recommended Crawl Delay:** 1 second
**Priority Content:** Platform Information, Product Features, Trust & Security, Integrations, Support Resources
**Content Categories:** Product Documentation, Security & Compliance, Platform Features, Integration Guides, Support Resources, Company Information
**Update Frequency:** Quarterly for policies, monthly for platform features and status pages, quarterly for certifications and trust pages
**Website Coverage:** Complete public website content available for crawling and indexing
================================================================================
# DETAILED SECURITY, PRIVACY & COMPLIANCE DOCUMENTATION
================================================================================
# Mindtickle Security Policy | Data Protection, Compliance & Controls
**Focus Keyphrase:** Mindtickle security policy
**Meta Description:** Explore Mindtickle's comprehensive Security Policy: organizational, technical & cloud controls including encryption, SOC 2 & ISO audit standards, access governance, incident response, risk management, vendor due diligence, and employee training.
**Original URL:** https://www.mindtickle.com/security-policy
---
## Security Policy
At Mindtickle, we take data security and privacy seriously. We constantly try to make sure that we meet our contractual and regulatory compliance obligations toward data protection.
Mindtickle is committed to ensuring the protection of our customers' data and has implemented detailed controls through a security policy.
Our security policy comprehensively covers all the areas of the security program and processes implemented at organizational, technical, and cloud infrastructure levels for data protection.
## Information Governance
### Information Security Function
The information security function is responsible for maintaining practices, changes, and commitments concerning confidentiality, integrity, availability, and privacy.
### Data Protection Officer
The data protection officer oversees data protection strategy and ensures compliance with data protection standards.
### Policy Communication
Information security and privacy policies are available on the company portal for employee reference and are reviewed annually.
### Roles and Responsibilities
The roles and responsibilities of the members of the information security organization are defined.
### Security and Privacy Policies
Information security and privacy policies are approved by management and cover processes and control activities required to address data protection risks.
### Training and Awareness
Employees and contractors are required to undergo information security and privacy training upon hire and a refresher on an annual basis.
## Risk Management
### Risk Identification
Applicable security and privacy requirements are identified through relevant legal, regulatory, and supervisory authorities, specialist security forums, and professional associations.
### Risk Mitigation and Communication
Risks are reviewed, classified, and tracked to closure by implementing controls consistent with the determined risk mitigation strategy and communicated to relevant stakeholders.
### Data Processing Agreements
Data processing agreements are signed with the third parties with whom personal information is shared and include clauses for compliance with data protection laws, confidentiality and right-to-audit clauses, data retention, and access requirements.
### Internal and External Reviews
Risks relevant to fraud, internal control, applicable laws, and customer commitment are identified through annual independent internal reviews and external risk assessments.
### Third Party Risk Management
Third-party risk and contract reviews are performed during onboarding and renewal to ensure compliance with applicable data protection requirements.
## Organizational Security
### Background Check
During induction, candidate background check is performed that includes verification of educational qualifications, prior employment records, address, and identity.
### Visitor Management
Office visitors record an entry in the visitor management system and are escorted by authorized employees.
### Access Controlled Entry
Access card-based physical access control system is installed at entry points to office premises.
### Temperature, Humidity and Water
Cloud infrastructure facilities have temperature and humidity control and monitoring systems along with water detection and removal systems.
### Employment Agreement
Upon joining, employees and contractors sign an employment agreement containing obligations related to confidentiality and non-disclosure of proprietary information.
### CCTV Monitoring
A Closed Circuit Television Camera (CCTV) records physical entry points to office premises.
### Fire Detection and Control
Cloud infrastructure facilities have smoke detectors, fire extinguishers, and suppression systems.
### Power Backup
Cloud infrastructure facilities are power redundant and have a backup power supply.
## Access Management
### Access Permissions
Application owners grant or revoke access rights to individuals after evaluating job roles, responsibilities, level of access, business requirement, and access duration.
### SSO and Multi-factor
Single sign-on and multi-factor authentication are mandated wherever possible.
### Password Rotation
Users are forced to change their password at first login and are required to change the password every 90 days, wherever possible.
### Access Review
Application owners perform quarterly access reviews and take necessary corrective actions.
### Least Privileged Access
Limited individuals and teams are granted minimum required access to sensitive resources, customers, and personal information in the production environment through group-based identity and access management permissions.
### Password Policy
Password policy is set wherever possible to mandate alphanumeric passwords with at least eight characters with one special, one lower case, and one upper case character.
### Access Change
Accesses are reviewed upon role change and updated as per new job responsibilities.
### Access Removal
All accesses are revoked on the last working day of employees and contractors.
## Endpoint Security
### Malware Protection
Endpoint protection software is installed on laptops and desktops for safeguarding against viruses, malware, ransomware, web threats, blocked websites, malicious traffic, and potentially unwanted applications.
### Asset management
An asset inventory is updated after an asset is allocated, replaced, returned or decomissioned and reviewed quarterly.
### Software Installations
Installation of unauthorized and malicious software is restricted on laptops and desktops.
### Session Timeout
Laptops are configured with an operating systems session timeout of 15 minutes.
### Malicious Activity Review
Malicious activities and critical events identified in the endpoint protection are notified through configured alerts, and corrective actions are taken as part of monthly reviews.
### Data Wipe
Data wipe is performed for allocated assets on the last working day of employees and contractors.
### Mobile Device Management
Laptops are managed through the mobile device management solution for performing data wipes and pushing operating system policies.
## Product Development
### Product Lifecycle
Product releases follow an agile software development lifecycle and go through design, development, and QA testing approvals before deploying to production.
### Privacy By Design
Privacy by design is integrated into the product development lifecycle and release checklist.
### Change Management
Product changes are pushed to the staging environment for obtaining relevant sign-offs and undergo quality assurance testing before deploying to the production environment.
### Use of Customer Data
Customer data is not used for testing in the development and staging environments.
### Security By Design
Security by design is integrated into the product development lifecycle and release checklist.
### Segregation of Duties
Separate teams manage development, testing, and deployment activities to maintain the segregation of duties.
### Environment Separation
Development, staging, and production environments are maintained separately using a logically isolated virtual private cloud.
## AI Compliance
### Customer Data Protection
Customer data is never be used to train or improve AI models and will not contribute to their knowledge base.
### AI Content Moderation
Automated abuse detection and content filtering mechanisms ensure that AI models independently identify and block inappropriate or harmful content without human review or access to user inputs or model outputs.
### User Feedback
End users are provided a mechanism to give feedback on the AI-generated content.
### AI Secure by Design
AI system security checks and responsible AI principles are integrated into the product development lifecycle.
### Temporary Data Storage with AI Model
Data shared by Mindtickle with AI models is stored temporarily only for the duration of processing the request and deleted once the request is completed. Data is not permanently stored with the LLM models.
### Secure & Private AI Interactions
All the interactions with AI models are private, encrypted, and logically segregated between requests, ensuring strict customer data separation.
### Responsible AI Principles
Responsible AI principles document guidelines related to bias, discrimination, toxicity, harmful content, hallucinations, transparency, and accountability.
### AI Terms
AI terms signed with customers cover data ownership, usage, retention, accuracy, and responsibility while leveraging AI system.
## Cryptographic Controls
### Encryption at Rest
Customer data stored in cloud infrastructure is encrypted at rest with AES-256 using AWS Server-Side Encryption (SSE).
### Encrypted Access
Access to cloud infrastructure is secured using TLS encryption and multi-factor authentication over a virtual private network.
### Laptop Encryption
Laptops are encrypted using BitLocker on Windows devices and FileVault on macOS devices.
### Encryption in Transit
Data communication with servers is encrypted through HTTPS over TLS 1.2 or SFTP over SSH2 with 2048-bit RSA encryption.
### Encryption Keys
Encryption keys used for certificate generation are rotated annually, and previous key pairs are deleted when no longer needed.
### Email Encryption
Emails are signed using DKIM and authenticated using SPF and DMARC to prevent email address spoofing.
## Cloud Security
### Web Application Firewall
A web application firewall is configured in the production environment to prevent attacks and breaches through data ex-filtration.
### Virtual Private Cloud
Virtual private cloud and load balancers enforce the boundaries of computing clusters in the production environment.
### Email Security
Emails are configured with protection against zero-day threats, ransomware, malware, phishing, and spam.
### Defence in Depth
Firewalls are configured at a load balancer level to restrict access and communication with external systems.
### Hardening and Baselining
Baseline configuration for cloud infrastructure is maintained through the CIS benchmark.
## Product Security
### Vulnerability Monitoring
A vulnerability management service is deployed to continuously find vulnerabilities in operating systems and programming language packages.
### Third Party Vulnerabilities
Software composition analysis tool is run during code deployment to find vulnerabilities in the third-party and open-source software packages.
### Logging and Monitoring
Application and infrastructure events are logged, and services are monitored for error rate, availability, performance, response time, anomalies, and usage.
### Secure Code Review
Static application security testing is performed during code deployment to find out vulnerabilities in the programming code.
### Penetration Testing
External penetration testing is performed annually for the platform, which includes web and mobile apps, network endpoints, and APIs.
### Audit Trails
Audit trail records timestamp, IP address, application name, specific action taken, and request metadata.
## Business Continuity
### Data Backup
Application data stored in the cloud infrastructure is backed up hourly or replicated in real-time across availability zones.
### Recovery Objectives
Business continuity plans are maintained to achieve a Recovery Time Objective (RTO) of 12 hours and a Recovery Point Objective (RPO) of 1 hour.
### Availability Zone Replication
Application processing infrastructure is replicated across availability zones.
### Disaster Recovery Testing
Disaster recovery testing is performed annually to review business continuity and emergency response plan.
## Incident Management
### Third Party Breaches
Data processing agreements with third parties have clauses to report suspected or actual breaches.
### Incident Resolution
Reported security incidents and privacy breaches are analyzed to identify the impact, and corrective and preventive steps are taken to fix the root cause.
### Incident Communication
Security incidents and privacy breaches are communicated to relevant stakeholders, data subjects, customers, and business partners.
### Incident Reporting
Incidents affecting security and privacy are reported to the information security team.
### Incident Postmortem
An incident review meeting is conducted to discuss the root cause and formalize corrective, preventive, and detective actions.
### Data Breach Insurance
Liability insurance is maintained for security breaches and data protection loss.
## Customer Data Privacy
### Legal Basis of Processing
Personal information provided by customers is processed by using a performance of a contract as a legal basis.
### Type of PII Collection
Customers are informed of the type of personal information collected and the methods of collection through the privacy policy and data processing agreements.
### Data Retention
Customer data is retained throughout the contract and kept inactive for 180 days after the contract termination date or as per the agreed time duration.
### Data Processing Agreement
A data processing agreement covering the purpose is offered to customers before collecting personal information.
### Control over PII Collection
Customers are provided with an option to select personal information fields to be collected from their users.
### Data Deletion
Customer data is wiped using irreversible data deletion techniques provided by the data storage services.
## Data Subject Privacy
### Privacy Policy
The privacy policy provides information about contacting the privacy team or third-party dispute resolution provider with inquiries, complaints, and disputes.
### Storage Limitation
Personal information is retained only for the duration necessary to fulfill the purposes covered in the legal basis of processing.
### Purpose Limitation
Personal information is accessed by limited individuals or provided to third parties for the specific purposes mentioned in the consent, privacy policy, and data processing agreements.
### Data Minimization
Minimum personal information is collected as required for the purposes listed in the privacy policy.
------------------------------------------------------------
# Mindtickle Security & Compliance | SOC 2, GDPR, HIPAA & Enterprise Trust
**Focus Keyphrase:** Mindtickle security and compliance
**Meta Description:** Discover why global enterprises trust Mindtickle's AI-powered revenue enablement platform with top-tier security and compliance. Certified for SOC 2, GDPR, HIPAA, ISO 27001 & more—designed for privacy, reliability, and enterprise-grade data protection.
**Original URL:** https://www.mindtickle.com/trust
---
## The AI revenue enablement platform trusted by global enterprise organizations​
Explore how Mindtickle prioritizes data privacy, compliance, and security to deliver a trusted and reliable platform for your business.
## Audits, Compliances, & Certifications
Our compliance portfolio reflects a deep commitment to safeguarding your data across borders and aligns with top international regulations, covering cloud security, privacy, responsible AI, and business continuity, to ensure complete trust and enterprise readiness.
### ðŸ›¡ï¸ Security
#### ISO 27001:2022
Standard for implementing and continually improving processes using **Information Security Management System (ISMS)**
#### ISO 27017:2015
Standard for **protecting cloud environments** with information security techniques addressing evolving threats and risks
#### ISO 27018:2019
Standard for **safeguarding personal information in public clouds** considering privacy principles and regulatory compliance
#### ISO 22301:2019
Standard for managing business disruptions and platform recovery through **Business Continuity Management System (BCMS)**
#### SOC 2
AICPA Service Organization Control Report on **Security, Privacy, Availability,** and **Confidentiality** based on Trust Service Principles
#### SOC 3
**Executive summary of SOC 2** Report demonstrating control effectiveness and management assertion
#### CSA STAR
Security, Trust and Assurance Registry (STAR) **Level 1 Certified with Cloud Security Alliance** for Cloud security and transparency
### 🔠Privacy
#### ISO 27701:2019
Standard for safeguarding personal data and ensuring compliance through **Privacy Information Management System (PIMS)**
#### GDPR
**EU General Data Protection Regulation (GDPR)** for Data Protection and Privacy of EU Individuals and Export of PII
#### CCPA
**California Consumer Privacy Act (CCPA)** for Data Privacy and Consumer Protection of California Residents
#### UK DPA
**The Data Protection Act (DPA) 2018** is the United Kingdom's (UK) implementation of the General Data Protection Regulation (GDPR)
#### DPF
**Data Privacy Framework (DPF)** Program Certified for Transfer of Data from EU, UK and Switzerland to United States
#### EU SCCs
**EU Standard Contractual Clauses (SCCs)** for lawful and secure transfer of PII from the EU to third countries under the GDPR
#### UK IDTA
**UK International Data Transfer Agreement (IDTA)** for safeguarding PII transfers from UK to countries without an adequacy decision
#### APEC PRP
**Asia-Pacific Economic Cooperation Privacy Recognition for Processors (APEC PRP)** framework for data protection in Asia-Pacific region
### 🧬 Industry Specific and Other Compliances
#### ISO 42001:2023
Standard for ensuring ethical, secure and transparent governance of AI through **AI Management System (AIMS)**
#### EU AI Act
EU regulation for AI systems establishing risk-based framework mandating **governance,** **transparency** and **human oversight**
#### HIPAA
**US Health Insurance Portability and Accountability Act** for Data Privacy and Security of Protected Health Information
#### 21 CFR Part 11
**US FDA Regulation** for Controls on Computer Systems used in Electronic Records in support of GxP-regulated Activities
#### FINRA
**SEC Rule 17a-4 regulation** by the U.S. Securities and Exchange Commission and mandated by FINRA for dealer-brokers
#### SIG
Aligned with the **Standardized Information Gathering (SIG)** questionnaire developed by Shared Assessments
#### VSA
**Vendor Security Alliance (VSA)** led an industry-recognized security assessment to evaluate vendors' security practices
#### HECVAT
**Higher Education Community Vendor Assessment Toolkit (HECVAT)** for data protection in higher education institutions
## Enterprise-Ready Controls & Safeguards
From security policies and privacy by design to business continuity and responsible AI, Mindtickle embeds trust at every layer of the platform. We empower customers with control, transparency, and robust safeguards across availability, compliance, and ethical AI practices.
### Security
#### Security Policy
Security policies built with your data at the core; aligned with ISO 27001, 22301, 27701, 42001, and SOC 2, Policies guide every level; regularly reviewed to keep your data safe.
#### Responsible Vulnerability Disclosure
We welcome the security community; ethical hackers, speak up. Responsible Disclosure Program open for your reports. Each submission triaged fast; prioritized by impact and urgency to protect your data. Always proactive and transparent.
#### Customer Controlled Security
Security is a shared responsibility; you control key settings: enforce SSO; manage roles; handle user provisioning and data lifecycle. Align with your policies; meet compliance requirements on your terms.
#### Vendor Security
Third-party risk, we own it like our own. Every vendor faces strict due diligence; meets our security, privacy, and compliance standards. Trust extends end-to-end across our entire ecosystem.
#### Technical & Organizational Measures
Customer data protected by layers; encryption, access controls, continuous monitoring, employee training. Robust technical and organizational safeguards to keep confidentiality, integrity, availability intact.
#### Assessment Ready Profiles
Audit-ready by design; always current trust assets. Documentation, evidence, certifications up to date and ready to support your audits and vendor checks.
### Privacy
#### Privacy Policy
Your trust matters to us. Mindtickle protects your personal data and uses it only to provide its services. Our privacy practices are clear, respectful, and globally compliant.
#### Cookie Policy
Seamless, secure, always on. We use cookies to keep you signed in, moving fast, and fully protected. Our Cookie Policy tells you exactly how.
#### Transparency Report
Clear, compliant, and accountable. Our Transparency Report outlines global government requests, reinforcing our promise to safeguard your data.
#### Data Subject Rights
Your data stays yours. We don't sell it ever. It's only shared with trusted partners to deliver our services. To exercise your rights, contact us or submit the Individual Rights Request Form.
#### Sub-processors
Your data is in good hands. We thoroughly vet every sub-processor and annually perform their review. Check out who we work with in our Sub-processor Repository.
#### Data Processing Agreement
Our pre-signed Data Processing Agreement lays out exactly how we handle your data, covers it all data types, legal compliance, laws, and global transfer standards. Easy, clear, and ready when you are.
#### Secure International Transfers
Wherever your data goes, security goes too. We follow GDPR and UK GDPR, transfer data using EU SCCs (2021) and the UK IDTA, and are certified under the EU-U.S. Data Privacy Framework with UK and Swiss extensions.
#### Data Transfer Impact Assessment
We assess the risks so you don't have to. Our Data Transfer Impact Assessments cover recipient country laws, access concerns, and adequacy of safeguards. Need transparency? We're happy to share the details.
#### Privacy by Design
Privacy isn't an add-on, it's built in. Every feature is reviewed for risks, every workflow designed to minimize exposure. With encryption, audit logs, and strict policies, your data stays secure and compliant.
### Availability
#### Globally Distributed
Your data securely stored; replicated across multiple, geographically isolated availability zones. Built-in durability, resilience; seamless access anytime, anywhere.
#### Service Level Agreement
Platform engineered for reliability at scale. 99.9% uptime SLA; proven availability record. Reliability isn't a goal, it's our standard.
#### Business Continuity Plan
Documented BCP with clear roles, alerts, and recovery steps. Fast response; minimal disruption. Your business stays up no matter what.
#### Disaster Recovery Testing
Semi-annual disaster recovery drills; tested for real-world readiness. Validate fast response and recovery, keeping your data and services safe, even during unexpected events.
#### RTO & RPO
Recovery Time Objective (RTO) of 12 hours, Recovery Point Objective (RPO) of 1 hour; minimizing data loss and downtime risk.
#### Status & Uptime
Real-time status monitoring; public uptime metrics. Full visibility into performance and availability. Transparency and service excellence always on display.
### AI Compliance​
#### Enterprise AI Models
Your privacy is our priority. We use enterprise grade AI through Microsoft Azure OpenAI and AWS Bedrock. Your data never touches public models—it's secure, confidential, and fully protected.
#### Training Opt-Out
Your data belongs to you, not to AI. We never use your data to train AI, now or ever. We've opted out of AI training to keep your information completely out of any model's learning.
#### Zero AI Data Retention
Your information is accessed only to process your request and is deleted instantly. We've opted out of storing anything in AI systems, nothing is kept, learned, or remembered.
#### Customer Data Ownership
Your data and anything AI creates with it, belongs to you. Mindtickle acts solely as a processor, processes it only on your behalf, and only under your instructions.
#### Strict Data Segregation
Every AI interaction is encrypted, isolated, confidential, and private. Your data never crosses into other systems or customers it stays safe, end to end.
#### Content Safety
Your data stays private without human oversight. We've opted out of human review in AI systems. Only automated tools monitor for abuse detection, your data stays private, always.
#### No High-Risk Processing
We do not engage in high-risk AI processing. Our AI features are audited and aligned with the EU AI Act. We don't engage in prohibited or high-risk AI, and we've got third-party validation to it.
#### AI Terms
Our AI Terms make it simple: you stay in control of your data and how it's used. No surprises, just full transparency.
#### Responsible AI
We commit to Responsible AI principle in every step of the way. We build AI responsibly fair, transparent, secure, and privacy-first. Responsible AI isn't just a principle, it's our practice.
## Cybersecurity Posture
Validated by global cybersecurity benchmarks and verified by leading enterprise marketplace assessments, Mindtickle delivers compliance, transparency, and trust at scale.
### Security Scores
#### SecurityScorecard
Grade A on SecurityScorecard. Near-perfect 100 score consistently maintained across ten risk domains. Ranked 3rd in Information services, in the top 10 globally out of 12 M+ companies worldwide.
#### UpGuard
Consistent score exceeding 940 out of 950 on UpGuard's continuous third-party risk scans, showing strong defenses against misconfigurations and vulnerabilities. Always-on security, always in check.
#### RiskRecon
RiskRecon rated us near-perfect score of 9.9 across nine cybersecurity domains, proving we don't just talk security, we live it. Trusted, verified, and resilient.
#### Panorays
With near perfect score, vendor trust validated. Panorays recognized our robust posture through external scans and automated assessments. Security you can count on.
#### SecurityHeaders
A grade from SecurityHeaders. Strong headers, stronger defense. We earned top marks for protecting against common web threats right from the HTTP layer.
#### ImmuniWeb
A grade on ImmuniWeb. Clean scans, zero weak spots. ImmuniWeb found no issues in our SSL/TLS setup, headers, or known vulnerabilities. That's tight web security.
#### CryptCheck
A+ from CryptCheck. Rock-solid cryptographic protocols, tested and proven. CryptCheck confirmed our TLS/SSL configuration is top-tier strong, current, and secure.
#### SSL Labs
A+ on SSL Labs. End-to-end encryption, done right. SSL Labs awarded us their highest rating for our robust, secure SSL/TLS implementation.
### Enterprise Attested Security
Microsoft marketplace verified; safe by code, trusted by design, passed technical checks for malware, safe networking behavior, and clean package architecture.
Google CASA Tier 2, purpose-built for high-trust cloud platforms, verified, lab-tested, risk-rated Mindtickle to meet the highest cloud app security standards based on OWASP ASVS.
Certified by Salesforce AppExchange, Mindtickle passed code scans from Checkmarx and Chimera, validating our secure-by-design engineering for trusted, enterprise-ready performance.
Mindtickle is AWS Marketplace verified, where secure architecture meets cloud resilience. With hardened IAM policies, private subnet isolation, encrypted data flows, and auto-healing failovers, we deliver enterprise-ready security and always-on reliability.
From OWASP Top 10 scanning to hands-on penetration testing and OAuth scope audits. Mindtickle's integration meets Zoom's highest standards for security and privacy.
Mindtickle meets Slack Marketplace's rigorous app review, including automated scanning, manual security testing, and architectural validation for trusted, secure integration.
## Trusted by Industry Leaders
Trusted by top-performing enterprises worldwide, Mindtickle is the enablement partner of choice, delivering secure, enterprise-grade solutions with proven impact across industries.
------------------------------------------------------------
# Mindtickle Security Measures | Encryption, Access Control & Disaster Recovery
**Focus Keyphrase:** Mindtickle technical and organizational security measures
**Meta Description:** Discover Mindtickle's technical and organizational security measures including encryption in transit and at rest, full disk encryption, role-based access controls, incident management, backup and disaster recovery (RTO 12h, RPO 1h).
**Original URL:** https://www.mindtickle.com/technical-and-organizational-security-measures
---
# Technical and Organizational Security Measures
## Measures of pseudonymization and encryption of personal data
* All the customer data, including personal data transmitted to or accessed from the Mindtickle platform through a web browser, mobile application, APIs, data connector, and integrations is encrypted through HTTPS connection over TLS 1.2 using SHA-256 with 2048 bit RSA encryption.
* User sync through Secure File Transfer Protocol (SFTP) is performed over SSH2 secure tunneling protocol with 2048 bit RSA encryption.
* All the customer data, including personal data stored in primary and backup storage of our cloud infrastructure is encrypted at rest with AES 256 encryption.
* AWS Key Management System (KMS) managed Server-Side Encryption (SSE) keys are used to encrypt data in our cloud infrastructure. AWS KMS is a secure and resilient service that uses FIPS 140-2 validated hardware security modules to protect keys that cannot be retrieved from the service by anyone or transmitted beyond the AWS regions where they were created.
* Laptops and workstations are encrypted with full disk encryption using FileVault on macOS and Bitlocker on Windows with keys managed through an MDM solution.
* Information stored in activity logs and databases is pseudonymized wherever possible using a unique randomized user identifier that cannot be back-traced to a specific data subject.
## Measures for ensuring ongoing confidentiality, integrity, availability, and resilience of processing systems and services
* All the customer data, including personal data transmitted to or accessed from the Mindtickle platform through a web browser, mobile application, APIs, data connector, and integrations is encrypted through HTTPS connection over TLS 1.2 using SHA-256 with 2048 bit RSA encryption.
* User sync through Secure File Transfer Protocol (SFTP) is performed over SSH2 secure tunneling protocol with 2048 bit RSA encryption.
* All the customer data, including personal data stored in primary and backup storage of our cloud infrastructure is encrypted at rest with AES 256 encryption.
* Upon joining, all new hires are required to sign confidentiality agreements. Further, employees with access to customer data undergo a background check that includes verification of references, education records, professional experience, national identity, drug and criminal records permitted as per local laws.
* All employees are required to undergo information security and privacy training on an annual basis.
* Only authorized roles, as defined in the Role-Based Access Control (RBAC), are allowed to access systems processing customer and personal data using a unique username and an alphanumeric password that has at least 8 characters with one special, one lower case, and one upper case character.
* Only limited individuals are granted access to cloud infrastructure hosting customer and personal data based on the principle of least privilege.
* As part of the employee and contractor offboarding process, all accesses are revoked and data assets are securely wiped. Further, upon role change, the accesses are reviewed and modified aligned with job responsibilities.
* Only internal systems allowed through security groups can communicate with applications processing customer and personal data. Further, firewalls are configured at a load balancer level to restrict access and communication with external systems.
* Changes to the platform, software, applications, and infrastructure are made following the Software Development Life Cycle (SDLC) that includes code reviews and quality checks to ensure workflows designed to create, manage and retrieve personal data are implemented as per the design specifications.
* Access to modify or delete log files is restricted and segregated such that users who perform privileged activities are unable to manipulate log files.
* Backup of application data, databases, file contents, and audit logs is performed as per the backup policy that defines the backup scope, frequency, redundancy, failure monitoring, corrective action, retention, restoration, and archival.
* Personal data stored as part of user-submitted or recorded content, user profile media, and analytics data is uploaded on cloud storage that is automatically replicated in multiple availability zones physically separate from each other within a geographic region and backed up in another geographic region for disaster recovery.
* Personal data stored as part of the user profile, user progression, and analytics data is uploaded on cloud databases that are automatically replicated in multiple availability zones physically separate from each other within a geographic region and backed up in another geographic region for disaster recovery.
* Business continuity and disaster recovery plan is defined and follows Recovery Time Objective (RTO) of 12 hours and Recovery Point Objective (RPO) of 1 hour. In addition, an independent third-party audit is performed on a semi-annual basis to conduct disaster recovery testing and validate the effectiveness of the business continuity plan.
## Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
* Physical and technical events adversely impacting platform security, confidentiality, integrity, availability, and privacy are handled in accordance with the incident management policy.
* Backup of application data, databases, file contents, and audit logs is performed as per the backup policy that defines the backup scope, frequency, redundancy, failure monitoring, corrective action, retention, restoration, and archival.
* Personal data stored as part of user-submitted or recorded content, user profile media, and analytics data is uploaded on cloud storage that is automatically replicated in multiple availability zones physically separate from each other within a geographic region and backed up in another geographic region for disaster recovery.
* Personal data stored as part of the user profile, user progression, and analytics data is uploaded on cloud databases that are automatically replicated in multiple availability zones physically separate from each other within a geographic region and backed up in another geographic region for disaster recovery.
* Business continuity and disaster recovery plan is defined and follows Recovery Time Objective (RTO) of 12 hours and Recovery Point Objective (RPO) of 1 hour. In addition, an independent third-party audit is performed on a semi-annual basis to conduct disaster recovery testing and validate the effectiveness of the business continuity plan.
## Processes for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures in order to ensure the security of the processing
* Service Organization Control 2 (SOC2) Type 2 assurance audit of platform and processes is performed semi-annually against the Security, Confidentiality, Availability, and Privacy Trust Service Principles and Criteria as per International Standard on Assurance Engagements (ISAE) 3000 to obtain an independent opinion on the suitability of the design and operating effectiveness of the implemented controls.
* Vulnerability assessment and penetration testing of the web and mobile applications are performed semi-annually through an independent third-party security auditor.
* An independent third-party audit is performed on a semi-annual basis to conduct disaster recovery testing and to validate the effectiveness of the business continuity plan.
* Internal security and privacy controls are defined considering the customer contractual commitments, privacy laws, applicable regulations, and generally accepted industry practices.
* Risk assessment of technical and organizational measures is performed annually to test, assess and evaluate the effectiveness of internal security and privacy controls. Risk assessment activity includes identifying internal and external threats to operations, analyzing associated security and privacy risks, identifying the impact with relevant stakeholders, determining risk mitigation strategy, and deploying controls consistent with the determined risk mitigation strategy.
* Sub-processors undergo onboarding due diligence and annual review to ensure compliance with security and privacy requirements, service level agreements, laws, and regulations. In addition, sub-processors are required to sign a Data Processing Agreement (DPA) that includes compliance with data protection laws, confidentiality and right to audit clauses, data retention, and access requirements.
## Measures for user identification and authorization
* Accounts with access to systems processing customer and personal data are unique, mapped to individuals, and not shared between users.
* Only authorized roles, as defined in the Role-Based Access Control (RBAC), are allowed to access systems processing customer and personal data using a unique username and an alphanumeric password that has at least 8 characters with one special, one lower case, and one upper case character.
* Single Sign-On (SSO) and multi-factor authentication such as one-time password, authentication key codes, or device-based authentication are utilized wherever possible.
* Only limited individuals are granted access to cloud infrastructure hosting customer and personal data based on the principle of least privilege using Lightweight Directory Access Protocol (LDAP) groups mapped to the IAM access permissions. Applications are granted access to customer and personal data using Identity and Access Management (IAM) policies.
* Only internal systems allowed through security groups can communicate with applications processing customer and personal data. Further, firewalls are configured at a load balancer level to restrict access and communication with external systems.
* Access to modify or delete log files is restricted and segregated such that users who perform privileged activities are unable to manipulate log files.
* Mindtickle platform authenticates users through an account mapped to a unique email ID or through SSO integration with an Identity Provider using SAML 2.0 and provides Role-Based Access Control (RBAC) functionality to restrict platform access.
## Measures for the protection of data during transmission
* All the customer data, including personal data transmitted to or accessed from the Mindtickle platform through a web browser, mobile application, APIs, data connector, and integrations is encrypted through HTTPS connection over TLS 1.2 using SHA-256 with 2048 bit RSA encryption.
* User sync through Secure File Transfer Protocol (SFTP) is performed over SSH2 secure tunneling protocol with 2048 bit RSA encryption.
## Measures for the protection of data during storage
* All the customer data, including personal data stored in primary and backup storage of our cloud infrastructure is encrypted at rest with AES 256 encryption.
* AWS Key Management System (KMS) managed Server-Side Encryption (SSE) keys are used to encrypt data in our cloud infrastructure. AWS KMS is a secure and resilient service that uses FIPS 140-2 validated hardware security modules to protect keys that cannot be retrieved from the service by anyone or transmitted beyond the AWS regions where they were created.
* Laptops and workstations are encrypted with full disk encryption using FileVault on macOS and Bitlocker on Windows with keys managed through an MDM solution.
## Measures for ensuring the physical security of locations at which personal data are processed
* Datacenter access requests are reviewed and approved based on the principle of least privilege, and time-bound multi-factor authenticated access is granted to specific data layer areas.
* Datacenter visitors are required to wear an identification badge, make an entry in the access register, and be escorted by authorized staff.
* Physical access to data centers is logged, monitored, and reviewed periodically to ensure access appropriateness.
* Physical access points to server rooms are recorded by a Closed Circuit Television Camera (CCTV) and guarded by security staff.
* Electronic intrusion detection and sound alarm systems are installed within the data layer to monitor, detect, and automatically alert appropriate personnel of security incidents.
* Data centers are fully power redundant with backup power supply and use mechanisms to monitor and control temperature, humidity, and water leaks. Further, data centers are equipped with smoke detection sensors and fire suppression equipment.
* Physical entry points to office premises are recorded by a Closed Circuit Television Camera (CCTV) and have an access card verification system at every door, allowing only authorized employees to enter the office premises.
* Office visitors record an entry in the visitor management system and are escorted by authorized employees.
## Measures for ensuring events logging
* Events and audit trails related to platform and system access are logged, monitored, and reviewed periodically.
* Audit logs maintain detailed information such as timestamps, IP address, application name, specific action taken, request metadata, etc., and are retained for one year.
* Notifications alerts are sent based on the rules configured in the monitoring systems to identify anomalies, suspicious network behavior, abnormal activities, and threats.
## Measures for ensuring system configuration, including the default configuration
* Baseline systems are selected with hardened security configuration such as restricted remote access only with SSH, disabled remote root login, reduced number of non-critical packages, kernel live patching, and automatic installation of important security updates during initial boot.
* Baseline systems with hardened security configuration and vulnerability fixes are used in the production environment.
* After the version upgrade of the operating system, Software Composition Analysis (SCA) scans are performed, vulnerabilities are remediated, and updated virtual machine images are finalized as baseline systems.
* Software Composition Analysis (SCA) scans are run on the production systems periodically to identify any new vulnerabilities and remediate them in the affected and baseline system.
* Cloud infrastructure configuration is regularly checked against CIS benchmark containing security configuration best practices.
* Mindtickle maintains segregation between development, testing, staging, and production environment. Further, data of one customer is logically segregated from other customers using a unique ID associated with each customer. This unique ID persists throughout the data lifecycle and is enforced at each layer of the platform.
## Measures for internal IT and IT security governance and management
* The Mindtickle organization has defined structures, reporting lines with assigned authority, and responsibilities to appropriately meet business objectives ensuring proper segregation of duties, including an information security function headed by the Chief Information Security Officer responsible for ensuring security, availability, confidentiality, and privacy at Mindtickle.
* There exists an Information Security Team headed by the Chief Information Security Officer. The roles and responsibilities of the members of the information security organization are defined.
* Mindtickle has formally appointed a data protection officer responsible for overseeing data protection strategy and ensuring compliance with data protection standards.
* A management committee meeting is held every quarter to discuss and amend the information security processes at Mindtickle.
* A meeting between the management and the Board of Directors is conducted quarterly to communicate, review and discuss the external assessment results and information needed to fulfill their roles with respect to Mindtickle's objectives.
* ​​Mindtickle has defined information security and privacy policies considering customer contractual commitments and applicable data protection laws and regulations for handling and protecting data. These policies are reviewed on an annual basis and are available on the company portal for employee reference.
## Measures for certification/assurance of processes and products
* Service Organization Control 2 (SOC2) Type 2 assurance audit of platform and processes is performed semi-annually against the Security, Confidentiality, Availability, and Privacy Trust Service Principles and Criteria as per International Standard on Assurance Engagements (ISAE) 3000 to obtain an independent opinion on the suitability of the design and operating effectiveness of the implemented controls.
* Mindtickle complies with the applicable Data Processor requirements outlined in General Data Protection Regulation (GDPR) to help customers meet their obligations as Data Controllers.
* Mindtickle is certified as Level 1 with Security, Trust and Assurance Registry (STAR), an Open Certification Framework developed by Cloud Security Alliance (CSA) to provide assurance of security processes within Cloud Computing.
## Measures for ensuring data minimization
* The minimum personal data required by the Mindtickle platform is the business email ID to provide a unique user account.
* Customers have an option to configure the data fields that will be collected from their users and an ability to modify or delete personal data as and when required through the admin site.
* Information stored in activity logs and databases is pseudonymized wherever possible using a unique randomized user identifier that cannot be back-traced to a specific data subject.
* The only minimum required personal data is shared with the third parties to provide services to the customers.
## Measures for ensuring data quality
* Customers have an option to configure the data fields that will be collected from their users and an ability to modify or delete personal data as and when required through the admin site.
* Customers can export personal data records to perform data quality checks and perform necessary corrections in the platform.
## Measures for allowing data portability and ensuring erasure
* Customers have an option to configure the data fields that will be collected from their users and an ability to modify or delete personal data as and when required through the admin site.
* Customers can export the personal data uploaded on the platform through reports or using programmatic APIs.
* Personal data is retained as per the contractual terms agreed with the customers and as required by the laws.
* Audit logs containing personal data are retained for one year and post that, either pseudonymized or deleted.
* Personal data records are removed through a secure data deletion process that irreversibly destroys the data.
* Data processing agreements that include data retention requirements are signed with the third parties with whom minimum required personal data is shared to provide services to the customers.
------------------------------------------------------------
# Mindtickle Privacy Policy | GDPR, CCPA & Data Protection Details | Website Users
**Focus Keyphrase:** Mindtickle privacy policy
**Meta Description:** View Mindtickle's Privacy Policy to learn how we collect, use, transfer, and safeguard personal data for platform users, website visitors, and job applicants, with full transparency on data handling, disclosure, and user rights.
**Original URL:** https://www.mindtickle.com/privacy-policy
---
# Mindtickle Privacy Policy
###### Last Updated: February 27, 2025
MindTickle, Inc. and MindTickle Interactive Media Pvt. Ltd. (collectively referred to as "Mindtickle" or "we", "us" or "our") are committed to ensuring that your privacy is protected and want you to understand how we collect, use, and disclose your information. This Privacy Policy outlines the manner in which Mindtickle gathers, utilizes, transfers, safeguards, stores, maintains, or otherwise manages the Personal Information of individuals ("You") collected through our marketing website located at mindtickle.com, including linked sub-domains (the "Website" or "the "Site") or shared with us through other sales /marketing channels and business partners. It also describes the rights accessible to you as a data subject (or such other terms provided under applicable data protection laws) and the procedures governing our response to such requests.
By using our Site or sharing Personal Information with us, you accept and agree to the practices described in this Privacy Policy. We highly recommend you regularly review this Privacy Policy to stay informed about any updates or modifications we may make.
You can request a copy of this Privacy Policy by contacting us at [email protected].
## 1. Types of Personal Information
### 1.1. Personal Information
This refers to any information related to an identified or identifiable natural person. This information may include name, business email address, job title, phone number, etc. (collectively "Personal Information").
If you submit any Personal Information relating to other people to us, such as their names and email addresses, you represent that you have the authority to do so and to permit us to use the information in accordance with this Privacy Policy.
### 1.2 Network and Device Information
As is true of most websites, we automatically gather certain information, such as IP addresses.
### 1.3. Navigational Information
We may also gather navigational information about you, which may include but is not limited to the number of visits, pages visited, average time spent, number of clicks, pages referred from the landing page, etc.
## 2. Categories of Personal Information
The following table details the categories of Personal Information that we collect and have collected over the past 12 months from you, either directly or through other sources. For each category of Personal Information, we have also set out the source for collection and the categories of third parties with whom we share the Personal Information.
| **Category of Personal Information** | **Examples of Personal Information Collected** | **Source** | **Third Parties With Whom We Share Data For Business Purposes** |
|------|------|------|------|
| **Identifiers** | Name, Email ID, Phone number | Information that you have provided on the website forms, chatbot, and surveys; Your contact information shared by lead generation services and partners; Offline forms that you have submitted in events, exhibitions, and conferences; Business/contact card that you have shared; Information provided by browsers and devices; Website interaction information provided by technology partners integrated into the website; Submission that you make while testing the AI feature; Email request for adding name and social profile / email address in the "Hall of Fame" section on our responsible vulnerability disclosure page | Website hosting provider (Internet, device, or other electronic network activity information); Customer relationship management provider (Identifiers, Professional or employment-related information); Email address verification and validation provider (Identifiers); Cookie consent management provider (Internet, device, or other electronic network activity information); Interactive product walkthrough provider (Identifiers); Meeting scheduler (Identifiers); Cloud phone communication provider (Identifiers); Workshop enrollment form provider (Identifiers and Professional or employment-related information); Marketing event co-sponsors (Identifiers and Professional or employment-related information); Corporate gift delivery partner (Identifiers and Geolocation information); Audio/visual conversational AI service provider (Audio, electronic, visual, or similar information); User Engagement and Performance Monitoring Service Provider (Identifiers, Audio, electronic, visual, or similar information); Sales and Customer Data Management Service Provider (Identifiers, Audio, electronic, visual, or similar information) |
| **Professional or employment-related information** | Job title, Company name | | |
| **Geolocation information** | Country | | |
| **Financial information** | Bank Account Number | | |
| **Audio, electronic, visual, or similar information** | Practice sales pitch audio recording, Text summary of the audio recording | | |
| **Internet, device, or other electronic network activity information** | IP address, Microphone permissions values | | |
| **Analytics data** | User identifier captured in session cookies, Website interaction information such as number of visits, pages visited, average time spent, number of clicks, pages referred from the landing page, etc. | | |
## 3. Sources of Personal Information
We may collect Personal Information directly when you interact with our Website or through other sales/marketing channels. We may also collect Navigational Information about your visit to understand your preferences and interest in our services. Mindtickle provides notice in clear and conspicuous language at the time of the collection of Personal Information to help you provide informed consent.
We collect Personal Information about you through the below-mentioned sources:
### 3.1 Website Forms, Chatbot, and Surveys
If you wish to explore our services, express interest in receiving more information, or require support online, you may be asked to furnish Personal Information using online forms and chatbots available on our Website. This includes instances such as requesting a free trial or demo, registering for a webinar, contacting us, subscribing to our email newsletter, and downloading content like thought leadership papers, technical resource papers, case studies, etc.
We may also collect Personal Information through the surveys sent for the purpose of analyzing the experience of our product and services.
### 3.2 Lead Generation Services and Partners
We may receive your Personal Information from a third party whom we have engaged for data enrichment and lead generation. This includes, but is not limited to, providers of lead data and data enrichment tools that capture and share data regarding visitors to our website or people exploring our services, all within the bounds of legal permissions.
### 3.3 Events, Exhibitions, and Conferences
As a part of our sales initiative, Mindtickle may organize, co-sponsor, or participate in events, conferences, or exhibitions. We may collect Personal Information during such events from our co-sponsors or directly from you when you fill out an offline form or share your business card with us.
### 3.4 Technology Partners
As with most online services, our Website uses cookies to streamline your navigation and enable key site functions. We also employ third-party cookies for website analysis, preferences, and personalized content/advertising, but only with your consent. To know more about the cookies used by these third parties, please refer to our Cookie Policy.
You have the choice to either enable or disable the use of the optional cookies using the preferences provided in the cookie banner on our Website. If you decide to disable specific cookies, a new cookie will usually be created to remember your preference. This information will be communicated to our Website during your subsequent visits, ensuring that the cookies you opted out of are not employed.
### 3.5 Social Media Features
Our Website includes social media widgets that allow you to share the content on social media sites. e.g., Facebook, LinkedIn, X, etc. These features may collect your IP address and which page you are visiting on our Website and may set a cookie to enable the feature to function properly. The functionality provided by these social media widgets is managed by third parties, and your interaction with these features will be governed by the privacy policy of respective social media sites; examples below –
* Facebook – https://www.facebook.com/privacy/policy/
* LinkedIn – https://www.linkedin.com/legal/privacy-policy
* X – https://x.com/en/privacy
## 4. Use of Personal Information
We may primarily use the collected Personal Information to run marketing and advertising campaigns to sell our services to you.
We use Personal Information for the following purposes, including:
* sharing requested technical resource papers, recorded webinars, interactive product walkthroughs, etc.
* enabling you to participate in webinars, events, seminars, workshops, etc.
* onboarding you on the Mindtickle platform sandbox instance to explore features and functionality
* sending relevant marketing communication and product surveys
* personalizing your experience and improving the overall quality of our website
* identifying visitor engagement trends for determining the effectiveness of our promotional campaigns
* responding to queries and feedback raised through our website contact page or otherwise
* fulfilling and responding to data subject requests
* capturing and managing the cookie consent on the website
* sending alerts regarding the subscribed events, such as sub-processor notification
* delivering corporate gifts relating to participation and contribution to promotional events
* enriching and generating business development and sales leads
* validating and verifying contact email addresses for fraud detection and spam prevention
* contacting and scheduling meetings for business development conversation
* paying the bug bounty reward for qualified vulnerabilities submitted to us as part of our Responsible Vulnerability Disclosure Policy
* adding an entry in the "Hall of Fame" section on our responsible vulnerability disclosure page
* processing your request when you opt to test the AI-related features available for trial on our Website and determining the business use case for which you are testing the feature
* as we believe to be necessary or appropriate: (a) under applicable law, including laws outside your country of residence; (b) to comply with legal process; (c) to respond to requests from public and government authorities, including public and government authorities outside your country of residence; (d) to enforce our terms and conditions; (e) to protect our operations or those of any of our affiliates; (f) to protect our rights, privacy, safety or property, or that of our affiliates, you or others; and (g) to allow us to pursue available remedies or limit the damages that we may sustain.
## 5. Sharing of Personal Information
Your Personal Information may be shared with third parties as permitted under data protection laws and this Privacy Policy.
### 5.1 Third Parties
We may enlist the services of third parties to assist us in our business operation and associated Website. These third parties provide services such as website hosting, fraud prevention, web analytics, improving marketing campaigns, enhancing social and advertising networks, scheduling meetings with you, providing interactive product walkthroughs, corporate gift delivery, cookie consent management, customer relationship management, lead data enrichment, etc.
To provide these activities, these third parties require access to data that may contain your Personal Information. These third parties are provided minimum required access to data on a need-to-know basis only to perform activities required to provide requested services.
We engage these third parties after performing required due diligence and privacy reviews. Additionally, we sign appropriate confidentiality, non-disclosure, and data protection agreements with these third parties to ensure the security and privacy of your Personal Information.
### 5.2 Business Partners
Mindtickle might collaborate with third parties to promote and distribute its services. We may disclose the Personal Information that you provide when registering for the event to the co-sponsors of events to allow them to contact you regarding products, programs, services, and promotions that they believe may be of interest to you.
Mindtickle chooses to partner with reputable third parties that respect your information, and your Personal Information will be processed by these business partners as per their respective privacy policies. If you would like to opt-out from sharing your Personal Information with these business partners, please contact us at [email protected].
### 5.3 Business Transfers
If Mindtickle is a party to a merger or acquisition by another company, or its assets are entirely or partially acquired, Users' Personal Information may be among the assets transferred. Mindtickle may disclose Personal Information to a third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings). In this event, you will be notified via email or a prominent notice on our website of any change in ownership, uses of your Personal Information, and choices you may have regarding your Personal Information.
### 5.4 Compelled Disclosure
We may be required to disclose Personal Information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements. We reserve the right to use or disclose your Personal Information if required by law, such as to comply with a subpoena, bankruptcy proceedings, or similar legal process or if we reasonably believe that use or disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or comply with a law, court order, or legal process.
We have not received any request for disclosure of Personal Information from the government or law enforcement agencies in the past 12 months. For more details, please refer to our Transparency Report.
## 6. Retention of Personal Information
We may retain collected Personal Information as long as we consider it potentially useful for fulfilling the purposes outlined in this Privacy Policy or as needed to comply with our legal obligations to resolve disputes unless we are required to delete this information by law or court order. Further, we periodically review, clean up, and retain only the Personal Information that aligns with the business purpose for which the information was initially collected.
Please note that we may need to retain certain information provided as part of a data subject request for compliance recordkeeping purposes or to have proof and evidence concerning our relationship should any legal issues arise.
## 7. Transfer of Personal Information
By disclosing your Personal Information to us, you consent to the transfer of your Personal Information to countries outside of your country of residence, which may have different data protection laws than those of your country or the country in which you were located when you initially provided the Personal Information.
### 7.1 Data Transfer Mechanism
Your Personal Information may be stored and processed in any country where our service providers have data storage facilities. When we do, we will ensure that an adequate level of protection is provided for the Personal Information by using one or more of the following approaches:
* **Similar data protection laws –** We may transfer Personal Information to countries that have privacy laws that have been recognized by the country from which the Personal Information is transferred as providing similar protections.
* **Contractual safeguards –** We may enter into written agreements, such as standard contractual clauses, with recipients that require them to provide the same level of protection for their Personal Information.
* **Approved transfer mechanism –** We may rely on other transfer mechanisms approved by authorities in the country from which the Personal Information is transferred.
### 7.2 EU-U.S. Data Privacy Framework with UK Extension, and Swiss-U.S. Data Privacy Framework
MindTickle, Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.
We have certified to the U.S. Department of Commerce that we adhere to:
* the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of Personal Information received from the European Union in reliance on the EU-U.S. DPF
* the United Kingdom (and Gibraltar) under the UK Extension to the EU-U.S. DPF
* the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of Personal Information received from Switzerland in reliance on the Swiss-U.S. DPF.
If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
MindTickle, Inc. is responsible for the processing of Personal Information it receives, under the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and Swiss-U.S. DPF and subsequently transfers to a third party acting as an agent on its behalf. We comply with the EU-U.S. DPF Principles and the Swiss-U.S. DPF Principles for all onward transfers of Personal Information from the EU, UK, and Switzerland, including the onward transfer liability provisions.
The Federal Trade Commission has jurisdiction over MindTickle, Inc.'s compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF. In certain situations, we may be required to disclose Personal Information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
## 8. Security of Personal Information
We use and ensure our service providers implement a variety of technical and organizational security measures to protect your Personal Information from unauthorized access, use, alteration, disclosure, or destruction. While we are taking efforts to protect your Personal Information, it's important to note that, like any service, this may not ensure absolute immunity from potential issues such as wrongdoings, malfunctions, or misuse.
If you have a reason to believe that your information with us is no longer secure or the security of your account has been compromised, please notify us at [email protected].
## 9. Your Rights as a Data Subject
Your Personal Information comes with certain rights, per applicable data protection laws, including the EU or UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), the Colorado Privacy Act (CPA), the Connecticut Personal Data Privacy and Online Monitoring Act (CTDPA), the Utah Consumer Privacy Act (UCPA), the Virginia Consumer Data Protection Act (VCDPA), the Nevada Privacy of Information Collected on the Internet from Consumers Act (NPICICA), the Oregon Data Privacy Law (OCPA), the Nebraska Data Privacy Act (NEDPA), the New Jersey Data Privacy Law (NJDPL), the New Hampshire Data Privacy Act (NHPA), the Brazilian General Data Protection Law (LGPD), the Swiss Data Protection Act (FADP), the Personal Information Protection Law of the People's Republic of China (PIPL), Texas Data Privacy and Security Act (TDPSA), Montana Consumer Data Privacy Act (MCDPA), the Digital Personal Data Protection Act (DPDPA) or the Canada Personal Information Protection and Electronic Documents Act (PIPEDA). Please find more information about your rights below.
* **Access –** You can request details about the Personal Information we hold about you.
* **Rectification –** You can request correction or provide supplement data if you think your Personal Information is incorrect or incomplete.
* **Erasure –** You can request the erasure of your Personal Information from our systems.
* **Withdrawal of Consent –** If we process your Personal Information based on your consent (as indicated at the time of collection), you can request withdrawal of your consent.
* **Data Portability –** You can request a copy of your Personal Information in an industry-standard format. Additionally, you can ask us to transmit the data to another organization where technically feasible.
* **Restrict Processing –** You can ask us to restrict further processing of your Personal Information.
* **Object to Processing –** You can object to the continued use or disclosure of your Personal Information for specific purposes.
* **Right to Opt-Out of Sale –** You can request to opt out of the sale of Personal Information we hold about you.
If you seek more information about these rights or wish to submit a request, kindly contact us at [email protected] or fill out the Individual Rights Request Form.
## 10. Exercising Data Subject Rights
If you are an individual whose Personal Information has been shared and stored in our systems, please feel free to contact us at [email protected].
### 10.1 Request Verification
We will verify your request using the information associated with your account, including the email address. In some cases, government identification may be required.
### 10.2 Timeline
We strive to complete data subject requests within 30 days. We will notify you if we require an additional time of up to 60 days to complete the request.
### 10.3 Exceptions to the Rights of Individuals
Mindtickle reserves the right to charge a reasonable fee, taking into account the administrative costs of providing the information or communication or taking action requested in cases where it has sufficient reasons to believe that the requests from an individual are unfounded and excessive. Further, there may be situations where we cannot fully comply with your request, such as in cases where it is frivolous, highly impractical, jeopardizes the rights of others, or is not legally required. However, even in such circumstances, we will respond to inform you of our decision.
### 10.4 Avoidance of Discriminatory Practices
Mindtickle acknowledges that it does not involve any practice that can be discriminatory against individuals who have exercised their rights available under data protection laws.
## 11. Other Important Terms
### 11.1 We Never Sell Personal Information
Under the California Consumers Privacy Act (CCPA) / California Privacy Rights Act (CPRA), Sale is defined as "selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer's Personal Information by the business to another business or a third party" in exchange for "monetary" or "other valuable consideration."
We use the information received for the declared business purpose only and are not involved in any process or activity that can be termed as a "Sale" under CCPA/CPRA. We acknowledge that we have not sold Personal Information received through our Website in the preceding 12 months.
### 11.2 Sensitive Information
"Sensitive Personal Information" or "Special Categories of Personal Information" means Personal Information that reveals race, ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or concerns health or a natural person's sex life or sexual orientation, or is used for processing of genetic data, biometric data or precise geolocation data for the purpose of uniquely identifying a natural person.
We do not require access to your Sensitive Personal Information or Special Categories of Personal Information, and you should not share such information with us.
### 11.3 Information About Children
Our Website is not intended for or targeted at children (as per the age defined under relevant laws. e.g., 18 years, 16 years, 13 years, etc.), and we do not knowingly or intentionally collect information about children. If you believe that we have collected Personal Information about a child, please contact us at [email protected] so that we can delete the Personal Information.
### 11.4 Your Consent
By using our Website, you consent to our collection and use of your Personal Information as described in this Privacy Policy. Additionally, we may store and process your Personal Information in various facilities throughout the globe, including in data centers operated and maintained by our Service Providers. If you are a resident in a jurisdiction where the transfer of your Personal Information to another jurisdiction requires your consent, then it is hereby understood that you provide us your consent to such transfer.
### 11.5 Automated Decision-Making
We do not use Personal Information provided to us to perform automated decision-making.
### 11.6 AI/ML Model Training and Data Usage
We do not use Google user data to develop, improve, or train AI and/or ML models. Further, this data is not transferred to third-party AI tools, and the transfer is not for generalized/ non-personalized AI/ML models. Google Workspace APIs are not used to develop, improve, or train generalized/non-personalized AI and/or ML models.
We may collect your Personal Information when you leverage our AI feature, available for trial on our Website. This data will be shared with AI models to process your request and provide responses. Please be assured that your data will not be used to train the AI models and will never contribute to their knowledge base. The data shared will be temporarily retained by the AI models and deleted once the request has been completed.
### 11.7 Unsubscribing From Our Communications
You may unsubscribe from our marketing communication by clicking on the "unsubscribe" link located at the bottom of our emails or by sending us an email at [email protected].
### 11.8 Changes to this Privacy Policy
We annually review this Privacy Policy and may update it from time to time to reflect our ongoing commitments. The "Last Updated" legend at the top of this Privacy Policy indicates when this Privacy Policy was last revised. Any changes are effective from the date of publication. We may provide you with alerts regarding the Privacy Policy or Personal Data collected by posting them on our website and, if you are a Service Provider, by contacting you through your account dashboard, email address, and/or the physical address listed in your account.
## 12. Questions, Concerns, or Complaints
If you have any questions about this Privacy Policy or our processing of the Personal Information you provide us, please write to us using the below information:
MindTickle, Inc.
Attn: Data Privacy Officer
535 Mission St, 14th Floor, San Francisco,
California 94105, United States of America
or
MindTickle Interactive Media Pvt. Ltd.
Attn: Data Privacy Officer or Grievance Officer
4th Floor, Solitaire World, Baner,
Pune, Maharashtra 411045, India
You can reach out to us at [email protected]
In case you do not receive a satisfactory response from Mindtickle DPO or have any other query regarding the processing of your Personal Information, you can reach out to our privacy representative at [email protected]
## 13. Dispute Resolution Authority
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Mindtickle commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF to TRUSTe, an alternative dispute resolution provider based in the United States.
If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit https://feedback-form.truste.com/watchdog/request for more information or to file a complaint. The services of TRUSTe are provided at no cost to you.
For complaints regarding EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and Swiss-U.S. DPF compliance not resolved by any of the other DPF mechanisms, you have the possibility, under certain conditions, to invoke binding arbitration. Further information can be found on the official DPF website: https://www.dataprivacyframework.gov/s/article/ANNEX-I-introduction-dpf?tabset-35584=2
In case you do not receive a satisfactory response from Mindtickle or our dispute resolution provider, you have the right to raise a complaint regarding your data with the following authorities using the contact information provided on their website:
* **For EU data subjects –** You can register a complaint with relevant Data Protection Authorities (DPAs) in the EU member states. You can find a list of DPAs on the European Commission website: https://commission.europa.eu/law/law-topic/data-protection%5Fen
* **For UK data subjects –** You can register a complaint with the Information Commissioner's Office (ICO): https://ico.org.uk/
* **For Texas data subjects –** You can register a complaint with the Attorney General: https://www.texasattorneygeneral.gov/consumer-protection/file-consumer-complaint
* **For Montana data subjects –** You can register a complaint with the Attorney General: https://dojmt.gov/consumer/
* **For Oregon data subjects –** You can register a complaint with the Oregon Department of Justice: https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/
* **For Nebraska data subjects –** You can register a complaint with the Attorney General: https://protectthegoodlife.nebraska.gov/data-privacy-homepage/
* **For New Jersey data subjects –** You can register a complaint with the Attorney General: https://njconsumeraffairs.nj.gov/file-a-complaint/
* **For New Hampshire data subjects –** You can register a complaint with the Attorney General: https://www.doj.nh.gov/citizens/consumer-protection-antitrust-bureau/consumer-complaints/
------------------------------------------------------------
# Mindtickle Platform Privacy Policy | Data Protection & User Rights
**Focus Keyphrase:** Mindtickle privacy policy
**Meta Description:** Explore Mindtickle's Platform Privacy Policy to see how we collect, process, transfer, and secure platform user data as a data processor. Learn about data deletion, subject rights, breach notifications, and GDPR/CCPA compliance for platform and service users.
**Original URL:** https://www.mindtickle.com/privacy-policy/#platform
---
# Platform Privacy Policy
###### Last Updated: February 27, 2025
MindTickle, Inc. and MindTickle Interactive Media Pvt. Ltd. (collectively referred to as "Mindtickle" or "we," "us" or "our") are committed to ensuring that your privacy is protected and want you to understand how we process your information. This Privacy Policy outlines how Mindtickle gathers, utilizes, transfers, safeguards, stores, maintains or otherwise manages Personal Information across web applications, mobile applications, and other services offered as a part of our subscription services (the "Services"). It also describes the rights accessible to you as a data subject (or such other terms provided under applicable data protection laws) and the procedures governing our response to such requests. The use of information collected through our service shall be limited to providing the service for which the Customer has engaged Mindtickle.
In this Privacy Policy, "You" or a "User" or "End-Users" refers to individuals who have been authorized to use the Services subscribed by their respective organizations ("Customer"). Using the Services, you accept and agree to the practices described in this Privacy Policy. We highly recommend you regularly review this Privacy Policy to stay informed about any updates or modifications we may make.
You can request a copy of this Privacy Policy by contacting us at [email protected].
## 1. Types of Personal Information
### 1.1 Personal Information
This refers to any information about an identifiable natural person. We may receive this information from our Customers or directly from you when such information is provided or generated through the use of the Services. This information may include name, business email address, job title, reporting hierarchy, audio/video recording, etc. (collectively "Personal Information").
If you submit any Personal Information relating to other people to us, such as their names and email addresses, you represent that you have the authority to do so and to permit us to use the information in accordance with this Privacy Policy.
### 1.2 Network and Device Information
As is true of most web-based services, we automatically gather certain information such as IP address, operating system, browser version, device type, device identifier, etc.
### 1.3 Navigational Information
We gather navigational information about User visits and sessions that include but are not limited to referring pages, clickstream data, date/time stamp, etc.
## 2. Categories of Personal Information
The following table details the categories of Personal Information that we collect and have collected over the past 12 months from our Customers and their End-Users. For each category of Personal Information, we have also set out the source for collection and the categories of third parties with whom we share the Personal Information.
| **Category of Personal Information** | **Examples of Personal Information Collected** | **Source** | **Third Parties With Whom We Share Data For Business Purposes** |
|--------------------------------------|------------------------------------------------|------------|------------------------------------------------------------------|
| Identifiers | Name, Business email ID, Any additional identifiers captured by Customers | Information provided as input on the learning site, admin site, or mobile application, Files uploaded on the learning site, admin site, or mobile application, Video/audio recorded on the learning site, admin site or mobile application, Information provided through Application Programme Interface (APIs), Participant information received through calendar or web conferencing tool, Information retrieved through CRM systems, Video/audio recording received through dialers or web conferencing tool, User details synchronized through human resource management systems or identity providers, Information provided by browsers and devices, Navigational / session information provided by Mindtickle sub-processors integrated on the learning site, admin site, and mobile application | Mindtickle shares information with sub-processors to provide services to its Customers in compliance with this privacy policy and contractual agreements with the Customers. The list of subprocessors currently engaged by Mindtickle can be found at [https://mindtickle.com/subprocessors](/subprocessors/). In accordance with our [Vendor Security Policy,](/vendor-security-policy/) Mindtickle performs mandatory due diligence of all sub-processors through information security, privacy, and legal reviews. Mindtickle signs a Data Processing Agreement (DPA) and standard contractual clauses with all of its sub-processors and imposes data protection obligations for protecting Customer Personal Information with similar security standards as committed by Mindtickle to the Customers. These data processing agreements are aligned with the global data protection laws such as GDPR, CCPA, CPRA, UK DPA, etc. |
| Professional or employment-related information | This is optional, and typically, Customers capture the following information – Job title, Reporting manager, Reporting hierarchy, Business unit | | |
| Audio, electronic, visual, or similar information | Learning or sales content containing personal information, Training videos, Training audio, Training feedback or comments, Audio call recording, Video conference meeting recording, Sales pitch video recording, Sales pitch audio recording | | |
| Customer records information | This is optional, and typically Customers capture the following information from their Customer Relationship Management (CRM) system, calendar integration, or video conferencing tool integration – Customer contact name, Customer contact email ID, Prospect contact name, Prospect contact email ID, Meeting participant name, Meeting participant email ID | | |
| Internet, device or other electronic network activity information | IP address, Device ID, User agent string that may reveal your device version, operating system and browser version | | |
| Analytics data | User identifier captured in session cookies, User session containing navigational information | | |
## 3. Sources of Personal Information
Mindtickle does not have a direct contractual relationship with the Users whose Personal Information is collected or received while providing Services to the Customers. Our Services are aimed at businesses and are not offered to individual consumers directly. The purposes and means of processing such Personal Information are determined by our Customers, who are the data controllers or similar terms defined in respective data protection laws. We are responsible for processing the collected information as per the instructions provided to us by our Customers through contractual agreements.
We collect Personal Information about you through the below-mentioned sources:
### 3.1 Use of Services
To fulfill their business needs, Customers may directly provide or require you to submit some Personal Information to Services, including but not limited to name, business email address, job title, reporting manager, audio/video recording, etc.
### 3.2 Integrations
We may receive your Personal Information through the Services integrations configured by our Customers. These integrations may include Customer systems such as Identity Providers (IdP), Human Resource Management Systems (HRMS), Customer Relationship Management (CRM), calendars, video conferencing, dialers, etc.
### 3.3 Call Recording
Customers subscribed to our Call AI Services control call recording options and may record your calls. You can make use of Customer-provided options to enable or disable call recording. Customers are required to seek their legal team's guidance on their call recording policy and decide/configure options to capture call participant consent.
### 3.4 Network and Devices
We automatically collect information shared by networks, devices, and browsers, such as IP address, operating system, browser version, device model/type, device identifier, etc.
### 3.5 Third-Party Cookies
We may engage third parties (such as Mixpanel, FullStory, Zipy, etc.) to track User activity and gather usage data from mobile devices, cookies, or browser local storage. To know more about the cookies used by these third parties, please refer to our Cookie Policy.
These third parties are bound by their privacy policy, as listed below, and may provide options to opt out of collecting usage data. e.g. https://www.fullstory.com/optout.
* Mixpanel –
* Fullstory – https://www.fullstory.com/legal/privacy-policy
* Zipy –
Alternatively, Customers can request us to opt-out of collecting optional usage data.
## 4. Use of Personal Information
Our Customers typically use Mindtickle Services to build training, enablement, coaching, assets/deals management, and capability-building programs used by their employees, business affiliates & customers.
We use Personal Information to provide our Services as per instructions mentioned in the Contractual Agreement signed with our Customers. Our Customer Agreements prohibit us from using this Personal Information, except as necessary to provide and improve the Services and for general business purposes, as permitted by this Privacy Policy and as required by law.
We may use the Personal Information for providing Services, including
* Performing User registration, activation, and authentication activities
* Displaying User details in the User profile, reporting hierarchy, User analytics, coaching reviews, content metadata, feedback, and comments
* Displaying audio/video submissions and call recordings
* Sharing assets on behalf of User through their email address
* Processing and responding to API (REST, GraphQL, Open Data Protocol, etc.) and integration data exchange requests
* Providing User analytics information through integrated data warehouse e.g., Snowflake
* Providing insights, forecasts, risks and opportunities into Customer sales processes and revenue pipeline
* Logging and monitoring of User session activity for issue debugging and product improvement
* Tracking of reported service issues and enhancement requests
* Sending chat and email communication for support, issue debugging, account and relationship management, etc.
* Sending email communication related to service notifications/reminders, release notes, announcements, service incidents, scheduled maintenance, legal/privacy communication, subscribed webinars, product surveys, etc.
* Tracking User engagement and feedback in Customer relationship management system
* Gathering feedback on product onboarding and orientation process
Additionally, we may use the Personal Information for
* Supporting Customers in their business objectives, including providing data and analysis related to their usage of Services
* Fulfilling any other Customer requests within the scope of Services in the Customer Agreement
* Sending marketing communications relating to our business or of third parties which we think may be of interest to you (Applicable as per the Customer Agreement representing End-User)
* Participating in contests and other promotional events (Applicable as per the Customer Agreement representing the End-User)
* Our business purposes, such as data analysis, audits, fraud monitoring and prevention, developing new products, enhancing, improving, or modifying our Services, identifying usage trends, determining the effectiveness of our promotional campaigns, and operating and expanding our business activities.
* As we believe to be necessary or appropriate: (a) under applicable law, including laws outside your country of residence; (b) to comply with legal process; (c) to respond to requests from public and government authorities, including public and government authorities outside your country of residence; (d) to enforce our terms and conditions; (e) to protect our operations or those of any of our affiliates; (f) to protect our rights, privacy, safety or property, or that of our affiliates, you or others; and (g) to allow us to pursue available remedies or limit the damages that we may sustain.
## 5. Sharing of Personal Information
Your Personal Information may be shared with third parties or authorities as permitted or required by the contractual agreement signed with our Customers, data protection laws, and this Privacy Policy.
### 5.1 Third Parties
We may engage third parties for performing activities as required to provide Services to our Customers. These third parties enable us to build capabilities related to technology infrastructure, product features, system integration, technical support, etc. To provide these activities, these third parties require access to data that may contain your Personal Information. These third parties are provided minimum required access to data on a need-to-know basis only to perform activities required to provide Services.
We engage these third parties after performing required due diligence, security evaluation, privacy review, and as per contractual agreements signed with our Customers. Additionally, we sign appropriate confidentiality, non-disclosure, and data protection agreements with these third parties to ensure the security and privacy of your Personal Information.
To know more about the third parties engaged by us, please refer to our sub-processor repository.
### 5.2 Business Transfers
If Mindtickle is a party to a merger or acquisition by another company, or its assets are entirely or partially acquired, Users' Personal Information may be among the assets transferred. Mindtickle may disclose Personal Information to a third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings). In this event, our Customers will be notified via email or a prominent notice on our website of any change in ownership, uses of your Personal Information, and choices you may have regarding your Personal Information.
### 5.3 Compelled Disclosure
We may be required to disclose Personal Information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements. We reserve the right to use or disclose your Personal Information if required by law, such as to comply with a subpoena, bankruptcy proceedings, or similar legal process or if we reasonably believe that use or disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or comply with a law, court order, or legal process.
We have not received any request for disclosure of Personal Information from the government or law enforcement agencies in the past 12 months. For more details, please refer to our Transparency Report.
## 6. Retention of Personal Information
Your Personal Information will be retained only for the duration required to provide Services to our Customers, to fulfill our obligations towards you as outlined in this Privacy Policy, as required by law, or for dispute resolution.
Your Personal Information is retained throughout the duration of an active contract with the Customers. Upon the end of or on termination of the contract signed with the Customer, your Personal Information will be retained, returned to the Customer, or deleted as per the terms agreed in the Customer contract.
Please note that we may need to retain certain information provided as part of a data subject request for compliance recordkeeping purposes or to have proof and evidence concerning our relationship should any legal issues arise following your discontinuance of use.
## 7. Transfer of Personal Information
By using our Services or disclosing Personal Information to us, you consent to the transfer of your Personal Information to countries outside of your country of residence, which may have different data protection laws than those of your country or the country in which you were located when you initially provided the Personal Information.
### 7.1 Data Transfer Mechanism
Unless otherwise agreed to in a separate Customer agreement, your Personal Information may be stored and processed in any country where we have facilities or in which we engage service providers. When we do, we will ensure that an adequate level of protection is provided for the Personal Information by using one or more of the following approaches:
* **Similar data protection laws –** We may transfer Personal Information to countries that have privacy laws that have been recognized by the country from which the Personal Information is transferred as providing similar protections.
* **Contractual safeguards –** We may enter into written agreements, such as standard contractual clauses, with recipients that require them to provide the same level of protection for their Personal Information.
* **Approved transfer mechanism –** We may rely on other transfer mechanisms approved by authorities in the country from which the Personal Information is transferred.
### 7.2 EU-U.S. Data Privacy Framework with UK Extension, and Swiss-U.S. Data Privacy Framework
MindTickle, Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.
We have certified to the U.S. Department of Commerce that we adhere to:
* the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of Personal Information received from the European Union in reliance on the EU-U.S. DPF
* the United Kingdom (and Gibraltar) under the UK Extension to the EU-U.S. DPF
* the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of Personal Information received from Switzerland in reliance on the Swiss-U.S. DPF.
If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit .
MindTickle, Inc. is responsible for the processing of Personal Information it receives, under the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and Swiss-U.S. DPF and subsequently transfers to a third party acting as an agent on its behalf. We comply with the EU-U.S. DPF Principles and the Swiss-U.S. DPF Principles for all onward transfers of Personal Information from the EU, UK, and Switzerland, including the onward transfer liability provisions.
The Federal Trade Commission has jurisdiction over MindTickle, Inc.'s compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF. In certain situations, we may be required to disclose Personal Information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
## 8. Security of Personal Information
We use a variety of technical and organizational security measures to protect your Personal Information from unauthorized access, use, alteration, disclosure, or destruction. While we are taking efforts to protect your Personal Information, it's important to note that, like any service, this may not ensure absolute immunity from potential issues such as wrongdoings, malfunctions, or misuse.
If you have a reason to believe that your information with us is no longer secure or the security of your account has been compromised, please notify us at [email protected].
## 9. Your Rights as a Data Subject
Your Personal Information comes with certain rights, per applicable data protection laws, including the EU or UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), the Colorado Privacy Act (CPA), the Connecticut Personal Data Privacy and Online Monitoring Act (CTDPA), the Utah Consumer Privacy Act (UCPA), the Virginia Consumer Data Protection Act (VCDPA), the Nevada Privacy of Information Collected on the Internet from Consumers Act (NPICICA), the Oregon Data Privacy Law (OCPA), the Nebraska Data Privacy Act (NEDPA), the New Jersey Data Privacy Law (NJDPL), the New Hampshire Data Privacy Act (NHPA), the Brazilian General Data Protection Law (LGPD), the Swiss Data Protection Act (FADP), the Personal Information Protection Law of the People's Republic of China (PIPL), Texas Data Privacy and Security Act (TDPSA), Montana Consumer Data Privacy Act (MCDPA), the Digital Personal Data Protection Act (DPDPA) or the Canada Personal Information Protection and Electronic Documents Act (PIPEDA). Our Services generally have the option to access or rectify your Personal Information directly or through your organization's administrator of the Services. Please find below more information about your rights as a data subject.
* **Access –** You can request details about the Personal Information we hold about you.
* **Rectification –** You can request correction or provide supplement data if you think your Personal Information is incorrect or incomplete.
* **Erasure –** You can request the erasure of your Personal Information from our systems.
* **Withdrawal of Consent –** If we process your Personal Information based on your consent (as indicated at the time of collection), you can request withdrawal of your consent.
* **Data Portability –** You can request a copy of your Personal Information in an industry-standard format. Additionally, you can ask us to transmit the data to another organization where technically feasible.
* **Restrict Processing –** You can ask us to restrict further processing of your Personal Information.
* **Object to Processing –** You can object to the continued use or disclosure of your Personal Information for specific purposes.
* **Right to Opt-Out of Sale –** You can request to opt out of the sale of Personal Information we hold about you.
If you seek more information about these rights or wish to submit a request, kindly reach out to us at [email protected] or fill out the Individual Rights Request Form.
## 10. Exercising Data Subject Rights
If you are an individual whose Personal Information who has shared Personal Information is stored in our systems, please feel free to reach out to us at [email protected].
### 10.1 Request Verification
We will verify your request using the information associated with your account, including the email address. In some cases, government identification may be required. We will forward verified requests to your organization and act as per their instructions. Consumers can also designate an authorized agent to help them fulfill data subject requests.
### 10.2 Timeline
We strive to complete data subject requests within 30 days. We will notify you if we require an additional time of up to 60 days to complete the request.
### 10.3 Exceptions to the Rights of Individuals
Mindtickle reserves the right to charge a reasonable fee, taking into account the administrative costs of providing the information or communication or taking action requested in cases where it has sufficient reasons to believe that the requests from an individual are unfounded and excessive. Further, there may be situations where we cannot fully comply with your request, such as in cases where it is frivolous, highly impractical, jeopardizes the rights of others, or is not legally required. However, even in such circumstances, we will respond to inform you of our decision.
### 10.4 Avoidance of Discriminatory Practices
Mindtickle acknowledges that it does not involve any practice that can be discriminatory against individuals who have exercised their rights available under data protection laws.
## 11. Other Important Terms
### 11.1 We Never Sell Personal Information
Under the California Consumers Privacy Act (CCPA) / California Privacy Rights Act (CPRA), Sale is defined as "selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer's Personal Information by the business to another business or a third party" in exchange for "monetary" or "other valuable consideration."
We use the information received from the Users themselves for the declared business purpose only and are not involved in any process or activity that can be termed as a "Sale" under CCPA/CPRA. We acknowledge that we have not sold Personal Information received through our Services in the preceding 12 months.
### 11.2 Sensitive Information
"Sensitive Personal Information" or "Special Categories of Personal Information" means Personal Information that reveals race, ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or concerns health or a natural person's sex life or sexual orientation, or is used for processing of genetic data, biometric data or precise geolocation data for the purpose of uniquely identifying a natural person.
In order to provide our Website, we do not require access to your Sensitive Personal Information or Special Categories of Personal Information, and you should not share such information with us.
### 11.3 Information About Children
Our Website is not intended for or targeted at children (as per the age defined under relevant laws. e.g., 18 years, 16 years, 13 years, etc.), and we do not knowingly or intentionally collect information about children. If you believe that we have collected Personal Information about a child, please contact us at [email protected] so that we can delete the Personal Information.
### 11.4 Your Consent
By using our Services, you consent to our collection and use of your Personal Information as described in this Privacy Policy. Additionally, we may store and process your Personal Information in various facilities throughout the globe, including in data centers operated and maintained by cloud-based service providers. If you are a resident in a jurisdiction where the transfer of your Personal Information to another jurisdiction requires your consent, then it is hereby understood that you provide us your consent to such transfer.
### 11.5 Automated Decision-Making
We do not encourage the use of information provided or generated by our Services to perform automated decision-making.
### 11.6 AI/ML Model Training and Data Usage
We do not use Google user data to develop, improve, or train AI and/or ML models. Further, this data is not transferred to third-party AI tools, and the transfer is not for generalized/ non-personalized AI/ML models. Google Workspace APIs are not used to develop, improve, or train generalized/non-personalized AI and/or ML models.
### 11.7 Unsubscribing From Our Communications
You may unsubscribe from our marketing communication by clicking on the "unsubscribe" link located at the bottom of our emails or by sending us an email at [email protected]. You cannot opt out of receiving transactional emails and notifications related to the Services subscribed through our Customers. You may reach out to your organization to configure the email and notification preferences in the Services.
### 11.8 Changes to this Privacy Policy
We annually review this Privacy Policy and may update it from time to time to reflect our ongoing commitments. If we make any material change to our existing privacy commitments, we will send a notification as per the communication details provided in the contractual agreement signed with our Customers. The "Last Updated" legend at the top of this page indicates when this Privacy Policy was last revised. Your continued use of our Services will be subject to the terms of the then Privacy Policy.
## 12. Questions, Concerns, or Complaints
If you have any questions about this Privacy Policy or our processing of the Personal Information you provide us, please write to us using the below information:
MindTickle, Inc.
Attn: Data Privacy Officer
535 Mission St, 14th Floor, San Francisco,
California 94105, United States of America
or
MindTickle Interactive Media Pvt. Ltd.
Attn: Data Privacy Officer or Grievance Officer
4th Floor, Solitaire World, Baner,
Pune, Maharashtra 411045, India
You can reach out to us at [email protected]
In case you do not receive a satisfactory response from Mindtickle DPO or have any other query regarding the processing of your Personal Information, you can reach out to our privacy representative at [email protected]
## 13. Dispute Resolution Authority
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Mindtickle commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF to TRUSTe, an alternative dispute resolution provider based in the United States.
If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit for more information or to file a complaint. The services of TRUSTe are provided at no cost to you.
For complaints regarding EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and Swiss-U.S. DPF compliance not resolved by any of the other DPF mechanisms, you have the possibility, under certain conditions, to invoke binding arbitration. Further information can be found on the official DPF website:
In case you do not receive a satisfactory response from Mindtickle or our dispute resolution provider, you have the right to raise a complaint regarding your data with the following authorities using the contact information provided on their website:
* **For EU data subjects –** You can register a complaint with relevant Data Protection Authorities (DPAs) in the EU member states. You can find a list of DPAs on the European Commission website:
* **For UK data subjects –** You can register a complaint with the Information Commissioner's Office (ICO):
* **For Texas data subjects –** You can register a complaint with the Attorney General:
* **For Montana data subjects –** You can register a complaint with the Attorney General:
* **For Oregon data subjects –** You can register a complaint with the Oregon Department of Justice:
* **For Nebraska data subjects –** You can register a complaint with the Attorney General:
* **For New Jersey data subjects –** You can register a complaint with the Attorney General:
* **For New Hampshire data subjects –** You can register a complaint with the Attorney General:
------------------------------------------------------------
# Mindtickle Job Applicants Privacy Policy | Data Collection, Retention & Rights
**Focus Keyphrase:** Mindtickle job applicants privacy policy
**Meta Description:** Discover Mindtickle's Job Applicant Privacy Policy, detailing the personal information we collect during the recruitment process, its sources, and your data subject rights.
**Original URL:** https://www.mindtickle.com/privacy-policy/#jobapplicants
---
# Job Applicants Privacy Policy
###### Last Updated: March 17, 2025
MindTickle, Inc. and MindTickle Interactive Media Pvt. Ltd. (collectively referred to as "Mindtickle," "us," "we," or "our") respect your privacy and are committed to protecting your Personal Information. This Privacy Policy outlines the manner in which Mindtickle gathers, utilizes, transfers, safeguards, stores, maintains, or otherwise manages the Personal Information of individuals ("You") collected from your job application, résumé, curriculum vitae or via other sources throughout the recruitment process. It also describes the rights accessible to you as a data subject (or such other terms provided under applicable data protection laws) and the procedures governing our response to such requests.
By choosing to apply for a job at Mindtickle and appearing for the hiring process, you accept and agree to the practices described in this Privacy Notice. We highly recommend you regularly review this Privacy Policy to stay informed about any updates or modifications we may make.
You can request a copy of this Privacy Policy by contacting us at [email protected].
## 1. Personal Information
Personal Information refers to any information related to an identified or identifiable natural person. This information may include name, phone number, email ID, address, etc.
If you submit any Personal Information relating to other people to us, such as their names and email addresses, you represent that you have the authority to do so and to permit us to use the information in accordance with this Privacy Policy.
## 2. Categories of Personal Information
The following table details the categories of Personal Information that we collect and have collected over the past 12 months from you, either directly or through other sources. For each category of Personal Information, we have also set out the source for collection and the categories of third parties with whom we share the Personal Information.
| **Category of Personal Information** | **Examples of Personal Information Collected** | **Source** | **Third Parties With Whom We Share Data For Business Purposes** |
|--------------------------------------|------------------------------------------------|------------|------------------------------------------------------------------|
| Identifiers | Name, Email ID, Phone number, Address | Information that you have provided on the job application forms, resume, curriculum vitae, or cover letter, Information shared by recruitment agencies and headhunters, Information provided during interviews, assessments, and evaluation processes, Information provided by browsers and devices, Information retrieved from professional networking sites, social media profiles, and publicly available sources, Information provided by references and former employers, Information received through background verification services, Information provided through Application Programme Interface (APIs), Information synchronized through human resource management systems or identity providers | We may share the following categories of personal information with the below-mentioned categories of third parties: Human resource management system provider (Identifiers, Professional or employment-related information), Background verification service provider (Identifiers, Professional or employment-related information, Education information), Recruitment agencies and headhunters (Identifiers, Professional or employment-related information), Interview scheduling and coordination service provider (Identifiers), Video conferencing service provider (Identifiers, Audio, electronic, visual, or similar information), Assessment and evaluation service provider (Identifiers, Professional or employment-related information, Audio, electronic, visual, or similar information), Reference verification service provider (Identifiers, Professional or employment-related information), Relocation service provider (Identifiers and Geolocation information), Immigration and visa processing service provider (Identifiers, Immigration information), Legal and compliance service provider (Identifiers, Professional or employment-related information) |
| Professional or employment-related information | Job title, Company name, Work experience, Skills, Qualifications, Salary expectations, Notice period | | |
| Education information | Educational qualifications, Degrees, Certifications, Training programs, Academic records | | |
| Audio, electronic, visual, or similar information | Interview recordings, Assessment videos, Presentation recordings, Portfolio samples | | |
| Geolocation information | Current location, Preferred work location, Willingness to relocate | | |
| Immigration information | Work authorization status, Visa status, Citizenship information | | |
| Internet, device, or other electronic network activity information | IP address, Device ID, User agent string that may reveal your device version, operating system and browser version | | |
| Analytics data | User identifier captured in session cookies, Application tracking information, Recruitment funnel analytics | | |
## 3. Sources of Personal Information
We collect Personal Information about you through the below-mentioned sources:
### 3.1 Job Application Process
When you apply for a position at Mindtickle, you may provide Personal Information through job application forms, resume, curriculum vitae, cover letters, and other application materials submitted through our careers website, job portals, or directly to our recruitment team.
### 3.2 Recruitment Agencies and Headhunters
We may receive your Personal Information from recruitment agencies, headhunters, and talent acquisition firms that we engage to identify and recruit potential candidates for open positions.
### 3.3 Interviews and Assessments
During the interview and assessment process, we may collect Personal Information through video interviews, technical assessments, coding challenges, presentations, and other evaluation methods used to assess your suitability for the role.
### 3.4 Professional Networks and Public Sources
We may collect Personal Information from professional networking sites such as LinkedIn, publicly available social media profiles, company websites, and other publicly accessible sources to verify information or learn more about potential candidates.
### 3.5 References and Background Verification
We may collect Personal Information from references you provide, former employers, educational institutions, and background verification service providers to validate the information you have provided and assess your suitability for employment.
### 3.6 Technology Integration
We may collect Personal Information through integrations with human resource management systems, applicant tracking systems, video conferencing platforms, and other technology tools used in our recruitment process.
## 4. Use of Personal Information
We use Personal Information for the following purposes related to the recruitment process:
* Processing and evaluating job applications and candidacy
* Conducting interviews, assessments, and evaluation processes
* Verifying the accuracy of information provided in application materials
* Conducting background checks and reference verification as permitted by law
* Coordinating interview schedules and communication with candidates
* Assessing skills, qualifications, and suitability for specific roles
* Making hiring decisions and extending job offers
* Facilitating onboarding processes for successful candidates
* Maintaining records for compliance with employment laws and regulations
* Analyzing and improving our recruitment processes and candidate experience
* Communicating with candidates regarding their application status and opportunities
* Providing feedback to candidates as appropriate
* Managing candidate databases and talent pools for future opportunities
* Complying with legal obligations related to equal opportunity employment
* Protecting our rights, property, and safety, and that of our employees and candidates
* As we believe to be necessary or appropriate: (a) under applicable law, including laws outside your country of residence; (b) to comply with legal process; (c) to respond to requests from public and government authorities; (d) to enforce our terms and conditions; (e) to protect our operations; (f) to protect our rights, privacy, safety or property, or that of others; and (g) to allow us to pursue available remedies or limit damages
## 5. Sharing of Personal Information
Your Personal Information may be shared with third parties as permitted under applicable data protection laws and this Privacy Policy.
### 5.1 Third Parties
We may engage third parties to assist us in our recruitment processes. These third parties provide services such as applicant tracking systems, background verification, reference checks, assessment platforms, video interviewing tools, recruitment analytics, and other services necessary for effective talent acquisition.
To provide these services, these third parties may require access to data that contains your Personal Information. These third parties are provided minimum required access to data on a need-to-know basis only to perform activities required to support our recruitment processes.
We engage these third parties after performing required due diligence and privacy reviews. Additionally, we sign appropriate confidentiality, non-disclosure, and data protection agreements with these third parties to ensure the security and privacy of your Personal Information.
### 5.2 Internal Teams
Your Personal Information may be shared with relevant internal teams including hiring managers, human resources personnel, interviewers, and other employees involved in the recruitment and decision-making process for the position you have applied for.
### 5.3 Business Transfers
If Mindtickle is a party to a merger or acquisition by another company, or its assets are entirely or partially acquired, candidates' Personal Information may be among the assets transferred. In this event, candidates will be notified via email or a prominent notice on our website of any change in ownership, uses of Personal Information, and choices available regarding Personal Information.
### 5.4 Compelled Disclosure
We may be required to disclose Personal Information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements. We reserve the right to use or disclose Personal Information if required by law or if we reasonably believe that use or disclosure is necessary to protect our rights, protect safety, investigate fraud, or comply with a law, court order, or legal process.
## 6. Retention of Personal Information
Your Personal Information will be retained for the duration necessary to fulfill the purposes outlined in this Privacy Policy, as required by law, or for dispute resolution.
For successful candidates, Personal Information collected during the recruitment process will be transferred to employee records and retained in accordance with our employee data retention policies.
For unsuccessful candidates, Personal Information will typically be retained for a period of up to 2 years from the completion of the recruitment process, unless a longer retention period is required by applicable law or you have consented to be included in our talent pool for future opportunities.
Please note that we may need to retain certain information for compliance recordkeeping purposes or to have proof and evidence concerning our recruitment process should any legal issues arise.
## 7. Transfer of Personal Information
By applying for a position at Mindtickle and providing Personal Information to us, you consent to the transfer of your Personal Information to countries outside of your country of residence, which may have different data protection laws than those of your country.
### 7.1 Data Transfer Mechanism
Your Personal Information may be stored and processed in any country where we have facilities or engage service providers. When we do, we will ensure that an adequate level of protection is provided for the Personal Information by using one or more of the following approaches:
* **Similar data protection laws** – We may transfer Personal Information to countries that have privacy laws recognized as providing similar protections.
* **Contractual safeguards** – We may enter into written agreements, such as standard contractual clauses, with recipients that require them to provide the same level of protection for Personal Information.
* **Approved transfer mechanism** – We may rely on other transfer mechanisms approved by authorities in the country from which the Personal Information is transferred.
### 7.2 EU-U.S. Data Privacy Framework with UK Extension, and Swiss-U.S. Data Privacy Framework
MindTickle, Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.
We have certified to the U.S. Department of Commerce that we adhere to the applicable Data Privacy Framework Principles with regard to the processing of Personal Information received from the European Union, United Kingdom, and Switzerland in reliance on the respective frameworks.
## 8. Security of Personal Information
We use a variety of technical and organizational security measures to protect your Personal Information from unauthorized access, use, alteration, disclosure, or destruction. While we take efforts to protect your Personal Information, it's important to note that no service can ensure absolute immunity from potential security issues.
If you have reason to believe that your information with us is no longer secure, please notify us at [email protected].
## 9. Your Rights as a Data Subject
Your Personal Information comes with certain rights under applicable data protection laws, including the EU or UK General Data Protection Regulation (GDPR), various U.S. state privacy laws, and other applicable privacy regulations. Please find more information about your rights below:
* **Access** – You can request details about the Personal Information we hold about you.
* **Rectification** – You can request correction or provide supplemental data if you think your Personal Information is incorrect or incomplete.
* **Erasure** – You can request the erasure of your Personal Information from our systems.
* **Withdrawal of Consent** – If we process your Personal Information based on your consent, you can request withdrawal of your consent.
* **Data Portability** – You can request a copy of your Personal Information in an industry-standard format.
* **Restrict Processing** – You can ask us to restrict further processing of your Personal Information.
* **Object to Processing** – You can object to the continued use or disclosure of your Personal Information for specific purposes.
If you seek more information about these rights or wish to submit a request, kindly reach out to us at [email protected] or fill out the Individual Rights Request Form.
## 10. Exercising Data Subject Rights
If you are a job applicant whose Personal Information is stored in our systems, please feel free to reach out to us at [email protected].
### 10.1 Request Verification
We will verify your request using the information associated with your application, including the email address. In some cases, government identification may be required.
### 10.2 Timeline
We strive to complete data subject requests within 30 days. We will notify you if we require additional time of up to 60 days to complete the request.
### 10.3 Exceptions to the Rights of Individuals
Mindtickle reserves the right to charge a reasonable fee in cases where we have sufficient reasons to believe that requests are unfounded and excessive. Further, there may be situations where we cannot fully comply with your request, such as cases where it would jeopardize the rights of others or is not legally required. However, even in such circumstances, we will respond to inform you of our decision.
## 11. Other Important Terms
### 11.1 We Never Sell Personal Information
We use Personal Information received from job applicants for recruitment purposes only and are not involved in any process or activity that constitutes a "sale" under applicable privacy laws. We acknowledge that we have not sold Personal Information received from job applicants.
### 11.2 Sensitive Information
"Sensitive Personal Information" means Personal Information that reveals race, ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health information, sex life or sexual orientation, genetic data, or biometric data.
We do not require access to your Sensitive Personal Information for recruitment purposes, and you should not share such information with us unless specifically requested and legally permissible.
### 11.3 Information About Children
Our recruitment processes are not intended for individuals under the age of 18, and we do not knowingly collect information from minors. If you believe we have collected Personal Information about a minor, please contact us so we can delete the information.
### 11.4 Your Consent
By applying for a position at Mindtickle, you consent to our collection and use of your Personal Information as described in this Privacy Policy. Additionally, we may store and process your Personal Information in various facilities throughout the globe.
### 11.5 Automated Decision-Making
We do not use Personal Information for automated decision-making in our recruitment processes. All hiring decisions involve human review and consideration.
### 11.6 Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect our ongoing commitments. The "Last Updated" legend at the top indicates when this Privacy Policy was last revised. Your continued participation in our recruitment process will be subject to the terms of the then-current Privacy Policy.
## 12. Questions, Concerns, or Complaints
If you have any questions about this Privacy Policy or our processing of your Personal Information, please write to us using the below information:
MindTickle, Inc.
Attn: Data Privacy Officer
535 Mission St, 14th Floor, San Francisco,
California 94105, United States of America
or
MindTickle Interactive Media Pvt. Ltd.
Attn: Data Privacy Officer or Grievance Officer
4th Floor, Solitaire World, Baner,
Pune, Maharashtra 411045, India
You can reach out to us at [email protected]
In case you do not receive a satisfactory response from Mindtickle DPO or have any other query regarding the processing of your Personal Information, you can reach out to our privacy representative at [email protected]
## 13. Dispute Resolution Authority
In compliance with applicable Data Privacy Frameworks, Mindtickle commits to refer unresolved complaints concerning our handling of personal data to appropriate dispute resolution providers.
If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please visit the appropriate dispute resolution mechanism for more information or to file a complaint.
In case you do not receive a satisfactory response from Mindtickle or our dispute resolution provider, you have the right to raise a complaint regarding your data with the following authorities using the contact information provided on their website:
* **For EU data subjects** – You can register a complaint with relevant Data Protection Authorities (DPAs) in the EU member states. You can find a list of DPAs on the European Commission website: https://commission.europa.eu/law/law-topic/data-protection_en
* **For UK data subjects** – You can register a complaint with the Information Commissioner's Office (ICO): https://ico.org.uk/
* **For various U.S. state data subjects** – You can register a complaint with the relevant state Attorney General or designated privacy authority as applicable under state law
------------------------------------------------------------
# Mindtickle GDPR Compliance | EU Data Protection, DPA & International Transfers
**Focus Keyphrase:** Mindtickle GDPR compliance
**Meta Description:** Learn how Mindtickle ensures GDPR compliance as a data processor via its GDPR compliant DPA, Standard Contractual Clauses, UK International Data Transfer Addendum, Transfer Impact Assessment, encryption, data subject rights, and breach response.
**Original URL:** https://www.mindtickle.com/mindtickle-general-data-protection-regulation
---
# Mindtickle and the General Data Protection Regulation (GDPR)
At Mindtickle, we take data security and privacy seriously. We constantly try to make sure that we meet our obligations under GDPR and are transparent about processing data.
Mindtickle is committed to ensuring the protection of our customers' data by complying with the General Data Protection Regulation (GDPR) and other applicable privacy-related regulations such as California Consumer Privacy Act (CCPA) and the UK Data Protection Act (UK DPA) 2018.
The GDPR is designed to give European Union residents more control over their data and unify several privacy and security laws under one comprehensive rule. Any organization that offers goods or services to EU residents must comply with the GDPR. Regardless of the company's location, GDPR applies to organizations within the EU and all companies processing and holding the personal data of data subjects residing in the EU.
## We are here to support our customers
The GDPR defines different organizations' roles when managing or dealing with personal data.
There are two major roles – Controllers and Processors. Controllers are organizations that own personal data. Mindtickle customers are Controllers because they collect personal data, decide its purpose and method for using it. Mindtickle plays the role of the Processor since Mindtickle processes this personal data provided by the customers.
We're committed to helping our customers meet their obligations in their role as Controller under the GDPR. Mindtickle has implemented data security and privacy processes and controls to ensure that our customers meet their GDPR obligations.
## Approach to Security and Privacy
As the global leader in sales readiness, Mindtickle delivers a cloud platform that the leading enterprises across the globe trust for business-critical services. Protecting our customers' information and their user's privacy is essential for Mindtickle. Mindtickle has adopted privacy and security by design for all developments on the platform, ensuring that security and privacy are built into every layer of the Mindtickle platform. Visit Mindtickle's **Trust Page** to learn more about our approach to security and privacy.
## Security Architecture
Data protection laws require organizations to use appropriate technical and organizational security measures to protect Personal Data against unauthorized processing and accidental disclosure, access, loss, destruction, or alteration. Mindtickle has a robust security and privacy program that meets industry standards. These enable Mindtickle and its Customers to comply with various data protection laws and regulations applicable to the Mindtickle platform and services.
## International Data Transfers
Mindtickle understands the rules for onward transfers of personal data outside of the European Economic Area (EEA) and offers customers a robust international data transfer framework as a part of our **Data Processing Addendum**. This addendum ensures that our customers can lawfully transfer personal data to the Mindtickle platform outside the EEA by relying on the Standard Contractual Clauses.
## Data Processing Addendum (DPA)
Mindtickle offers a GDPR-compliant **Data Processing Addendum** to provide our customers with privacy protection assurance, which helps us comply with our obligations as a Data Processor and helps our customers meet their obligations as Data Controllers. Mindtickle's DPA supplements the **Terms of Service** or any master subscription agreement. This addendum reflects our requirements as a processor of Customer Data.
## Standard Contractual Clauses
The Commission Implementing Decision (EU) 2021/914 of 4 June 2021 to transfer personal data to third countries under Regulation (EU) 2016/679 of the European Parliament and the Council published **New Standard Contractual Clauses** (SCCs, also known as Model Contractual Clauses) to help safeguard European personal data. Following the applicable transition period, these new SCCs will replace the SCCs previously adopted by the EC. Mindtickle has incorporated the new SCCs into our **Data Processing Addendum** to help protect our customers' data and meet the requirements of European privacy legislation.
## UK International Data Transfer Addendum
Mindtickle is fully compliant with the provisions of Article 46 of the UK GDPR and offers an International Data Transfer Addendum (IDTA) issued by the Information Commissioner's Office (ICO) under Section 119A of the Data Protection Act 2018. The IDTA acts as a transfer tool that allows organizations to transfer personal data outside of the UK. The addendum is part of Mindtickle's **pre-signed Data Processing Addendum (DPA)** offered to its customers.
## Transfer Impact Assessment
Mindtickle has prepared a Transfer Impact Assessment (TIA) report in response to the recent Schrems II decision related to the international transfer of Personal Data. The TIA report describes the safeguards Mindtickle has put to transfer customer personal data from the European Economic Area, United Kingdom, or Switzerland ("EEA"). This report also lists Mindtickle's ability to comply with its obligations as a "data importer" under the Standard Contractual Clauses ("SCCs"). Upon request, Mindtickle can share the TIA report with customers and prospects.
## Data Privacy Framework (DPF)
Mindtickle is certified for compliance with EU-U.S. and Swiss-U.S. Data Privacy Framework (DPF), along with its UK Extension, which were developed by U.S. Department of Commerce and the European Commission, UK Government, and Swiss Federal Administration.
Data Privacy Framework provides us with a reliable mechanism for personal data transfers to the United States from the European Union, United Kingdom, and Switzerland while ensuring data protection that is consistent with EU, UK, and Swiss law.
Our Data Privacy Framework compliance certification along with participation status, the purpose of data collection, and dispute resolution mechanism can be accessed here.
## Data Location and Residency
Mindtickle hosts primarily three categories of customer data –
1. **Learning Content & Call Recordings –** This data includes the learning content uploaded for the user's consumption (e.g. training videos, SCORM packages, images, PDF documents, PowerPoint presentations, etc.) and the call recordings along with the transcripts. This is mainly the training content used by the sales enablement and readiness teams to train their sales representatives.
2. **User Profile Data –** This data includes the learner profile fields such as business email ID, job title, business title, department, user group, region, employee ID, managers, reviewers, directors, supervisors, hire date, work city, work country, etc.
3. **User Progression Data –** This data includes the progress of the learners, statistics, completion status, analytics, quiz score, call recording metadata, etc.
Customer data is stored on Amazon Web Services (AWS), distributed across multiple availability zones. Data hosting location determinations are based on reducing latency and achieving optimal performance for you and your users. Mindtickle optimizes where to host customer data based on how it is accessed worldwide. Mindtickle provides the below options for prospects to choose the AWS data center for storing learning content and/or call recordings.
* Ireland in **Europe** Region
* Singapore in **Asia** Region
* North Virginia in **United States** Region
Mindtickle stores the user profile and user progression data in the Singapore region.
With the above-mentioned options, Mindtickle will access the customer data in India and the United States for administrative and customer success, professional services, and technical support activities respectively. Before configuring and setting up the Mindtickle site, you can contact your Mindtickle point of contact to understand the data storage location options.
## Access Management
Mindtickle may need access to customer learning sites to provide customer success, professional services, and technical support services. This access is controlled and managed by the customers.
Cloud infrastructure hosting customer data can be accessed from India for performing administrative and maintenance activities.
* Only limited individuals, from DevOps and Storage teams, part of Mindtickle's India entity are granted access to cloud infrastructure hosting customer and personal data.
* This access is provided based on the principle of least privilege using Lightweight Directory Access Protocol (LDAP) groups mapped to the IAM access permissions and reviewed on a quarterly basis.
## Encryption
Customer data is encrypted in transit through HTTPS connection over TLS 1.2 using SHA-256 with 2048-bit RSA encryption and at rest with AES 256 encryption through cryptographic keys maintained in AWS Key Management Security (AWS KMS). For data encryption in transit, AES 128 Encryption with Galois Counter Mode (GCM) Block Operation Mode for SHA-256 signature and AES 256 Encryption with Galois Counter Mode (GCM) Block Operation Mode for SHA 384 are supported. This is selected based on the handshake and negotiation with the browser.
Access to the AWS console for administration requires multi-factor authentication and this entire access is encrypted at rest (at both AWS and Mindtickle laptop end) and in transit through a secure encrypted HTTPS connection used by AWS for console access.
## AWS Key Management Security
Mindtickle uses AWS Server-Side Encryption (SSE) – Key Management System (KMS) that requires AWS to manage the data encryption keys. Mindtickle makes use of the option of SSE-KMS encryption during the creation of S3 buckets storing customer data.
The decryption process is managed by AWS before serving the data to authenticated requests made by the authorized Mindtickle account. In this entire process, the keys used to encrypt/decrypt the customer content are not used by Mindtickle in any of the workflows. AWS Key Management System (KMS) uses hardware security modules (HSMs) to protect keys inside the HSM devices and can never leave the device in an unencrypted/plaintext form. This ensures that no one has access to the keys that were used to encrypt the data.
## Certifications
We have invested heavily towards ensuring our platform is built and designed per widely accepted standards and certifications. These standards mirror many of the security and privacy requirements of GDPR and give our customers a transparent framework by which they can measure our software development and data management practices.
Mindtickle regularly audits its platform against the Trust Service Principles and Criteria prescribed by The American Institute of Certified Public Accountants (AICPA) and obtains a Service Organization Control 2 (SOC2) Type 2 report. This third-party assurance audit is performed annually to get an independent opinion on the suitability of the design and operating effectiveness of the implemented controls. Mindtickle can share its SOC2 Type 2 report with customers and prospects upon request.
## Privacy and Security Measures
Information security is our highest priority, and we have implemented robust **technical and organizational measures** to ensure that our customers' data remains secure.
Mindtickle's technical and organizational security measures, as updated from time to time, provide an appropriate level of security and privacy to all its users, taking into account the nature, scope, context, and purpose of the processing, and the risks to the rights and freedom of natural persons.
## Privacy Policy
We have worked with independent auditors and lawyers to ensure our **privacy policy** complies with GDPR. Our policy outlines our commitment to maintaining the privacy of our customers' data. It also explains what we have done to ensure our customers' data is secure and what choices are available to them.
## Pseudonymization
Information stored in activity logs and databases is pseudonymized wherever possible using a unique randomized user identifier that cannot be back-traced to a specific data subject.
## Data Minimization
Mindtickle only collects the minimum information necessary for the provision of our service. Mindtickle platform administrators of customer organizations typically need user details (name, business titles, and business email addresses) and training content to run enablement programs on the Mindtickle platform. The customer-designated administrators will decide the exact data scope based on the use case.
We do not process special personal data categories (as per Article 9 of GDPR). We have signed contractual agreements and DPA with third parties to store and process your personal data and that of your customers. You can find the list of these sub-processors in our **Sub Processor Repository**.
## Purpose of Data Collection and Storage
Mindtickle hosts data as part of the service it provides to its customers but doesn't make any claim to said data. Mindtickle's customers are the owners and controllers of all data they submit onto the platform.
## Controls with Sub-processors
As specified in the Data Processing Addendum, Mindtickle
1. takes responsibility for the actions of its Sub-processors, and
2. has entered into a written agreement with each Sub-processor containing, in substance, data protection obligations no less protective than those in our Customer agreements.
Customers can find up-to-date information about the hosting locations of Sub-processors in our **Sub Processor Repository**. Customers may subscribe to notifications of new Sub-processors. Mindtickle will notify all subscribed Customers of a new Sub-processor before authorizing the new Sub-processor to process Customer Data. Customers may object to the intended use of a new Subprocessor using the procedure set out in the Data Processing Addendum.
## Mindtickle's Access to Customer Personal Data
Mindtickle's Data Processing Addendum contains a contractual commitment from Mindtickle that its personnel may access Personal Data only in accordance with the Customer's documented instructions for specific purposes. These purposes include: (i) as required under the Data Processing Addendum; (ii) as initiated by the Customer in their use of the Mindtickle Services; and (iii) to comply with other instructions provided by the Customer. The locations of Mindtickle's Affiliates that employ personnel who may access Personal Data for these purposes are set out in the Sub-processor List.
## Mindtickle Employee Training and Confidentiality Obligations
Mindtickle commits in its Data Processing Addendum to ensure that personnel has been appropriately trained, are reliable, and enter into confidentiality agreements. Employees also regularly undergo security, data protection, and privacy training.
## The Rights of Data Subjects
Our customers and their end-users can access, correct, and modify their data stored on the Mindtickle platform. End-users can also contact us at **[email protected]** if they want to access, correct, or remove their data. As a Processor, we will forward these requests to the relevant customers and help them respond if needed.
## Right to Access and Data Portability
Mindtickle supports individuals' right to access and right to portability of their personal data. Any Mindtickle platform user will be able to request an export of their personal data and the personal data of their end-users.
Mindtickle also provides easy access and options to export all platform data, including learning content and user profile data. Mindtickle administrators of customer organizations can perform these actions from the admin site via reporting APIs and can download or email the required data. Further, they can reach out to the Mindtickle support team at **[email protected]** for assistance.
## Right to Accuracy, Correction, Deletion, and Modification
Mindtickle provides ways of keeping all personal data of your learners accurate via its platform and APIs.
Mindtickle also supports all data subject requests for change, correction, or deletion of their personal information. Users can reach out to us at **[email protected]** for such requests, and as a Processor, we will forward these requests to the relevant customers and help them respond if needed.
## Data Retention Policy
As processors of its customer's data and to protect the privacy of information it stores, Mindtickle holds data no longer than is needed to provide its services. Mindtickle has implemented the following data retention policy:
* Mindtickle deletes all customer personal information from the platform 180 days after contract termination.
* Customers can also ask us to permanently delete their company data or individual users' data stored on our platform anytime.
We have put in place robust mechanisms to delete our customers' data upon request or at the end of their contract. If you are a Mindtickle customer and would like to delete specific data, please contact us at **[email protected]**. The only information retained post-contract termination is that which is necessary from a compliance or legal standpoint.
## Right to Notice
Mindtickle enables customers to notify their users about collecting and using their Personal Data through a privacy policy link (drafted by the customer) that can be displayed on the Mindtickle platform login page.
## Incident Management
Mindtickle maintains multiple monitoring systems to detect and alert incidents. Mindtickle will notify Customers after becoming aware of any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data, including Personal Data, within the period required under applicable Data Protection Laws. Mindtickle will also provide such timely information to Customers to enable customers to fulfill any data breach reporting obligations under Data Protection Laws.
## Data Protection Officer
Mindtickle has a dedicated Data Protection Officer (DPO) and a team of privacy and security professionals dedicated to security and privacy to help our customers maintain their compliance when using Mindtickle.
If you would like to reach our DPO or have or have follow-up questions, please reach out to us at **[email protected]**.
## EU Representative
As required under Article 27 of the GDPR, regarding representatives of processors not established in the European Union (EU), Mindtickle has employed its EU legal representatives appointed in one of the Member States. You can contact our privacy team or data protection officer for further information.
## New Product Features
As a leader in Sales Readiness Software Solutions, we are constantly innovating and adding new product capabilities. Our new product capabilities follow three cornerstone principles:
* They align with GDPR principles of "privacy by design" and "privacy by default."
* They give EU and non-EU customers flexibility within the GDPR guidelines.
* All significant changes are communicated to our customers.
## We are Here to Answer Your Questions
We are always happy to answer any questions about the privacy and security of our customers' data, GDPR, or Sales Enablement, in general. Feel free to contact us at **[email protected]** for security questions or **[email protected]** for privacy questions.
------------------------------------------------------------
# Mindtickle CCPA Compliance | California Consumer Privacy & CPRA Service Provider
**Focus Keyphrase:** Mindtickle CCPA compliance
**Meta Description:** Discover Mindtickle's CCPA & CPRA compliance as a service provider—covering our Data Processing Addendum, data security processes, no selling pledge, consumer rights, and safeguards for California resident data.
**Original URL:** https://www.mindtickle.com/california-consumer-privacy-act
---
# Mindtickle and the California Consumer Privacy Act (CCPA)
At Mindtickle, we take **data security and privacy** seriously. Mindtickle is committed to protecting our customers' data by complying with California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). CCPA is a data privacy law regulating how businesses worldwide are allowed to handle the personal information of California residents. CCPA is one of the first laws of its kind in the United States and is effective from January 1, 2020. CPRA builds upon CCPA, which established a foundation for consumer privacy regulations, and is effective from January 1, 2023.
## We are Here to Support our Customers
The CCPA defines organizations' different roles when dealing with personal information. There are two major roles – 'Businesses' and 'Service Providers'
* 'Businesses' are organizations that own personal information. Mindtickle customers are 'Businesses' because they collect personal information, decide its purpose, and the method for using it.
* Mindtickle plays the role of the 'Service Provider' since Mindtickle receives this personal information provided by the customers and operates under a contract entered with the customer.
We're committed to helping our customers meet their obligations in their role as a 'Business' under the CCPA.
## Mindtickle's Responsibility
For our customers that need to comply with CCPA, Mindtickle is a 'Service Provider' as defined in the CCPA. The personal information submitted by our customers and processed by Mindtickle may contain California consumer personal information. As a 'Service Provider,' Mindtickle will limit the use of this information as per the specific purposes defined in our **terms of service**, **data processing addendum**, and **privacy policy**. Further, Mindtickle has implemented **data security and privacy processes and controls** to ensure that our customers meet their CCPA obligations.
## We do not sell your personal information
We strictly use the information received from our customers for providing services to our customers, aligned with the signed contract, **terms of service**, and **privacy policy**. We do not sell this information, and it is not used for any other commercial purposes. We have provided this information in our **privacy policy** and will happily sign any contractual document or amendments to reflect this intent. Mindtickle hosts data as part of the service it provides to its customers but doesn't make any claim to said data. Mindtickle's customers are the owners and controllers of all data they submit onto the platform.
## Data Processing Addendum (DPA)
Mindtickle offers a CCPA-compliant **Data Processing Addendum (DPA)** to provide our customers with privacy protection assurance, which helps us comply with our obligations as a 'Service Provider' and helps our customers meet their obligations as a Business. This addendum reflects Mindtickle's requirements as a 'Service Provider' to use, retain and disclose customer personal information for delivering services, including (i) disclosures to Subprocessors under a written contract with Mindtickle; and (ii) as authorized by the CCPA.
## Privacy and Security Measures
Information security is our highest priority, and we have implemented robust **technical and organizational measures** to ensure that our customers' data remains secure. Mindtickle's technical and organizational security measures, as updated from time to time, provide an appropriate level of security and privacy to all its users.
## Privacy Policy
We have worked with independent auditors and lawyers to ensure our **privacy policy** complies with CCPA. Our policy outlines our commitment to maintaining the privacy of our customers' data. It also explains what we have done to ensure our customers' data is secure and what choices are available.
## Controls with Subprocessors
"Subprocessor" means any subcontractor engaged by Mindtickle as a 'Service Provider' that processes CCPA Personal Information on behalf of Mindtickle.
As specified in the **Data Processing Addendum**, Mindtickle
1. takes responsibility for the actions of its Subprocessors, and
2. has entered into a written agreement with each Subprocessor containing, in substance, data protection obligations no less protective than those in our Customer agreements.
Customers can find up-to-date information about the hosting locations of Subprocessors in our **Sub Processor Repository.** Customers may subscribe to notifications of new Subprocessors. Mindtickle will notify all subscribed Customers before authorizing a new Subprocessor to process customer personal information. Customers may object to the intended use of a new Subprocessor using the procedure set out in the **Data Processing Addendum.**
## The Rights of Consumer under CCPA
Our customers and end-users may ask to disclose what personal information we have about them and what we do with that information, to delete their personal information, and not to sell it. End-users can contact us at **[email protected]** if they want to access, correct, or remove their data. As a 'Service Provider,' we will forward these requests to the relevant Customers and help them respond if needed.
## Right to Access and Data Portability
Mindtickle supports individuals' right to access and right to portability of their data. Mindtickle provides easy access and options to export all platform data, including user personal information. Mindtickle administrators of customer organizations can perform these actions from the admin site via reporting APIs and download or email the required data. Further, they can reach out to the Mindtickle support team at **[email protected]** for assistance.
## Right to Notice
Mindtickle enables customers to notify their users about collecting and using their data through a privacy policy link (drafted by the customer) that can be displayed on the Mindtickle platform login page.
## We Are Here to Answer Your Questions
We are always happy to answer any questions about the privacy and security of our customers' data, CCPA, or Sales Enablement, in general. Feel free to contact us at **[email protected]** for security questions or **[email protected]** for privacy questions.
------------------------------------------------------------
# Mindtickle AI Compliance | Responsible AI, Data Privacy & EU AI Act
**Focus Keyphrase:** Mindtickle AI compliance
**Meta Description:** Learn how Mindtickle ensures responsible AI usage—leveraging secure enterprise models (Azure OpenAI, AWS Bedrock), no public AI, zero retention, segregation, fairness guardrails, and compliance with EU AI Act and ISO_42001.
**Original URL:** https://www.mindtickle.com/ai-compliance
---
# Secure & Responsible AI
At Mindtickle, we integrate AI with a strong commitment to security, ethics, and regulatory compliance. Our goal is to enhance customer experience without compromising trust or transparency.
We use enterprise-grade AI models from trusted providers like Microsoft Azure OpenAI and AWS Bedrock. All third parties undergo thorough due diligence, including security certifications and privacy reviews. Data access, processing, and retention are tightly controlled.
Our AI features prioritize safety, fairness, and accountability. Customer data is never used for public model training, retained, or manually reviewed. With clear AI terms, strict data segregation, and strong governance, customers stay fully in control of their AI experience.
## Third-Party Oversight
### Enterprise AI Models
Mindtickle leverages private enterprise AI models provided by Microsoft Azure OpenAI and AWS Bedrock.
### Approved Third Parties
Third parties, including AI model providers, are evaluated by Mindtickle and approved by Customers before use.
### Supplier Due Diligence
Third parties used by Mindtickle undergo mandatory evaluation through a review of compliances and audits such as SOC 2, ISO, Penetration Testing, AI Controls, Security and Privacy Policies, etc.
### Data Privacy
Third parties processing customer data are transparently documented in a [public sub-processor repository](https://www.mindtickle.com/subprocessors), sign data processing agreements with Mindtickle, and commit to standard contractual clauses for secure data transfer.
### International Transfers
Mindtickle performs GDPR-mandated transfer impact assessment through an independent legal auditor to review all the locations where data could be transferred.
## AI Guardrails
### No Public AI
Customer data is never transmitted to public AI models.
### Opt-out of Model Training
Customer data is never used to train or improve AI models.
### Zero AI Data Retention
AI models access data only temporarily to process requests. Data is deleted immediately upon request completion and is never stored permanently.
### Data Confidentiality
Customer data will never be used to contribute to the AI models' knowledge base.
### No Manual Oversight
We have opted out of human review from AI models to eliminate manual oversight.
### Content Safety
A content filtering system prevents the generation of inappropriate, harmful, unethical, and copyrighted content through AI features.
## Data Use and Access
### Data Ownership
Customers completely own the data provided as input, user instructions, additional context, and the generated response/output, and Mindtickle does not make any ownership claims to such data.
### No Sharing of Sensitive Data
Audio/Video recordings are never shared with AI models; only the limited subset of the learner's audio/video recording text transcript is shared.
### Data Minimization
Only the minimum required data is shared with the AI models.
### No High-Risk Processing
Mindtickle does not use AI to perform facial recognition or biometric analysis.
### Data Segregation
AI requests are strictly segregated at the tenant and user levels to ensure that customer data remains isolated and there is no cross-tenant access to AI interactions.
### AI Terms
We maintain dedicated [AI terms](https://www.mindtickle.com/ai-terms) that outline our commitment to responsible data usage and retention while addressing key topics like data ownership, accuracy, and accountability.
## Responsible AI
### Responsible AI Measures
Mindtickle follows responsible AI principles in alignment with the EU AI Act, and general industry standards to remain ethical, transparent, and aligned with regulatory requirements.
### Inclusive AI
System prompts are designed to prevent bias, toxicity, and discrimination by AI models.
### Human-in-the-Loop
Content generated by AI features is saved in draft mode, requiring human review and approval before publishing — ensuring accuracy and accountability.
### Model Diversity
We select AI models that have been trained on a broad and diverse range of datasets to ensure fairness, equity, and non-discrimination.
### AI Support, Human Leadership
AI features are designed to enhance human capabilities, boost productivity, and provide data-driven insights—not replace human roles.
### AI Use Disclosure
AI-powered features and output are clearly labeled with the "Mindtickle Copilot" title and an icon indicating AI use.
## AI Governance
### Documentation
All AI features are thoroughly documented to highlight the data fields used, the purpose of each data field, and the generated output/response to help in AI use case evaluation.
### Granular AI Access
Customers decide who can use AI features via the platform's Role Based Access Control (RBAC) framework.
### Auditability
Mindtickle logs all requests between users and AI models, capturing relevant data points, including user input, system instructions, and pre-defined constraints for a transparent and secure audit trail.
### Flexible AI Control
Mindtickle provides customers full control over their AI experience, with the flexibility to enable or disable AI features based on their organization's use cases.
### End-User Feedback
End users are provided a mechanism to give feedback on AI-generated content to identify and address any problematic content, unintended biases, or ethical concerns.
### Explainability
AI outputs are context-aware, rule-based, and constrained to ensure clear reasoning behind the response and feedback.
## Audits and Compliance
### EU AI Act
Mindtickle has formally assessed itself through an external auditor and has implemented all the controls to comply with the EU AI Act, ensuring ethical and safe AI deployment.
### AI Penetration Testing
Mindtickle rigorously tests its platform, and all AI features through semi-annual VAPT audits, covering OWASP's top 10 AI/LLM risks, including prompt injection, output manipulation, model inversion, data poisoning, etc., along with responsible AI measures.
### AI Principles
Responsible AI principles, AI compliance policy, and AI system security checks are integrated into the AI product development lifecycle.
### ISO 42001
Mindtickle has been audited by an independent assessor and complies with all the requirements provided by ISO 42001 – the world's first comprehensive AI system security standard.
### Robust Compliance Ecosystem
Mindtickle adheres to rigorous industry standards and compliance frameworks, including SOC 2, SOC 3, ISO 27001, ISO 22301, ISO 27701, ISO 27017, ISO 27018, HIPAA, 21 CFR Part 11, GDPR, SCCs, DPF, CCPA, CPRA, UK DPA 2018, and various US state privacy laws.
------------------------------------------------------------
# Mindtickle Sub_processor Repository | Third_Party Data Processors Compliance
**Focus Keyphrase:** Mindtickle Sub-Processor Repository
**Meta Description:** Explore Mindtickle's Sub_processor Repository: a complete list of third_party vendors engaged in processing customer data, their locations, roles, compliance (SOC 2, ISO 27001), and sub_processor controls including due diligence, audit rights, and data protection safeguards.
**Original URL:** https://www.mindtickle.com/sub-processor-repository
---
# Sub-processor Repository
#### **What is a sub-processor?**
A sub-processor is a third-party data processor engaged by Mindtickle to carry out personal data processing activities as required to provide services to customers per the **terms of service**, agreement, and the **DPA**.
#### **List of sub-processors**
The table below indicates the current list of sub-processors authorized to process customer personal data on the Mindtickle platform and related services.
| **Legal entity name** | **Service applicability** | **Nature and purpose of processing** | **Data location** | **Personal data processed** | **Registered address** | **Status** |
| --------------------------------------------- | ----------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- | ---------- |
| MindTickle Interactive Media Private Limited1 | All services | Product development and customer support | India | **Mandatory** – Name, Email ID**Optional** – Photograph, Audio Recording, Video Recording | 4th Floor, Solitaire World, Baner, Pune, Maharashtra 411045, India | Active |
| Amazon Web Services, Inc. | Platform, Asset Hub, Call AI, RevOps, DSR | Cloud infrastructure, storage, and services | United States of America, Ireland, Singapore, and Japan based on the customer's choice | **Mandatory** – Name, Email ID**Optional** – Photograph, Audio Recording, Video Recording | 410 Terry Avenue North, Seattle, WA 98109-5210, United States of America | Active |
| Google LLC and affiliates | All services | Cloud infrastructure and Workspace services | United States of America or Ireland based on the customer's choice | **Mandatory** – Name, Email ID**Optional** – Audio Recording | 1600 Amphitheatre Parkway Mountain View, CA 94043, United States of America | Active |
| Microsoft Corporation | All services | Microsoft 365, Microsoft Power Platform and Azure Cognitive Services | United States of America for US data residency customers.Sweden, Netherlands and Japan for rest of the customers. | **Optional -** Personal information part of call transcript, learning content, sales assets and analytics | 1 Microsoft Way, Redmond, Washington, 98052, United States of America | Active |
| Box, Inc. | Platform | Media processing and transformation | Unites States of America | Name, Email ID | 900 Jefferson Avenue, Redwood City, CA 94063, United States of America | Active |
| Filestack, Inc. | Platform, Asset Hub | Media processing and transformation | Unites States of America | Name, Email ID | IDERA Headquarters 10801 N Mopac Expressway Building 1, Suite 100 Austin, TX, 78759, United States of America | Active |
| Snowflake, Inc. | Platform, Asset Hub, Call AI, RevOps, DSR | Data analytics and insights | United States of America or Singapore based on the customer's choice | Name, Email ID | Suite 3A, 106 East Babcock Street, Bozeman, Montana 59715, United States of America | Active |
| Nylas, Inc. | Asset Hub | Email accounts integration and message delivery | United States of America or Ireland based on the customer's choice | Email ID | 944 Market St, San Francisco, CA 94102, United States of America | Active |
| Workato, Inc. | Platform, Asset Hub, Call AI, RevOps, DSR | Integration platform between customers' third-party applications and Mindtickle | United States of America | Email ID | 215 Castro Street, Suite 300, Mountain View, California 94041, United States of America | Active |
| Sumo Logic, Inc. | Platform, Asset Hub, Call AI, RevOps, DSR | Log monitoring and analytics | United States of America | Name, Email ID | 305 Main Street Redwood City, CA 94063, United States of America | Active |
| Mixpanel, Inc. | Platform, Asset Hub, Call AI, RevOps, DSR | Platform event monitoring and analytics | United States of America | Name, Email ID | One Front Street, 28th Floor, San Francisco, CA 94111, United States of America | Active |
| Zipy, Inc. | Platform, Asset Hub, Call AI, RevOps, DSR | User session analytics and debugging | United States of America | **Mandatory** – Name, Email ID**Optional** – Photograph | 1010, Silliman Street, San Francisco, CA 94134, United States of America | Active |
| Atlassian Pty Ltd. | Platform, Asset Hub, Call AI, RevOps, DSR | Production issues/incidents tracking and communication | United States of America | **Mandatory** – Name, Email ID**Optional** – Support Call Audio Recording, Support Call Video Recording | Level 6, 341 George St, Sydney NSW 2000, Australia | Active |
| Freshworks, Inc. | Platform, Asset Hub, Call AI, RevOps, DSR | Managing tickets for customer support | United States of America | **Mandatory** – Name, Email ID**Optional** – Support Call Audio Recording, Support Call Video Recording | 2950 S. Delaware Street, Suite 201, San Mateo, CA 94403, United States of America | Active |
| Marketo, Inc. | All services | Communication management with customers' users and administrators | United States of America | Name, Email ID | 901 Mariners Island Blvd Suite 200, San Mateo, CA, 94404, United States of America | Active |
| Qualtrics, LLC | All services | Product feedback and surveys | United States of America | Name, Email ID | 333 W. River Park Dr. Provo, UT 84604, United States of America | Active |
| Salesforce.com, Inc. | All services | Customer account and relationship management | United States of America | Name, Email ID | 415 Mission Street, 3rd Floor, San Francisco, CA 94105, United States of America | Active |
| Articulate Global, LLC | CaaS | Content creation and collaboration | United States of America | Name, Email ID | 244 5th Avenue, Suite 2960, New York, NY 10001, United States of America | Active |
| Filestage GmbH | CaaS | Content creation and collaboration | Germany | Name, Email ID | Filestage GmbH, Lautenschlagerstraße 16, 70173, Stuttgart, Germany | Active |
| BoostUp.ai (Also known as Vocalo, Inc.) | RevOps | Provides sales forecasting and pipeline analysis | United States of America or Ireland based on the customer's choice | **Mandatory** – Name, Email ID, Address, Phone Number, Calendar Information**Optional** – Audio Call Recording, Audio Call Transcript | 2040 Martin Ave, Santa Clara, California 95050, United States of America | Active |
| OpenAI L.L.C. and affiliates | Platform, Call AI | Machine learning models for insights and workflows • Public ChatGPT not used or contributed to.• Customer data not used for training OpenAI models.• Customers control the AI-features to use. | United States of America | **Optional** – Name, personal information part of call transcript, learning content, and sales assets | 3180 18th Street, San Francisco, California 94110, United States of America | Active |
| Whatfix, Inc. | Platform, Asset Hub, Call AI, RevOps, DSR | Platform navigation training and walkthrough | United States of America | Name, Email ID | 2107 N. 1st Street, Suite 450, San Jose, California 95131, United States of America | Active |
| APIHub, Inc. dba Clearbit | DSR | Data enrichment service | United States of America | Email ID, IP Address | 548 Market Street Suite, #95879, San Francisco, California 94104, United States of America | Active |
| Berry, Inc. | All services | Customer success and support services | United States of America | Name, Email ID | 10505 NE 144th St, Kirkland, Washington 98034, United States of America | Active |
| Superpowered Labs Inc. | Platform | Audio/visual conversational AI service | United States of America | **Mandatory** \- Audio recording, Video recording**Optional** \- Personal information part of the audio transcript | 95 3rd Street, 2nd Floor, San Francisco, California 94103, United States of America | Active |
| Hyperdoc Inc. | Call AI | Video/audio recordings, transcription, and metadata provider for Call AI meetings | United States of America for US customersGermany for EU customersGermany and Japan for rest of the customers | **Mandatory** \- Name, Email ID, audio recording, video recording**Optional** \- Calendar Information, personal information part of the audio transcript | 2261 Market Street #4339 San Francisco, CA 94114, United States of America | Active |
| Sisense Ltd. | Platform, Asset Hub, Call AI, RevOps, DSR | Data Analytics and Visualization | United States of America for US Customers.Singapore for the rest of the customers. | Name, Email ID | 1359 Broadway, 4th Floor, NY, 10018, United States | Active |
1 For Customers, where MindTickle Interactive Media Private Limited is a party to the Agreement, this entity is a processor, not a sub-processor.
For the DSR exclusive customers, who have been using standalone DSR services since before Mindtickle acquired Enable Us, please find below the table indicating the current list of sub-processors authorized to process customer personal data.
| **Legal entity name** | **Nature and purpose of processing** | **Data location** | **Personal data processed** | **Registered address** | **Status** |
| --------------------- | ------------------------------------------------------------------------------------------------------------------ | ----------------- | ------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------- | ---------- |
| Intercom, Inc. | Customer support and product tools | United States | **Mandatory** – Name, Email ID**Optional** – Support Call Audio Recording, Support Call Video Recording | 55 2nd Street, 4th Floor, San Francisco, CA 94105 | Active |
| SendGrid, Inc. | Email communications | United States | Name, Email ID | 1801 California Street, Denver, United States of America | Active |
| HubSpot | Customer account and relationship management and Communication management with customers' users and administrators | United States | Name, Email ID | 125 1st St Fl 2, Cambridge, Massachusetts, 02141, United States | Active |
| ConvertAPI UAB | File Conversion API | Lithuania | Name, Email ID | Lauksargio g. 111, Vilnius LT- 10105, Lithuania, company code 304461332 | Active |
Note: The duration of processing by these sub-processors will be as per the terms of the Agreement signed with the Customers. Subject to specific approval of corresponding customers, we may use additional sub-processors for processing personal data controlled by the said customer.
**Additional information about definitions used in the service applicability**
* "Platform" includes Course, Quick Update, Checklist, Instructor-Led Training, Assessment, Missions (Virtual Role-Play), Coaching Session & Competency Assessment (Field Coaching), Spaced Reinforcement
* Conversational Intelligence (Call AI)
* Revenue Operations & Intelligence (RevOps)
* Digital Sales Rooms (DSR)
* Content as a Service (CaaS)
**Contractual controls**
Mindtickle signs data processing agreements and standard contractual clauses with all of its sub-processors and imposes data protection obligations for protecting customer personal data with similar security standards as committed by Mindtickle to the customers. These data processing agreements are aligned with the global data protection laws such as GDPR, CCPA, CPRA, UK DPA, etc.We include the following controls in the agreements to ensure the protection of customer personal data –
* **Right to audit** – to allow an audit of the procedures relevant to customer personal data protection.
* **Data deletion** – to delete personal data to fulfill data subject or customer requests or upon contract termination
* **Confidentiality agreements** – to ensure employees and contractors with access to customer personal data have understood the confidential nature of the information and have signed confidentiality agreements
* **Training** – to educate the employees on security and privacy practices to be followed while handling customer personal data
* **Incidents and breaches** – to identify the root cause and impact, remediate the incident, and inform Mindtickle of impacted customer personal data relevant to the incident or breach
* **Security measures** – to mandate technical and organizational security measures through **vendor security policy** or similar controls required by data protection laws and customer agreements
* **Fourth party risk** – to impose the same standards of processing and security controls under applicable data protection laws to sub-processors of Mindtickle sub-processors
**Onboarding and annual due diligence**
In accordance with our supplier security policy, Mindtickle performs mandatory due diligence of all sub-processors through information security, privacy, and legal reviews. Sub-processor due diligence is performed during onboarding and once annually and includes a review of the following –
* SOC 2 Type 2, ISO 27001, NIST, or similar industry-standard security reports
* Compliance with applicable data protection laws and regulations
* Vulnerability assessment and penetration testing reports
* Information security and privacy policy documents
* Privacy notice
* Service level agreements, including uptime commitments, RTO, and RPO
* Business continuity plans and disaster recovery reports
* Supplier due diligence questionnaire
Only the carefully selected suppliers that are approved by security, privacy, and legal teams in the due diligence process are authorized as sub-processors and granted access to customer personal data.
**Data sharing and responsibility**
Mindtickle engages sub-processors to process personal data only in accordance with the customer agreement and documented instructions through the following –
* **Onward data transfer** – includes using relevant transfer mechanisms for the transfer of personal data in accordance with the applicable data protection laws.
* **Data minimization** – sharing only the minimum required personal data that is absolutely necessary to provide services to our customers.
* **RoPA** – to maintain a detailed record of processing activities, including types, attributes, purposes, and safeguards of personal data shared with our sub-processors, which is reviewed quarterly.
* **Risk ownership** – Mindtickle takes full responsibility for the security and privacy of the customer data transferred to its sub-processors and will remain liable for any breach of customer personal data caused by any of its sub-processors.
**Changes to sub-processors**
Mindtickle provides at least 30 days prior notice to our subscribed customers before authorizing any new sub-processors to process customer personal data and provides customers with a window to object to such appointments.
Customers can use below subscription form to receive sub-processor change communication.
------------------------------------------------------------
# Mindtickle Vendor Security Policy | Third-party & Sub-Processor Due Diligence & Controls
**Focus Keyphrase:** Mindtickle vendor security policy
**Meta Description:** Learn about Mindtickle's Vendor Security Policy, outlining contractual measures and technical safeguards for vendors processing customer and organizational personally identifiable information (PII), detailing annual sub-processor due diligence, onboarding audits, SOC_2 & ISO_27001 compliance, RBAC access controls, encryption standards, and rigorous security monitoring for customer data.
**Original URL:** https://www.mindtickle.com/vendor-security-policy
---
# Vendor Security Policy
Mindtickle has defined below technical and organizational measures that are contractually bound to all the vendors that are processing customer or organizational personally identifiable information (PII).
These measures are designed to ensure an appropriate level of security is implemented, considering the data processing's nature, scope, context, and purpose and the risks to the rights and freedom of natural persons.
## Measures of pseudonymization and encryption of personal data
* All the Customer Data, including personal data transmitted through a web browser, mobile application, APIs, data connector, and integrations, is encrypted through HTTPS connection over TLS 1.2 using SHA-256 with 2048-bit RSA encryption.
* All the Customer Data, including personal data stored in primary and backup storage, is encrypted at rest with AES 256 encryption.
* Encryption keys with which Customer Data is encrypted shall be stored securely so that no one can retrieve keys from the service. In case the keys need to be retrieved, only limited individuals should be able to access those with specific authorization for a defined period. Further, the keys should be rotated at least on an annual basis.
* Laptops and workstations storing and accessing customer data are encrypted with full disk encryption.
* Information stored in activity logs and databases is pseudonymized wherever possible using a unique randomized user identifier that cannot be back-traced to a specific data subject.
## Measures for ensuring ongoing confidentiality, integrity, availability, and resilience of processing systems and services
* All the Customer Data, including personal data transmitted through a web browser, mobile application, APIs, data connector, and integrations, is encrypted through HTTPS connection over TLS 1.2 using SHA-256 with 2048-bit RSA encryption.
* All the Customer Data, including personal data stored in primary and backup storage, is encrypted at rest with AES 256 encryption.
* All new hires with access to Customer Data must sign confidentiality agreements. Further, employees with access to Customer Data undergo a background check that includes verification of references, education records, professional experience, national identity, and drug and criminal records permitted as per local laws.
* All employees with access to customer data are required to undergo information security and privacy training on an annual basis.
* Only authorized roles, as defined in the Role-Based Access Control (RBAC), are allowed to access systems processing customer and personal data using a unique username and an alphanumeric password with at least eight characters with one special, one lowercase and one uppercase character.
* Only limited individuals are granted access to infrastructure hosting customers and personal data based on the principle of least privilege and need-to-know basis.
* As part of the employee and contractor offboarding process, all accesses are revoked, and data assets are securely wiped. Further, the accesses are reviewed, modified, and aligned with job responsibilities upon role change.
* Only internal systems allowed through security groups can communicate with applications processing customer and personal data. Further, firewalls are configured to restrict access and communication with external systems.
* Changes to the software, applications, and infrastructure are made following the Software Development Life Cycle (SDLC), which includes code reviews and quality checks to ensure workflows designed to create, manage and retrieve personal data are implemented as per the design specifications.
* Access to modify or delete log files is restricted and segregated so that users who perform privileged activities cannot manipulate log files.
* Backup of application data, databases, file contents, and audit logs is performed per the backup policy that defines the backup scope, frequency, redundancy, failure monitoring, corrective action, retention, restoration, and archival.
* Customer data is automatically replicated in multiple availability zones physically separate from each other within a geographic region and backed up in another region for disaster recovery.
* A business continuity and disaster recovery plan is defined and follows a Recovery Time Objective (RTO) of 12 hours and a Recovery Point Objective (RPO) of 1 hour. In addition, an independent third-party audit is performed annually to conduct disaster recovery testing and validate the effectiveness of the business continuity plan.
## Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
* The incident management policy handles physical and technical events that adversely impact customer data security, confidentiality, integrity, availability, and privacy.
* Backup of application data, databases, file contents, and audit logs is performed per the backup policy that defines the backup scope, frequency, redundancy, failure monitoring, corrective action, retention, restoration, and archival.
* Customer data is automatically replicated in multiple availability zones physically separate from each other within a geographic region and backed up in another region for disaster recovery.
* A business continuity and disaster recovery plan is defined and follows a Recovery Time Objective (RTO) of 12 hours and a Recovery Point Objective (RPO) of 1 hour. In addition, an independent third-party audit is performed annually to conduct disaster recovery testing and validate the effectiveness of the business continuity plan.
## Processes for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures in order to ensure the security of the processing
* ISO 27001 or Service Organization Control 2 (SOC2) Type 2 assurance audit is performed annually to obtain an independent opinion on the suitability of the design and operating effectiveness of the implemented controls.
* An independent third-party security auditor annually performs vulnerability assessment and penetration testing of the applications (web, mobile, etc.) and network infrastructure.
* An independent third-party audit is performed annually to conduct disaster recovery testing and validate the effectiveness of the business continuity plan.
* Internal security and privacy controls are defined considering the customer's contractual commitments, privacy laws, applicable regulations, and generally accepted industry practices.
* Risk assessment of technical and organizational measures is performed annually to test and evaluate the effectiveness of internal security and privacy controls. Risk assessment includes identifying internal and external threats to operations, analyzing associated security and privacy risks, identifying the impact with relevant stakeholders, determining risk mitigation strategy, and deploying controls consistent with the determined risk mitigation strategy.
* Sub-processors undergo onboarding due diligence and annual review to ensure compliance with security and privacy requirements, service level agreements, laws, and regulations. In addition, sub-processors are required to sign a Data Processing Agreement (DPA) that includes compliance with data protection laws, confidentiality and right to audit clauses, data retention, and access requirements.
## Measures for user identification and authorization
* Accounts with access to systems processing customer and personal data are unique, mapped to individuals, and not shared between users.
* Only authorized roles, as defined in the Role-Based Access Control (RBAC), are allowed to access systems processing customer and personal data using a unique username and an alphanumeric password with at least eight characters with one special, one lowercase, and one uppercase character.
* Single Sign-On (SSO) and multi-factor authentication, such as one-time password, authentication key codes, or device-based authentication, are utilized wherever possible.
* Only limited individuals are granted access to infrastructure hosting customer and personal data based on the principle of least privilege using groups mapped to the IAM access permissions. Applications are granted access to customer and personal data using Identity and Access Management (IAM) policies.
* Only internal systems allowed through security groups can communicate with applications processing customer and personal data. Further, firewalls are configured to restrict access and communication with external systems.
* Access to modify or delete log files is restricted and segregated so that users who perform privileged activities cannot manipulate log files.
## Measures for the protection of data during transmission
* All the Customer Data, including personal data transmitted through a web browser, mobile application, APIs, data connector, and integrations, is encrypted through HTTPS connection over TLS 1.2 using SHA-256 with 2048-bit RSA encryption.
* All the Customer Data, including personal data stored in primary and backup storage, is encrypted at rest with AES 256 encryption.
## Measures for the protection of data during storage
* All the Customer Data, including personal data stored in primary and backup storage, is encrypted at rest with AES 256 encryption.
* Encryption keys with which Customer Data is encrypted shall be stored securely so that no one can retrieve keys from the service. In case the keys need to be retrieved, only limited individuals should be able to access those with specific authorization for a defined period. Further, the keys should be rotated at least on an annual basis.
* Laptops and workstations storing and accessing customer data are encrypted with full disk encryption.
## Measures for ensuring the physical security of locations at which personal data are processed
* Datacenter access requests are reviewed and approved based on the principle of least privilege, and time-bound multi-factor authenticated access is granted to specific data layer areas.
* Datacenter visitors are required to wear an identification badge, make an entry in the access register, and be escorted by authorized staff.
* Physical access to data centers is logged, monitored, and reviewed periodically to ensure access appropriateness.
* Physical access points to server rooms are recorded by a Closed Circuit Television Camera (CCTV) and guarded by security staff.
* Electronic intrusion detection and sound alarm systems are installed within the data layer to monitor, detect, and automatically alert appropriate personnel of security incidents.
* Data centers have a backup power supply and use mechanisms to monitor and control temperature, humidity, and water leaks. Further, data centers are equipped with smoke detection sensors and fire suppression equipment.
* Physical entry points to office premises are recorded by a Closed Circuit Television Camera (CCTV) and have an access card verification system at every door, allowing only authorized employees to enter the office premises.
* Office visitors record an entry in the visitor management system and are escorted by authorized employees.
## Measures for ensuring events logging
* Events and audit trails related to access to systems processing Customer Data are logged, monitored, and reviewed periodically.
* Audit logs maintain detailed information such as timestamps, IP address, application name, specific action taken, request metadata, etc., and are retained for one year.
* Notification alerts are sent based on the rules configured in the monitoring systems to identify anomalies, suspicious network behavior, abnormal activities, and threats.
## Measures for ensuring system configuration, including the default configuration
* Baseline systems are selected with hardened security configurations such as restricted remote access only with SSH, disabled remote root login, reduced number of non-critical packages, kernel live patching, and automatic installation of important security updates during initial boot.
* Baseline systems with hardened security configurations and vulnerability fixes are used in the production environment.
* After the version upgrade of the operating system, security scans are performed, vulnerabilities are remediated, and updated operating system images are finalized as baseline systems.
* Security scans are run on the production systems periodically to identify new vulnerabilities and remediate them in the affected and baseline system.
* Infrastructure configuration is regularly checked against the CIS benchmark containing security configuration best practices.
* Segregation between development, testing, staging, and production environment is maintained. Further, the data of one customer is segregated from other customers.
## Measures for internal IT and IT security governance and management
* Organization structure, reporting lines with assigned authority, and responsibilities are defined to appropriately meet business objectives ensuring proper segregation of duties, including an information security function headed by the Chief Information Security Officer responsible for ensuring security, availability, confidentiality, and privacy.
* There exists an Information Security Team headed by the Chief Information Security Officer. The roles and responsibilities of the members of the information security organization are defined.
* The data protection officer is formally appointed to oversee data protection strategy and ensure compliance with data protection standards.
* A management committee meeting is held at least once annually to discuss and amend the information security processes.
* A meeting between the management and the Board of Directors is conducted at least once annually to communicate, review and discuss the external assessment results and information needed to fulfill their roles aligned with the organization's objectives.
* Information security and privacy policies are defined considering customer contractual commitments and applicable data protection laws and regulations for handling and protecting data. These policies are reviewed annually and are available on the company portal for employee reference.
## Measures for certification/assurance of processes and products
* ISO 27001 or Service Organization Control 2 (SOC2) Type 2 assurance audit is performed annually to obtain an independent opinion on the suitability of the design and operating effectiveness of the implemented controls.
* Applicable requirements outlined in General Data Protection Regulation (GDPR) are complied with to help customers meet their obligations as Data Controllers or Data Processors.
## Measures for ensuring data minimization
* Information stored in activity logs and databases is pseudonymized wherever possible using a unique randomized user identifier that cannot be back-traced to a specific data subject.
* The only minimum required personal data is shared with third parties to provide customer services.
## Measures for ensuring data quality
* Customers can export personal data records to perform data quality checks and corrections.
## Measures for ensuring limited data retention
* Personal data is retained per the contractual terms agreed with the customers and as the laws require.
* Audit logs containing personal data are retained for one year and, after that, either pseudonymized or deleted.
* Data processing agreements that include data retention requirements are signed with third parties with a minimum required personal data shared to provide customer services.
## Measures for ensuring accountability
* Accounts with access to systems processing customer and personal data are unique, mapped to individuals, and not shared between users.
* Events and audit trails related to access to systems processing Customer Data are logged, monitored, and reviewed periodically.
* Audit logs maintain detailed information such as timestamps, IP address, application name, specific action taken, request metadata, etc., and are retained for one year.
* Access to modify or delete log files is restricted and segregated so that users who perform privileged activities cannot manipulate log files.
## Measures for allowing data portability and ensuring erasure
* Customers can export their data through reports or programmatic APIs.
* Personal data is retained per the contractual terms agreed with the customers and as the laws require.
* Audit logs containing personal data are retained for one year and, after that, either pseudonymized or deleted.
* Personal data records are removed through a secure deletion process that irreversibly destroys the data.
* Data processing agreements that include data retention requirements are signed with third parties with a minimum required personal data shared to provide customer services.
------------------------------------------------------------
# Mindtickle Service Level Agreement (SLA) | 99.9% Uptime, RTO 12h & RPO 1h
**Focus Keyphrase:** Mindtickle Service Level Agreement
**Meta Description:** Read Mindtickle's SLA, designed for reliability with 99.9% uptime, recovery objectives (RTO 12_h and RPO 1_h), exclusions and service credits for exceptional reliability.
**Original URL:** https://www.mindtickle.com/service-level-agreement
---
# Service Level Agreement
## Objective
This Mindtickle Service Level Agreement ("SLA") is a policy governing the usage and availability of Mindtickle Platform under the terms of the Agreement. This SLA applies separately to each account (not per User, but per Agreement) using Mindtickle. Unless otherwise provided herein, this SLA is subject to the terms of the Agreement and capitalized terms will have the meaning specified in the Agreement.
## Service Commitment
Mindtickle will use commercially reasonable efforts to make Mindtickle Platform available with a Monthly Uptime Percentage (defined below) of at least 99.9%, over any calendar month (the "Service Commitment"). In the event Mindtickle Platform does not meet the Service Commitment, Customer may be eligible to receive a Service Credit as described below.
## Definitions
* "Monthly Uptime Percentage" is calculated by subtracting from 100% the percentage of hours during the month in which Mindtickle Platform was Unavailable. Monthly Uptime Percentage measurements exclude downtime resulting directly or indirectly from any Mindtickle SLA Exclusion (defined below).
* "Unavailable" and "Unavailability" mean when all the Mindtickle applications (e.g. admin site, learning site, mobile apps etc.) do not have any external connectivity, i.e. all Users of a Customer can't access the Mindtickle Platform, and such inability to access the Platform is not attributable to Mindtickle SLA Exclusions, as defined below.
* A "Service Credit" is a dollar credit, calculated as set forth below, that Mindtickle may credit back to an eligible account.
* Recovery Time Objective (RTO): The Recovery Time Objective is measured from the time the Mindtickle Platform is Unavailable until such Unavailability is remedied. Except for Unavailability due to Mindtickle SLA Exclusions, as defined below, Mindtickle's standard RTO is 12 hours.
* Recovery Point Objective (RPO): The Recovery Point Objective is measured from the time that the first transaction is lost until the Mindtickle Platform became Unavailable. Except for Unavailability due to Mindtickle SLA Exclusions, as defined below, Mindtickle's standard RPO is 1 hour.
## Service Commitments and Service Credits
Service Credits are calculated as a percentage of the charges for Subscription Fees paid by Customer (excluding one-time payments such as Professional service charge, Single-Sign-On charges, integration charges, etc.) for Mindtickle Platform for the agreed calendar month in which the Unavailability occurred in accordance with the schedule below.
| **Monthly uptime percentage** | **Service credit percentage** |
| ----------------------------- | ----------------------------- |
| 99.1% to 99.8% | 1% |
| 95.1% to 99.0% | 10% |
| 90.1% to 95.0% | 20% |
| Less than 90.0 % | 30% |
* Mindtickle will apply any Service Credits only against future Mindtickle Platform payments otherwise due from Customer, but if no such payments are due (e.g., Customer does not renew its subscription) then the term of the Agreement will be extended for the period equivalent to the Service Credits accumulated.
* At Mindtickle's discretion, Mindtickle may issue the Service Credit to the credit card Customer used to pay for the billing cycle in which the Unavailability occurred. Except as expressly set forth herein, Service Credits will not entitle Customer to any refund or other payment from Mindtickle.
* A Service Credit will be applicable and issued only if the credit amount for the applicable agreed billing cycle is greater than hundred dollars ($100 USD). Service Credits may not be transferred or applied to any other account.
* Unless otherwise provided in the Agreement, Customer's sole and exclusive remedy for any Unavailability, non-performance, or other failure by Mindtickle to provide Mindtickle Platform is the receipt of a Service Credit (if eligible) in accordance with the terms of this SLA.
## Credit Request and Payment Procedures
To receive a Service Credit, Customer must submit a ticket on help.www.mindtickle.com or send an email to [email protected]. To be eligible, the Service Credit request must be received by Mindtickle within 60 days from when the incident occurred and must include:
1. the words "SLA Credit Request" in the subject line;
2. the dates of each Unavailability incident that Customer is claiming;
3. the affected location; and
4. documentation of the errors that corroborate Customer's claimed outage (any confidential or sensitive information in these logs should be removed or replaced with asterisks).
If the Monthly Uptime Percentage for the periods corresponding to such requests is confirmed by Mindtickle to be less than the Service Commitment, then Mindtickle will issue the Service Credit to Customer within 60 days from end of the month in which Customer's request is confirmed by Mindtickle. Customer's failure to provide the request and other information as required above will disqualify Customer from receiving a Service Credit.
## Mindtickle SLA Exclusions
The Service Commitment does not apply to any Unavailability, suspension or termination of Mindtickle Platform, or any other Mindtickle Platform performance issues that: (i) result from an explicit suspension or termination of Mindtickle Services in accordance with the Agreement; (ii) are caused by factors outside of Mindtickle's reasonable control, including any force majeure event or Internet access or related problems beyond the demarcation point of the Mindtickle Platform; (iii) result from any actions or inactions of Customer or any third party, including failure to acknowledge a recovery; (iv) result from Customer's equipment, software or other technology and/or third party equipment, software or other technology (other than third party equipment within Mindtickle's direct control); (v) result from failures attributable to regional unavailability of Amazon Web Services; or (vi) any planned maintenance required to provide the Services as pursuant to the Agreement and notified to the Customer in advance; or (vii) arising from Mindtickle's suspension and termination of Customer's right to use Mindtickle Platform in accordance with the Agreement (collectively, the "Mindtickle SLA Exclusions").
------------------------------------------------------------
# Mindtickle Acceptable Use Policy | Permitted Use & Prohibited Actions
**Focus Keyphrase:** Mindtickle acceptable use policy
**Meta Description:** Read Mindtickle's Acceptable Use Policy outlining permitted use, prohibited activities (e.g., no data scraping or malware), security obligations, and liability terms to ensure platform integrity and compliance.
**Original URL:** https://www.mindtickle.com/acceptable-use-policy
---
# Acceptable Use Policy
Use of the Services is subject to this acceptable use policy.
Customer agrees not to, and not to allow third parties or End Users, to use the Services:
* to generate or facilitate unsolicited bulk commercial email;
* to violate, or encourage the violation of, the legal rights of others;
* for any unlawful, invasive, infringing, defamatory, or fraudulent purpose;
* to distribute viruses, worms, Trojan horses, corrupted files, hoaxes, or other items of a destructive or deceptive nature;
* to interfere with the use of the Services, or the equipment used to provide the Services, by Mindtickle's other customers, authorized resellers, or other authorized users;
* to alter, disable, interfere with or circumvent any aspect of the Services;
* to test or reverse-engineer the Services in order to find limitations, vulnerabilities or evade filtering capabilities;
* to gain unauthorized access to Mindtickle's Platform or the data of any third party; or
* in a manner that violates any applicable law, rule or regulation.
------------------------------------------------------------
# Mindtickle Insurance Coverage | Cyber, Liability & Employee Protection
**Focus Keyphrase:** Mindtickle insurance coverage
**Meta Description:** Discover Mindtickle's insurance programs, including $4M general liability, $5M professional E&O, $5M cyber/privacy, auto liability, workers' compensation, and employer's liability—designed to protect customers and employees.
**Original URL:** https://www.mindtickle.com/insurance
---
# Insurance
The list of insurance maintained by Mindtickle as of the Effective Date of this MSA as follows:
(a) **Comprehensive General liability insurance** in the amount of not less than US$4,000,000 for bodily injury, death, personal injury, and broad form property damages, per occurrence, and a US$4,000,000 aggregate. Required limits may be attained by use of Commercial Umbrella Liability coverage;
(b) **Business automobile liability insurance** in the amount of not less than US$1,000,000 for bodily injury or death of person and property damages, per occurrence, including hired and non-owned liability;
(c) **Professional liability/Errors and Omissions insurance coverage** of not less than US$5,000,000 each claim and annual aggregate for liabilities;
(d) **Privacy and cyber liability** of not less US$5,000,000 (which may be included as a coverage under Mindtickle's professional liability/errors and omissions insurance and if so, then covered by the same policy limits for such insurance);
(e) **Worker's Compensation** in accordance with statutory limits; and
(f) **Employer's Liability** with a limit not less than US$1,000,000 each employee by disease, US$1,000,000 each employee by accident, or minimum amount legally required, whichever amount is the greater.
## Insurance Coverage Summary
### General Liability Insurance
- **Coverage Amount:** US$4,000,000
- **Coverage Type:** Bodily injury, death, personal injury, and broad form property damages
- **Per Occurrence:** US$4,000,000
- **Aggregate:** US$4,000,000
- **Additional Notes:** Required limits may be attained by use of Commercial Umbrella Liability coverage
### Business Automobile Liability Insurance
- **Coverage Amount:** US$1,000,000
- **Coverage Type:** Bodily injury or death of person and property damages
- **Per Occurrence:** US$1,000,000
- **Includes:** Hired and non-owned liability
### Professional Liability/Errors and Omissions Insurance
- **Coverage Amount:** US$5,000,000
- **Coverage Type:** Professional liability and errors and omissions
- **Each Claim:** US$5,000,000
- **Annual Aggregate:** US$5,000,000
### Privacy and Cyber Liability Insurance
- **Coverage Amount:** US$5,000,000
- **Coverage Type:** Privacy and cyber liability protection
- **Special Note:** May be included as a coverage under Mindtickle's professional liability/errors and omissions insurance and if so, then covered by the same policy limits for such insurance
### Worker's Compensation
- **Coverage:** In accordance with statutory limits
- **Compliance:** Meets all regulatory requirements
### Employer's Liability
- **Coverage Amount:** Not less than US$1,000,000
- **Each Employee by Disease:** US$1,000,000
- **Each Employee by Accident:** US$1,000,000
- **Minimum Requirement:** Minimum amount legally required, whichever amount is the greater
## Purpose of Insurance Coverage
These comprehensive insurance policies are designed to:
1. **Protect Customers:** Provide financial protection and peace of mind to Mindtickle customers through comprehensive liability coverage
2. **Protect Employees:** Ensure adequate coverage for all Mindtickle employees through workers' compensation and employer's liability insurance
3. **Mitigate Business Risks:** Cover various business operations including professional services, cyber security, and general business activities
4. **Ensure Compliance:** Meet contractual and regulatory requirements for insurance coverage
5. **Financial Protection:** Provide substantial financial protection across multiple risk categories with multi-million dollar coverage limits
## Key Insurance Features
- **Multi-Million Dollar Coverage:** Total coverage exceeding $19 million across all insurance categories
- **Comprehensive Protection:** Coverage for both traditional business risks and modern cyber threats
- **Professional Standards:** Professional liability coverage meeting industry standards
- **Regulatory Compliance:** All insurance meets or exceeds statutory requirements
- **Customer Assurance:** Robust insurance portfolio providing confidence to enterprise customers
- **Employee Protection:** Complete coverage for employee-related incidents and workplace injuries
------------------------------------------------------------
# Mindtickle Information Requests Transparency Report
**Focus Keyphrase:** Mindtickle transparency report
**Meta Description:** Read Mindtickle's Transparency Report, detailing the number and types of government requests for user information requests received globally. Zero requests received from US or Non_US agencies since 2019, in compliance with GDPR, SCCs & global privacy standards.
**Original URL:** https://www.mindtickle.com/information-requests-transparency-report
---
## Information Requests Transparency Report
Data protection laws across the globe have provisions that allow government agencies and public and data protection supervisory authorities to request user information for civil, administrative, criminal, and national security purposes.
GDPR, through new standard contractual clauses, requires data processors to maintain this information through a transparency report¹. In this transparency report, we have shared information about the number and type of requests Mindtickle has received from government agencies globally, where permitted by applicable laws.
## 0
#### Total information requests received
## Requests received by Mindtickle from Government and Law Enforcement Entities
| **Period** | **Authority** | **Requests received** | **Requests challenged** | **Requests denied** | **Requests accepted** | **No data to disclose** | **Content disclosed** | **Only non-content disclosed** |
|------------|---------------|----------------------|------------------------|--------------------|-----------------------|------------------------|----------------------|-------------------------------|
| **Jan 2025 – Present** | US Subpoena | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US Search Warrants | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US Court Orders | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US National Security Requests | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | Non-US Requests | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| **Jan 2024 – Dec 2024** | US Subpoena | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US Search Warrants | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US Court Orders | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US National Security Requests | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | Non-US Requests | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| **Jan 2023 – Dec 2023** | US Subpoena | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US Search Warrants | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US Court Orders | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US National Security Requests | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | Non-US Requests | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| **Jan 2022 – Dec 2022** | US Subpoena | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US Search Warrants | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US Court Orders | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US National Security Requests | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | Non-US Requests | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| **Jan 2021 – Dec 2021** | US Subpoena | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US Search Warrants | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US Court Orders | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US National Security Requests | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | Non-US Requests | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| **Jan 2020 – Dec 2020** | US Subpoena | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US Search Warrants | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US Court Orders | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US National Security Requests | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | Non-US Requests | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| **Jan 2019 – Dec 2019** | US Subpoena | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US Search Warrants | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US Court Orders | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | US National Security Requests | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| | Non-US Requests | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
**NOTE:** Mindtickle has not received any requests for access to User Data by the U.S. or any Non-US Government and Law Enforcement Agencies in the period that is not covered in the above table.
## Footnotes
**Subpoena:** Subpoenas are valid and binding legal demands for information or testimony issued by courts, lawyers, law enforcement agencies, or grand juries, usually without any substantive review by a judge or magistrate.
**Search warrants:** Search warrants may be issued by local, state, or federal courts upon a showing of probable cause and must specifically identify the place to be searched and the items to be seized.
**Other court orders:** Other court orders refer to valid and binding orders issued by local, state, or federal courts, other than search warrants or court-issued subpoenas.
**National security requests:** National security requests include National Security Letters ("NSLs") and court orders issued under the Foreign Intelligence Surveillance Act ("FISA").
**Requests from Non-US Governments and Law Enforcement Entities:** Non-U.S. requests include legal demands from non-U.S. governments, including legal orders issued pursuant to the Mutual Legal Assistance.
¹Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council referenced into C/2021/3972, Mindtickle is required under below sections to maintain a transparency report –
* Section III (Local Laws and Obligations in case of Access by Public Authorities) – Clause 15 (Obligations of the data importer in case of access by public authorities) – 15.1 Notification (c) – Where permissible under the laws of the country of destination, the data importer agrees to provide the data exporter, at regular intervals for the duration of the contract, with as much relevant information as possible on the requests received (in particular, number of requests, type of data requested, requesting authority/ies, whether requests have been challenged and the outcome of such challenges, etc.).
* Section III (Local Laws and Obligations in case of Access by Public Authorities) – Clause 15 (Obligations of the data importer in case of access by public authorities) – 15.1 Notification (d) – The data importer agrees to preserve the information pursuant to paragraphs (a) to (c) for the duration of the contract and make it available to the competent supervisory authority on request.
------------------------------------------------------------
# Mindtickle Responsible Vulnerability Disclosure Policy | Ethical Bug Reporting & Security
**Focus Keyphrase:** Mindtickle vulnerability disclosure policy
**Meta Description:** Review Mindtickle's Responsible Vulnerability Disclosure Policy with scope, guidelines and safe_harbor for ethical security researchers. Report platform, API or mobile app bugs responsibly and help us secure customer data.
**Original URL:** https://www.mindtickle.com/responsible-vulnerability-disclosure
---
## Policy
At Mindtickle, we are committed to **protecting the privacy and security of the data** our customers have entrusted to us. We have implemented numerous **measures** to secure our infrastructure and the platform.
Despite the measures, due to evolving nature of the technology landscape, it is always possible that we are affected by new vulnerabilities. We acknowledge the importance of time spent and valuable assistance provided by independent security researchers to make our web experience more secure.
We are promoting a culture of responsible disclosure of vulnerabilities that affects the security and privacy of our platform and its users.
## Scope
The sites, applications, and APIs covered in this policy are listed below.
* Platform admin site – **admin.mindtickle.com**
* Platform learning sites – **.mindtickle.com**
* Other platform pages – **\*.mindtickle.com**
* Open API – **api.mindtickle.com**
* **iOS mobile application**
* **Android mobile application**
## Exclusions
We have carefully chosen the exclusions to prioritize our remediation efforts on the vulnerability that can be exploited and directly impact our platform hosting customer data. We request you not to report any vulnerabilities that only focus on the enumeration and information gathering and have no potential to penetrate our systems. Anything not declared in the scope above is considered out of scope.
The below list covers the exclusions –
* Denial of Service (DoS) / Distributed Denial of Service (DDoS)
* Cross-origin resource sharing (CORS)
* WordPress XML-RPC.php
* Server-side request forgery (SSRF)
* Brute force attack on any of the pages
* Session timeout since it is configured at a customer level
* Uploading masqueraded file by changing the extension
* Ability to upload/down viruses or malicious files to the platform
* Rate limiting restrictions imposed by the platform or API
* Missing captcha on the pages
* Ability to accept web browser 'autocomplete' or 'saved passwords' functionality
* Known third party library vulnerabilities that cannot be exploited on the platform
* Missing HTTP security headers that do not pose any security threats
* Missing Secure, HTTPOnly flags on cookies that do not hold any confidential or authentication information
* Learning site settings enumeration containing non-sensitive information
* Fingerprinting, host header, and banner grabbing issues
* Descriptive error messages (e.g., stack traces, application error messages, server HTTP response)
* Information gathered through social engineering (e.g., phishing, vishing)
* Physical security of the Mindtickle offices or employee working environment
* Conducting any kind of physical or electronic attack on Mindtickle personnel or property
## Guidelines
We encourage the efforts spent by security researchers to identify legitimate vulnerabilities. To make this process smooth, we have defined a set of guidelines that help us differentiate malicious intent from the genuine discovery that helps us make our platform safer.
* Sending automated reports generated by tools and scanners is prohibited.
* Seek consent from your organization before using any company-provided user accounts for performing any testing or research activity.
* Do not attempt to gain access to another user's account.
* Performing social engineering or sending unsolicited messages such as spam, phishing, etc., is not allowed.
* Do not violate any laws or regulations by compromising any other data that is not your own; use test data.
* Avoid any activity that violates user privacy, disrupts the platform, destructs or modifies the data, exfiltrates unnecessary confidential information, or degrades the application performance.
* Do not disclose any information about discovered vulnerabilities unless authorized by Mindtickle. Only use the approved process defined in the below section to send vulnerability reports to Mindtickle.
* Immediately report if you inadvertently encounter any customer or personal information. Do not view, alter, save, store, transfer, or otherwise access the data, and immediately purge any local information upon reporting the vulnerability.
* Do not validate or make use of any sensitive customer or personal information you may have encountered during your research and testing.
* Although we encourage responsible vulnerability disclosure, the specific bug bounty awards offered for the vulnerabilities are at the discretion of Mindtickle.
* Bug bounty awards would be considered only in cases of critical/high impact vulnerabilities that can penetrate our systems affecting platform availability or customer data.
* We withhold the right to grant, modify or deny grants. In such cases, the reporter would be responsible for the tax implications of payouts.
## Disclosure Process
If you have found any in scope security or privacy vulnerability and adhere to the exclusions and guidelines, please report it to us promptly by emailing it to the Mindtickle security team at **security@mindtickle.com**. We ask that you do not share any of the details of the identified vulnerability publicly or with anyone else apart from the Mindtickle security team.
Include the following details with your report:
* Name of the reporter
* Email address where we can contact you
* The scoped site, application, or API impacted
* The potential impact of the vulnerability on the systems or data
* Steps to reproduce the vulnerability (please include screenshots, videos, scripts, commands, etc.)
* Any specific information that will help us remediate the vulnerability faster.
We will get back to you as soon as possible and keep you updated on the progress of the vulnerability remediation activity.
## Safe Harbor
If you comply with this policy while reporting the vulnerability, we will safeguard you against any legal action under Computer Fraud and Abuse Act (CFAA) or Digital Millennium Copyright Act (DMCA).
## Hall of Fame
We extend our sincere gratitude to the following security researchers who contributed to strengthening Mindtickle's security posture through our Responsible Vulnerability Disclosure Policy. Your collective efforts in identifying and assisting with vulnerability remediation are vital to protecting our customers and building a more secure platform.
| **Researcher Name** | **Social Profile / Email** | **Number of Reports** |
| --------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------- |
| Armaan Sidana | [LinkedIn](https://www.linkedin.com/in/armaan-sidana/) | 1 |
| Rishyendra M | Email: rishyendra.m@email.com | 1 |
| Akash Singh | [LinkedIn](https://www.linkedin.com/in/akashsingh2310) | 1 |
| Ambika Dave | [LinkedIn](https://www.linkedin.com/in/ambikadave1510) | 1 |
| Ayush Kumar | [LinkedIn](https://www.linkedin.com/in/ayush-kumar-66177021b) | 1 |
| A Sai Vardhan | [LinkedIn](https://www.linkedin.com/in/a-sai-vardhan-39930321a) | 1 |
| Nikhil Chaudhari | [LinkedIn](https://www.linkedin.com/in/nikhil-chaudhari-9408bb269) | 1 |
| Sheetal Sangle | [LinkedIn](https://www.linkedin.com/in/sheetal-sangle-2016ba2b5?utm%5Fsource=share&utm%5Fcampaign=share%5Fvia&utm%5Fcontent=profile&utm%5Fmedium=android%5Fapp) | 1 |
| Mohd Ali | [Instagram](https://www.instagram.com/revengerali/) | 1 |
| Gaurang Maheta | [LinkedIn](https://www.linkedin.com/in/gaurang883) | 2 |
| Yogeswaran M | [LinkedIn](https://www.linkedin.com/in/yogeswaran-m) | 1 |
| Navaneethan M | [LinkedIn](https://www.linkedin.com/in/1h3ll) | 1 |
| Shivam Dhingra | [LinkedIn](https://linkedin.com/in/shivam-dhingra) | 1 |
| Ali Raza | [LinkedIn](https://www.linkedin.com/in/ali-raza-a4085719b) | 1 |
| Vinayak Sakhare | [LinkedIn](https://www.linkedin.com/in/vinayak-sakhare-63b343119/) | 1 |
| Rahul Karki | [X(Twitter)](https://x.com/kaks3c) | 1 |
| Sumit Sahoo | [Website](https://www.sumitsahoo.com/) | 2 |
| Foysal Ahmed Fahim | [X(Twitter)](https://x.com/foysal1197) | 1 |
| Devansh Chauhan | [LinkedIn](https://www.linkedin.com/in/devansh-chauhan-b36b6a1b1/) | 1 |
| Pushkar Vyas | [LinkedIn](https://www.linkedin.com/in/pushkar-vyas-838979229/) | 1 |
| Gaurav Shukla (Ciphershade) | [LinkedIn](https://www.linkedin.com/in/gaurav-shukla-ciphershade-%E2%9C%A8-ab9b892b4/) | 1 |
------------------------------------------------------------
# Mindtickle "Do Not Sell My Personal Information" | Opt_Out Form & Privacy Rights
**Focus Keyphrase:** Do Not Sell My Personal Information
**Meta Description:** Exercise your privacy rights with Mindtickle's "Do Not Sell My Personal Information" form. Submit an opt_out request, request data deletion or access, and control how your personal information is shared or sold.
**Original URL:** https://www.mindtickle.com/do-not-sell-my-personal-information
---
# Individual Rights Request Form
You may have the right to request certain personal data relating to you to be deleted from or modified in our systems, or you may have the right to request a copy of personal data about you stored in our systems. Please complete this form to exercise those rights relating to the personal data we hold about you.
## Request Form
*Terms & Conditions*
We will endeavor to respond promptly and in any event within one month of receipt of this request. However, the period may be extended taking into account the complexity and number of requests. In such case, we will inform you of any such extension along with the reason for the delay.
Please note that if the information you request reveals details directly or indirectly about another person we will have to seek the consent of that person before we can share that information. In certain circumstances, where disclosure would adversely affect the rights and freedoms of others, we may not be able to disclose the information to you, in which case you will be informed promptly and given full reasons for that decision.
While in most cases we will provide you with copies of the information you request free of cost, we nevertheless reserve the right to charge a fee or refuse the request if it is considered to be "manifestly unfounded or excessive".
------------------------------------------------------------
# Mindtickle Cookie Policy | Website Cookies, Consent & User Controls
**Focus Keyphrase:** Mindtickle website cookie policy
**Meta Description:** Learn how Mindtickle uses cookies on its website, including essential, analytics, and functional cookies. Understand your cookie preferences, consent options, and how to manage or reject cookies via your browser settings.
**Original URL:** https://www.mindtickle.com/cookie-policy
---
**Last Updated:** January 24, 2024
This Cookie Policy describes how Mindtickle, Inc. and its affiliates use cookies and other similar technology on its marketing website at the following link – **https://mindtickle.com/**.
This policy explains what cookies are, how we use them, the types of cookies we use, i.e., the information we collect using cookies and how that information is used, and how to manage the cookie settings.
## What is a Cookie?
Cookies are text files that are used to store small pieces of information. They are stored on your device when the website is loaded on your browser. These cookies help the website function correctly, make it more secure, provide a better user experience, understand how the website performs, and analyze what works and where it needs improvement.
## How do we use cookies?
As with most online services, our website use first-party and third-party cookies for several purposes. First-party cookies are necessary to provide correct functionality and typically do not collect any of your personally identifiable data.
The third-party cookies are mainly for understanding performance and interactions, keeping the services secure, providing marketing website advertisements that are relevant to you, and, all in all, providing you with a better and improved user experience and helping speed up your future interactions with our website and the Mindtickle platform.
## Type of cookies we use
1. **Necessary** – Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.
2. **Functional** – Functional cookies help perform certain functionalities like sharing the website's content on social media platforms, collecting feedback, and other third-party features.
3. **Performance** – Performance cookies are used to understand and analyze the key performance indexes of the website, which helps in delivering a better user experience for the visitors.
4. **Analytics** – Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.
5. **Advertisement** – Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.
6. **Others** – Other uncategorized cookies are those that are being analyzed and have yet to be classified into a category.
## Manage cookie preferences for the marketing website
A cookie in no way gives us access to your computer, mobile, or any personal information about you other than the data you choose to share with us. You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can modify your browser setting to decline cookies if you prefer. Before making changes to the cookie preferences, please consider that deleting and blocking cookies may impact your user experience.
You can change your cookie preferences anytime by clicking the below button. This option will let you revisit the cookie consent banner, change your preferences, or withdraw your consent immediately.
**Change Cookie Preferences**
In addition, different browsers provide different methods to block and delete cookies used by websites. You can change your browser's settings to block/delete the cookies. Listed below are the links to the support documents on how to manage and delete cookies from major web browsers.
- **[Chrome Support Article](https://support.google.com/accounts/answer/32050)**
- **[Safari Support Article](https://support.apple.com/en-in/guide/safari/sfri11471/mac)**
- **[Firefox Support Article](https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox?redirectslug=delete-cookies-remove-info-websites-stored&redirectlocale=en-US)**
- **[Microsoft Edge Support Article](https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09)**
- **[Opera Support Article](https://www.opera.com/use-cases/clean-browser-and-remove-trackers)**
- **[Brave Support Article](https://support.brave.com/hc/en-us/articles/360048833872-How-Do-I-Clear-Cookies-And-Site-Data-In-Brave-)**
- **[Vivaldi Support Article](https://help.vivaldi.com/desktop/privacy/cookies/)**
Please visit your browser's official support documents if you use any other web browser.
## List of cookies we use on the marketing website
Please refer to the below table for the list of cookies that our website uses –
### Necessary
Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.
| Cookie | Duration | Description |
|--------|----------|-------------|
| mutiny.user.session_number | 1 hour | This cookie stores session number used by Mutiny software to track a user's journey on the website in order to make improvements in website experience. |
| mutiny.user.token | 1 year 1 month 4 days | This cookie stores user token ID used by Mutiny software to track a user's journey on the website in order to make improvements in website experience. |
| mutiny.user.session | 1 hour | This cookie stores user session ID used by Mutiny software to track a user's journey on the website in order to make improvements in website experience. |
| _mkto_trk | 1 year 1 month 4 days | This cookie, provided by Marketo, has information (such as a unique user ID) that is used to track the user's site usage. The cookies set by Marketo are readable only by Marketo. |
| cookieyesID | 1 year | Unique identifier for visitors used by CookieYes with respect to the consent. |
| cky-consent | 1 year | The cookie is set by CookieYes to remember the user's consent to the use of cookies on the website. |
| cookieyes-necessary | 1 year | This cookie is set by CookieYes and is used to remember the consent of the users for the use of cookies in the 'Necessary' category. |
| cookieyes-functional | 1 year | This cookie is set by CookieYes and is used to remember the consent of the users for the use of cookies in the 'Functional' category. |
| cookieyes-analytics | 1 year | This cookie is set by CookieYes and is used to remember the consent of the users for the use of cookies in the 'Analytics' category. |
| cookieyes-performance | 1 year | This cookie is set by CookieYes and is used to remember the consent of the users for the use of cookies in the 'Performance' category. |
| cookieyes-advertisement | 1 year | This cookie is set by CookieYes and is used to remember the consent of the users for the use of cookies in the 'Advertisement' category. |
| cookieyes-other | 1 year | This cookie is set by CookieYes and is used to remember the consent of the users for the use of cookies in the 'Others' category. |
| cky-action | 1 year | This cookie is set by CookieYes and is used to remember the action taken by the user. |
| qualified_session | Session | Identifies a user of the Qualified Application's (this is a Qualified user using the Qualified application) login to the Qualified Application. This cookie isn't set on website visitors. This cookie is only used to ensure users using the Qualified application can log into the service. |
| __q_domainTest | session | This is a cookie used in rare cases if Qualified is unable to detect the domain where Qualified is being instantiated. It is set and immediately unset. |
| __q_state_NDfhNaW4kM53Cmmy | 1 year 1 month 4 days | Contains a number of attributes identifying the website visitor and his/her interaction with the Qualified Chat Messenger. |
| _vis_opt_test_cookie | session | This cookie is created to detect if the cookies are enabled on the visitor's browser or not. It also helps in tracking the number of browser sessions a visitor has gone through. The value of this cookie is always 1. |
| ELOQUA | 1 month | This cookie is generated by Oracle Eloqua marketing product which is used by Zoominfo for Marketing Automation. |
| _vis_opt_s | 3 months 8 days | This cookie tracks session created for a visitor, i.e., the number of times the browser was closed and reopened. |
| _px3 | 2 hours | This cookie is used by Zoominfo.com service to remember visitor cookie consent preferences. |
| _vwo_uuid_v2 | 1 year | This cookie is created for each cross-domain campaign. It generates a unique id for every visitor and is used for the report segmentation feature in VWO, and it also allows you to view data in a more refined manner. |
| insent-user-id | 2 years | This cookie is set by Zoominfo and is used to identify and initiate conversations with users when they are onsite. |
| _gid | 1 day | Registers a unique ID that is used to generate statistical data on how the visitor uses the website. |
| CookieConsent | 1 year | This cookie is set by Zoominfo to store the user's cookie consent state for the current domain. |
| _vwo_ds | 2 months | This cookie stores persistent user-level data for Zoominfo.com |
| _cq_suid | Session | This cookie monitors the technical information and use of devices that connect to our website to protect it from malicious traffic. |
| _gcl_au | 3 months | This cookie is provided by Google Tag Manager to experiment advertisement efficiency of websites using their services. |
| _ga | 1 year 1 month 4 days | The _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors. |
| _cq_duid | 3 months | This cookie monitors the technical information and use of devices that connect to our website to protect it from malicious traffic. |
| _pxvid | 1 year | Used by Zoominfo.com to detect fraud and bot activity. |
| pxcts | Session | Used by Zoominfo.com to detect fraud and bot activity. |
| __utm_tracking_session | 8 minutes | This cookie is used to identify the referrer information from the URLs that redirected users to Mindtickle website. This is used to track the performance of marketing campaigns and content as well as website's traffic sources. |
| __ft_referrer | 3 months | This cookie is used to identify the referrer information from the URLs that redirected users to Mindtickle website. This is used to track the performance of marketing campaigns and content as well as website's traffic sources. |
| mkto_referrer | 3 months | This cookie is used by Marketo to identify the referrer information from the URLs that redirected users to Mindtickle website. This is used to track the performance of marketing campaigns and content as well as website's traffic sources. |
| __ft_utm_source | 3 months | This cookie is created by Marketo and is used to identify the source. |
| mkto_utm_source | 3 months | This cookie is created by Marketo and is used to identify the source. |
| __ft_utm_medium | 3 months | This cookie is created by Marketo and is used to identify the medium. |
| mkto_utm_medium | 3 months | This cookie is created by Marketo and is used to identify the medium. |
| __ft_utm_campaign | 3 months | This cookie is created by Marketo and is used to identify the campaign. |
| mkto_utm_campaign | 3 months | This cookie is created by Marketo and is used to identify the campaign. |
| __ft_utm_term | 3 months | This cookie is created by Marketo and is used to identify the medium. |
| mkto_utm_term | 3 months | This cookie is created by Marketo and is used to identify the medium. |
| __ft_utm_content | 3 months | This cookie is created by Marketo and is used to identify the performance of marketing content. |
| mkto_utm_content | 3 months | This cookie is created by Marketo and is used to identify the performance of marketing content. |
| top_level_domain | session | These cookies allow us to improve the performance of our Websites. They may collect your IP address but only for the purpose of identifying general locations of visitors and identifying fraudulent or spam traffic. |
| test_cookie | 15 minutes | The test_cookie is set by doubleclick.net and is used to determine if the user's browser supports cookies. |
| IDE | 1 year 24 days | Google DoubleClick IDE cookies are used to store information about how the user uses the website to present them with relevant ads and according to the user profile. |
| cookieyes-other | 1 year | This cookie is set by CookieYes and is used to remember the consent of the users for the use of cookies in the 'Others' category. |
| _GRECAPTCHA | 6 months | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
| datadome | session | This is a security cookie set by Force24 to detect BOTS and malicious traffic. |
| _ga_* | 1 year 1 month 4 days | Google Analytics sets this cookie to store and count page views. |
| _gat_UA-* | 1 minute | Google Analytics sets this cookie for user behaviour tracking. |
| NID | 6 months | Google sets the cookie for advertising purposes; to limit the number of times the user sees an ad, to unwanted mute ads, and to measure the effectiveness of ads. |
| BIGipServer* | session | Marketo sets this cookie to collect information about the user's online activity and build a profile about their interests to provide advertisements relevant to the user. |
| rc::a | Never Expires | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
| rc::f | Never Expires | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
| rc::c | session | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
| rc::b | session | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
| wpEmojiSettingsSupports | session | WordPress sets this cookie when a user interacts with emojis on a WordPress site. It helps determine if the user's browser can display emojis properly. |
| _vis* | 3 months 8 days | Visual Website Optimizer sets this cookie to track sessions created for a user. |
| dd_cookie_test_* | 1 minute | Datadog Real User Monitoring (RUM) Browser SDK sets this cookie as a temporary cookie used to test for cookie support. |
| __test__ | session | This cookie is created by WordPress and Marketo to check if a user's browser supports cookies, which are essential for various site functionalities. |
### Functional
Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.
| Cookie | Duration | Description |
|--------|----------|-------------|
| __cf_bm | 1 hour | This cookie, set by Cloudflare, is used to support Cloudflare Bot Management. |
| sp_t | 1 year | The sp_t cookie is set by Spotify to implement audio content from Spotify on the website and also registers information on user interaction related to the audio content. |
| sp_landing | 1 day | The sp_landing is set by Spotify to implement audio content from Spotify on the website and also registers information on user interaction related to the audio content. |
| _hly_root_domain_test_readinessresources_mindtickle_com | session | This cookie is used by Hushly to test root domain of the page on which Hushly is being used. |
| S | 1 hour | Used by Yahoo to provide ads, content or analytics. |
| VISITOR_PRIVACY_METADATA | 6 months | This cookie is created by YouTube to store visitor privacy metadata. |
| COMPASS | 1 hour | This cookie is set by Google Docs for session management and temporary data storage. |
### Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.
| Cookie | Duration | Description |
|--------|----------|-------------|
| _vwo_sn | 1 hour | This cookie calculates unique traffic on a website. |
| _rdt_uuid | 3 months | Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences. |
| _vwo_uuid | 1 year | This cookie is set by Zoominfo and is used to calculate unique traffic on a website. |
| CLID | 1 year | Microsoft Clarity set this cookie to store information about how visitors interact with the website. The cookie helps to provide an analysis report. The data collection includes the number of visitors, where they visit the website, and the pages visited. |
| _clck | 1 year | Microsoft Clarity sets this cookie to retain the browser's Clarity User ID and settings exclusive to that website. This guarantees that actions taken during subsequent visits to the same website will be linked to the same user ID. |
| _clsk | 1 day | Microsoft Clarity sets this cookie to store and consolidate a user's pageviews into a single session recording. |
| SM | session | Microsoft Clarity cookie set this cookie for synchronizing the MUID across Microsoft domains. |
| MR | 7 days | This cookie, set by Bing, is used to collect user information for analytics purposes. |
| _zitok | 1 year | This is a third-party cookie used to identify new visitors. |
| mp_*_mixpanel | Never Expires | Mixpanel sets this cookie to determine how users use the website so that a good user experience can be provided. |
| __gtm_campaign_url | session | This cookie is created by google and used to collect campaign information from the referring URL, used to improve campaign relevance. |
| _reb2buid | 1 year | This cookie is created by RB2B to store a website visitor's RB2B user ID. |
| _reb2bsessionID | 1 hour | This cookie is created by RB2B to store the website visitor's RB2B session ID. |
| _reb2bgeo | 20 days | This cookie is created by RB2B to store the website visitor's geographical location. |
| _reb2bref | 15 days | This cookie is created by RB2B to store the referring URL for the website visit. |
| events_distinct_id | session | Description is currently not available. |
| _g2_session_id | session | This cookie is created by g2 and sets a unique ID for the session, which allows the website to obtain data on visitor behavior for statistical purposes. |
| _gat_* | 1 minute | Google Analytics sets this cookie to throttle the request rate. |
| 736b8d58_utms | 6 hours | This cookie is created by Zipy and is used to store the UTM parameters, which are used to track the effectiveness of marketing campaigns by capturing information about traffic sources. |
| __Secure-ROLLOUT_TOKEN | 6 months | This cookie is used by YouTube to manage the phased rollout of new features and updates. This cookie helps assign users to specific test groups for experimental features, such as changes to the user interface or video player. |
| 736b8d58_zsession-data | 6 hours | This cookie is created by Zipy and is used to store session-related information, such as user interactions during a single visit, to help in replaying user sessions for analysis. |
| 736b8d58_zlast-activity-time | 6 hours | This cookie is created by Zipy and is used to record the timestamp of the user's last activity on the website, aiding in tracking user engagement and session duration. |
| 736b8d58_zenduser-last-activity-time | 6 hours | This cookie is created by Zipy and is used to specifically track the last activity time of an end user, assisting in monitoring individual user engagement. |
| 736b8d58_ztotal-data-sent | 6 hours | This cookie is created by Zipy and is used to keep a record of the total amount of data sent during a user's session, which is useful for performance monitoring and analytics. |
| _vis_opt_exp_52_combi | 3 months 8 days | Visual Website Optimizer (VWO) sets this cookie to keep track of which test variant a user is placed in. |
### Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
| Cookie | Duration | Description |
|--------|----------|-------------|
| AWSALBCORS | 7 days | This cookie is managed by Amazon Web Services and is used for load balancing. |
| AWSALB | 7 days | AWSALB is an application load balancer cookie set by Amazon Web Services to map the session to the target. |
| lidc | 1 day | LinkedIn sets the lidc cookie to facilitate data center selection. |
| _cfuvid | session | Used by Zoominfo to distinguish individual users to apply Cloudflare WAF Rate Limiting Rule. |
| SRM_B | 1 year 24 days | Used by Microsoft Advertising as a unique ID for visitors. |
| _reb2bloaded | Less than a minute | This cookie is created by RB2B to check whether or not the script loaded for the visitor |
### Advertisement
Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.
| Cookie | Duration | Description |
|--------|----------|-------------|
| tuuid | 1 year 1 month | The tuuid cookie, set by BidSwitch, stores an unique ID to determine what adverts the users have seen if they have visited any of the advertiser's websites. The information is used to decide when and how often users will see a certain banner. |
| tuuid_lu | 1 year 1 month | This cookie, set by BidSwitch, stores a unique ID to determine what adverts the users have seen while visiting an advertiser's website. This information is then used to understand when and how often users will see a certain banner. |
| li_gc | 6 months | Used to store consent of guests regarding the use of cookies for non-essential purposes |
| _fbp | 3 months | This cookie is set by Facebook to display advertisements when either on Facebook or on a digital platform powered by Facebook advertising, after visiting the website. |
| bcookie | 1 year | LinkedIn sets this cookie from LinkedIn share buttons and ad tags to recognize browser ID. |
| pxrc | 2 months | This cookie is used to deliver adverts more relevant to you and your interests. It is also used to limit the number of times you see an advertisement as well as help measure the effectiveness of the advertising campaign. |
| rlas3 | 1 year | This cookie is used to deliver adverts more relevant to you and your interests. It is also used to limit the number of times you see an advertisement as well as help measure the effectiveness of the advertising campaign. |
| bitolsSecure | 1 year | Beeswax sets this cookie for targeting and advertising. The cookie is used to serve the user with relevant advertisements based on real time bidding. |
| YSC | session | YSC cookie is set by Youtube and is used to track the views of embedded videos on Youtube pages. |
| VISITOR_INFO1_LIVE | 6 months | A cookie set by YouTube to measure bandwidth that determines whether the user gets the new or old player interface. |
| MUID | 1 year 24 days | Bing sets this cookie to recognize unique web browsers visiting Microsoft sites. This cookie is used for advertising, site analytics, and other operations. |
| ANONCHK | 10 minutes | The ANONCHK cookie, set by Bing, is used to store a user's session ID and also verify the clicks from ads on the Bing search engine. The cookie helps in reporting and personalization as well. |
| tvid | 1 year | Tremorhub sets this cookie to present the user with relevant content and advertisement. |
| tv_UIDM | 1 year 1 month 4 days | Tremorhub sets this cookie to present the user with relevant content and advertisement. |
| CMID | 1 year | Casale Media sets this cookie to collect information on user behaviour for targeted advertising. |
| CMPS | 3 months | CasaleMedia sets CMPS cookie for anonymous user tracking based on users' website visits to display targeted ads. |
| CMPRO | 3 months | CasaleMedia sets CMPRO cookie for anonymous usage tracking and targeted advertising. |
### Uncategorized
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
| Cookie | Duration | Description |
|--------|----------|-------------|
| _csrf-prod | 1 month | This is a Mindtickle platform cookie and is not used by the Mindtickle Website. Cross-site request forgery (also known as CSRF) is a web security vulnerability that allows attackers to induce users to perform actions they do not intend to perform. This cookie stores a unique token such that an attacker is not able to perform an operation in a web application on behalf of a user without their explicit consent. |
| _dd_s | 15 minutes | This cookie is created by the Mindtickle Platform and is not used by the Mindtickle Website. This cookie from Datadog is used for performance monitoring, error management, and analytics. It registers the website's speed and performance. This function can be used in context with statistics and load-balancing. |
| EXP-feature | 1 day | This cookie is created by the Mindtickle Platform and is not used by the Mindtickle Website. This cookie is used instead of feature flag to avoid its code cleanup after General Availability of a feature or enhancement. It changes the request URL for the application for loading code for new feature. |
------------------------------------------------------------
# Mindtickle Platform Cookie Policy | Necessary Cookies Only
**Focus Keyphrase:** Mindtickle platform cookie policy
**Meta Description:** Mindtickle's platform uses only essential cookies to enable secure sessions, authentication, language settings, and performance routing. Learn how these necessary cookies support user experience and platform functionality without tracking or analytics.
**Original URL:** https://www.mindtickle.com/cookie-policy/#platform
---
**Last Updated:** February 27, 2025
This Cookie Policy describes how Mindtickle, Inc. and its affiliates use cookies and other similar technology on the Mindtickle platform provided to customers as part of Subscription Services.
This policy explains what cookies are, how we use them, the types of cookies we use, i.e., the information we collect using cookies and how that information is used, and how to manage the cookie settings.
## What is a Cookie?
Cookies are text files that are used to store small pieces of information. They are stored on your device when the website is loaded on your browser. These cookies help the website function correctly, make it more secure, provide a better user experience, understand how the website performs, and analyze what works and where it needs improvement.
## How do we use cookies?
As with most online services, the Mindtickle platform uses first-party and third-party cookies for several purposes. First-party cookies are necessary to provide correct functionality and typically do not collect any of your personally identifiable data.
The third-party cookies are mainly for providing service functionality and logging the interactions as required for maintaining secure audit trail and debugging information to help keep the services secure.
## List of cookies we use on the Mindtickle Platform
| Category | Cookie Name | Duration | Cookie Description |
|----------|-------------|----------|-------------------|
| Necessary | lsCname-prod | 1 hour | This cookie is created by Mindtickle. It is used for redirecting the user to the data center location associated with the customer instance of the Mindtickle platform. |
| Necessary | mts | 2 hours | This cookie is created by Mindtickle. It is used for authentication and session management. |
| Necessary | Play_session | Session | This cookie is created by Mindtickle. It is used for session management. |
| Necessary | connect.sid | Session | This cookie is created by Mindtickle. It is used for storing session ID utilized by Call AI for communication with the API gateway. |
| Necessary | _csrf-prod | 30 days | This cookie is created by Mindtickle. It is used for storing a unique token to prevent Cross-Site Request Forgery (CSRF) attacks. |
| Necessary | Mtr | 30 days | This cookie is created by Mindtickle. It is used for storing data centre location associated with customer instance of Mindtickle platform to help route requests to appropriate region. |
| Necessary | _locale | Session | This cookie is created by Mindtickle. It is used for storing the language selection of users in order to serve Mindtickle platform pages as per the language preference. |
| Necessary | userLocale | 1 day | This cookie is created by Mindtickle. It is used for storing the language selection of users in order to serve Mindtickle platform pages as per the language preference. |
| Necessary | EXP-feature | 1 day | This cookie is created by Mindtickle. It is used for loading the code of newly launched features on the Mindtickle platform. |
| Necessary | learner_maintenance_* | 30 days | This cookie is created by Mindtickle. It is used for displaying banner on the Mindtickle platform to communicate incident and maintenance related messages. |
| Necessary | JSESSIONID | Session | This cookie is created by Mindtickle. It is used for maintaining sessions used by interactive reports and dashboards in the Mindtickle platform. |
| Necessary | AWSELB | Session | This cookie is created by AWS. It is used for routing user requests to the same backend server for the duration of their session. |
| Necessary | _cf_bm | 1 hour | This cookie is created by Freshworks. It is used for Mindtickle support and the chat widget to identify and mitigate automated traffic from bots. |
| Necessary | _fw_crm_v | 365 days | This cookie is created by Freshworks. It is used for maintaining user session on Mindtickle support and chat widget. |
| Necessary | _x_w | Session | This cookie is created by Freshworks. It is used for load balancing and directing user requests to the appropriate server within Mindtickle support and chat widget. |
| Necessary | _helpkit_session | Session | This cookie is created by Freshworks. It is used for managing user sessions on Mindtickle support and chat widget. |
| Necessary | _dd_s | 15 mins | This cookie is created by Datadog. It is used for logging actions and events that help identify debugging information needed to resolve reported issues. |
| Necessary | dd_cookie_test_* | 1 minute | This cookie is created by Datadog. It is used for testing whether the user's browser supports cookie creation. |
| Necessary | _mt_sp_id.e330 | 400 days | This cookie is created by Mixpanel. It is used for logging actions and events that help identify debugging information needed to resolve reported issues. |
| Necessary | _mt_sp_ses.e330 | 30 mins | This cookie is created by Mixpanel. It is used for logging actions and events that help identify debugging information needed to resolve reported issues. |
| Necessary | mp_*_mixpanel | 365 days | This cookie is created by Mixpanel. It is used for logging actions and events that help identify debugging information needed to resolve reported issues. |
| Necessary | CoachingSnowplowCollectorCookieName | 365 days | This cookie is created by Snowplow. It is used for logging actions and events that help identify debugging information needed to resolve reported issues. |
| Necessary | ContentSnowplowCollectorCookieName | 365 days | This cookie is created by Snowplow. It is used for logging actions and events that help identify debugging information needed to resolve reported issues. |
| Necessary | SnowplowCollectorCookieName | 366 days | This cookie is created by Snowplow. It is used for logging actions and events that help identify debugging information needed to resolve reported issues. |
| Necessary | wfx_unq | 100 days | This cookie is created by Whatfix. It is used for user authentication to provide in-app guidance on the Mindtickle platform. |
| Necessary | *_isSurveyAlreadyShown | 1 year | This cookie is created by Whatfix. It is used for determining whether certain workflows related to in-app guidance have been completed by the user on the Mindtickle platform. |
------------------------------------------------------------
# Mindtickle EnableUs Cookie Policy | Manage Consent & Preferences
**Focus Keyphrase:** Mindtickle EnableUs cookie policy
**Meta Description:** Discover how Mindtickle's EnableUs cookie settings allow you to control essential, analytics, and functional cookies. Adjust preferences, manage consent, and understand how your data is used across the EnableUs interface.
**Original URL:** https://www.mindtickle.com/cookie-policy/#enableus
---
**Last Updated:** January 25, 2024
This Cookie Policy describes how Enable Us (by Mindtickle) and its affiliates use cookies and other similar technology on its marketing website located at the following link – **https://www.enableus.com/**.
This policy explains what cookies are, how we use them, the types of cookies we use, i.e., the information we collect using cookies and how that information is used, and how to manage the cookie settings.
## What is a Cookie?
Cookies are text files that are used to store small pieces of information. They are stored on your device when the website is loaded on your browser. These cookies help the website function correctly, make it more secure, provide a better user experience, understand how the website performs, and analyze what works and where it needs improvement.
## How do we use cookies?
As with most online services, our website use first-party and third-party cookies for several purposes. First-party cookies are necessary to provide correct functionality and typically do not collect any of your personally identifiable data.
The third-party cookies are mainly for understanding performance and interactions, keeping the services secure, providing marketing website advertisements that are relevant to you, and, all in all, providing you with a better and improved user experience and helping speed up your future interactions with our website and the Mindtickle platform.
## Type of cookies we use
1. **Necessary** – Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.
2. **Functional** – Functional cookies help perform certain functionalities like sharing the website's content on social media platforms, collecting feedback, and other third-party features.
3. **Analytics** – Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.
4. **Advertisement** – Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.
## List of cookies we use on the Mindtickle Platform
| Category | Domain | Cookie Name | Duration | Cookie Description |
|----------|--------|-------------|----------|-------------------|
| Necessary | .linkedin.com | li_gc | 6 months | This cookie is set by LinkedIn to store cookie consent preferences. |
| Functional | .hubspot.com | __cf_bm | 1 hour | This cookie is set by Cloudflare to support Cloudflare Bot Management. |
| Functional | .linkedin.com | lidc | 1 day | This cookie is used by LinkedIn to set the lidc cookie to facilitate data center selection. |
| Functional | .g2crowd.com | __cf_bm | 1 hour | This cookie is set by Cloudflare to support Cloudflare Bot Management. |
| Functional | www.g2.com | AWSALBCORS | 7 days | This cookie is set by Amazon Web Services for load balancing. |
| Functional | www.g2.com | __cf_bm | 1 hour | This cookie is set by Cloudflare to support Cloudflare Bot Management. |
| Functional | .grow.clearbitjs.com | _cfuvid | session | This cookie is set by Cloudfare to distinguish individual users to apply Cloudflare WAF Rate Limiting Rule. |
| Functional | .g2.com | AWSALB | 7 days | This is an an application load balancer cookie set by Amazon Web Services to map the session to the target. |
| Functional | .hubspot.com | _cfuvid | session | This cookie is set by Cloudfare to distinguish individual users to apply Cloudflare WAF Rate Limiting Rule. |
| Analytics | tracking.g2crowd.com | _session_id | 14 days | This cookie is set by G2 for storing a unique session ID that tracks visitors' navigation for website improvement purposes. |
| Analytics | .enableus.com | _gcl_au | 3 months | This cookie is set by Google Tag Manager to experiment with the advertisement efficiency of websites using their services. |
| Analytics | .enableus.com | __q_state_NDfhNaW4kM53Cmmy | 1 year 1 month 4 days | This cookie set by Qualified contains attributes identifying the website visitor and their interaction with the Qualified Chat Messenger. |
| Analytics | .enableus.com | _ga_* | 1 year 1 month 4 days | This cookie is set by Google Analytics to store and count page views. |
| Analytics | .enableus.com | _ga | 1 year 1 month 4 days | This cookie is set by Google Analytics to calculate visitor, session and campaign data and track site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognise unique visitors. |
| Analytics | .enableus.com | _gid | 1 day | This cookie is set by Google Analytics to store information on how visitors use a website while also creating an analytics report of the website's performance. Some of the collected data includes the number of visitors, their source, and the pages they visit anonymously. |
| Analytics | .enableus.com | _gat_UA-* | 1 minute | This cookie is set by Google Analytics for user behaviour tracking. |
| Analytics | .enableus.com | fs_lua | 1 hour | This cookie is set by FullStory and captures the timestamp of the last user action. It is used to assist with the FullStory session lifecycle, ensuring user activity extends the session. |
| Analytics | .enableus.com | fs_uid | 1 year | This cookie is set by Fullstory used to track the user across sessions and pages. |
| Analytics | .enableus.com | _hjIncludedInSessionSample_3372702 | 1 hour | This cookie is set by Hotjar to determine if a user is included in the data sampling defined site's daily session limit. |
| Analytics | .enableus.com | _hjSessionUser_* | 1 year | This cookie is set by Hotjar to ensure that data from subsequent visits to the same site are attributed to the same user ID. |
| Analytics | .enableus.com | _hjSession_* | 1 hour | This cookie is set by Hotjar to ensure that subsequent requests in the session window are attributed to the same session. |
| Analytics | .linkedin.com | AnalyticsSyncHistory | 1 month | This cookie is set by Linkedin to store information about the time a sync took place with the lms_analytics cookie. |
| Analytics | enableus.com | _fs_uid | never | This cookie is set by Fullstory to create a unique anonymized user ID and used by Fullstory to record user session events for issue tracking, debugging, and analytics. |
| Analytics | .g2.com | _g2_session_id | session | This cookie is used by G2 to set a unique ID for the session. This allows the website to obtain data on visitor behaviour for statistical purposes. |
| Analytics | www.g2.com | events_distinct_id | session | This cookie is set by G2, which sets a unique ID for the session. This allows the website to obtain data on visitor behaviour for statistical purposes. |
| Advertisement | .doubleclick.net | test_cookie | 15 minute | This cookie is set by doubleclick.net to determine if the user's browser supports cookies. |
| Advertisement | .linkedin.com | li_sugr | 3 months | This cookie is set by LinkedIn to collect user behaviour data to optimise the website and make advertisements on the website more relevant. |
| Advertisement | .linkedin.com | bcookie | 1 year | This cookie is set by LinkedIn from LinkedIn share buttons and ad tags to recognize browser IDs. |
| Advertisement | .linkedin.com | UserMatchHistory | 1 month | This cookie is set by LinkedIn for LinkedIn Ads ID syncing. |
| Advertisement | .www.linkedin.com | bscookie | 1 year | This cookie is set by LinkedIn to store performed actions on the website. |
------------------------------------------------------------
# Compliance, Certifications, and Security at Mindtickle
**Focus Keyphrase:** Mindtickle compliance overview
**Meta Description:** Explore Mindtickle's comprehensive compliance frameworks like ISO_27001, 22301, 27701, SOC_2/3, GDPR, CCPA, HIPAA, EU AI Act, ISO_42001 and more, backed by third_party audits and trust_ready certifications.
**Original URL:** https://www.mindtickle.com/compliance
---
## Our Commitment to Compliance
At Mindtickle, we adhere to global standards and regulatory frameworks to ensure the highest levels of security, privacy, and compliance.
As the global leader in sales readiness, Mindtickle delivers a cloud platform that leading enterprises across the globe trust for business-critical services.
## Security
### ISO 27001:2022
- ISO 27001 is a globally recognized standard for Information Security Management System (ISMS) which ensures data protection through effective risk management and comprehensive controls encompassing technical, organizational, people, and physical security measures.
- We have completed an external audit of our platform and organizational practices aligned with established ISO 27001 requirements and have been certified, with our internal controls and policies successfully meeting the standard. You can access our ISO 27001:2022 certificate [here](https://www.mindtickle.com/iso27001).
### SOC 2
- Mindtickle has audited its platform against the Trust Service Principles and Criteria prescribed by The American Institute of Certified Public Accountants (AICPA) and obtained a Service Organization Control 2 (SOC2) Type 2 report.
- This third-party assurance audit is performed on a semi-annual basis to obtain an independent opinion on the suitability of the design and operating effectiveness of the implemented controls. Our SOC2 Type 2 report can be shared on request with customers and prospects.
### SOC 3
- Mindtickle's SOC 3 is a general-use executive summary of the SOC 2 Type 2 Report and the auditor's opinion on the design and operational effectiveness of our implemented controls.
- This report provides a concise summary of our adherence to the Trust Service Principles, control effectiveness, and management's assertion for broader distribution.
- Mindtickle undergoes the SOC 3 audit on an annual basis, and you can access this publicly available report [here](https://mindtickle.com/soc3).
### VAPT
- Vulnerability Assessment and Penetration Testing (VAPT) is Mindtickle's proactive security strategy for identifying, assessing, and mitigating potential security weaknesses across our infrastructure, applications, and services.
- Mindtickle undergoes semi-annual independent third-party VAPT for its network, web, API, mobile applications, integrations and AI systems. These assessments cover OWASP Top 10 vulnerabilities and include testing for XSS, SQL injection, parameter manipulation, and other risks relevant to the application profile. A summary report is available upon request.
## Privacy
### ISO 27701:2019
- ISO 27701 is the standard providing a framework for establishing and improving a Privacy Information Management System (PIMS), helping organizations manage privacy risks, ensure compliance with data protection laws, and implement controls to protect personally identifiable information (PII) throughout its lifecycle.
- Mindtickle is aligned with the standard, demonstrated robust privacy practices during the external audit, and has achieved the certification. You can access our ISO 27701:2019 certificate [here](https://www.mindtickle.com/iso27701).
### GDPR
- Mindtickle is fully compliant with General Data Protection Regulation (GDPR), a European Union (EU) law on data protection and privacy for all individuals within the EU and the European Economic Area (EEA) and their personal data exported outside the EU and EEA.
- We offer GDPR-compliant Data Processing Addendum (DPA) to provide our customers privacy protection assurance and to comply with our obligations as a Data Processor and help our customers meet their obligations as the Data Controllers. More details on our GDPR compliance can be accessed [here](https://www.mindtickle.com/gdpr).
### CCPA
- Mindtickle is fully compliant with applicable provisions of California Consumer Privacy Act (CCPA), a state-wide statute intended for enhancing the data privacy and consumer protection rights for residents of California, United States (CA-US).
- We offer CCPA-compliant Data Processing Addendum (DPA) to provide our customers privacy protection assurance and to comply with our obligations as a Service Provider and help our customers meet their obligations as the business entities. More details on our CCPA compliance can be accessed [here](https://www.mindtickle.com/ccpa).
### UK DPA
- Mindtickle is fully compliant with applicable provisions of the UK Data Protection Act (UK DPA) 2018, the United Kingdom's national law, that complements the European Union's General Data Protection Regulation (GDPR) replaces the Data Protection Act 1998.
- We offer UK DPA-compliant Data Processing Addendum (DPA) to provide our customers with privacy protection assurance and comply with our obligations as a Data Processor and help our customers meet their obligations as the Data Controller.
## Cross-Border Data Protection
### Data Privacy Framework (DPF)
- Mindtickle is certified for compliance with EU-U.S. and Swiss-U.S. Data Privacy Framework (DPF), along with its UK Extension, which were developed by U.S. Department of Commerce and the European Commission, UK Government, and Swiss Federal Administration.
- Data Privacy Framework provides us with a reliable mechanism for personal data transfers to the United States from the European Union, United Kingdom, and Switzerland while ensuring data protection that is consistent with EU, UK, and Swiss law.
- Our Data Privacy Framework compliance certification along with participation status, the purpose of data collection, and dispute resolution mechanism can be accessed [here](https://www.mindtickle.com/dpf).
### EU Standard Contractual Clauses
- The Commission Implementing Decision (EU) 2021/914 of 4 June 2021 to transfer personal data to third countries under Regulation (EU) 2016/679 of the European Parliament and the Council published [New Standard Contractual Clauses](https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj) (SCCs, also known as Model Contractual Clauses) to help safeguard European personal data.
- Mindtickle has incorporated the new SCCs into our [Data Processing Addendum](https://mindtickle.com/dpa) to help protect our customers' data and meet the requirements of European privacy legislation.
- We offer GDPR-compliant Data Processing Addendum (DPA) to provide our customers privacy protection assurance and to comply with our obligations as a Data Processor and help our customers meet their obligations as the Data Controllers. More details on our GDPR compliance can be accessed [here](https://www.mindtickle.com/gdpr).
### UK International Data Transfer Addendum
- Mindtickle is fully compliant with the provisions of Article 46 of the UK GDPR and offers an International Data Transfer Addendum (IDTA) issued by the Information Commissioner's Office (ICO) under Section 119A of the Data Protection Act 2018.
- The IDTA acts as a transfer tool that allows organizations to transfer personal data outside of the UK. The addendum is part of Mindtickle's [pre-signed Data Processing Addendum (DPA)](https://mindtickle.com/dpa) offered to its customers.
- This third-party assurance audit is performed on an annual basis to obtain an independent opinion on the suitability of the design and operating effectiveness of the implemented controls. Our SOC2 Type 2 report can be shared on request with customers and prospects.
### APEC PRP Compliance Program
- The Asia-Pacific Economic Cooperation (APEC) has designed the APEC Privacy Framework to provide an accountable approach to managing data privacy protection and the flow of personal information across borders.
- Mindtickle, as a data processor, can demonstrate its adherence to APEC Privacy Framework and assist personal information controllers in complying with relevant privacy obligations by providing assurance around baseline requirements through completed standard intake questionnaire required for Privacy Recognition for Processors (PRP) compliance. You can access Mindtickle's APEC PRP self assessment form [here](https://www.mindtickle.com/prp).
## Business Continuity
### ISO 22301:2019
- ISO 22301 is the international standard for Business Continuity Management Systems (BCMS), providing a framework to continually enhance resilience and ensure a systematic response to crises.
- To strengthen the security and resilience of the Mindtickle platform, we have aligned our practices and implemented controls in accordance with the standard's requirements, achieving certification through an external audit. You can access our ISO 22301:2019 certificate [here](https://www.mindtickle.com/iso22301).
### Disaster Recovery
- Disaster Recovery (DR) test validates the resilience and recoverability of Mindtickle's critical systems and services in the event of a disruptive incident.
- Mindtickle conducts semi-annual DR tests to simulate realistic scenarios such as database failures and infrastructure component loss to ensure business continuity and compliance with recovery time objectives (RTO) and recovery point objectives (RPO) defined in our Business Continuity and Disaster Recovery (BCDR) plan. A summary of our most recent DR test and its outcomes can be shared upon request with customers and prospects.
## Cloud Security
### ISO 27017:2015
- ISO 27017 provides guidelines for information security controls specific to cloud services. The standard addresses key security concerns such as data protection, access management, and shared responsibilities between cloud service providers and customers to ensure robust security practices in cloud-based services.
- Mindtickle has identified and mitigated the unique security risks associated with providing cloud services and has undergone an external audit to achieve this certification. You can access our ISO 27017:2015 certificate [here](https://www.mindtickle.com/iso27017).
### ISO 27018:2019
- ISO 27018 specifies guidelines taking into consideration the regulatory requirements for the protection of personally identifiable information (PII) within the context of the information security risk environment of public cloud service providers. It establishes commonly accepted control objectives for implementing privacy principles.
- Mindtickle successfully demonstrated its stringent privacy controls for protecting PII in the public cloud environments, aligning with applicable data protection laws and privacy risk assessments. Following the audit, Mindtickle was awarded the certification for this standard. You can access our ISO 27018:2019 certificate [here](https://www.mindtickle.com/iso27018).
### CSA STAR
- Mindtickle is compliant and certified as Level 1 with Security, Trust and Assurance Registry (STAR), an Open Certification Framework developed by Cloud Security Alliance (CSA) to promote best practice in the security assurance within Cloud Computing.
- Mindtickle has completed the CSA Consensus Assessments Initiative Questionnaire (CAIQ), which provides visibility into Mindtickle's processes and practices followed to ensure security, confidentiality, and integrity of customer information. You can access Mindtickle's registry entry [here](https://www.mindtickle.com/star).
## AI Compliance
### ISO 42001:2023
- ISO 42001 is the first international, certifiable standard for Artificial Intelligence Management Systems (AIMS), providing requirements and guidance to establish, implement, maintain, and continually improve governance, risk assessment, ethical safeguards, and transparency across the entire AI lifecycle.
- We have successfully aligned our AI governance processes and controls with ISO 42001 requirements and have undergone an independent third-party audit to validate our implementation and adherence to the standard. Our ISO 42001:2023 compliance report can be shared on request with customers and prospects.
### EU AI Act
- The EU Artificial Intelligence Act is a comprehensive, risk-based regulation for AI, classifying systems by risk level and imposing mandatory governance, transparency, safety, and human-oversight requirements for high-risk applications to ensure ethical and trustworthy AI deployment.
- Mindtickle has fully aligned its AI governance framework with the EU AI Act by implementing risk assessments, technical documentation, human-in-the-loop measures, and semi-annual penetration tests with a focus on its AI features. Our EU AI Act compliance report can be shared on request with customers and prospects.
## Industry Specific Compliance
### HIPAA
- Mindtickle is compliant with U.S. Health Insurance Portability and Accountability Act of 1996 (HIPAA) and undergoes an annual third-party HIPAA assessment to review our controls around privacy of individually identifiable health information as defined in the Privacy Rule and security of Electronic Protected Health Information as defined in the Security Rule.
- Our HIPAA compliance report can be shared upon request with customers and prospects. We also offer HIPAA-compliant Business Associate Agreement (BAA) to our customers who are subject to HIPAA.
### FINRA
- U.S. Securities and Exchange Commission (SEC) Rule 17a-4 outlines the requirements for broker-dealers that fall under the Financial Industry Regulatory Authority (FINRA) jurisdiction to create, preserve and furnish a comprehensive record of each securities transaction.
- Mindtickle helps customers in the financial services industry to meet the applicable FINRA compliance requirements. We have implemented technical and organizational measures to comply with the SEC Rule 17a-4 clause around data retention, indexing, accessibility, and format.
### 21 CFR Part 11
- Mindtickle is compliant with GxP regulation enforced by the US Food and Drug Administration (FDA) and defined in Title 21 of the Code of Federal Regulations (21 CFR) Part 11. We have implemented controls for computer systems that create, modify, maintain, archive, retrieve, or distribute electronic records under GxP-regulated activities.
- The third-party independent assessment is performed on an annual basis to ensure our ongoing compliance with 21 CFR Part 11. Our 21 CFR Part 11 compliance report can be shared on request with customers and prospects.
## Standardized Vendor Compliance
### SIG
- The Standardized Information Gathering (SIG) questionnaire, developed by Shared Assessments, offers a comprehensive set of questions to evaluate service providers' risk controls. Organizations widely use SIG to manage their Third-Party Risk Management (TPRM) programs.
- Mindtickle has assisted multiple customers in their TPRM compliance journey by providing information as necessary for the SIG questionnaire and associated documentation. Our SOC2 controls are aligned to meet the compliance obligations set forth by the SIG questionnaire.
### Vendor Security Alliance (VSA)
- The Vendor Security Alliance (VSA) is an industry-recognized security assessment created to help organizations evaluate their vendors' security practices. This assessment covers domains such as data protection, risk management, access control, incident response, system monitoring, secure SDLC, and compliance audit practices.
- We have thoroughly documented our responses to the VSA full questionnaire to provide visibility into our security, privacy, and compliance practices. This VSA assessment report, along with the supporting evidence, can be shared with customers and prospects upon request.
### HECVAT
- Higher Education Cloud Vendor Assessment Tool (HECVAT) is a framework designed for higher education institutions to assess vendor risk, ensuring security and privacy policies and controls protect sensitive institutional data and constituents' PII.
- We have completed HECVAT toolkit that offers clarity into our security, privacy, and compliance measures. This toolkit is listed in Higher Education Information Security Council's Community Broker Index and you can [request](https://www.mindtickle.com/hecvat) HECVAT assessment for performing security evaluation.
### Accessibility VPAT
- Voluntary Product Accessibility Template (VPAT) is used to evaluate how accessible a product is to people with disabilities. Organizations use VPAT to assess whether a product meets requirements for regulations like the Americans with Disabilities Act (ADA), Web Content Accessibility Guidelines (WCAG), Section 508 and European accessibility standards for ICT products and services (EN 301 549).
- Mindtickle has evaluated its media and content player against the applicable criteria in WCAG 2.2 and has comprehensively documented its conformance against level AA in a VPAT version 2.5 document, which can be made available on request. You can also view the accessibility features provided by Mindtickle [here](https://www.mindtickle.com/accessibility).
------------------------------------------------------------
---
**Document Generated:** 2025-06-26 16:36:54
**Total Sections:** 21
**Content Categories:** Security, Privacy, Compliance, AI Governance, Operational Policies
**Source:** Mindtickle Trust & Security Documentation