Legal
Privacy Policy
Last updated: 14 August 2026 · Operated by Phyner Ltd
Phyner Ltd (“we”, “us”, “our”) operates the IdentiMind platform at identimind.com. We take your privacy seriously. This policy explains what personal data we collect, why we collect it, how it is used, and what rights you have over it.
1. Who we are
The data controller is Phyner Ltd, a company registered in England and Wales (company number 13008071), ICO registration number ZB182114, with registered address at 93 Springfield Drive, Ilford, Essex, IG2 6QS, UK.
You can contact us at hello@phyner.com.
2. Data we collect
We collect only the data that is necessary to provide the IdentiMind assessment service.
Assessment responses
Your responses are stored in your own browser (in local storage on your device), not in a central database on our servers. They are the input used to generate your profile. When you request a report, your responses are sent to our server so it can calculate your scores, and the result is returned to your browser — we do not retain your responses or report server-side after that request completes. For the free assessment, this browser-stored data automatically expires after a short period (24 hours by default). If you purchase the Premium Report, the data is kept in your browser so you can return to your report; you can clear it at any time from your browser, or by using the “start over” option.
Email address (optional)
If you choose to receive your report link or purchase confirmation by email, we collect your email address. Providing an email is not required to take the free assessment or to view your report. We do not currently operate user accounts.
Payment data
If you purchase the Premium Report, payment is processed by our payment processors (Paddle, Stripe, or PayPal). We do not receive or store your full card number or banking details. We receive a transaction reference and confirmation of payment.
Contact form submissions
If you contact us via our Teams enquiry form or by email, we collect your name, email address, organisation name, and the content of your message.
Technical and usage data
We collect standard server logs including IP addresses, browser type, referring URLs, and page visit timestamps. This data is used for security, performance monitoring, and diagnosing technical issues.
3. How we use your data
- To generate and deliver your IdentiMind thinking profile and report
- To process your payment and send a purchase confirmation
- To let you restore access to a purchased report using your access token
- To respond to enquiries and support requests
- To detect and prevent fraud, abuse, or security incidents
- To improve the reliability and performance of the platform
- To comply with legal obligations
We do not sell your personal data to third parties. We do not use your assessment responses for advertising or profiling unrelated to your own report. We do not share your individual results with employers, third parties, or any organisation without your explicit consent.
4. Legal basis for processing
We process your data under the following legal bases (as applicable under UK GDPR and EU GDPR):
- Contract performance — processing your assessment responses and generating your report is necessary to fulfil the service you requested.
- Legitimate interests — maintaining security logs, diagnosing technical issues, and preventing fraud are necessary for the safe operation of the service.
- Legal obligation — retaining transaction records to comply with applicable tax and financial regulations.
- Consent — where we send optional marketing communications, we do so only with your explicit consent, which you may withdraw at any time.
5. Third-party processors
We share limited personal data with the following third-party processors, each under appropriate data processing agreements:
Paddle
Merchant of Record and payment processor for applicable transactions. Paddle acts as the seller of record and processes payment data independently under its own privacy policy.
Privacy policy →Stripe
Payment processor. Stripe handles card data independently under PCI-DSS compliance.
Privacy policy →Cloud infrastructure provider
Our platform is hosted on secure cloud infrastructure. Servers are located in Singapore. Hosting providers process data only as directed by us.
Transactional email service
Used to deliver report links and purchase confirmations by email where an email address is provided.
We do not share your data with any other third parties except as required by law.
7. Data retention
We retain your data for as long as necessary to provide the service and comply with our legal obligations:
- Assessment responses and report data — stored in your own browser, not on our servers. Free assessments expire automatically after a short period (24 hours by default). Paid assessments remain in your browser until you clear them, use “start over”, or clear your browser data. Because this data lives on your device, you are in direct control of it; we do not hold a server-side copy to delete.
- Transaction records — retained for 7 years in accordance with standard financial record-keeping requirements.
- Contact form submissions — retained for up to 3 years from the date of the last communication.
- Server logs — retained for up to 90 days for security and diagnostic purposes.
8. Your rights
Under UK GDPR and EU GDPR, you have the following rights regarding your personal data:
- Right of access — you may request a copy of the personal data we hold about you.
- Right to rectification — you may ask us to correct inaccurate data.
- Right to erasure — you may ask us to delete your data, subject to overriding legal obligations (e.g., financial records we are required to retain).
- Right to restrict processing — you may ask us to limit how we process your data in certain circumstances.
- Right to data portability — you may request a machine-readable copy of data you have provided to us.
- Right to object — you may object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, contact us at hello@phyner.com. We will respond within 30 days.
9. International data transfers
Your assessment responses and report are stored in your own browser and are not held in a central database, so they are not transferred to or retained on our servers. Our hosting infrastructure is located in Singapore, which is not covered by a UK or EU adequacy decision; where any personal data (for example, a support email or a stateless scoring request) is processed outside the UK or EEA, we rely on appropriate safeguards such as Standard Contractual Clauses / the UK International Data Transfer Agreement, together with a transfer risk assessment.
Our payment processors (Paddle, Stripe, PayPal) operate globally and their data transfers are governed by their respective privacy policies and transfer mechanisms.
10. Children
IdentiMind is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page. Where required by law, we will notify you of significant changes.
Continued use of IdentiMind after a policy update constitutes acceptance of the revised policy.
12. Contact & complaints
For any privacy-related questions or to exercise your rights, contact us at:
Phyner Ltd — IdentiMindEmail: hello@phyner.com
We aim to respond to all privacy requests within 30 days.
If you are in the UK, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk (Phyner Ltd ICO registration: ZB182114). If you are in the EU, you may complain to the supervisory authority in your country of residence.