The Authentic Advisor Podcast – essential topics, practical insights from leading business advisors.

PRIVACY POLICY

Last Updated: 10th June 2026
Applies to: Mindshop International Pty Ltd (ACN 074 286 212) | Mindshop Australia Pty Ltd (ABN 16 083 124 467) | Mindshop UK Ltd (Company Reg: 03530512)

Quick Reference – Who this applies to

This Privacy Policy applies to all users of Mindshop websites, the Mindshop platform, and related services — including Advisors, Online Members, prospective clients, and website visitors. It governs how we collect, use, store, disclose, and protect your personal information.

Table of Contents
1. About Mindshop & This Policy

The Mindshop Group of Companies (collectively “Mindshop”, “we”, “us”, “our”) is committed to protecting your personal information and being transparent about how we handle it. This Privacy Policy explains how we manage Personal Information across all our products and services, including:

  • The Mindshop websites (mindshop.com and related domains)
  • The Mindshop Online platform
  • Community forums, events, webinars, and learning resources
  • Communications via email, telephone, SMS, and social media

 

By using our services, you consent to the practices described in this policy. If you do not agree, please discontinue use of our services and contact us at help@mindshop.com.

2. What Personal Information We Collect

What we do NOT collect

We do not collect or process Sensitive Personal Information (such as racial/ethnic origin, political opinions, religious beliefs, health data, sexual orientation, criminal records) unless you have given explicit consent or it is required by law. We do not knowingly collect personal data from children under 16.

3. How We Collect Your Information

3.1 Directly From You
We collect information when you:

  • Register as an Advisor or Online Member
  • Fill in contact or enquiry forms on our website
  • Communicate with us by email, phone, or social media
  • Respond to surveys, promotions, or research activities
  • Attend events or webinars hosted by Mindshop
  • Provide feedback or post in community forums

 

3.2 Automatically
When you interact with our platforms, we automatically collect technical and usage data via cookies, web analytics tools, and server logs. See Section 11 (Cookies) for detail.

3.3 From Third Parties
We may receive information about you from:

  • Your Advisor (if you are an Online Member they have enrolled)
  • Publicly available professional directories or LinkedIn
  • Event or partner referrals

 

Where third parties provide information about you, we take reasonable steps to ensure you are informed.

4. How We Use Your Information & Legal Bases

We process your personal information only where we have a lawful basis. The table below sets out our primary purposes, the data used, and the legal basis under the GDPR and Australian Privacy Act.

You may opt out of marketing communications at any time using the unsubscribe link in any email or by contacting help@mindshop.com.

5. Data Retention & Deletion

5.1 Retention Periods
We retain personal information only for as long as necessary for the purpose it was collected, or as required by law. Our standard retention periods are:

5.2 Deletion Process
When an Advisor’s subscription ends or an Online Member is removed:

  • Platform access is revoked within one business day.
  • Active data and course progress are deleted within one business day of the deletion request.
  • Data is held in a secure backup for 1 month for emergency recovery purposes only.
  • After the 1-month window, all data is permanently and irreversibly deleted.

Right to Erasure

You may request deletion of your personal information at any time (subject to legal retention obligations). See Section 12 for how to exercise this right. We will confirm completion of deletion requests within 30 days.

6. Disclosure of Personal Information

We do not sell your personal information to third parties. We may share your information with:

Any disclosure to third parties is made only to the extent necessary and with appropriate safeguards in place.

7. Third-Party Processors & Sub-Processors

We use carefully selected third-party processors to help deliver our services. All processors are contractually bound to protect your data consistent with this Policy and applicable law.

“SCCs applied” means Standard Contractual Clauses approved by the European Commission are in place for transfers to non-adequate countries.
Mindshop Online’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

8. Artificial Intelligence (AI) & Data Processing

Our Commitment on AI

Mindshop is committed to transparent, ethical, and secure use of AI. Your data is never used to train third-party AI models without your explicit consent. We use AI only to enhance service delivery, and we identify where AI is used within the platform.

8.1 How We Use AI
Mindshop uses AI technologies to power features including:

  • The Mindshop AI Assistant and other AI powered features – powered by Azure AI (Australia East region) and ChatGPT APIs
  • Search and content recommendations within Mindshop Online
  • Analytics and performance insights

 

8.2 Data Handling in AI Features

  • Queries submitted to the AI Assistant are transmitted to our AI provider(s) via encrypted SSL connections for processing.
  • Query data is not stored by third-party AI providers for model training purposes.
  • We use only trusted AI providers who adhere to strict data privacy standards (including GDPR and the Australian Privacy Act).
  • Client information and sensitive advisory data must not be entered into the AI Assistant (see Fair Use Policy below).

 

8.3 No Unauthorised AI Training
Mindshop expressly prohibits the use of its proprietary content (including tools, videos, articles, models, courses, forum posts, and papers) for training any AI or machine learning model. We implement access controls, monitoring of fair use, and contractual safeguards to enforce this.

8.4 Fair Use of the AI Assistant
Use of the Mindshop AI Assistant is limited to:

  • Supporting client advisory activities
    Research for client or internal advisory opportunities
  • Guidance on using the Mindshop platform
  • Accessing Mindshop documentation, tools, and resources

 

The AI Assistant must NOT be used for:

  • General business administration unrelated to advisory (HR, payroll, marketing, accounting operations, etc.)
  • Inputting sensitive personal data, financial account details, or client confidential information
  • Activities by anyone other than the named licence holder

 

8.5 AI Transparency
Where AI-generated insights are presented within the Mindshop platform, we endeavour to clearly identify them as AI-assisted and indicate the underlying service used. Mindshop maintains human oversight of all AI-assisted service delivery.

8.6 AI Compliance & Review
Our AI usage policies are reviewed regularly against GDPR, the Australian Privacy Act, and emerging AI governance frameworks. We update our approach in response to regulatory developments as and when applicable.

9. International Data Transfers

Mindshop primarily operates across Australia, the United Kingdom, Asia and North America. Personal information may be transferred, stored, or processed in these regions.

9.1 Transfer Safeguards
All international transfers are protected by one or more of the following:

  • Standard Contractual Clauses (SCCs) approved or adopted by the European Commission
  • Binding Corporate Rules (BCRs) — available on request from our Privacy Officer
  • Adequacy decisions by the European Commission (where applicable)

 

9.2 Primary Hosting
Our primary platform infrastructure is hosted on Microsoft Azure in the Australian East region. EU-based users should note that backup data may be stored outside the EU with appropriate safeguards in place.

10. Data Security

Mindshop takes reasonable and appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, alteration, or disclosure. Our security measures include:

Despite these measures, no system is completely secure. In the event of a data breach affecting your rights or freedoms, we will notify you and the relevant supervisory authority as required by applicable law.

11. Cookies & Tracking Technologies

We use cookies and similar technologies on our websites and platform. Cookies are small text files placed on your device. We use them for:

You can manage cookie preferences via the cookie consent banner displayed on your first visit, or by adjusting your browser settings. Withdrawing consent to non-essential cookies will not affect your access to core services.

12. Your Rights

Depending on your location, you have certain rights in relation to your personal information. These are described in Section 13 (GDPR) and Section 14 (Australian Privacy Act) in detail. In summary, you may have the right to:

To exercise any right, contact our Privacy Officer (see Section 16). We may verify your identity before acting on a request. We will respond within 30 days (or as required by law).

We do not charge for access requests, though an administrative fee may apply for providing copies of large volumes of data.

13. GDPR - EU & UK Users

13.1 Our Role Under the GDPR
Mindshop acts as both:

  • Data Controller — when we determine the purposes and means of processing your personal information (e.g. account management, marketing).
  • Data Processor — when we process personal information on behalf of an Advisor in relation to their Online Members or clients.

 

Where Mindshop acts as a Processor on behalf of an Advisor (Controller), a Data Processing Agreement (DPA) governs that processing relationship.

13.2 Lawful Bases for Processing
We rely on the following GDPR lawful bases:

  • Contract — processing necessary to provide our services under your agreement with us
  • Legal Obligation — processing required to comply with applicable law
  • Legitimate Interests — processing for our business operations, security, and service improvement, where your interests do not override ours
  • Consent — for marketing communications and AI features (withdrawable at any time)

 

13.3 Your GDPR Rights
As an EU or UK resident, you have all the rights set out in Section 12, enforceable under Articles 15–22 of the GDPR. You also have the right to lodge a complaint with your local supervisory authority (e.g. the ICO in the UK, or the relevant EU DPA).

13.4 Children
Our services are not directed to individuals under 16. We do not knowingly collect personal data from children under 16. If you believe we hold data about a child, contact us immediately.

13.5 Automated Decision-Making
We do not make solely automated decisions about you that have legal or similarly significant effects, unless we have your explicit consent or it is permitted by law.

14. Australian Privacy Act

Mindshop complies with the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth). Further information about the APPs is available at www.privacy.gov.au.

If you are dissatisfied with our handling of your personal information, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au after first raising the matter with our Privacy Officer.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Where changes are material, we will notify you by email or a prominent notice within the Mindshop platform prior to the change taking effect. The “Last Updated” date at the top of this document reflects the most recent revision.
Continued use of our services following notice of changes constitutes acceptance of the updated Policy.

16. Contact Us & Complaints

For all privacy enquiries, requests to exercise your rights, or to lodge a complaint, please contact our Privacy Officer:

Privacy Officer – Mindshop

Email: help@mindshop.com Phone: +61 3 8807 0163 Postal Address: Unit 8, 20 Cato Street, East Hawthorn VIC 3123, Australia We aim to acknowledge all privacy requests within 5 business days and resolve them within 30 days.

If you are not satisfied with our response, you may contact the relevant supervisory authority:

Australia: Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au
United Kingdom: Information Commissioner’s Office (ICO) — www.ico.org.uk
European Union: Your local Data Protection Authority (list at edpb.europa.eu)