Privacy Policy

Last Updated: 25 November 2025

Mind Expedition (MindX)
Privacy Policy

1. INTRODUCTION

Welcome to MindX ("we," "us," or "our"). We operate an edutainment platform that offers skill-based knowledge challenges. We are committed to protecting your privacy and ensuring the integrity of your personal information.

This Privacy Policy explains how Mind Expedition pty Limited, acting as the Data Controller, collects, uses, discloses, and safeguards your information when you use our mobile application and website (the "Service").

2. INFORMATION WE COLLECT

We collect data necessary to verify your identity, process financial transactions, and ensure fair play.

A. Information You Provide to Us

  • Account Data: Name, email address, phone number, username, and password.
  • Verification Data (KYC): To comply with Anti-Money Laundering (AML) laws and age restrictions (18+), we may collect government-issued IDs, selfies, and proof of address when you reach certain withdrawal or deposit thresholds.
  • Financial Data: Bank account details or payment wallet information for processing withdrawals. Note: We do not store full credit card numbers; these are processed by our PCI-DSS compliant payment partners.
  • Profile Data: Profile pictures and optional bio information.

B. Information Collected Automatically

  • Device & Telemetry Data: Device model, operating system, unique device identifiers (UDID/IMEI), IP address, and battery status.
  • Gameplay Metadata: Response times, tap coordinates, and interaction patterns. This data is crucial for our "Fair Play" anti-cheat systems.
  • Location Data: We use Geolocation technology (GPS/IP) to ensure you are accessing the Service from a permitted jurisdiction.

C. Information from Third Parties

  • Referrals: If you sign up via an Ambassador (A22 program), we receive attribution data to calculate their revenue share.
  • Verification Services: We receive validation results from third-party identity verification providers.

3. HOW WE USE YOUR INFORMATION

We process your data for specific, lawful purposes:

  • To Provide the Service: Managing your account, facilitating gameplay, and maintaining your in-app wallet balance.
  • To Ensure Fair Play & Integrity: We analyze gameplay telemetry and device fingerprints to detect bots, collusion, and cheating. This is a legitimate interest to ensure the platform remains skill-based.
  • To Process Payments: Executing deposits and withdrawals.
  • To Comply with Legal Obligations: Adhering to AML (Anti-Money Laundering) regulations, tax reporting, and age-gating requirements.
  • To Calibrate Difficulty: analyzing aggregated player performance to adjust question difficulty without using RNG.
  • To Improve the Platform: Analyzing usage trends to fix bugs and improve user experience.

4. SHARING OF INFORMATION

We do not sell your personal data to advertisers. We only share data as follows:

  • Service Providers: With trusted third parties who perform services on our behalf, including:
    - Payment Processors: To handle money movement.
    - Identity Verification Partners: To validate your ID documents.
    - Cloud Hosting: AWS/Azure/Google Cloud for secure data storage.
  • Legal & Regulatory Authorities: If required by law, court order, or to report suspicious activity (e.g., money laundering fraud) to financial intelligence units.
  • Community & Sponsors: In "Community Social" or "Sponsored" modes, your username and score may appear on public leaderboards. In charity events, your contribution amount may be reported to the beneficiary institution (aggregated or anonymized unless otherwise consented).
  • Ambassadors: If you sign up via an Ambassador link, they may see your username and activity status (but not your personal or financial details) for revenue tracking.

5. DATA RETENTION

  • General Account Data: Retained as long as your account is active.
  • Transaction & KYC Data: Retained for a minimum of [e.g., 5 or 7] years after account closure, as strictly required by Anti-Money Laundering and tax laws.
  • Gameplay Data: Retained in anonymized or aggregated form for historical difficulty calibration.

6. SECURITY


We employ "Compliance-by-Design" architecture (A11/A12) to protect your data:

  • Encryption: Data is encrypted in transit (TLS) and at rest (AES-256).
  • Access Control: Strict role-based access control for our employees.
  • Ring-Fencing: Player funds and prize pools are segregated from operational funds, and data regarding these funds is subject to enhanced security auditing.

7. YOUR RIGHTS

Depending on your jurisdiction (e.g., GDPR, POPIA, CCPA), you may have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Update inaccurate information.
  • Deletion: Request deletion of your data (subject to our legal obligation to retain transaction records for AML purposes).
  • Portability: Receive your data in a structured format.
  • Opt-Out: Unsubscribe from marketing communications.

To exercise these rights, contact us at info@mindexpedition.com

8. CHILDREN'S PRIVACY

MindX cash-prize competitions are strictly for users aged 18 and over. We do not knowingly collect data from children. If we discover a minor has registered, we will immediately suspend the account and delete the data, subject to any legal retention requirements for financial audit trails.

9. INTERNATIONAL TRANSFERS

Your information may be transferred to—and maintained on—computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ. We ensure appropriate safeguards (such as Standard Contractual Clauses) are in place for such transfers.

10. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. We will notify you of any material changes via an in-app notification or email.

11. CONTACT US

If you have questions about this Privacy Policy or our data practices, please contact: info@mindexpedition.com