This policy explains what personal data Mentup collects, why it collects it, who it shares it with and what rights you have. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (the « GDPR ») and Italian Legislative Decree 196/2003, as amended by Legislative Decree 101/2018.
We wrote it to be understood. Where a technical word is unavoidable, we explain it.
1. Who the data controller is
Mentup Solutions
Via Romana 75 · 42028 Poviglio (RE) · Italia
VAT no. 03156100350
Email: privacy@mentup.eu
PEC: mentup@pec.it
2. Who Mentup is for
Mentup may be used by people aged 16 or over.
If you are 16 or 17, activating your account requires the consent of a parent or of whoever holds parental responsibility: without that consent the account stays inactive and you cannot use the service. How it works is explained in section 6.
Italian law would allow consent to data processing from the age of 14 (Art. 8 GDPR and Art. 2-quinquies of the Italian Privacy Code). We chose a higher threshold for two reasons: Mentup processes health data, and a subscription is a contract that a minor cannot enter into alone. The 16-year threshold matches the one set by the GDPR where no different national rule applies, and the one in force in Germany and the Netherlands. Where the law of your country sets a higher age, that age applies.
3. What data we collect
3.1 Data you give us when you create the account
First name, last name, email address, password (which we keep only in encrypted form and which none of us can read), date of birth, gender, phone number, preferred language, country and — if you choose to upload one — a profile picture.
We need your date of birth for one precise reason: to determine whether you are a minor and start the parental consent procedure.
3.2 Data about your wellbeing — the most sensitive part
By using Mentup you record:
- the daily actions you choose and complete, across the four areas (family, relationships, personal growth, health);
- your journal entries;
- your anxiety releases and anger releases, with their values;
- your daily satisfaction score, with the notes and photographs you choose to attach;
- the charity you choose to receive the donations generated by your actions.
This is data concerning your health, and it falls within the « special categories of personal data » of Art. 9 GDPR. It is the most protected data the Regulation knows, and we process it only on the basis of your explicit consent, which you can withdraw at any time (section 5).
3.3 Parent or guardian data (only for users who are minors)
First name, last name and email address of the parent or guardian, collected for the sole purpose of requesting, receiving and keeping proof of consent.
3.4 Technical data
IP address, browser or device type (user agent) and the date and time at which you gave or withdrew each consent. We keep these so we can demonstrate, if needed, that a consent was actually obtained: this is an obligation the GDPR places on us (Art. 7.1).
3.5 Payment data
Mentup does not see and does not store your card details. The subscription is purchased through the Apple App Store, Google Play or — on the website — through Stripe. From the provider we receive only the information needed to keep your subscription active: whether it is active, when it expires, whether it has been renewed or cancelled, and a transaction identifier.
3.6 What we do NOT collect — and this is not a formality
As at the date of this policy, Mentup:
- uses no analytics tools (no Google Analytics, no Firebase Analytics);
- uses no advertising pixels and no attribution SDKs;
- does not track your activity on other apps or sites and does not request the IDFA on iOS;
- does not use crash reporting tools;
- does not profile users and takes no automated decisions concerning you;
- does not sell, transfer or rent your data to anyone;
- does not use your emotional data for advertising purposes, whether our own or anyone else's — and will not: targeted advertising based on special category data is absolutely prohibited by Art. 26(3) of the Digital Services Act, even where consent is given.
If any of these points changes in the future, this policy will be updated before the change takes effect, and you will be asked for fresh consent where required.
4. Why we process your data and on what legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and managing your account, letting you sign in | 3.1 | Performance of the contract — Art. 6.1.b |
| Letting you use the wellbeing features (actions, journal, anxiety, anger, satisfaction, statistics) | 3.2 | Explicit consent — Art. 9.2.a |
| Verifying your age and obtaining parental consent if you are a minor | 3.1, 3.3 | Legal obligation — Art. 6.1.c and Art. 8 |
| Managing the subscription, renewals, receipts and support | 3.1, 3.5 | Performance of the contract — Art. 6.1.b |
| Showing your data to the health professional you have designated | 3.2 | Explicit and specific consent — Art. 9.2.a |
| Producing aggregated, anonymous statistics for your company or your school | 3.2 in aggregated form | Explicit consent — Art. 9.2.a |
| Recording and keeping proof of consents | 3.4 | Legal obligation — Art. 6.1.c |
| Sending you service messages (email verification, security alerts, subscription deadlines) | 3.1 | Performance of the contract — Art. 6.1.b |
| Sending you promotional messages about Mentup | Consent — Art. 6.1.a, withdrawable with one click in every message | |
| Keeping the service secure and preventing abuse | 3.4 | Legitimate interest — Art. 6.1.f |
| Establishing or defending a legal claim | as applicable | Legitimate interest / Art. 9.2.f |
Service messages are not advertising and cannot be switched off while you have an active account: without them we could not tell you that your subscription is about to be charged or that someone has asked to reset your password.
5. Consent to wellbeing data, and how to withdraw it
Consent to Art. 9 data is explicit, separate and specific: it is not buried in your acceptance of the Terms, it is not pre-ticked, and it covers one purpose at a time.
You can withdraw it at any time, from the app's Settings, without having to explain why and at no cost to you. Withdrawal:
- takes immediate effect for the future;
- does not make unlawful the processing carried out up to that point;
- immediately stops sharing with the professional, the company or the school, if you had authorised it.
It has to be said honestly: wellbeing data is the service. If you withdraw that consent, the journal, statistics and tracking features stop working, and the account is left with basic features only.
6. If you are 16 or 17
- When you register we ask for the email address of a parent or of whoever holds parental responsibility.
- Your account is created but stays inactive: you cannot sign in and no wellbeing data is collected.
- We send the parent a message containing the consent request and a link to this policy.
- The account is activated only once the parent confirms.
- If consent does not arrive within 30 days, the request expires and the data collected up to that point is deleted.
The parent can withdraw consent at any time by writing to the address given in section 1, whereupon the account is deactivated and the data deleted.
We do not advertise to minors and we do not profile users who are minors for any purpose.
7. Who we share your data with
We share nothing by default. Every kind of sharing below happens only if you switch it on, and it can be revoked.
7.1 With your professional (psychologist, doctor, coach)
If you link your account to a professional, they can see your daily satisfaction scores and how they change over time, your anxiety and anger releases — date, intensity and also the text you wrote — and receive an alert if you stop using the app.
- The journal stays yours: the professional cannot see it.
- Explicit and specific consent is required, separate from every other.
- Every access by the professional to your data is recorded in a log with the date, time, IP address and type of access.
- You can stop the sharing at any time, with immediate effect.
- Mentup shows the data to the professional: it does not interpret it, assign clinical scores or suggest when to intervene.
7.2 With your company
Your company never sees your individual data. Never. This is not a promise: it is how the system is built.
The company receives only the average satisfaction of all its employees and how it changes over time. No data per person, per department or per any group smaller than the whole company. The average is calculated only if at least 3 employees are enrolled: with fewer people, an « aggregated » figure would still point back to someone. For the same reason a company can only activate Mentup with at least 3 employees. You can also ask to be excluded from the average as well.
Mentup and your company are joint controllers under Art. 26 GDPR, on the basis of a written agreement, a copy of which you can request at the address given in section 1.
7.3 With your school
The same rule applies: the school receives only aggregated, anonymous data — average satisfaction and the number of releases recorded — per class and for the school as a whole, never per individual student. A class figure is shown only if at least 3 students in that class are enrolled. Participation is voluntary and has no bearing whatsoever on school assessment. For students who are minors, the procedure in section 6 applies.
7.4 With our providers
See section 8. They act as processors and are bound by contract under Art. 28 GDPR.
7.5 With the authorities
Only if and to the extent the law requires it.
7.6 Charities
The charities receiving the donations receive the donation, not your data. They do not know who you are.
8. The providers we rely on
| Provider | What it does | Where | Role |
|---|---|---|---|
| Netsons S.r.l. | Application and database servers | EU (Italy) | Processor, Art. 28 |
| Netsons S.r.l. | Sending service emails (SMTP) | EU (Italy) | Processor, Art. 28 |
| Apple — App Store | Purchase and renewal of the subscription on iOS | — | Independent controller for the payment |
| Google — Google Play | Purchase and renewal of the subscription on Android | — | Independent controller for the payment |
| Stripe | Payments made from the website | EU / USA | Processor, Art. 28 |
| RevenueCat | Checking that a subscription bought on the stores is active | USA | Processor, Art. 28 |
We never pass your wellbeing data to providers. They receive only what their function requires: a user identifier and the status of the subscription.
9. Cookies, and data kept on your device
9.1 On our websites
The details of our cookies — name, purpose, duration and who sets each one — are in the Cookie Policy. Today we use a single, technical cookie. If we were to introduce non-technical cookies in the future, they would be set only after your consent, which you could change or withdraw at any time.
9.2 In the app
There are no cookies in the Mentup app. Cookies are a web technology and talking about cookies in a native app is technically wrong. The app does, however, keep some information on your device:
| Information | What it is for | Where |
|---|---|---|
| Authentication token, user identifier | Keeping you signed in without asking for your password every time you open the app | Encrypted store of the operating system |
| Interface language, country | Showing you the app in the right language and the charities of your country | Local storage of the app |
| Display preferences | Remembering what you have already closed or hidden | Local storage of the app |
All of this stays on your phone. It is erased by uninstalling the app or signing out of the account.
10. How long we keep the data
| Data | Retention |
|---|---|
| Account and profile data | For as long as the account exists. Deleted within 30 days of a deletion request |
| Wellbeing data (journal, releases, ratings, photos) | As above: deleted with the account |
| Data from a relationship with a health professional | For the duration of the relationship and 10 years after it ends, in line with obligations in the health field |
| Log of the professional's accesses | 10 years |
| Proof of consents (date, time, IP, document version) | 10 years from withdrawal or termination |
| Data under a corporate welfare programme | For the duration of the programme; anonymised within 90 days of its end, save for legal obligations |
| Tax and accounting data for subscriptions | 10 years, as required by law |
| Aggregated, anonymous statistical data | No limit: it can no longer be traced back to a person |
11. Your rights, and how to exercise them
At any time you can:
- access your data and obtain a copy of it (Art. 15);
- correct it if it is wrong or incomplete (Art. 16);
- erase it (Art. 17);
- restrict its processing (Art. 18);
- take it elsewhere in a machine-readable format (Art. 20) — in the app you will find the « Download my data » feature;
- object to processing based on legitimate interest (Art. 21);
- withdraw a consent at any time (Art. 7.3).
How to do it. In the app's Settings you will find export and account deletion. You can also write to the address given in section 1, and the website has a public page for requesting account deletion without having to sign in: mentup.eu/cancella-account.
We reply within one month. If the request is complex we may take up to two further months, and we will tell you.
If you believe your data is being handled improperly you can lodge a complaint with the Garante per la protezione dei dati personali, the Italian data protection authority (Piazza Venezia 11, 00187 Rome — garante@gpdp.it — www.garanteprivacy.it), or with the authority of the country where you live, and you can go to the courts.
12. How we protect the data
Encrypted communications (HTTPS/TLS); passwords kept only as hashes and never in the clear; access tokens held in the device's encrypted store; access to data limited to the people who genuinely need it; every access by a professional traced and retained; regular backups.
No system is absolutely secure. Should a breach occur that entails a high risk to your rights, we will tell you and we will inform the supervisory authority within the time limits set by law (Arts. 33 and 34 GDPR).
13. Where the data is held
Data is kept on servers located in the European Union.
Some of the providers listed in section 8 (Apple, Google, Stripe, RevenueCat) may also process data outside the European Economic Area. In those cases the transfer takes place on the basis of the safeguards set out in Chapter V of the GDPR: an adequacy decision or Standard Contractual Clauses approved by the European Commission.
Wellbeing data does not leave the European Union.
14. Changes to this policy
If we change it, we publish the new version on this page with a new date and a new version number. Where the change is significant — new purposes, new recipients, new measurement tools — we tell you before it takes effect, and where necessary we ask for fresh consent.
Previous versions remain available on request.
This policy is drawn up in Italian. In the event of any discrepancy between the Italian version and a translation, the Italian version prevails.