---
title: "Data Protection Impact Assessment (DPIA) | Minds"
canonical_url: "https://getminds.ai/legal/dsfa"
last_updated: 2026-09-23
meta:
  description: "Last Updated: September 23, 2026"
  "og:description": "Last Updated: September 23, 2026"
  "og:title": "Data Protection Impact Assessment (DPIA) | Minds"
  "twitter:description": "Last Updated: September 23, 2026"
  "twitter:title": "Data Protection Impact Assessment (DPIA) | Minds"
---

Minds

September 23, 2026·Minds Team # **Data Protection Impact Assessment (DPIA)** Last Updated: September 23, 2026**Last Updated: September 23, 2026** This DPIA pursuant to Art. 35 GDPR evaluates data protection risks of the Minds platform by Art of X UG (haftungsbeschränkt). ## 1. Processing Description Minds enables customers to create and use synthetic AI personas ("Minds") for simulated panels, research, creative workflows, voice and messaging interactions, API/MCP workflows, and optional integrations. | Category | Details |
| --- | --- | | **Data subjects** | Controller employees, invited end users, individuals whose data is entered, and individuals referenced in submitted content, messages, calls, or public sources | | **Data types** | Contact data, credentials, usage data, content (text/images/audio/files/URLs), prompts and outputs, embeddings, API/OAuth tokens, SMS/voice metadata, technical data, payment data (Stripe) | | **Locations** | EU primary (DE, SE), USA and other third countries for selected APIs under DPF/SCCs | | **Retention** | Contract duration; deletion from active systems within 30 days and from protected backups within up to 30 further days, unless shorter feature-specific deletion, consent revocation, legal retention, or audit/security retention applies | | **Purpose** | AI platform services, customer-directed simulations, integrations, source collection, messaging/voice, security, and support. No training, fine-tuning, or improvement of general-purpose, foundation, generalized, shared, or third-party models or generalized datasets. | | **Technology** | LLM APIs (OpenAI, Anthropic, Google), voice services (Deepgram), source/search providers (Exa, Firecrawl, Apify), integrations (Twilio), infra (DigitalOcean Frankfurt, Supabase Stockholm), security (Cloudflare, TLS 1.2+, AES-256). | ## 2. Necessity and Proportionality - **Legal basis**: Art. 6(1)(b) GDPR (contract), Art. 28 GDPR (processor), Art. 6(1)(a) (consent for analytics) - **Purpose limitation**: Processing only per DPA. No model training, marketing, or unauthorized sharing. - **Data minimization**: UUIDs over names, aggregated analytics, automatic deletion - **Storage limitation**: deletion from active systems within 30 days after contract end; residual protected backups deleted or overwritten within up to 30 further days ## 3. Risk Assessment | Risk | Likelihood | Severity | Residual | Mitigation |
| --- | --- | --- | --- | --- | | Unauthorized access | Low | High | Low | MFA, RBAC, AES-256, Row-Level Security, scoped and revocable tokens | | Data breach | Low | High | Low | TLS 1.2+, encrypted backups, Cloudflare, incident process, 24h notification | | AI training on customer data contrary to the contract | Very Low | High | Very Low | Contractual prohibition on generalized/shared training for every plan and subprocessor; a private customer-specific model requires deliberate documented instruction and remains isolated to that customer | | Cross-tenant leakage | Very Low | Critical | Very Low | Row-Level Security, tenant checks, automated tests | | Material AI incident, including systemic provenance failure or unauthorized AI/integration action | Low | High | Low | Incident investigation, containment, customer notification, audit logs, human oversight, suspension and remediation controls | | Government access (FISA/CLOUD Act) | Low | Medium | Low | EU-primary infra, DPF/SCCs, transfer review, transparency clause | | Voice, likeness, or cloned-voice misuse | Low | High | Medium | Consent requirements, acceptable-use restrictions, logging, takedown and suspension rights | | Public source extraction of unlawful or sensitive data | Medium | Medium | Medium | User warranties, prohibited-use rules, source logging, minimization, deletion rights, provider controls | | Machine-readable AI marking and detection transition | Medium | Medium | Medium | Persistent interaction notice and UI labels now, generation metadata, implementation deadline 2 December 2026 for pre-existing systems | | Availability loss | Low | Medium | Low | Protected backups, recovery procedures, monitoring, and Order Form-specific recovery commitments where agreed | ## 4. Measures - **Technical**: TLS 1.2+, AES-256, MFA, RBAC, Row-Level Security, EU infrastructure, Langfuse (EU), scoped API/OAuth tokens, integration audit logs - **Organizational**: External DPO (Prof. Dr. Norman Uhlmann), NDAs, training, 24h incident response - **Contractual**: Required processor terms and transfer safeguards, no-generalized-training controls, 14-day subprocessor change notice, and government-request transparency where legally permitted ## 5. Consultation**DPO**: Prof. Dr. Norman Uhlmann, h3ko Innovations GmbH, Pappelallee 64, 16359 Biesenthal, Germany. [privacy@getminds.ai](https://getminds.ai/mailto:privacy@getminds.ai)**Art. 36**: Prior consultation not required (residual risk not "high").**Review**: Annually, on significant changes, or on supervisory authority request. ---**Art of X UG (haftungsbeschränkt)** | Köpenicker Straße 145, 10997 Berlin | [privacy@getminds.ai](https://getminds.ai/mailto:privacy@getminds.ai) ## **Continue your procurement review** Use the buyer-facing checklist and evidence pages alongside these legal terms. [Minds](https://getminds.ai/)© 2026 Minds. Your target audience. AI-driven and grounded in transparent evidence. Build within minutes. [Minds on X (Twitter)](https://x.com/mindsai_co) [Minds on LinkedIn](https://www.linkedin.com/company/mindsaicompany/) [Minds on Instagram](https://www.instagram.com/getminds.ai/)Minds is part of [![ESOMAR](https://getminds.ai/images/newsroom/logos/esomar-logo.svg)ESOMAR](https://esomar.org/) [![GreenBook](https://getminds.ai/images/newsroom/logos/greenbook.svg)GreenBook Directory](https://greenbook.org/company/Minds) [![Insight Platforms](https://getminds.ai/images/newsroom/logos/insight-platforms.png)Insight Platforms](https://www.insightplatforms.com/platforms/minds/) [![Capterra](https://getminds.ai/images/newsroom/logos/capterra.svg)Capterra](https://www.capterra.com/p/10046203/Minds/) [![G2](https://getminds.ai/images/newsroom/logos/g2.svg)G2](https://www.g2.com/products/minds/reviews) [![CSSDA Best UX Design Award](https://getminds.ai/images/newsroom/logos/cssda-best-ux-award.png)CSSDA Best UX Design Award](https://www.cssdesignawards.com/) [![CSSDA Best Innovation Award](https://getminds.ai/images/newsroom/logos/cssda-best-innovation-award.png)CSSDA Best Innovation Award](https://www.cssdesignawards.com/) [![CSSDA Best UI Design Award](https://getminds.ai/images/newsroom/logos/cssda-best-ui-award.png)CSSDA Best UI Design Award](https://www.cssdesignawards.com/)