Privacy Policy

Last updated: September 29, 2026

What changed in this update: We rewrote this policy to make it shorter and clearer. It now explains who operates Mentornity, where your data is hosted (in the European Union), which service providers we use, how we protect student data, and what we do if a data breach happens. We did not add any new uses of your data.

1. Who we are

Mentornity is software that organisations use to run mentoring, coaching and learning programs.

Mentornity is developed and operated by Plademy Oy, a company registered in Finland (Business ID 3386328-3, Lapinlahdenkatu 16, 00180 Helsinki, Finland). Plademy Oy builds the software, runs the servers and provides the service.

Organisations can buy Mentornity directly from Plademy Oy or through our authorised reseller Mentornity LLC in the United States (30 N Gould St, Ste 4000, Sheridan, WY 82801, USA). In this policy, "Mentornity", "we" and "us" mean Plademy Oy and, where it sells the service, Mentornity LLC.

If your organisation has signed a separate agreement with us (for example a data processing agreement or a student data privacy agreement), that agreement takes priority over this policy.

2. Who is responsible for your data

Program data. When you take part in a program that an organisation runs on Mentornity (for example your company, school, university or association), that organisation is the data controller. It decides who is invited, what information is collected and how the program is run. We process this data on the organisation's behalf and only on its instructions. Questions about program data, including requests to access or delete it, should go to your organisation first. We will help the organisation respond.

Our own data. Plademy Oy is the data controller for a small set of data we need to run our business: visits to our website, accounts of people who contact us or buy the service, billing contacts, and security logs.

3. What data we process

  • Account data: name, email address, password (stored only as a secure hash), language and time zone.
  • Profile and program data: the information you or your organisation add to your profile and to application or feedback forms, your role in a program, your matches, goals, meeting details, notes, messages and files you share.
  • Calendar and video data: if you connect Google, Microsoft or Zoom, the calendar and meeting information needed to schedule meetings. Live audio and video of in-platform meetings passes through our video servers.
  • Technical data: IP address, browser and device type, pages used, and error reports. We use these to run, secure and fix the service.
  • Billing data (organisations only): billing contact and payment details, processed by our payment provider. We do not store card numbers.

We do not ask for your date of birth, and we do not knowingly collect special categories of data. Organisations should not ask participants for such data unless they have a lawful reason.

4. How we use data

We use data only to:

  • provide, operate and support the service for your organisation;
  • send service messages, such as invitations, meeting reminders and notifications (you can manage most of these in your notification settings);
  • keep the service secure and prevent misuse;
  • fix problems and improve the service, using aggregated or de-identified information where possible;
  • meet our legal obligations.

What we do not do:

  • We do not sell personal data.
  • We do not show advertising for third-party products or services in the platform, and we do not use program data for targeted advertising. We may show information about our own products, products of our group companies, and mentoring or coaching programs. These messages are never targeted using program data and are not shown to students in school programs.
  • We do not use program data for marketing to participants.
  • We do not use your data to train AI models.

We may send product and service updates to organisation administrators and to people who contact us about our service. Every such email includes an unsubscribe link.

5. Student data

Some organisations, such as schools and school districts, use Mentornity with students. For student data we also commit to the following:

  • Student data is used only to provide the educational service the school has asked for.
  • We do not sell student data, use it for targeted advertising, or build profiles of students for any non-educational purpose.
  • We disclose student data only to the school, to the service providers listed in this policy, or where the law requires it.
  • The school controls the data. When the school asks, we return or delete student data.
  • For schools in the United States, we act as a "school official" with a legitimate educational interest under FERPA, under the school's direct control for the use and maintenance of education records. We also support compliance with state student privacy laws, such as the Illinois Student Online Personal Protection Act (SOPPA), through the school's data privacy agreement.
  • Parents and eligible students can exercise their rights through the school.

6. Children and minors

Mentornity is not directed at children. People under 16 (or under 13 in the United States) may use Mentornity only as part of a program run by their school or another organisation. That organisation is responsible for obtaining any consent required from parents or guardians.

7. Where your data is stored

Mentornity is hosted in the European Union. Our main servers, database, file storage and backups are in Amazon Web Services' Frankfurt region in Germany. This means your data is also protected under the EU General Data Protection Regulation (GDPR), one of the strictest privacy laws in the world.

Some service providers listed below are based outside the European Union, mainly in the United States. When data is transferred outside the EU, we rely on safeguards recognised by law, such as the EU Standard Contractual Clauses or the EU-US Data Privacy Framework.

8. Service providers

We share data only with service providers that help us run Mentornity, and only as much as they need. They may use the data only to provide their service to us.

ProviderWhat they doLocation
Amazon Web ServicesServers, database, file storage, backups, email delivery, logsFrankfurt, Germany (EU)
Hetzner OnlineSecure web gateway, video meeting servers, support mailboxGermany (EU)
CloudflareDomain name service, incoming email routing, certificate images and encrypted backupsGlobal network
Plademy Oy (Ekosistem)In-platform video meetings, provided by our group's video productEU and United States
Amazon Web Services (Amazon Bedrock, Claude models by Anthropic)AI assistance in our customer support and technical support systemsEU
TypeSafe AI, Inc.AI-assisted matching suggestions. Receives only the text of profile answers, without names or contact detailsUnited States
GoogleOnly if you connect it: sign-in and calendar. Also used to help us draft and translate support emailsUnited States
MicrosoftOnly if you connect it: sign-in and calendarUnited States
ZoomOnly if you connect it: creating Zoom meetingsUnited States
Jitsi (8x8)Only if your organisation chooses Jitsi meeting linksGlobal network
StripePayments for organisationsUnited States
Browser push services (Google, Apple, Mozilla)Only if you turn on browser notificationsUnited States

We may update this list as our service changes.

9. How we protect data

  • All connections to Mentornity are encrypted with HTTPS (TLS).
  • Passwords are stored only as salted bcrypt hashes. We never see your password.
  • Our servers run in the EU. Access to production systems is limited to our authorised personnel and to tools they operate.
  • The database is backed up every day. Backups are stored separately in the EU, encrypted, and kept for about one week.
  • We limit repeated attempts on sign-up, password reset and other sensitive actions to prevent abuse.
  • We monitor the service and receive automatic alerts about failures.

No system is completely secure. We keep improving our security as the service grows.

10. If a data breach happens

If we learn of a security incident that affects personal data, we will:

  1. act immediately to contain it and limit the harm;
  2. investigate what happened, which data was affected and whose;
  3. notify the affected organisations without undue delay, and in any case within the time required by applicable law or by our agreement with that organisation;
  4. give the organisation the information it needs to meet its own obligations, including notifying individuals or authorities where required;
  5. take steps to prevent it from happening again.

Where we are the data controller, we will notify the relevant supervisory authority and affected individuals as required by law.

11. How long we keep data

  • Program data is kept while your organisation uses Mentornity. When the organisation ends its subscription or asks us to delete its data, we delete or anonymise it within 90 days, unless the law requires us to keep it longer.
  • Accounts: you can ask us to delete your account at any time. We anonymise your personal data within 30 days.
  • Server logs are kept for up to 30 days.
  • Backups are overwritten after about one week, so deleted data also disappears from backups.

12. Your rights

Depending on where you live, you have the right to access, correct, delete, restrict or move your personal data, and to object to some uses of it. You can also withdraw any consent you have given.

For program data, please contact your organisation first. For anything else, or if you need help, email privacy@mentornity.com. We will reply within one month.

If you are in the European Economic Area, you may also complain to a data protection authority. Our lead authority is the Data Protection Ombudsman of Finland (tietosuoja.fi).

California and other US states: we do not sell or "share" personal information for cross-context behavioural advertising, and we do not use sensitive personal information for purposes that would require an opt-out.

13. Cookies

We use cookies that are needed to sign you in and keep the service working. For details, including any analytics cookies, see our Cookie Policy.

14. Changes to this policy

We may update this policy when our service or the law changes. We will post the new version on this page with a new date. If a change is significant, we will also tell you in the platform or by email.

15. Contact

Plademy Oy Lapinlahdenkatu 16, 00180 Helsinki, Finland Email: privacy@mentornity.com Data Protection Officer: dpo@mentornity.com

For customers in the United States: Mentornity LLC, 30 N Gould St, Ste 4000, Sheridan, WY 82801, USA

We use cookies to provide better user experience to you. You can find more detailed information on Terms of Use page.