EdMyst Inc. GDPR Policy

Last updated: April 12, 2026

 

1. Introduction

EdMyst Inc. is committed to protecting the privacy and personal data of its users. This GDPR Policy outlines how we collect, use, disclose, and protect your personal data across our platforms, including www.edmyst.com, www.edmyst.coach, and www.talentvector.com, in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

 

2. Data Controller and Contact Information

EdMyst Inc. is the data controller responsible for the processing of your personal data. If you have any questions or concerns regarding the processing of your personal data, you can contact us at:

Contact Information:

  • Name: EdMyst Inc.
  • Address: 16192 Coastal Hwy, Lewes, DE 19958, USA
  • Email: support@edmyst.com
  • Phone: +1 (203) 570 9086

Where required under applicable law, EdMyst Inc. will designate a Data Protection Officer (DPO) or equivalent responsible for overseeing data protection compliance.

 

3. Data Collected and Purpose of Processing

EdMyst Inc. collects and processes personal data for specific purposes, including but not limited to:

  • User registration and account management
  • Providing educational services and content
  • Communication with users
  • Analytics and improvement of our services
  • Legal compliance

The types of personal data we may collect include:

  • Contact information (name, email address, phone number)
  • User profile information (username, profile picture, bio)
  • Payment information (for paid services)
  • Usage data (such as access times, pages viewed, interactions)

In connection with our AI-driven assessment and talent development platforms (including TalentVector), we may process user inputs, assessment responses, and performance-related data to generate insights, benchmarking, and recommendations. Such processing is limited to defined purposes and conducted in compliance with applicable laws.

We do not rely solely on automated decision-making that produces legal or similarly significant effects without appropriate safeguards, transparency, and user rights.

We adhere to principles of data minimization and purpose limitation, ensuring that personal data collected is adequate, relevant, and limited to what is necessary.

 

4. Legal Basis for Processing

We process your personal data based on one or more legal bases, including:

  • Consent: Where you have given clear and explicit consent for specific processing activities.
  • Contractual Necessity: When processing is necessary for the performance of a contract.
  • Legal Obligation: When processing is required to fulfill legal obligations.
  • Legitimate Interests: Where processing is necessary for our legitimate interests, provided such interests are not overridden by your fundamental rights and freedoms.

 

5. Data Sharing and Disclosure

  • EdMyst Inc. may share your personal data with third parties under the following circumstances:
  • Service Providers: We may share data with third-party service providers who process personal data on our behalf under binding contractual obligations, including confidentiality, security, and data protection requirements in accordance with GDPR.
  • Legal Compliance: We may disclose data to comply with legal obligations or respond to lawful requests.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, personal data may be transferred.
  • Aggregated or Anonymized Data: We may share aggregated or anonymized data for analytics and reporting purposes.
  • We maintain oversight over all third-party processors and ensure appropriate data processing agreements are in place where required.

 

6. International Data Transfers

Your personal data may be transferred outside the European Economic Area (EEA). Where such transfers occur, we ensure appropriate safeguards are implemented in accordance with GDPR, including the use of Standard Contractual Clauses (SCCs) or other approved mechanisms.

 

7. Data Security

EdMyst Inc. employs appropriate technical and organizational measures designed to protect personal data from unauthorized access, disclosure, alteration, or destruction. However, no data transmission over the internet or storage can be guaranteed as 100% secure.

 

8. Data Retention

We retain your personal data for no longer than necessary to fulfill the purposes for which it was collected, in accordance with defined retention schedules and applicable legal requirements for which it was collected unless a longer retention period is required by law.

 

9. Your Rights

You have the right to:

  • Access your personal data
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten")
  • Restrict or object to processing
  • Data portability
  • Withdraw consent (where applicable)

You also have the right to lodge a complaint with a relevant data protection authority if you believe your data has been processed unlawfully.

 

10. Data Protection Impact Assessments

Where processing activities are likely to result in high risk to individuals’ rights and freedoms, EdMyst Inc. conducts Data Protection Impact Assessments (DPIAs) to identify and mitigate such risks prior to processing.

 

11. Changes to the Policy

EdMyst Inc. may update this GDPR Policy periodically to reflect changes in our practices or legal requirements. We will notify you of significant changes and obtain your consent if required.

 

12. Contact Us

If you have any questions, concerns, or requests related to this GDPR Policy or your personal data, please contact us using the provided contact information.

By using EdMyst Inc. services, you acknowledge that you have read and understood this GDPR Policy and acknowledge the processing of your personal data as described herein, in accordance with applicable legal bases.