Last updated: April 12, 2026
1. Introduction
EdMyst Inc. is committed to protecting the privacy and personal data of its users. This GDPR Policy outlines how we collect, use, disclose, and protect your personal data across our platforms, including www.edmyst.com, www.edmyst.coach, and www.talentvector.com, in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data Controller and Contact Information
EdMyst Inc. is the data controller responsible for the processing of your personal data. If you have any questions or concerns regarding the processing of your personal data, you can contact us at:
Contact Information:
Where required under applicable law, EdMyst Inc. will designate a Data Protection Officer (DPO) or equivalent responsible for overseeing data protection compliance.
3. Data Collected and Purpose of Processing
EdMyst Inc. collects and processes personal data for specific purposes, including but not limited to:
The types of personal data we may collect include:
In connection with our AI-driven assessment and talent development platforms (including TalentVector), we may process user inputs, assessment responses, and performance-related data to generate insights, benchmarking, and recommendations. Such processing is limited to defined purposes and conducted in compliance with applicable laws.
We do not rely solely on automated decision-making that produces legal or similarly significant effects without appropriate safeguards, transparency, and user rights.
We adhere to principles of data minimization and purpose limitation, ensuring that personal data collected is adequate, relevant, and limited to what is necessary.
4. Legal Basis for Processing
We process your personal data based on one or more legal bases, including:
5. Data Sharing and Disclosure
6. International Data Transfers
Your personal data may be transferred outside the European Economic Area (EEA). Where such transfers occur, we ensure appropriate safeguards are implemented in accordance with GDPR, including the use of Standard Contractual Clauses (SCCs) or other approved mechanisms.
7. Data Security
EdMyst Inc. employs appropriate technical and organizational measures designed to protect personal data from unauthorized access, disclosure, alteration, or destruction. However, no data transmission over the internet or storage can be guaranteed as 100% secure.
8. Data Retention
We retain your personal data for no longer than necessary to fulfill the purposes for which it was collected, in accordance with defined retention schedules and applicable legal requirements for which it was collected unless a longer retention period is required by law.
9. Your Rights
You have the right to:
You also have the right to lodge a complaint with a relevant data protection authority if you believe your data has been processed unlawfully.
10. Data Protection Impact Assessments
Where processing activities are likely to result in high risk to individuals’ rights and freedoms, EdMyst Inc. conducts Data Protection Impact Assessments (DPIAs) to identify and mitigate such risks prior to processing.
11. Changes to the Policy
EdMyst Inc. may update this GDPR Policy periodically to reflect changes in our practices or legal requirements. We will notify you of significant changes and obtain your consent if required.
12. Contact Us
If you have any questions, concerns, or requests related to this GDPR Policy or your personal data, please contact us using the provided contact information.
By using EdMyst Inc. services, you acknowledge that you have read and understood this GDPR Policy and acknowledge the processing of your personal data as described herein, in accordance with applicable legal bases.