Privacy policy
[Effective date] marks a detail we have not filled in yet.Effective date: [Effective date]. Last updated: [Publish date of this draft].
1. Who is responsible for your data
EO Mentorship is run for the pilot cohort by EO Berlin, the chapter of Entrepreneurs' Organization hosting the Borderless program. EO Berlin is the "controller" of your personal data under GDPR: the organisation that decides why and how it is processed.
Controller: [Controller legal name and registered address for EO Berlin]
Data protection contact: Carsten Hermann, reachable at privacy@eo-mentorship.com
As the platform grows beyond Berlin to other EO chapters, this section will be updated to describe how each chapter's data is governed.
2. What we collect, and why
- Your account and profile — name, email, chapter, timezone, language, and the role you hold (mentee, mentor, chapter chair, etc.). Needed to give you an account and to run the directory.
- Your enrolment answers — why you want a mentor or want to mentor, your experience, industry, availability and matching preferences. Needed to place you in a cycle and find you a match.
- Screening information, where a program requires it — needed for participant safety.
- Your match, sessions, goals and agendas — the record of the mentoring relationship you are part of.
- Session notes — the private notes you and your mentor/mentee write about your sessions. These get the strongest protection on the platform; see the confidentiality policy for exactly who can see them.
- Messages — the plain-text messages you and your mentor/mentee send each other inside the platform. Only the two of you can read them.
- Survey answers — short check-ins used to see how the program is going.
- Calendar connection, only if you choose to connect Google or Microsoft — used to put your sessions on your own calendar. Entirely optional; a downloadable calendar file is always available instead.
- Security and access logs — sign-ins, and a log of every time an administrator is granted temporary access to a note (see the confidentiality policy).
We do not collect payment or billing information — the platform has no billing layer at all. We do not run advertising or ask for government ID.
3. Our legal basis for processing your data
Most of what we do is one of three things:
- Necessary to provide the mentoring program you asked to join — your account, enrolment, matching, sessions, goals and notes.
- A legitimate interest we have balanced against your rights — screening for participant safety, relationship health tracking so a struggling match can be helped before it silently fails, and aggregate program reporting.
- Your explicit consent, which you can always refuse or withdraw — connecting a calendar, using celebration photos, and a separate tick specifically for writing private notes (because notes can incidentally touch on sensitive topics; see below).
We do not ask for consent to run the core program itself, because consent that you would have to give to receive a service you already asked for is not real consent under GDPR.
4. Notes and goals can touch on sensitive topics
A mentoring relationship sometimes surfaces personal things — a health issue, a family situation, a divorce. We do not ask for this information and have no field for it, but free-text notes and goals can end up containing it. Because of that, we treat notes and goals as capable of holding "special category" data under GDPR Article 9, and we ask for a separate, refusable consent to that specific risk when you first write a note. We never analyse, scan or run any automated process over note content, and access to note bodies is restricted far beyond what applies to the rest of your data — see the confidentiality policy.
5. Who can see what
- You and your matched mentor/mentee see your shared sessions, goals and agenda, the messages you send each other, and each other's notes only where marked shared (never a note you mark private to yourself).
- Your chapter chair sees that a match exists, its status, and whether notes were written — never the content of a note or the text of a goal, and nothing about your messages, not even whether you have sent any.
- A small number of platform administrators can, only in narrow, logged, dual-approved circumstances (a safety concern, a formal dispute, your own request, a legal obligation, or diagnosing a technical fault), read the content of a note. You are told when this happens. Full detail is in the confidentiality policy. This does not extend to messages: no administrator can read the messages between you and your mentor/mentee.
6. Where your data is stored
Your data is stored in the EU, in Frankfurt, Germany — both our database (Supabase) and the servers that run the website (Vercel) are pinned to that region. We do not run multiple regions and we do not keep a copy of production data anywhere else, including for testing.
The people who can administer the platform are currently all part of the same EU-based chapter, so there is no routine international transfer of note content or free-text data. If the platform expands to chapters outside the EU, this section — and the safeguards behind it — will be updated before that happens. See the subprocessors page for the specific companies involved.
7. How long we keep your data
Most of your programme history — matches, sessions, goals, surveys — is kept indefinitely as your own record of participation, and because EO uses it to run and improve the program over many years. There is one deliberate exception: the actual text of your private session notes is permanently redacted 12 months after your mentoring cycle finishes. The fact that a note existed (author, date, length) is kept; its content is not. The messages you and your mentor/mentee send each other follow the same rule: their text is permanently redacted 12 months after your mentoring cycle finishes.
Some records exist purely to prove the system worked correctly — for example, the log of who accessed a note and when — and those are kept for 24 months. Screening notes and a few other narrow categories have their own, shorter, schedules. You can ask us for the exact retention period for any category of your data at any time.
8. Cookies
The platform sets one cookie: the sign-in session cookie that keeps you logged in. It is strictly necessary for the site to work and cannot be turned off. We do not use advertising, tracking or analytics cookies, and we do not run any third-party analytics at all.
9. Your rights
You can ask us, at any time and free of charge, to:
- give you a copy of your data (access and portability);
- correct something that is wrong (rectification);
- delete your data, subject to what we are required to keep (erasure);
- pause certain processing while a concern is resolved (restriction);
- object to how your data is used for program evaluation or health scoring — an objection to health scoring is always honoured;
- withdraw a consent you previously gave.
Contact privacy@eo-mentorship.com to exercise any of these. We aim to respond within 14 days and, by law, no later than one month (extendable by up to two further months for a genuinely complex request, and we will tell you if that happens).
10. Who else handles your data
We use a small number of specialist companies to run the platform — a database provider and a hosting provider, both operating in the EU. We do not use a third-party email provider: notification emails are sent from EO's own mail server. The full list, with what each company does and where, is on the subprocessors page.
11. Changes to this policy
If we make a material change — for example, a new category of data, a new company handling your data, or a longer retention period — we will show you a notice and, where the change affects something you previously accepted, ask you to accept it again.
12. Contact us
Questions about this policy or your data: privacy@eo-mentorship.com. You also have the right to lodge a complaint with [the competent supervisory authority for the controller's jurisdiction].