Privacy Policy

Mentis handles sensitive mental-health information, and we treat it that way. This policy explains what we collect, why, and the choices you have.

Last updated: 28 June 2026

Template document. This policy is provided as a clear, NDPR-aware starting point. It is not legal advice and is pending review by Mentis' legal counsel before it becomes binding.

1. Who we are

Mentis ("Mentis", "we", "us") provides mental-health education and connects people with licensed mental-health professionals in Nigeria. We are the data controller for the personal data described in this policy. You can reach us at privacy@mentis.ng.

We process personal data in line with the Nigeria Data Protection Regulation (NDPR) and applicable guidance from the Nigeria Data Protection Commission.

2. The data we collect

  • Account details — your name, email address, phone number and password (stored encrypted).
  • Wellbeing and assessment data — your responses to check-ins and assessments, and any notes you choose to record. This is sensitive personal data and receives extra protection.
  • Booking and session data — the professionals you connect with and the sessions you book.
  • Payment data — processed by our payment provider; we do not store full card details.
  • Technical data — device, browser and usage information needed to keep the service secure and working.

3. How and why we use your data

  • To create and manage your account and provide the service.
  • To deliver courses, run assessments and connect you with providers you choose.
  • To process payments and prevent fraud.
  • To keep you informed about your bookings, security and important service changes.
  • To improve Mentis and, where you have consented, to produce aggregated, anonymised insights about mental health in Nigeria — never anything that identifies you.

4. Your assessment responses are private

Your assessment responses and session content are private to you and the professionals you choose to work with. We do not sell your personal data, and we do not share identifiable health data for advertising. Any research or reporting use is based on data that has been aggregated and anonymised so that it cannot be traced back to you.

5. Who we share data with

  • Providers you choose — so they can support you in a session.
  • Service providers — e.g. hosting, payments and email, who act on our instructions under contract.
  • Authorities— only where we are legally required to, or to protect someone's safety.

6. How long we keep it

We keep personal data only for as long as needed to provide the service and to meet legal and clinical record-keeping obligations, after which it is securely deleted or anonymised.

7. Your rights under the NDPR

You have the right to:

  • access the personal data we hold about you;
  • ask us to correct data that is wrong or incomplete;
  • ask us to delete your data, subject to legal limits;
  • withdraw consent at any time, where we rely on it;
  • object to or restrict certain processing;
  • lodge a complaint with the Nigeria Data Protection Commission.

To exercise any of these, contact privacy@mentis.ng.

8. Security

We use encryption in transit and at rest, strict access controls and regular reviews to protect your data. No system is perfectly secure, but we work hard to keep yours safe and to notify you and the relevant authority if anything goes wrong.

9. If you are in crisis

Mentis is not an emergency service. If you or someone else is in immediate danger, please contact local emergency services or a crisis line right away.

10. Changes to this policy

We may update this policy from time to time. We will post the new version here and update the date above; significant changes will be communicated to you directly.