Data protection

Data Protection at Mentessa

Secure, transparent, GDPR-compliant. We process all data in accordance with the EU General Data Protection Regulation (GDPR) and host it securely in Germany.

Privacy Policy

Terms of Use

Frequently Asked Questions

General questions

What service do we provide?

The Mentessa app is our Software-as-a-Service offering, provided exclusively over the internet. On behalf of our customers, we collect, process and transmit personal data of voluntarily participating employees in order to provide an in-house mentoring program.

Which contracts and documents do we provide?

  • Software-as-a-Service Agreement: all details of our service are set out in the main agreement.
  • Data Processing Agreement: contains all content required under Art. 28 GDPR, with Exhibit 1 (sub-processor list) and Exhibit 2 (data protection policy).

What needs to be considered regarding compliance with data protection regulations?

The Mentessa app is provided as part of a data-processing arrangement. The customer remains the controller under data protection law. We process employee data strictly on the customer's instructions, in accordance with the Data Processing Agreement.

Which personal data is processed, and for what purposes?

The Mentessa app processes personal data of our customers' employees: names, contact details, individual information about their role within the organization, and their skills, knowledge and expertise. The purpose of this processing is to provide an algorithm-based mentoring program that suggests other participants to each user, from whom they can learn specific skills through one-to-one exchange.

On what legal basis is employee data processed in the Mentessa app?

Registration is voluntary. Data processing is therefore based on the participating employee's consent under Art. 7 and Art. 6(1)(a) GDPR.

Where is personal data processed?

All data processed under the Data Processing Agreement is processed exclusively within the EU/EEA.

Should the works council be informed?

Yes, the works council should be informed about the introduction of the Mentessa app because of its supervisory function.

Does the works council have co-determination rights?

No, because the Mentessa app is not designed to monitor employees' performance or conduct within the meaning of § 87(1) no. 6 of the German Works Constitution Act (BetrVG).

Technical questions

What service do we provide?

The Mentessa app is our Software-as-a-Service offering, provided exclusively over the internet. On behalf of our customers, we collect, process and transmit personal data of participating employees in order to provide an in-house network.

Physical entry control

Data processing takes place exclusively on Mentessa GmbH's own systems, in an office building secured by a staffed reception. Entry to the data-processing facility is only possible using a key.

System access control

Mentessa GmbH has implemented an authorization concept for system use. All access is logged. Password protection follows the current state of the art. Accounts are locked after repeated incorrect password entries, and automatic session timeouts round out access security.

Data access control

Data processing for the Mentessa app is logically separated for each customer; access to another customer's personal data via the Mentessa app is excluded. Differentiated role- and permission concepts ensure access is granted only to the extent necessary for the authorized person (need-to-know principle), reviewed regularly by a data protection coordinator, with immediate revocation on a change in authorization.

Separation control

Development, test and production systems are separated. Data processing is also logically separated by tenant.

Pseudonymization

Mentessa receives no data, or only pseudonymized data, from the customer for creating participant profiles as part of the mentoring program.

Integrity

Internal emails are encrypted. Secure connections (VPN) are used to protect remote access to data processing.

Availability and resilience

Regular backups are performed. Antivirus and malware protection software are kept up to date with the current state of the art.

Rapid recoverability

See above.

Procedures for regular review, assessment and evaluation, and processor oversight

Mentessa has implemented a data protection management system. A record of processing activities (Art. 30(1) and (2) GDPR) is also in place. Employees receive regular training on data protection and data security.

Information for the works council

What is the Mentessa app?

The Mentessa app is our Software-as-a-Service offering, provided exclusively over the internet. On behalf of our customers, we collect, process and transmit personal data of participating employees in order to provide an in-house mentoring program.

What types of personal data are processed?

First and last name, contact details (email or, where applicable, a work phone extension), where applicable a profile photo, the employee's position and department, and individual information the employee enters themselves about their skills, knowledge in specific areas, or expertise.

Are employees required to participate in the Mentessa app?

No, participation is entirely voluntary and is offered as an additional benefit by the employer. Choosing not to participate, or completing only part of a profile, has no effect whatsoever on the employment relationship or performance appraisal. Data processing is based on consent under Art. 7 GDPR.

For what purposes is personal data processed in the Mentessa app?

The Mentessa app is designed to simplify in-house mentoring programs. Its algorithm-based data processing suggests other participants with a certain level of knowledge to a participant, so the latter can be supported through one-to-one exchange. Example: a participant records in their profile that they rate their French language skills as average. The Mentessa app will suggest a participant whose native language is French and establish contact (a “match”) to improve language skills.

Can the employer use the Mentessa app to monitor participating employees’ performance or conduct?

No, because all data is processed anonymized.

Is the Mentessa app linked to the employer's IT systems?

No, because the Mentessa app is offered exclusively online via browser. Data processing takes place exclusively on Mentessa GmbH’s own IT systems.

What access rights exist within the employer’s sphere?

Participants' access is not limited to the data profile of the participant with whom a match exists.

What technical and organizational security measures are taken?

The Mentessa app can only be accessed over the internet using login credentials individually provided to each participant. Access is SSL-encrypted.

Security Measures

Pseudonymization

Participant data used for skills-profile creation and matching is processed pseudonymized wherever feasible. Staff with access to personal data are trained regularly, and compliance is monitored through spot checks and ongoing audits.

Encryption

The platform is only accessible via encrypted connections (TLS). Passwords are stored using a modern, salted hashing algorithm — never in plain text.

Confidentiality & access control

Role- and permission-based access control on a strict need-to-know basis; all access is logged. Accounts lock after repeated failed logins, and sessions time out automatically. Our hosting infrastructure runs on certified, physically secured data-center facilities operated by an established European hosting provider.

Separation control

Data processing is logically separated per customer — one customer can never access another customer’s data through the platform. Development, test and production environments are kept separate.

Integrity

Access and changes to systems and data are logged in a tamper-evident, auditable way, including administrator activity, with defined retention and deletion periods for those logs. Sub-processors are contractually bound to equivalent data-protection and security obligations and are subject to review.

Availability & resilience

Regular backups, up-to-date malware protection, firewalled internal networks, and redundant power supply at the hosting facility. Backups are stored in a physically separate location from the primary systems.

Rapid restorability

Documented recovery plans and recovery routines are in place so that access to personal data can be restored promptly in the event of a physical or technical incident.

Ongoing review

We operate a data protection management system with a record of processing activities (Art. 30 GDPR), regular staff training on data protection and security, and recurring audits to test the effectiveness of these measures.