Data Processing Agreement

Last Updated: April 1, 2025

1. Purpose

This Data Processing Agreement ("DPA") describes how Midas Financial ("Processor") processes personal data on behalf of its members ("Controller") in accordance with applicable data protection laws, including GDPR, CCPA, and other relevant regulations.

2. Scope of Processing

Midas Financial processes personal data for the following purposes:

  • Account creation, authentication, and management
  • Delivery of platform features, tools, and content
  • Payment processing and billing
  • Customer support and communication
  • Security monitoring and fraud prevention
  • Analytics and service improvement
  • Compliance with legal obligations

3. Data Categories

Categories of personal data processed include: name, email address, phone number, billing information, IP address, device identifiers, usage data, business information, and any data users voluntarily submit through the platform.

4. Sub-Processors

We may engage trusted third-party sub-processors to assist with platform operations, including payment processors, cloud hosting providers, email delivery services, and analytics tools. All sub-processors are bound by data protection agreements consistent with this DPA. A list of current sub-processors is available upon written request.

5. Data Transfers

Personal data may be transferred to and processed in countries outside your home country, including the United States. We rely on appropriate legal mechanisms such as Standard Contractual Clauses (SCCs) for international data transfers where required.

6. Security Measures

Midas Financial implements technical and organizational security measures including encryption at rest and in transit, access controls, regular security assessments, and incident response procedures to protect personal data against unauthorized access, loss, or destruction.

7. Data Breach Notification

In the event of a personal data breach, we will notify affected users and relevant authorities as required by applicable law, within the timeframes specified by those laws (e.g., 72 hours under GDPR).

8. Retention & Deletion

Personal data is retained only as long as necessary to fulfill the purposes described in this DPA, or as required by law. Upon account termination, data is deleted within 90 days unless legally required to be retained longer.

9. Contact

Data protection inquiries: privacy@midasfinancial.com

We use cookies to improve your experience, analyze website traffic, and support marketing efforts. You can accept all cookies, reject non-essential cookies, or manage your preferences.

Read our Cookie & Privacy Policy →