Data Processing Addendum
Last updated: 22 June 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between TriMid Global (“Processor”) and the customer (“Controller”) for use of the GoldArkIQ Service. It applies where we process personal data on the Controller’s behalf and reflects the requirements of the GDPR and comparable laws.
1. Roles & scope
The Controller determines the purposes and means of processing Customer Data; we act as Processor and process personal data only on documented instructions from the Controller, including as set out in the agreement and the Controller’s configuration of the Service.
2. Nature & purpose of processing
We process personal data to provide the GRC Service: storing and managing risk, compliance, audit, vendor, privacy, and related records, and supporting integrations the Controller enables.
3. Subject matter & data subjects
- Data subjects: the Controller’s personnel, vendors’ contacts, and individuals referenced in the Controller’s GRC records.
- Categories of data: identifiers (name, email, role) and any content the Controller chooses to store.
4. Security measures
- Encryption in transit (TLS) and encryption of sensitive fields at rest.
- Strict tenant isolation — every record is scoped to the Controller’s organization.
- Role-based access control and optional multi-factor authentication / SSO.
- Immutable, append-only audit logging of changes.
- Least-privilege access for our personnel and vendor due-diligence on subprocessors.
5. Subprocessors
The Controller authorizes our use of subprocessors to provide the Service (e.g. cloud hosting, payment processing, transactional email, and error monitoring). We impose data-protection obligations on each subprocessor and remain responsible for their performance. We will give notice of new subprocessors and an opportunity to object on reasonable grounds. A current subprocessor list is available on request.
6. International transfers
Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards such as the Standard Contractual Clauses.
7. Data subject requests
We will assist the Controller, taking into account the nature of processing, in responding to requests from data subjects to exercise their rights, including via the Service’s data-export and deletion features.
8. Personal data breach
We will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, and provide information reasonably required for the Controller to meet its obligations.
9. Return & deletion
On termination, the Controller may export Customer Data for a reasonable period, after which we will delete or anonymize it, except where retention is required by law.
10. Audits
We will make available information necessary to demonstrate compliance with this DPA and allow for reasonable audits, subject to confidentiality and security constraints.
Contact
To execute a counter-signed copy or request our subprocessor list, contact info@trimidglobal.com.
