Data Processing Addendum

Last updated: 22 June 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between TriMid Global (“Processor”) and the customer (“Controller”) for use of the GoldArkIQ Service. It applies where we process personal data on the Controller’s behalf and reflects the requirements of the GDPR and comparable laws.

1. Roles & scope

The Controller determines the purposes and means of processing Customer Data; we act as Processor and process personal data only on documented instructions from the Controller, including as set out in the agreement and the Controller’s configuration of the Service.

2. Nature & purpose of processing

We process personal data to provide the GRC Service: storing and managing risk, compliance, audit, vendor, privacy, and related records, and supporting integrations the Controller enables.

3. Subject matter & data subjects

  • Data subjects: the Controller’s personnel, vendors’ contacts, and individuals referenced in the Controller’s GRC records.
  • Categories of data: identifiers (name, email, role) and any content the Controller chooses to store.

4. Security measures

  • Encryption in transit (TLS) and encryption of sensitive fields at rest.
  • Strict tenant isolation — every record is scoped to the Controller’s organization.
  • Role-based access control and optional multi-factor authentication / SSO.
  • Immutable, append-only audit logging of changes.
  • Least-privilege access for our personnel and vendor due-diligence on subprocessors.

5. Subprocessors

The Controller authorizes our use of subprocessors to provide the Service (e.g. cloud hosting, payment processing, transactional email, and error monitoring). We impose data-protection obligations on each subprocessor and remain responsible for their performance. We will give notice of new subprocessors and an opportunity to object on reasonable grounds. A current subprocessor list is available on request.

6. International transfers

Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards such as the Standard Contractual Clauses.

7. Data subject requests

We will assist the Controller, taking into account the nature of processing, in responding to requests from data subjects to exercise their rights, including via the Service’s data-export and deletion features.

8. Personal data breach

We will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, and provide information reasonably required for the Controller to meet its obligations.

9. Return & deletion

On termination, the Controller may export Customer Data for a reasonable period, after which we will delete or anonymize it, except where retention is required by law.

10. Audits

We will make available information necessary to demonstrate compliance with this DPA and allow for reasonable audits, subject to confidentiality and security constraints.

Contact

To execute a counter-signed copy or request our subprocessor list, contact info@trimidglobal.com.