Privacy Policy
Last updated: 22 June 2026
This Privacy Policy explains how TriMid Global (“we”, “us”) collects, uses, and protects personal data in connection with the GoldArkIQ platform (the “Service”). It applies to our marketing site and to data we process as a controller. Where we process personal data on behalf of a customer (as a processor), the customer’s instructions and our Data Processing Addendum govern.
Data we collect
- Account data — name, work email, organization, and role.
- Customer Data — the GRC records you create in the Service (risks, controls, evidence, etc.). You control this data.
- Usage & device data — log data, IP address, and browser information needed to operate and secure the Service.
- Billing data — processed by Stripe; we do not store full card numbers.
How we use data
- To provide, secure, and support the Service.
- To process payments and manage subscriptions.
- To communicate about your account, security, and service updates.
- To comply with legal obligations and enforce our Terms.
Legal bases (EEA/UK)
We rely on performance of a contract (to provide the Service), legitimate interests (to secure and improve the Service), consent (where required, e.g. certain cookies), and legal obligation.
Sharing & subprocessors
We share data with vetted service providers who help us run the Service (e.g. cloud hosting, payment processing, email delivery, error monitoring). These subprocessors are bound by confidentiality and data-protection obligations. We do not sell personal data.
International transfers
Where personal data is transferred across borders, we use appropriate safeguards such as Standard Contractual Clauses.
Retention
We retain account and Customer Data for the life of your subscription and a limited period thereafter, then delete or anonymize it unless a longer period is required by law. Certain audit logs are retained for compliance purposes.
Your rights
Subject to applicable law, you may request access, correction, deletion, portability, or restriction of your personal data, and may object to certain processing. End users whose data is held in a customer’s workspace should contact that customer (the controller). To exercise rights or ask questions, contact info@trimidglobal.com.
Security
We apply technical and organizational measures including encryption in transit, encryption of sensitive fields at rest, role-based access control, multi-factor authentication, and immutable audit logging. See our DPA for details.
Cookies
See our Cookie Policy for how we use cookies and similar technologies.
Changes
We may update this policy and will post the new effective date above. Material changes will be notified.
