1. Our Commitment to GDPR
Mingrow is fully committed to compliance with the General Data Protection Regulation (GDPR) of the European Union. Whether you are an EU-based customer or a global enterprise handling EU citizen data, we provide the controls, documentation, and processes needed for your compliance obligations.
2. Your Data Rights Under GDPR
Under GDPR and applicable data protection regulations, you have the following rights regarding your personal data stored within Mingrow OS: Right to Access (receive a copy of your data), Right to Rectification (correct inaccurate data), Right to Erasure (request deletion), Right to Data Portability (export your data in a machine-readable format), Right to Restrict Processing, and Right to Object to Processing.
3. Lawful Basis for Processing
Mingrow processes your personal data on the following lawful bases: (a) Contractual Necessity — to perform our services as agreed; (b) Legitimate Interests — to improve platform security and prevent fraud; (c) Consent — for optional analytics and marketing communications, which you may withdraw at any time.
4. Data Processing Agreement (DPA)
Enterprise customers requiring a signed Data Processing Agreement (DPA) for GDPR compliance may request one by contacting info@mingrow.com. Our DPA covers international data transfer mechanisms (Standard Contractual Clauses), sub-processor security requirements, breach notification obligations (within 72 hours of detection), and data retention schedules.
5. Sub-Processors
We maintain a list of approved sub-processors (cloud infrastructure, payment processing, email delivery) who are bound by GDPR-compliant data processing agreements. Our sub-processors are vetted for security certifications (SOC 2, ISO 27001) and located in GDPR-adequate jurisdictions or covered by Standard Contractual Clauses.
6. International Data Transfers
Where personal data of EU residents is transferred to third countries, we rely on the EU Standard Contractual Clauses (SCCs) as adopted by the European Commission to ensure adequate protection. We do not transfer EU personal data to countries without adequate protection unless SCCs or equivalent safeguards are in place.
7. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected customers within 72 hours of becoming aware of the breach, as required by Article 33 of the GDPR. Notifications will include the nature of the breach, affected data categories, and remediation steps taken.
8. Exercising Your Rights
To exercise any of your GDPR rights, submit a written request to info@mingrow.com with the subject line "GDPR Data Request". We will respond within 30 days. We may need to verify your identity before processing the request to protect the security of your data.
Still have questions?
Our team is ready to help you understand your rights, our policies, or any legal requirements specific to your industry or jurisdiction.