<< Back to login

Our commitment to your data privacy

We are wholly invested in our customers' success and the protection of customer data. One way that we deliver on this promise is by helping Midnight Mafia customers and users understand, and where applicable, comply with the General Data Protection Regulation (GDPR). The GDPR is the most significant change to European data privacy legislation in the last 20 years and went into effect on May 25, 2018.

It is designed to give EU citizens more control over their data and seeks to unify a number of existing privacy and security laws under one comprehensive law. The GDPR not only applies to organizations located within the EU, but it also applies to all companies processing and holding the personal data of data subjects residing in the European Union, regardless of the company’s location.

On this page, we explain our approach and investment in GDPR compliance and how we help our customers comply with the GDPR.


GDPR Compliance

We appreciate that our customers have requirements under the GDPR that are directly impacted by their use of Midnight Mafia products and services, which is why we have devoted significant resources toward helping our customers fulfill their requirements under the GDPR and local law.

To the right are several GDPR initiatives that have been implemented for our cloud products:

  • Midnight Mafia offer data portability and data management tools including:
    • Profile deletion tool: We help customers and end users delete personal information, such as names and email addresses. We help customers respond to user requests to delete personal information, and we also help end users with Midnight Mafia accounts delete their personal information, as well as people without Midnight Mafia accounts delete their personal information.
  • We have made required updates to relevant contractual terms.
  • We have ensured Midnight Mafia staff that access and process customer personal data have been trained in handling that data and are bound to maintain the confidentiality and security of that data.
  • We have committed to carrying out data impact assessments and consulting with EU regulators where appropriate.

Our Security and Certifications

Protecting our customers' information and their user's privacy is extremely important to us. We are entrusted with some of our customer's most valuable data, which is why we have built security into every layer of the Midnight Mafia Cloud architecture. We provide replication, backup, and disaster recovery planning, encryption in transit and at rest, advanced threat detection, and more.

Additionally, we have devoted significant resources towards ensuring our cloud products are built and designed in accordance with widely accepted standards and certifications. These standards mirror many of the security and privacy requirements of the GDPR and give our customers a transparent framework by which to measure our software development and data management practices.

International Data Transfers

We offer customers a robust international data transfer framework as a part our Data Processing Addendum. This addendum ensures that our customers can lawfully transfer personal data to Midnight Mafia Cloud products outside of the European Economic Area by relying on our Privacy Policy. This addendum also contains specific provisions to assist customers in their compliance with the GDPR.


Data Portability and the Right to Be Forgotten

We help you honor your customers' requests to export their data, should you host your customer data on Midnight Mafia products. Midnight Mafia provides robust data portability and data management tools for exporting product and user data.

We also help customers meet obligations under the GDPR right to be forgotten (or right to erasure) clause by making it easy to delete personal data from Midnight Mafia.

Midnight Mafia Organization Admins can facilitate the account deletion of their managed users from controls in their admin portal. End users may also request that their personal data be deleted by initiating an account deletion request from their Midnight Mafia account profile page. People who have provided their personal data or had their personal data provided to Midnight Mafia, but do not have Midnight Mafia accounts, may also initiate a request for deletion via email.

Privacy and Consent

Your privacy is important to us, and so is being transparent about how we collect, use, and share your information. In our Privacy Policy, we share what information we collect, how we use and store that data, and how you can access and control your information.