1. Scope and Who Is Responsible
This Privacy Policy explains how Midgard Labs, Inc. (‘Midgard Labs’, ‘we’, ‘us’, or ‘our’) collects, uses, shares, and retains information when you visit the Midgard Labs website, schedule a call, contact us, or report a security issue (together, the ‘Site’). The canonical website address is midgardlabs.io. For privacy questions or requests, contact info@midgardlabs.io. Midgard Labs is responsible for the personal information it processes for these purposes.
This Policy covers the Site and the inquiries, scheduling and communications described above. It does not describe the independent practices of third-party websites or blockchain network participants. Processing of client material to perform professional services is addressed in the applicable engagement documentation and any additional privacy information, without reducing rights under applicable data-protection law.
2. Information We Collect
We aim to collect little. The Site does not require an account. Depending on how you interact with us, we may collect: contact information you choose to provide (such as name, email address, organization, and social or messaging handles) when you contact us or schedule a call; appointment details; the content of your messages and security reports, including any attachments you include; technical information collected automatically when you visit the Site, such as IP address, browser and device type, pages viewed, referring page, approximate region, and similar log data; and wallet addresses or transaction identifiers only if you choose to include them in a message. We receive this information directly from you or through the service providers that host the Site and handle scheduling and communications. Browser preferences are described in our Cookie Notice.
Please do not submit seed phrases, private keys, passwords, government identifiers, or other unnecessary sensitive personal information through a website inquiry or security report. Access required for an agreed engagement must be arranged separately through an agreed secure process. If you send unnecessary sensitive information, we will restrict its use and delete it where practicable, subject to applicable legal and security obligations.
Providing contact information is voluntary. If you do not provide enough information to respond to an inquiry or arrange a call, we may be unable to help with that request. You can browse the Site without submitting contact information or connecting a wallet.
3. A Note on Public Blockchain Data
Information recorded on a public blockchain may be publicly accessible and replicated across independent systems. A wallet address can be personal information when it relates to an identifiable person, including when combined with other information. This Policy applies to personal information we process in connection with the Site, including blockchain information you send us. Deleting our copy does not delete records maintained independently on a public blockchain. This does not remove our obligations for the personal information we process.
4. How We Use Information
We use information to operate, maintain, secure, and improve the Site; respond to messages, requests, and security reports; arrange calls and discuss potential services; understand operational performance; prevent and investigate fraud, abuse, phishing, impersonation, and security incidents; comply with legal obligations; and establish, exercise, or defend legal claims.
Where applicable data-protection law requires a legal basis, we rely on our legitimate interests in running and securing the Site and responding to business inquiries; steps taken at your request before entering a contract, or performance of a contract with you; compliance with legal obligations; or your consent where required. Where we rely on consent, you may withdraw it by contacting us without affecting processing that occurred before withdrawal. We do not use Site information to make solely automated decisions that have legal or similarly significant effects on you.
7. Retention
We keep personal information only as long as needed for the purposes described above, and then delete or de-identify it. Scheduling information and correspondence are kept while we work with you and for a reasonable period afterward; security reports are kept while remediation and any disclosure coordination are in progress and for record-keeping after; and routine technical logs are kept for a limited operational window for security, troubleshooting, and abuse prevention. To determine appropriate retention periods, we consider the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process it, whether those purposes can be achieved through other means, and applicable legal requirements. We may retain information longer where required by law or to resolve disputes and enforce our agreements.
8. International Transfers
We are based in the United States. Our service providers may process information in the United States and other countries where they operate, whose data-protection laws may differ from those where you live. Where applicable law requires safeguards for an international transfer, we rely on a lawful transfer mechanism, such as an applicable adequacy decision or approved contractual safeguards. Contact info@midgardlabs.io for information about the safeguards applicable to your information. This Policy does not waive any protection or right you have under applicable law.
9. Your Rights and Choices
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, to withdraw consent, and to lodge a complaint with a supervisory authority. Where the California Consumer Privacy Act applies, California residents may exercise the rights it provides, including the rights to know, delete, and correct personal information. We do not sell personal information or share it for cross-context behavioral advertising. To exercise any right, contact info@midgardlabs.io with your request; we will verify your identity to the extent needed and respond within the time required by applicable law. We will not discriminate against you for exercising your rights. Requests apply to personal information we process; they do not enable us to erase records maintained independently on public blockchains.
An authorized agent may submit a request where applicable law permits. We may ask for proof of authority and limited information needed to verify the request. If we decline a request, we will explain why, subject to legal restrictions; you may contact us to appeal where that right applies. You may also complain to your local data-protection authority, including the UK Information Commissioner’s Office or your EU supervisory authority.
10. Children
The Site is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us so we can investigate and take appropriate steps to delete the information, subject to any retention required by law.
11. Security
We use reasonable administrative and technical measures appropriate to the nature of the data we hold. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Do not disclose wallet recovery phrases, wallet private keys or personal account passwords in an inquiry or security report. We do not need them to respond to you. Any access required for an agreed engagement must be arranged separately through an agreed secure process.
12. Changes to This Policy
We may update this Policy from time to time. We will post the updated version on this page with an updated ‘Last updated’ date, and where changes are material we will provide additional notice as appropriate.
13. Contact
Privacy questions and requests: info@midgardlabs.io.
