Last updated: 4 August 2026
This Privacy Policy explains how Midas Digital collects, uses and protects personal data when you:
Information about cookies and similar technologies is provided separately in the Cookie Policy.
Midas Digital is the controller responsible for the processing described in this Privacy Policy.
Midas Digital
Operated by Marnix Buijs
Aconietenhof 33
9951 HC Groningen
The Netherlands
Chamber of Commerce number: 98156624
VAT identification number: NL005311785B70
Email: marnix.buijs@midas-digital.com
Website: https://midas-digital.com
When you visit the website, technical information may be processed automatically, including:
This information is processed to provide the website, maintain its security, diagnose errors and prevent misuse.
The website is hosted by Hostinger. Hostinger acts as a processor for data handled through its hosting infrastructure and provides contractual safeguards for customer data.
When you use the contact form, Midas Digital collects the information you enter, which may include:
The form may also record technical metadata such as:
The contact form is built with Elementor. Contact form submissions are stored securely within the website’s WordPress administration environment and sent to Midas Digital by email. Elementor confirms that the Collect Submissions action stores submitted information in the WordPress administration environment.
An internal honeypot field is used to help identify automated submissions.
Please do not submit health information, identification documents, financial details or other sensitive personal data through the contact form unless this is genuinely necessary.
When you contact Midas Digital by email, information processed may include:
Correspondence is processed through the Midas Digital business mailbox provided through Google Workspace.
When you book a meeting through Calendly, information may include:
Calendly processes this information on behalf of Midas Digital to arrange and manage the meeting. Calendly states that invitee data may be stored in United States data centres and that international transfers are covered by mechanisms including the EU-US Data Privacy Framework and Standard Contractual Clauses.
Meetings may take place through Google Meet. The calendar event, participant details and associated correspondence may therefore be processed through Google Workspace.
Calls are not recorded, transcribed or summarised automatically unless you are informed beforehand and any legally required consent has been obtained.
Google Tag Manager is used to manage website tags. Google Analytics 4 is used to understand how the website is found and used.
Complianz communicates your consent preferences to Google through Google Consent Mode. Before statistics consent is granted, Google tags may receive limited consent-state or technical signals but Analytics cookies are not stored. When you grant statistics consent, Google Analytics may process information such as:
Google states that Google Analytics does not log or store the IP addresses of users in the European Union, Switzerland or the United Kingdom. Google may still use an IP address briefly at collection to determine approximate location before discarding it.
Statistics processing takes place only on the basis of your consent. You can withdraw or change that consent through the Cookie settings link in the website footer.
Further details about the cookies used by Google Analytics are provided in the Cookie Policy.
Complianz is used to display the consent banner, record your chosen cookie categories and communicate those choices to integrated services.
Information stored may include:
These preferences are necessary to remember and demonstrate your choices. The exact cookies and retention periods are listed in the Cookie Policy.
Optimole is used to optimise and deliver website images. Images may be served through Optimole infrastructure and Amazon CloudFront from a location close to the visitor.
When an image is requested, Optimole may process technical information including:
Optimole states that image requests are logged using the visitor’s IP address and user agent. Its image delivery network is powered by Amazon CloudFront.
This processing is used to deliver correctly sized images, improve loading performance, protect the service and monitor usage.
Midas Digital processes personal data for the following purposes.
Contact and correspondence data is used to understand your request, respond to it and discuss a potential engagement.
The legal bases are:
Booking information is used to schedule, administer and attend meetings.
The legal bases are:
Where an enquiry develops into a client engagement, personal data may be used to deliver the agreed work, communicate with stakeholders, administer the project and maintain business records.
The legal bases are:
Technical data and server logs are used to provide the website, detect errors, protect accounts, prevent abuse and investigate security incidents.
The legal basis is the legitimate interest of maintaining a secure and reliable business website.
Technical request information is processed through Optimole to provide appropriately sized images and improve website performance.
The legal basis is the legitimate interest of delivering an efficient and functional website.
Google Analytics is used to understand website usage and improve content, navigation and performance.
The legal basis is your consent.
Complianz stores consent choices so that the website can respect those choices and demonstrate its consent configuration.
The legal bases are compliance with applicable privacy and cookie obligations and the legitimate interest of maintaining reliable consent records.
Information may be retained or used where necessary to meet tax, accounting or other legal obligations, resolve disputes, enforce agreements or establish, exercise or defend legal claims.
The legal bases are compliance with legal obligations and legitimate interests relating to legal protection and business administration.
Personal data may be processed by the following categories of recipient where necessary:
Midas Digital does not sell personal data.
Midas Digital does not use contact-form or booking information to add people automatically to a marketing mailing list.
Some service providers may process data outside the European Economic Area, including in the United States.
Where personal data is transferred outside the European Economic Area, Midas Digital relies on safeguards made available by the relevant provider, such as:
Calendly specifically states that its transfers from the European Economic Area may rely on the EU-US Data Privacy Framework and Standard Contractual Clauses.
Midas Digital retains personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required by law. This follows the GDPR principle that personal data should not be kept for longer than necessary.
Contact form submissions, booking information and correspondence relating to an enquiry are normally retained for up to 24 months after the last substantive contact.
Information may be deleted sooner where it is clearly no longer required. Where an enquiry develops into a client relationship, relevant information may instead become part of the client and project records described below.
Client communications, project documents and related records may be retained for the duration of the engagement and afterwards where reasonably necessary for project continuity, business administration or the establishment, exercise or defence of legal claims.
Financial records and information forming part of the statutory business administration may be retained for the legally required period.
User-level and event-level data in Google Analytics is retained for up to 14 months. The retention period for user identifiers is not reset when a visitor returns. Aggregated reporting data may remain available for longer in accordance with Google Analytics’ reporting systems.
Cookie and consent preferences are retained for the periods stated in the Cookie Policy or until you change or withdraw your preferences.
Website access, security and error logs are retained for limited periods determined by operational, security and troubleshooting requirements.
Deleted information may remain temporarily in restricted backups until those backups are overwritten through the normal backup cycle.
Midas Digital takes reasonable technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration and disclosure.
Measures include, where appropriate:
No internet transmission or storage system can be guaranteed to be completely secure.
Depending on the circumstances, you may have the right to:
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
Requests can be sent to:
marnix.buijs@midas-digital.com
Midas Digital may ask for reasonable information to confirm your identity before completing a request. Privacy requests will normally be answered within one month, subject to the extensions permitted by the GDPR. The Autoriteit Persoonsgegevens also states that organisations must clearly explain how individuals can exercise their privacy rights.
Questions or concerns should first be sent to Midas Digital using the contact details above so that the issue can be investigated.
You also have the right to lodge a complaint with the Dutch supervisory authority:
Midas Digital does not use the personal data described in this Privacy Policy to make decisions based solely on automated processing that produce legal or similarly significant effects.
This Privacy Policy may be updated when:
The latest version will be published on this page with an updated revision date.