Legal Documents
Part X
Data Retention and Security
Retention lifecycles, global privacy principles, technical safeguards, and breach response
Effective: August 22, 2026
41
Data Retention
Clear retention timeframes tied directly to legitimate operational needs and legal duties.
Milynx retains personal data only for periods reasonably necessary to provide active platform services, maintain authenticated accounts, prevent financial fraud, preserve transaction receipts, and fulfill statutory tax obligations.
When data is no longer necessary, Milynx permanently deletes, aggregates, or cryptographically anonymizes the records. Temporary backup snapshots are systematically rotated and purged according to backup lifecycle routines.
Key Takeaway
Data is kept only as long as your account is active and deleted permanently once retention duties end.
42
Milynx Global Privacy Principles
Foundational architectural pillars guiding engineering and platform development.
Milynx operates under seven core architectural principles embedded directly into our engineering lifecycle:
Data Minimization: Collect only what is strictly necessary for legitimate platform functions
Purpose Limitation: Process data strictly within disclosed, lawful, and authorized boundaries
Privacy by Design: Embed privacy safeguards and encryption into every new software release
User Control: Provide intuitive settings, consent controls, and friction-free rights management
Transparency: Communicate all data practices in clear, unambiguous, plain language
Accountability: Maintain verified documentation and technical audit trails for compliance
Continuous Review: Periodically test security defenses, third-party integrations, and privacy safeguards
Key Takeaway
Seven foundational principles ensure privacy is built into every line of code on Milynx.
43
Security Safeguards
AES-256 encryption, TLS 1.3, multi-factor authentication, firewalls, and DDoS mitigation.
Milynx implements robust technical, administrative, and organizational cybersecurity safeguards to protect personal information against unauthorized access, destruction, or interception.
Safeguards include AES-256 encryption at rest, TLS 1.3 encryption in transit, salted password hashing, isolated database clusters, continuous vulnerability scanning, automated DDoS mitigation, and strict multi-factor access protocols for engineering personnel.
Key Takeaway
Enterprise-grade encryption (AES-256 & TLS 1.3) protects your data at rest and in transit.
44
Security Incidents and Data Breaches
Incident response protocol and regulatory notification timelines under GDPR/state statutes.
Milynx maintains an active Cybersecurity Incident Response Plan. In the event of a verified personal data breach, Milynx will evaluate the incident immediately and notify affected users and supervisory regulators within statutory timeframes (such as 72 hours under GDPR).
Milynx coordinates with certified forensic investigators, legal counsel, and law enforcement authorities where appropriate.
Key Takeaway
Prompt regulatory and user notification protocols in the unlikely event of a security breach.
© 2026 Milynx International Enterprise LLC. All Rights Reserved.
Questions: Milynx@Milynx.com · 307-242-1093

