MIDAS Knowledge Base MIDAS Knowledge Base

MIDAS Information Security Policy

Last Updated: 31st August 2026

This Information Security Policy sets out how we protect the confidentiality, integrity, and availability of the information entrusted to us in the course of providing our MIDAS room booking and resource scheduling software and our associated "cloud-hosted" service.

It should be read alongside our Data Processing Agreement, our Data Retention Policy, our Software Privacy Policy, our Sub-Processors & Third Party Services list, and the material published at our dedicated security centre.

1. Scope

This policy applies to:It does not extend to our customers' own internal environments, nor to "self-hosted" MIDAS installations running on customer-controlled infrastructure, where responsibility for the operating environment rests with the customer.

2. Responsibility

3. The information we hold

4. Access control

Access is granted on the principle of least privilege, and is limited to what is necessary to operate and support the service.

5. Security controls available to our customers

MIDAS provides controls allowing customers to enforce their own access policy within their booking system:We encourage all customers to enable two-factor authentication or single sign-on across all of their user accounts.

6. Encryption

7. Operational security

8. Secure development

9. Security testing and assurance

10. Backup and recovery

11. Physical security

12. Suppliers and sub-processors

13. Data protection, retention, and disposal

14. Security incidents

15. Vulnerability disclosure

16. Acceptable use

17. Compliance with, and exceptions to, this policy

18. Review

We reserve the right to amend this Information Security Policy at any time without prior notification

Further Reading


← Return to the Knowledge Base