Compliance

Data Security & Governance Policy

Effective Date: July 20, 2026
Last Updated: July 20, 2026
Approved by: Larry Simpson

1. Our Commitment

Momentum Data Solutions is committed to handling business, personal, financial, healthcare, and operational data responsibly.

We recognize that our clients may rely on us to extract, validate, clean, transform, organize, migrate, automate, or otherwise process information that is confidential or sensitive. Our goal is to protect that information throughout its lifecycle while maintaining its confidentiality, integrity, availability, accuracy, and appropriate use.

This Data Security & Governance Policy describes the principles and safeguards we use when handling data through our website, services, technology platforms, system integrations, and client engagements.

This policy supplements our Privacy Policy, client agreements, statements of work, data processing agreements, business associate agreements, confidentiality agreements, and other contractual obligations.

2. Scope

This policy applies to data that Momentum Data Solutions receives, accesses, creates, processes, transmits, stores, or manages while:

  • Providing data extraction, transformation, and loading services;
  • Performing data cleansing, validation, normalization, or reconciliation;
  • Supporting system implementations and data migrations;
  • Processing spreadsheets, CSV files, PDFs, system reports, or business records;
  • Developing APIs, connectors, webhook-enabled workflows, and automations;
  • Preparing data for reporting, dashboards, payroll, human resources, financial, operational, or compliance purposes;
  • Managing information submitted through our website or client communication channels; and
  • Working with approved vendors, cloud platforms, consultants, or service providers.

The specific safeguards applied to a project may depend on the type and sensitivity of the data, applicable law, client requirements, contractual obligations, and the systems involved.

3. Data Governance Principles

Momentum Data Solutions follows several core data-governance principles.

Authorized and Purpose-Limited Processing: We process client data only for legitimate business purposes, authorized services, documented project requirements, or other purposes permitted by the client agreement or applicable law. Client data is not used for unrelated purposes.

Data Minimization: We seek to collect, access, transfer, and retain only the information reasonably necessary to perform the requested services. When practical, unnecessary fields, records, identifiers, or duplicate data are excluded from the project.

Accuracy and Data Quality: We use reasonable validation, reconciliation, and quality-control procedures to identify incomplete records, invalid formats, duplicate information, inconsistent values, mapping errors, or other data-quality concerns. Because clients remain responsible for the accuracy of their source information and business rules, identified discrepancies may require client review and approval.

Least-Privilege Access: Access to data is limited to authorized individuals, systems, and service providers that reasonably require access to perform an approved business function. Access may be restricted according to role, project, client account, system, data classification, and level of sensitivity.

Accountability and Traceability: When appropriate to the engagement, Momentum Data Solutions may maintain processing records, change histories, validation results, workflow logs, mapping documentation, or audit information to support accountability and traceability.

Secure Data Lifecycle Management: Security and governance considerations are applied throughout the data lifecycle, including collection, transfer, staging, processing, validation, storage, delivery, retention, archival, and disposal.

4. Data Categories

The information handled by Momentum Data Solutions may include the following categories.

Business and Operational Data: This may include system records, reports, files, account information, project documentation, workflow data, configuration information, and other operational records supplied by a client.

Personal Data: Personal data may include information that identifies, relates to, describes, or can reasonably be linked to an individual. Depending on the project, this may include names, contact information, employment information, identification numbers, account information, or other individual-level records.

Sensitive Personal Data: Sensitive data receive additional protections based on the nature, the risks associated with unauthorized access, applicable law, and contractual requirements. Sensitive information may include government identification numbers, financial account information, health information, precise geolocation information, authentication credentials, or other protected data.

Healthcare Information: Healthcare-related projects may involve protected health information (PHI) and electronic protected health information (ePHI). HIPAA applies only when the entities, information, and services involved meet the applicable legal definitions. When Momentum Data Solutions performs services as a business associate or subcontractor business associate, the engagement must be governed by an appropriate written agreement, such as a Business Associate Agreement, before regulated PHI is processed. The HIPAA Security Rule requires regulated entities to use appropriate administrative, physical, and technical safeguards to protect ePHI.

Financial, Tax, and Payment Information: Financial or tax-related data may include payroll information, banking information, account records, transaction data, tax documents, consumer-report information, or payment-related records. Where applicable, additional requirements may arise under laws or standards such as the Gramm-Leach-Bliley Act, the FTC Safeguards Rule, the Fair Credit Reporting Act, Regulation S-P, the Payment Card Industry Data Security Standard, or other regulatory requirements. The FTC Safeguards Rule requires covered financial institutions to maintain an information-security program appropriate to their size, activities, and the sensitivity of the customer information involved. Momentum Data Solutions does not represent that every service is automatically governed by these requirements; applicability must be evaluated based on the client, project, data, contractual relationship, and legal circumstances. Federal Tax Information obtained from the Internal Revenue Service or qualifying secondary sources is subject to specialized restrictions — Momentum Data Solutions will not accept or process regulated Federal Tax Information unless the project's legal authority, contractual requirements, and required security controls have been reviewed and approved. IRS Publication 1075 primarily establishes safeguards for federal, state, and local agencies and authorized recipients of Federal Tax Information.

5. ETL and Data-Processing Controls

Momentum Data Solutions uses structured procedures when extracting, transforming, and loading data. Depending on the project, these procedures may include:

  • Confirming the authorized source and destination systems
  • Documenting data requirements and approved business rules
  • Identifying required and optional data fields
  • Developing source-to-target data mappings
  • Using secure transfer methods
  • Separating temporary staging data from final deliverables when appropriate
  • Standardizing dates, names, identifiers, values, and file formats
  • Removing unnecessary duplicate records
  • Validating required fields and record counts
  • Reconciling source and destination totals
  • Recording transformation rules and exceptions
  • Restricting unauthorized changes to source data
  • Testing outputs before production use
  • Obtaining client approval at defined project checkpoints
  • Securely disposing of temporary data when it is no longer required

Production data should not be placed in unsecured development, demonstration, or testing environments. When testing requires realistic information, minimized, masked, synthetic, or de-identified data should be used when reasonably practical.

6. Security Safeguards

Momentum Data Solutions uses administrative, technical, and organizational safeguards appropriate to the nature of its operations and the sensitivity of the information involved. These safeguards may include:

  • Role-based or need-to-know access restrictions
  • Multi-factor authentication where supported and appropriate
  • Strong authentication and credential-management practices
  • Encryption or protected transmission methods where appropriate
  • Secure file-transfer procedures
  • Access logging and activity monitoring
  • Endpoint and account protection
  • Software-update and vulnerability-management procedures
  • Backup and recovery measures
  • Secure configuration of systems and integrations
  • Vendor and service-provider reviews
  • Confidentiality obligations
  • Workforce security awareness
  • Incident identification and escalation procedures
  • Secure retention and disposal practices

Our governance approach is informed by recognized risk-management concepts, including the NIST Cybersecurity Framework's Govern, Identify, Protect, Detect, Respond, and Recover functions.

No method of electronic transmission, storage, or processing can be guaranteed to eliminate every security risk. Momentum Data Solutions therefore uses a risk-based approach and reviews its safeguards as technologies, threats, services, and legal obligations evolve.

7. Access Management

Access to client information is granted according to business need and may be modified or removed when:

  • A project or assigned responsibility ends
  • An individual no longer requires access
  • A user changes roles
  • A client requests an authorized access change
  • A security concern is identified
  • An agreement is suspended or terminated

Credentials must not be knowingly shared with unauthorized individuals. Clients should provide individual accounts or approved service credentials whenever supported by the applicable platform. Access to highly sensitive information may require additional authorization, contractual documentation, or security controls.

8. APIs, Connectors, Webhooks, and Integrations

Momentum Data Solutions may use APIs, connectors, secure exports, managed file transfers, and webhook-enabled workflows to move information between authorized systems. Integration credentials, tokens, keys, secrets, and configuration information should be:

  • Used only for the approved integration
  • Limited to the permissions reasonably required
  • Stored through appropriate credential-management methods
  • Protected from public exposure
  • Reviewed when access requirements change
  • Revoked or rotated when a project ends, access changes, or compromise is suspected

We will not intentionally connect to, extract from, or transmit data to a system without client authorization or another valid legal basis. Clients are responsible for confirming that they have the authority to provide system access and direct the processing of the affected data.

9. Consumer Privacy Requests

When Momentum Data Solutions acts as a business that determines the purposes and means of processing personal data, individuals may have rights under applicable privacy law. Depending on the law and circumstances, those rights may include requesting:

  • Confirmation of whether personal data is being processed
  • Access to certain personal data
  • Correction of inaccurate personal data
  • Deletion of personal data
  • A portable copy of personal data
  • Opt-out from certain sales, targeted advertising, or profiling activities
  • An appeal of a decision concerning a privacy request

The Texas Data Privacy and Security Act grants qualifying Texas residents rights that include access, correction, deletion, portability, and certain opt-out rights.

When Momentum Data Solutions processes personal data solely on behalf of a client, the client may be the party responsible for responding to the individual's request. In those circumstances, we may refer the request to the appropriate client or assist the client as required by our agreement and applicable law. We may need to verify the identity and authority of the person submitting a request before taking action.

10. Healthcare Data and Business Associate Agreements

Momentum Data Solutions will only process PHI or ePHI under terms appropriate to the relationship and services involved. When a Business Associate Agreement is required, it should identify:

  • Permitted and required uses of PHI
  • Restrictions on further use or disclosure
  • Required security safeguards
  • Incident and breach-reporting responsibilities
  • Subcontractor requirements
  • Return or destruction requirements
  • Cooperation with individual-rights requests
  • Responsibilities when the engagement ends

HHS guidance provides that covered entities and business associates generally must enter into written agreements requiring appropriate safeguards when a business associate creates, receives, maintains, or transmits PHI on behalf of a covered entity. Momentum Data Solutions does not describe a service as “HIPAA compliant” merely because it can technically process health-related information. HIPAA applicability and readiness must be evaluated for the specific service, environment, contract, vendors, and data involved.

11. Financial and Payment Data

Momentum Data Solutions seeks to eliminate unnecessary exposure to financial account and payment-card information. Unless specifically required by an approved project:

  • Complete payment-card information should not be submitted through ordinary website forms or email
  • Financial credentials should not be shared through unsecured communication methods
  • Access should be limited to authorized personnel and systems
  • Data should be minimized to the fields required for the project
  • Temporary copies should be securely removed when no longer required

Projects involving payment-card information may require additional controls under the current Payment Card Industry Data Security Standard. The PCI Security Standards Council currently identifies PCI DSS version 4.0.1 in its standards library. Momentum Data Solutions does not claim PCI DSS validation unless a formal assessment or validation applicable to the relevant environment has been completed.

12. Vendors and Service Providers

Momentum Data Solutions may use cloud platforms, software providers, hosting companies, consultants, contractors, or other vendors to support its services. Before providing a vendor with access to sensitive client data, we may consider:

  • The services being performed
  • The nature and sensitivity of the data
  • The vendor's access requirements
  • Available security and privacy documentation
  • Contractual confidentiality and data-protection terms
  • Incident-notification responsibilities
  • Data location and subcontractor arrangements
  • Data-return and deletion capabilities
  • The client's requirements

Vendors should receive only the access and information reasonably necessary to perform their approved function.

13. Data Retention and Disposal

Momentum Data Solutions retains data only for as long as reasonably necessary to provide contracted services, complete validation and project closeout, meet legal/accounting/audit/compliance requirements, resolve disputes, enforce agreements, or support another documented business need.

Retention periods may be established by the client agreement, project requirements, applicable law, or the type of information involved. When information is no longer required, it may be deleted, destroyed, anonymized, returned to the client, or otherwise removed using methods appropriate to the format, system, and sensitivity of the data. Certain backup copies may remain for a limited period until they are overwritten or removed through routine backup-management processes.

14. Security Incident Response

Momentum Data Solutions maintains procedures for evaluating suspected unauthorized access, disclosure, loss, alteration, destruction, or misuse of information. Depending on the circumstances, our response may include:

  • Identifying and documenting the suspected incident
  • Containing affected accounts, systems, integrations, or workflows
  • Preserving relevant records and evidence
  • Assessing the nature and scope of the incident
  • Determining the data and parties potentially affected
  • Correcting vulnerabilities or control failures
  • Coordinating with clients, vendors, legal counsel, insurers, or authorities
  • Providing legally or contractually required notifications
  • Restoring affected services or data
  • Reviewing the event for corrective actions and process improvements

Clients will be notified of confirmed incidents involving their data as required by applicable agreements and law. Texas requires qualifying breaches affecting at least 250 Texas residents to be reported to the Office of the Attorney General as soon as practicable and no later than 30 days after discovery. Other notification obligations may apply depending on the location of affected individuals, the information involved, the client's industry, and the circumstances of the incident.

15. Client Responsibilities

Effective data security is a shared responsibility. Clients are responsible for:

  • Providing accurate project requirements and business rules
  • Confirming their authority to disclose and direct the processing of data
  • Identifying regulated or highly sensitive information before transfer
  • Using approved transfer and communication methods
  • Maintaining the security of their own systems and accounts
  • Reviewing and approving data mappings and transformed outputs
  • Managing access within client-controlled systems
  • Promptly reporting suspected credential or security incidents
  • Maintaining required notices, consents, contracts, and legal authority
  • Determining whether the final output is suitable for production, reporting, payroll, compliance, or other operational use

16. Policy Governance and Review

Momentum Data Solutions may periodically review this policy to account for changes to our services or technology; new integrations, vendors, or processing activities; changes in applicable laws or contractual obligations; identified security risks; lessons learned from incidents or testing; and changes in industry practices. Material revisions will be reflected by updating the “Last Updated” date shown at the beginning of this policy.

17. Contact Us

Questions concerning this Data Security & Governance Policy, security practices, or privacy requests may be submitted to:

Momentum Data Solutions
Email: compliance@momentumdatasolutions.com
Website: momentumdatasolutions.com