Data Security & Retention Policy
1. Introduction
Aevum News is committed to protecting the confidentiality, integrity, and availability of your personal and usage data. This policy outlines the technical and organizational measures we implement to safeguard your information, as well as our data retention, processing, and deletion practices.
2. Security Infrastructure
Our digital infrastructure is engineered to prevent unauthorized access, data breaches, and service disruptions. Key security controls include:
- Zero-Trust Architecture: All internal and external access requires multi-factor authentication and continuous identity verification.
- Network Segmentation: Production databases, user endpoints, and editorial systems operate in isolated environments with strict firewall rules.
- Intrusion Detection & Monitoring: 24/7 automated threat detection, log analysis, and automated incident response protocols.
- Access Controls: Role-based access control (RBAC) with principle of least privilege. Administrative access requires dual-approval workflows.
3. Encryption & Protection
All sensitive data is encrypted both in transit and at rest using industry-standard cryptographic protocols:
| Data State | Encryption Standard | Key Management |
|---|---|---|
| In Transit | TLS 1.3 / HTTPS | Automated certificate rotation (Let's Encrypt / DigiCert) |
| At Rest | AES-256-GCM | HSM-backed keys, separated from data storage |
| Backups | AES-256 + Hash Verification | Geo-redundant, immutable storage with 30-day versioning |
4. Data Retention Schedule
We retain personal and usage data only for as long as necessary to fulfill the purposes outlined in our Privacy Policy, comply with legal obligations, and resolve disputes. Retention periods are strictly enforced via automated lifecycle management:
| Data Category | Retention Period | Storage Location |
|---|---|---|
| Account & Profile Data | Duration of account + 12 months | Primary EU/US Cloud Regions |
| Subscription & Payment Records | 7 years (tax/legal compliance) | Encrypted financial ledger |
| Reading History & Preferences | 24 months of activity | Analytics cluster (aggregated after 6 months) |
| Server & Security Logs | 90 days | SIEM platform (read-only access) |
| Customer Support Tickets | 3 years | Secure helpdesk database |
5. Data Deletion & Anonymization
When data reaches the end of its retention period, or upon valid user request, it undergoes one of the following processes:
- Secure Deletion: Overwritten using cryptographic erasure standards (NIST SP 800-88 Rev. 1). Database records are permanently purged, and backup copies are marked for exclusion during the next restoration cycle.
- Anonymization: Where legally permissible, data may be transformed into anonymized datasets for editorial analytics, trend reporting, or system optimization. Re-identification is technically and procedurally prevented.
- Archival Exceptions: Data subject to legal holds, ongoing investigations, or regulatory requirements is segregated and retained until the obligation expires.
6. User Rights & Controls
Under GDPR, CCPA, and equivalent frameworks, you have the following rights regarding your data:
- Access & Portability: Request a complete export of your personal data in machine-readable formats (JSON/CSV).
- Correction: Update or rectify inaccurate profile, contact, or preference data at any time via your account dashboard.
- Deletion: Submit a "Right to be Forgotten" request. Processing occurs within 30 calendar days.
- Opt-Out: Disable personalized content recommendations, analytics tracking, and promotional communications.
- Restriction: Request temporary suspension of processing while disputes or verification is underway.
7. Compliance & Audits
Aevum News maintains compliance with global data protection standards through continuous governance:
- Annual third-party penetration testing and vulnerability assessments
- ISO 27001 certification for information security management
- GDPR, CCPA/CPRA, and PECR compliance mapping
- Data Protection Impact Assessments (DPIAs) for all new features
- Vendor risk management and binding data processing agreements (DPAs)
Our compliance reports are reviewed quarterly by an independent data governance board. Summary findings are published annually in our Transparency Report.
8. Contact & Support
For questions regarding this policy, data requests, or security concerns, please reach out to our dedicated Data Protection team:
Data Protection Officer
Email: dpo@aevumnews.com
Security Hotline: security@aevumnews.com
Response Time: Within 2 business days for inquiries, 30 days for data requests