Data Retention & Deletion Policy

📅 Last Updated: January 15, 2026 🏢 Applies to: All Aevum Zenth Subsidiaries 🔒 Governance: Privacy & Data Protection Office

1. Overview

Aevum Zenth Conglomerate is committed to responsible data stewardship. This policy outlines how we collect, store, retain, and securely delete personal and operational data across our 400+ subsidiaries. We balance business necessity, legal obligations, and individual privacy rights through automated lifecycle management and transparent user controls.

⚠️ Important Notice

Data retention practices may vary slightly by division due to industry-specific regulations (e.g., healthcare, finance, aerospace). This policy establishes the corporate baseline; subsidiary-specific addendums apply where legally required.

2. Scope & Applicability

This policy applies to all personal data, transactional records, system logs, and analytics collected by Aevum Zenth entities, including but not limited to:

  • Digital platforms, mobile applications, and enterprise SaaS products
  • Customer relationship management (CRM) and billing systems
  • Human resources, payroll, and contractor management records
  • Network infrastructure, IoT telemetry, and operational telemetry

3. Data Categories Collected

CategoryExamplesCollection Purpose
Personal IdentifiersName, email, phone, government IDsAccount creation, verification, communication
Financial & TransactionalPayment methods, invoices, contract termsBilling, auditing, tax compliance
Technical & UsageIP addresses, device IDs, cookies, logsSecurity, analytics, service optimization
Healthcare & BiometricMedical records, consent forms, device telemetryTelehealth, clinical trials, wellness platforms
Employment & HRResumes, performance reviews, payroll dataRecruitment, compliance, benefits administration

4. Retention Periods

Data is retained only as long as necessary to fulfill the purpose for which it was collected, comply with legal obligations, or resolve disputes. Our automated data lifecycle engine enforces the following baseline schedules:

Data TypeRetention PeriodDisposition Method
Customer Account DataActive + 24 months post-closureSecure deletion or anonymization
Financial & Tax Records7 years (or as required by jurisdiction)Archival storage → Secure destruction
System & Security Logs12 months (active), 36 months (archive)Cryptographic shredding
Marketing & Preference DataUntil opt-out or 36 months of inactivityImmediate suppression → Purge
Employment RecordsDuration of employment + 5 yearsSecure archival → Destruction
Healthcare / PHI10 years (or per HIPAA/regional law)Encrypted archival → Certified destruction

Retention clocks begin when the data is no longer actively required for its original purpose. Automated purge jobs run daily across all cloud and on-premise storage tiers.

5. Deletion Process & User Rights

Under applicable privacy frameworks, you hold enforceable rights over your data. Aevum Zenth supports the following mechanisms:

  • Right to Erasure: Request permanent deletion of your personal data. We will process verified requests within 30 calendar days.
  • Right to Portability: Export your data in machine-readable formats (JSON, CSV, or PDF).
  • Right to Rectification: Update or correct inaccurate or outdated information.
  • Right to Object: Opt out of automated processing, profiling, or direct marketing at any time.

🗑️ How Deletion Works

When deletion is confirmed, data is removed from active databases, backups are flagged for exclusion from restore operations, and encryption keys are rotated where applicable. Anonymized aggregates may be retained for research and compliance purposes, as they cannot be used to identify you.

6. Legal Exceptions & Holds

Data deletion may be delayed or restricted when required by law, litigation holds, regulatory investigations, or internal fraud/abuse inquiries. In such cases:

  • Affected records are isolated from standard purge cycles
  • Legal and compliance teams are notified within 48 hours
  • Hold durations are tracked and automatically released upon case closure
  • You will be informed of any applicable limitations, subject to legal privilege

7. Regulatory Compliance

Aevum Zenth maintains active compliance programs aligned with:

  • GDPR (EU/EEA) & UK GDPR
  • CCPA / CPRA (California)
  • HIPAA & HITECH (Healthcare Division)
  • SOX & SEC regulations (Financial Services)
  • PIPEDA (Canada), LGPD (Brazil), PDPA (Singapore/APAC)

Cross-border data transfers utilize Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), and regional data localization architectures where mandated.

8. How to Submit a Request

To exercise your data rights, please use one of the following verified channels:

  1. Privacy Portal: privacy.aevumzenth.com/request (Recommended, fastest processing)
  2. Email: datarequests@aevumzenth.com
  3. In-App: Account Settings → Privacy & Data → Manage My Data
  4. Phone: +1-800-AEVUM-PRIV (1-800-238-8677) • Mon-Fri, 09:00-18:00 EST

For verification, we may request government-issued ID, account credentials, or recent transaction references. Processing times: ≤ 30 days (extendable by 60 days for complex requests, with notification).

9. Contact & Support

Questions about this policy, data handling practices, or your rights? Our Data Protection Office is available to assist.

🔒 Aevum Zenth Privacy Team

📧
Global DPO dpo@aevumzenth.com
📍
Headquarters Zenth Tower, Neo Geneva, Switzerland
🌐
Privacy Center privacy.aevumzenth.com
📞
Secure Line +41 22 Zenth PRIV