Data Retention Policy

Last Updated: November 15, 2024

1. Introduction & Purpose

At That Is A Q, we take data privacy and security seriously. This Data Retention Policy outlines how long we keep different types of information, why we retain it, and how it is securely managed and eventually disposed of. We are committed to collecting only what is necessary and retaining it only for as long as required to fulfill legal, operational, and business obligations.

2. How We Collect & Store Data

We collect and process data solely for the purpose of delivering our services, maintaining secure client communications, complying with applicable laws, and improving our platform. All data is stored on encrypted, access-controlled infrastructure hosted in certified secure data centers.

  • Client project files and communications are stored in encrypted workspaces.
  • User account data is retained only while the account is active or as required by law.
  • System logs, analytics, and security metadata are anonymized where possible.

3. Data Retention Schedule

The following table outlines our standard retention periods for different data categories. Where legal obligations require longer retention, we will comply accordingly.

Data Category Purpose Retention Period
Client Contracts & Invoices Financial & legal compliance 7 years
Project Files & Deliverables Service fulfillment & support 3 years post-engagement
User Account Information Platform access & authentication Inactive: 12 months, then archived
Communication Logs (Email/Chat) Operational support & record-keeping 2 years
System & Security Logs Threat detection & audit trails 6 months (anonymized after)
Marketing Consent Data Newsletter & campaign communications Until unsubscribe or 24 months of inactivity

4. Data Deletion & User Rights

You have the right to request access to, correction of, or deletion of your personal data at any time. Upon request, and subject to legal retention obligations, we will securely erase your data from our active systems within 30 business days. Archived data retained for legal compliance will be logically isolated and excluded from routine processing.

How to submit a request: Send a detailed request to our Data Protection Officer at dpo@thatisaq.com with subject line "Data Retention Request". We will verify your identity and process your request promptly.

5. Legal & Compliance Obligations

Certain data may be retained beyond standard periods to comply with tax laws, intellectual property regulations, litigation holds, or industry-specific mandates. In such cases, data will be stored in restricted, encrypted archives with strictly limited access. We regularly review our retention schedules with legal counsel to ensure alignment with evolving regulations including GDPR, CCPA, and ISO 27001 standards.

6. Secure Disposal

When data reaches the end of its retention period and is no longer legally required, it is permanently deleted using industry-standard secure erasure protocols. Physical media is destroyed, and digital storage is cryptographically wiped. Third-party vendors processing data on our behalf are contractually bound to follow identical disposal standards.

Questions About Our Data Practices?

We believe in transparency. If you need clarification on how your data is handled or wish to exercise your rights, our compliance team is here to help.

Contact Data Protection Team →