Data Retention Policy
1. Introduction & Purpose
At That Is A Q, we take data privacy and security seriously. This Data Retention Policy outlines how long we keep different types of information, why we retain it, and how it is securely managed and eventually disposed of. We are committed to collecting only what is necessary and retaining it only for as long as required to fulfill legal, operational, and business obligations.
2. How We Collect & Store Data
We collect and process data solely for the purpose of delivering our services, maintaining secure client communications, complying with applicable laws, and improving our platform. All data is stored on encrypted, access-controlled infrastructure hosted in certified secure data centers.
- Client project files and communications are stored in encrypted workspaces.
- User account data is retained only while the account is active or as required by law.
- System logs, analytics, and security metadata are anonymized where possible.
3. Data Retention Schedule
The following table outlines our standard retention periods for different data categories. Where legal obligations require longer retention, we will comply accordingly.
| Data Category | Purpose | Retention Period |
|---|---|---|
| Client Contracts & Invoices | Financial & legal compliance | 7 years |
| Project Files & Deliverables | Service fulfillment & support | 3 years post-engagement |
| User Account Information | Platform access & authentication | Inactive: 12 months, then archived |
| Communication Logs (Email/Chat) | Operational support & record-keeping | 2 years |
| System & Security Logs | Threat detection & audit trails | 6 months (anonymized after) |
| Marketing Consent Data | Newsletter & campaign communications | Until unsubscribe or 24 months of inactivity |
4. Data Deletion & User Rights
You have the right to request access to, correction of, or deletion of your personal data at any time. Upon request, and subject to legal retention obligations, we will securely erase your data from our active systems within 30 business days. Archived data retained for legal compliance will be logically isolated and excluded from routine processing.
How to submit a request: Send a detailed request to our Data Protection Officer at dpo@thatisaq.com with subject line "Data Retention Request". We will verify your identity and process your request promptly.
5. Legal & Compliance Obligations
Certain data may be retained beyond standard periods to comply with tax laws, intellectual property regulations, litigation holds, or industry-specific mandates. In such cases, data will be stored in restricted, encrypted archives with strictly limited access. We regularly review our retention schedules with legal counsel to ensure alignment with evolving regulations including GDPR, CCPA, and ISO 27001 standards.
6. Secure Disposal
When data reaches the end of its retention period and is no longer legally required, it is permanently deleted using industry-standard secure erasure protocols. Physical media is destroyed, and digital storage is cryptographically wiped. Third-party vendors processing data on our behalf are contractually bound to follow identical disposal standards.
Questions About Our Data Practices?
We believe in transparency. If you need clarification on how your data is handled or wish to exercise your rights, our compliance team is here to help.
Contact Data Protection Team →