Data Retention Policy

Last updated: November 14, 2025

Overview

At That Is A Q, we are committed to handling your personal and project data responsibly. This Data Retention Policy outlines how long we keep different types of information, why we retain it, and the measures we take to secure and eventually dispose of it. Our practices align with applicable data protection regulations, including GDPR, CCPA, and industry best standards.

We only retain data for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce agreements.

What Data We Collect

We collect and process data primarily to deliver our services, maintain secure client relationships, and improve our platform. This includes:

  • Account Information: Name, email, company details, and authentication credentials.
  • Project Data: Files, designs, code repositories, specifications, and collaboration logs.
  • Communication Records: Support tickets, email correspondence, and meeting notes.
  • Technical Data: IP addresses, device identifiers, usage analytics, and security logs.
  • Billing Information: Invoice records, payment references, and tax documentation (processed securely via PCI-compliant providers).

Retention Periods

Each category of data has a defined retention schedule. Once the period expires, data is securely anonymized or permanently deleted unless a legal hold applies.

Data Category Retention Period Reason for Retention
Account & Profile Data Duration of service + 24 months Service continuity, support, re-onboarding
Project Files & Repositories Duration of engagement + 12 months Delivery verification, warranty, reference
Support & Communications Duration of ticket + 24 months Quality assurance, dispute resolution
Usage & Analytics Logs 12 months Performance optimization, security monitoring
Billing & Financial Records 7 years Tax compliance, audit requirements
Security & Access Logs 6–12 months Threat detection, forensic investigation

If a project requires extended archival for regulatory or enterprise compliance, we can arrange secure cold storage with explicit consent and separate agreements.

Why We Retain Data

Data retention is never arbitrary. We maintain information to:

  • Fulfill contractual obligations and deliver ongoing services
  • Ensure platform security, stability, and performance
  • Comply with legal, tax, and regulatory requirements
  • Resolve disputes, prevent fraud, and enforce terms of service
  • Provide accurate support and historical context for client accounts

Security & Storage

All retained data is protected using industry-standard safeguards:

  • Encryption: AES-256 at rest and TLS 1.3 in transit
  • Access Controls: Role-based permissions, MFA, and least-privilege principles
  • Infrastructure: Hosted on audited cloud providers (AWS/GCP) with regular penetration testing
  • Backups: Geographically distributed, encrypted, and isolated from primary systems
  • Deletion Process: Cryptographic erasure and secure overwrite protocols for storage media

Your Rights & Controls

Depending on your jurisdiction, you may have the right to:

  • Access, export, or request a copy of your data
  • Rectify inaccurate or incomplete information
  • Request restriction or deletion of personal data
  • Object to certain processing activities
  • Withdraw consent where processing is consent-based

Our team will respond to valid requests within 30 days, or sooner where feasible. Deletion requests are processed in accordance with retention schedules and legal holds.

How to Submit a Request

To exercise your data rights, report a concern, or request manual data deletion outside standard schedules, contact our Data Protection Officer:

  • Email: dpo@thatisaq.com
  • Subject Line Format: [Data Request] – [Your Name/Company]
  • Verification: For security, we may request proof of identity or authorization before processing sensitive requests.

We take data privacy seriously. If you believe we have handled your information in a way that breaches applicable laws, you have the right to lodge a complaint with your local data protection authority.