esc

Type at least two characters.

    Export
    PrintView as Markdown

    Data Management And Retention Policy

    How Copperlane classifies, retains, maintains, and securely disposes of information.

    1. Purpose And Scope

    This policy explains how Copperlane manages information throughout its lifecycle, from creation or receipt through retention and deletion.

    It applies to all employees, contractors, and third parties who can access Copperlane information, regardless of its format or storage location.

    2. Data Classification And Labeling

    Copperlane classifies information by sensitivity so that each type receives the correct handling and retention controls.

    Classification Description Examples Handling Requirements
    Public Information intended for public release. Disclosure creates no expected harm. Press releases, public website content, marketing material, and annual reports Copperlane can share this information internally and externally. It must be reviewed for accuracy before publication.
    Internal Information intended for use within Copperlane. Disclosure could cause limited harm. Internal messages, employee directories, policies, procedures, and project schedules Share only within Copperlane. Encrypt it when transmitting it externally. Use caution in public places and dispose of it securely.
    Confidential Sensitive information that requires protection. Disclosure could cause moderate or substantial harm. Customer data, financial records, contracts, and intellectual property Share only when a person needs it for their work. Encrypt it at rest and in transit. Apply strong access controls and contractual protections. Dispose of it securely.
    Secret Highly sensitive information. Disclosure could cause severe harm. Passwords, encryption keys, acquisition plans, and trade secrets Apply the strictest access controls, encryption, audit logging, and access monitoring. Do not store it on mobile devices. Use certified destruction methods.

    3. Data Inventory

    Copperlane maintains an inventory of the structured and unstructured information it processes. The inventory includes:

    • the data type
    • the owner or custodian
    • the storage location
    • the format
    • the sensitivity classification
    • the retention period and disposal requirements

    Copperlane reviews the inventory regularly. New data sources and material changes must be added promptly.

    4. Data Flow Mapping

    Copperlane maintains maps that show how information moves within the company and to third parties. It updates these maps when processes, systems, or third-party relationships change.

    5. Retention Periods

    Copperlane retains information only for as long as needed for the purpose for which it was collected, or as required by legal, regulatory, or contractual obligations.

    The following default periods apply unless business, legal, regulatory, or contractual needs require a different period:

    Data Type Default Retention Period
    Financial records Seven years
    Customer data For the customer relationship, plus at least 30 days to allow the customer to restore an account to good standing
    Personal information For the period required by applicable privacy law, or until the purpose for collection is complete
    Intellectual property For the period of legal protection, or until Copperlane no longer needs it
    Security logs At least one year and not more than five years
    Backup data One year, followed by secure deletion or overwrite

    A litigation hold or regulatory investigation can extend a retention period.

    6. Disposal And Deletion

    Copperlane securely deletes or anonymizes information that it no longer needs. Physical records must be shredded. Electronic records must be permanently erased with secure destruction methods.

    Backup data must be deleted after its retention period, or when it is no longer needed for recovery, in accordance with Copperlane's backup controls.

    Copperlane manages information in accordance with applicable legal, regulatory, and contractual requirements. These requirements can include the General Data Protection Regulation, the California Consumer Privacy Act, and other applicable privacy laws.

    Copperlane maintains a process for applicable data-subject requests, including access, correction, and deletion requests.

    8. Data Minimization And Accuracy

    Copperlane collects and retains only the information needed for a business purpose. It takes reasonable steps to keep that information accurate, relevant, and current.

    9. Breach Notification

    Copperlane maintains a process to identify, report, and respond to data breaches. It notifies affected parties and authorities within the time required by applicable law and contract. See the Information Security Policy for security incident response controls.

    10. Compliance And Exceptions

    Employees, contractors, and third parties with access to Copperlane information must comply with this policy. Non-compliance can result in disciplinary action, including termination.

    Management must approve exceptions that are necessary because of a business need, local law, or regulation. An approved exception must include alternative controls.

    11. Review

    Copperlane reviews this policy annually and after a material change. Each review considers changes to applicable laws and regulations.

    Version Last Review Date Next Review Date Reviewed By Approved By
    1.0 May 12, 2026 May 12, 2027 Brianna Lin Brianna Lin