1. Purpose And Scope
This policy explains how Copperlane manages information throughout its lifecycle, from creation or receipt through retention and deletion.
It applies to all employees, contractors, and third parties who can access Copperlane information, regardless of its format or storage location.
2. Data Classification And Labeling
Copperlane classifies information by sensitivity so that each type receives the correct handling and retention controls.
| Classification | Description | Examples | Handling Requirements |
|---|---|---|---|
| Public | Information intended for public release. Disclosure creates no expected harm. | Press releases, public website content, marketing material, and annual reports | Copperlane can share this information internally and externally. It must be reviewed for accuracy before publication. |
| Internal | Information intended for use within Copperlane. Disclosure could cause limited harm. | Internal messages, employee directories, policies, procedures, and project schedules | Share only within Copperlane. Encrypt it when transmitting it externally. Use caution in public places and dispose of it securely. |
| Confidential | Sensitive information that requires protection. Disclosure could cause moderate or substantial harm. | Customer data, financial records, contracts, and intellectual property | Share only when a person needs it for their work. Encrypt it at rest and in transit. Apply strong access controls and contractual protections. Dispose of it securely. |
| Secret | Highly sensitive information. Disclosure could cause severe harm. | Passwords, encryption keys, acquisition plans, and trade secrets | Apply the strictest access controls, encryption, audit logging, and access monitoring. Do not store it on mobile devices. Use certified destruction methods. |
3. Data Inventory
Copperlane maintains an inventory of the structured and unstructured information it processes. The inventory includes:
- the data type
- the owner or custodian
- the storage location
- the format
- the sensitivity classification
- the retention period and disposal requirements
Copperlane reviews the inventory regularly. New data sources and material changes must be added promptly.
4. Data Flow Mapping
Copperlane maintains maps that show how information moves within the company and to third parties. It updates these maps when processes, systems, or third-party relationships change.
5. Retention Periods
Copperlane retains information only for as long as needed for the purpose for which it was collected, or as required by legal, regulatory, or contractual obligations.
The following default periods apply unless business, legal, regulatory, or contractual needs require a different period:
| Data Type | Default Retention Period |
|---|---|
| Financial records | Seven years |
| Customer data | For the customer relationship, plus at least 30 days to allow the customer to restore an account to good standing |
| Personal information | For the period required by applicable privacy law, or until the purpose for collection is complete |
| Intellectual property | For the period of legal protection, or until Copperlane no longer needs it |
| Security logs | At least one year and not more than five years |
| Backup data | One year, followed by secure deletion or overwrite |
A litigation hold or regulatory investigation can extend a retention period.
6. Disposal And Deletion
Copperlane securely deletes or anonymizes information that it no longer needs. Physical records must be shredded. Electronic records must be permanently erased with secure destruction methods.
Backup data must be deleted after its retention period, or when it is no longer needed for recovery, in accordance with Copperlane's backup controls.
7. Legal And Regulatory Compliance
Copperlane manages information in accordance with applicable legal, regulatory, and contractual requirements. These requirements can include the General Data Protection Regulation, the California Consumer Privacy Act, and other applicable privacy laws.
Copperlane maintains a process for applicable data-subject requests, including access, correction, and deletion requests.
8. Data Minimization And Accuracy
Copperlane collects and retains only the information needed for a business purpose. It takes reasonable steps to keep that information accurate, relevant, and current.
9. Breach Notification
Copperlane maintains a process to identify, report, and respond to data breaches. It notifies affected parties and authorities within the time required by applicable law and contract. See the Information Security Policy for security incident response controls.
10. Compliance And Exceptions
Employees, contractors, and third parties with access to Copperlane information must comply with this policy. Non-compliance can result in disciplinary action, including termination.
Management must approve exceptions that are necessary because of a business need, local law, or regulation. An approved exception must include alternative controls.
11. Review
Copperlane reviews this policy annually and after a material change. Each review considers changes to applicable laws and regulations.
| Version | Last Review Date | Next Review Date | Reviewed By | Approved By |
|---|---|---|---|---|
| 1.0 | May 12, 2026 | May 12, 2027 | Brianna Lin | Brianna Lin |