Navigate through our legal documents and policies
Last updated: 12 June 2025
This policy establishes guidelines for the retention and secure disposal of data within ThinkDeck. Our comprehensive approach ensures compliance with legal requirements while minimizing risks and maintaining necessary data for business operations.
The purpose of this Data Retention Policy is to establish guidelines for the retention and secure disposal of data within ThinkDeck. This policy aims to ensure compliance with applicable legal and regulatory requirements, minimize risks associated with holding excessive data, and ensure that necessary data is available for business operations when required.
This policy applies to all data created, received, processed, and stored by ThinkDeck, regardless of format (electronic or physical) or location. This includes data held on ThinkDeck's systems, third-party services used by ThinkDeck, and employee devices where applicable.
Any information or records, in any format, that are created, received, or maintained by ThinkDeck in the course of its operations.
Any information relating to an identified or identifiable natural person.
The defined length of time that specific categories of data must be stored before they are eligible for secure destruction.
The process of permanently deleting or destroying data in a manner that makes it irrecoverable.
Data that requires the highest level of protection from unauthorized access and disclosure (e.g., sensitive personal data, internal financial records).
Data intended for use within ThinkDeck and not generally made public, but less sensitive than Confidential Data.
Can be freely disclosed without causing harm
Minimum of 8 years after the end of the fiscal year to which the records relate.
Minimum of 10 years after the employee's termination date, or as required by local labour laws.
After end of active relationship or account closure, unless a longer period is required for legal or business purposes (e.g., transaction records). Usage data may be retained longer in an anonymized or aggregated form for analytics.
Minimum of 3 years after the expiration or termination of the agreement, or longer if required by the contract terms or legal counsel.
Generally retained for up to 2 years, unless the correspondence is part of a record requiring a longer retention period.
Records of consent to marketing are retained for as long as the individual is subscribed and for a reasonable period thereafter to demonstrate compliance. Marketing analytics data (often anonymized) may be retained longer.
Electronic Data:
Must be permanently deleted from all systems, backups, and storage media using industry-standard data-wiping software or methods that render the data unrecoverable. Simply deleting files is not sufficient.
Paper Records: Must be securely shredded or incinerated.
Documentation: A record of the destruction process should be maintained where appropriate.
Legal or regulatory requirements mandating a longer retention period.
Data subject to a legal hold, litigation, investigation, or audit.
Data required for ongoing business operations that is explicitly documented and approved.
Any exception to this policy must be documented and approved by the designated authority, Ayush Sharma (or equivalent role such as CTO or Legal Counsel).
CTO/Designated Authority
Oversees the implementation, enforcement, and compliance of this policy. Approves exceptions.
Department Heads
Responsible for ensuring that data within their respective areas is managed according to this policy and that their teams are aware of their responsibilities.
All Employees
Responsible for managing data (creating, storing, accessing, and disposing) in compliance with this policy and ThinkDeck's security guidelines.
Mandatory Compliance
Compliance with this Data Retention Policy is mandatory for all employees and contractors of ThinkDeck.
Annual Review Schedule
This Data Retention Policy will be reviewed annually or more frequently as needed.
Responsibility
The CTO / Designated Authority oversees the review and update process.
Approved by: Ayush Sharma
Compliance is mandatory for all employees and contractors