Effective Date: January 4, 2026 | Last Updated: January 4, 2026 | Version: 1.0
This Data Retention and Disposal Policy establishes guidelines for the retention, archival, and secure disposal of data collected and processed by Iris Secure Financial. This policy ensures compliance with legal obligations, supports business operations, and protects customer privacy.
Policy Owner:
This policy applies to:
Retention Requirements:
| Data Category | Retention Period | Disposal Method |
|---|---|---|
| Financial Transactions | 7 years | Secure database deletion |
| Invoices | 7 years | Secure database deletion |
| Active User Accounts | Duration of activity | N/A |
| Closed User Accounts | 90 days | Secure deletion |
| Plaid Access Tokens | Active connection + 30 days | Token invalidation + deletion |
| System Logs | 90 days | Automated purge |
| Database Backups | 30-365 days (rotating) | Secure overwrite |
| Deleted User Data | 30-day grace period | Permanent deletion |
Retention Period: 7 years from transaction date
Rationale: IRS audit period requirements (3-7 years), business audit and dispute resolution needs, customer access to historical financial data
Storage:
Exceptions: Disputed transactions retained until resolution + 7 years; ongoing legal matters subject to litigation hold
Retention Period:
Disposal:
Retention Period:
Disposal: Tokens securely overwritten and removed from database; Plaid item deleted via API when account disconnected
Request a copy of your personal data delivered in machine-readable format (JSON/CSV) within 30 days.
Request account and data deletion with a 30-day grace period before permanent deletion. Note: Financial records are retained for 7 years (anonymized) for tax compliance.
Structured data provided in machine-readable format (JSON/CSV) within 30 days.
To exercise any rights: [email protected]
Trigger Events: Litigation notice, regulatory investigation, subpoena, or court order
Process:
Breach-related logs and data retained for 3 years. Forensic evidence preserved. Incident reports maintained per policy.
Document Version: 1.0
Approval Date: January 4, 2026
Next Review Date: January 4, 2027
Approved By: Support Team