CASHFLOWARC DATA RETENTION AND SECURE DISPOSAL POLICY ===================================================== Document owner: CashFlowArc Privacy Officer / Security Owner Version: 1.0 (draft for approval) Prepared: September 2, 2026 Review cadence: At least annually and upon a material change (see section 10) 1. PURPOSE AND POLICY COMMITMENT -------------------------------- CashFlowArc retains personal information only for as long as it is reasonably necessary and proportionate for the disclosed service purpose, to meet a legal obligation, or to establish, exercise, or defend legal claims. CashFlowArc securely deletes or de-identifies personal information when the applicable retention period expires or when a verified deletion request must be honored. This is a defined and enforceable retention and disposal policy. It is designed to support compliance with privacy laws that apply to CashFlowArc and its processing activities, including the GDPR storage-limitation principle and, where applicable, the CCPA/CPRA right to delete. It does not replace a jurisdiction-specific legal review; the strictest applicable law, contract, or valid legal hold controls if it requires a longer or shorter period. 2. SCOPE -------- This policy applies to all CashFlowArc systems, personnel, contractors, service providers, backups, exports, test environments, support tools, and paper records that process CashFlowArc personal information. It covers CollectArc, BudgetArc, CashFlowArc account administration, and financial-data connections. The policy covers, among other data: * account profile, login, password-reset, email-verification, and MFA data; * linked financial account metadata, transactions, balances, categories, budgets, rules, and user-entered notes; * encrypted third-party connection tokens and provider enrollment metadata; * security, sync, webhook, and operational event records; and * support communications and privacy-rights request records. CashFlowArc does not collect bank usernames, passwords, or bank MFA secrets. Bank authentication happens in the relevant financial-data provider's hosted flow. That provider's independent retention terms still apply to data it holds. 3. RETENTION SCHEDULE --------------------- The following maximum periods apply unless a documented legal obligation, litigation hold, fraud/security investigation, or another valid exception under applicable law requires a different period. The Privacy Officer must document the exception, its basis, the data covered, owner, and re-evaluation date. Data category Retention period and disposal trigger ----------------------------------- ---------------------------------------- Active account profile and service Retain while the account is active. data (including financial data) Permanently delete from production within 30 days after verified account deletion or closure, unless an exception applies. Third-party connection tokens, Retain only while the connection is provider enrollment identifiers, active. Revoke/remove the provider and connection metadata connection where the provider supports it, then delete the local encrypted token and connection data immediately on unlink, account deletion, or expiry. Password hashes, MFA secrets, Retain only while the related account is sessions, and authentication tokens active and the credential is required. Invalidate sessions immediately on logout, password reset, or account deletion; delete credential material with the account. Email-verification and password- Store only as one-way hashes. Expire and reset tokens delete no later than 24 hours after issue, or immediately after use or replacement. Security, access, sync, and Retain for 12 months after creation, operational audit records provided they do not contain raw financial payloads, credentials, access tokens, or unnecessary sensitive data. Delete or de-identify at expiry. Privacy-rights request records Retain for 24 months after closure to demonstrate handling and prevent abuse; retain only the minimum evidence needed. Support communications Retain for 24 months after resolution, then delete or de-identify. Backups and disaster-recovery copies Encrypted backups may retain deleted data for no more than 35 days. Deleted data must be inaccessible in production immediately and removed when the backup expires; backups must not be restored as a means of reintroducing deleted data. Aggregated or irreversibly May be retained without a fixed end date de-identified information only after a documented review confirms that it cannot reasonably identify or be re-linked to an individual. 4. DELETION AND DISPOSAL REQUIREMENTS -------------------------------------- 4.1 Account deletion A verified account-deletion request must trigger deletion of the account and all user-scoped personal information from the active production database within 30 days, subject only to a documented exception. The process must include financial accounts, transactions, raw provider records, budgets, categories, rules, alerts, tags, user edits, email tokens, connection records, and MFA secrets. The user must receive a confirmation or a legally permitted explanation of any retained data. 4.2 Connection deletion When a user unlinks a financial institution, CashFlowArc must delete the associated local access token, connection, accounts, transactions, related user overlays, and sync/webhook history. CashFlowArc must also request revocation or removal from the connected provider when that capability is available. Remaining provider-held data is governed by the provider's policy and applicable law. 4.3 Secure disposal * Database data must be deleted by transactional, user-scoped deletion procedures that preserve tenant isolation and produce an auditable result. * Data in backups must expire on the defined backup schedule. A restore must reapply the deletion queue before restored data is made available. * Encryption keys and credentials that are no longer needed must be removed from the secret-management system under the applicable key-retirement process. Key destruction is a supplemental safeguard, not a substitute for deleting records when deletion is required. * Paper records, if any, must be cross-cut shredded or handled by a vetted confidential-destruction provider. Storage media must be securely erased or physically destroyed before reuse or disposal. * No employee may retain personal information in personal devices, personal email, or unapproved exports after the business purpose ends. 5. PRIVACY-RIGHTS REQUESTS -------------------------- CashFlowArc will provide a clear privacy contact method and an authenticated account workflow for access, correction, and deletion requests. A requester may also use a designated privacy email or web form. CashFlowArc will: * verify the requester to a level appropriate to the sensitivity of the request, without collecting excessive additional personal information; * acknowledge a request within 10 calendar days; * respond and, when required, complete deletion within 30 calendar days, unless applicable law permits a documented extension; and * for CCPA/CPRA-covered requests, meet the applicable 45-day response period and provide any required notice of an extension or denial. If deletion is denied or narrowed because of a legal exception, CashFlowArc will retain only the minimum data needed for that exception, isolate it from ordinary use, document the basis, and communicate the outcome as required by law. CashFlowArc will direct relevant service providers to delete applicable personal information when required. 6. TECHNICAL AND OPERATIONAL ENFORCEMENT ---------------------------------------- The following controls are mandatory for this policy to be operating and enforced: 1. Production deletion: account and connection deletion procedures must be authenticated, CSRF-protected, user-scoped, transactional, and monitored for failures. 2. Lifecycle automation: a scheduled daily retention job must identify expired tokens, stale data, queued deletion requests, and expired retention periods; it must delete or de-identify the data and record a non-sensitive completion event. 3. Backup lifecycle: backup jobs and recovery tests must prove the 35-day maximum retention period and that deleted records are not reintroduced. 4. Vendor controls: contracts or documented provider settings must require service providers to return/delete data and assist with privacy requests as required by law. 5. Evidence: CashFlowArc must retain a retention register, deletion-job results, exception/hold log, and annual review record. Evidence must not contain raw credentials, access tokens, or raw financial payloads. 6. Access control: only authorized personnel may administer retention, backup, and legal-hold controls, using least-privilege access. 7. VERIFIED APPLICATION ALIGNMENT AND REQUIRED CLOSURE ------------------------------------------------------- The current CashFlowArc source snapshot contains the following operating deletion controls: * A signed-in user can request self-service account deletion after CSRF validation and an explicit "DELETE" confirmation. The application deletes the BUDGET_USERS record and a broad set of user-scoped financial, connection, authentication, sync, and raw-provider tables, then clears the session. * A signed-in user can delete a linked institution after CSRF validation and an explicit confirmation. The application attempts provider removal for Teller and Plaid where configured, deletes the local encrypted access token with the connection, and removes associated active account, transaction, sync, webhook, and user-overlay records. The source snapshot did not demonstrate a scheduled retention-purge job, backup-expiry verification, a formal privacy-request tracker, or equivalent evidence for MX/Finicity remote-connection removal. Those controls must be implemented, tested, and evidenced before CashFlowArc represents this policy as fully enforced in production or makes a compliance certification. This policy document alone is not proof of legal compliance. 8. LEGAL HOLDS AND EXCEPTIONS ----------------------------- Upon notice of a legal hold, regulatory preservation requirement, dispute, fraud investigation, or other lawful retention basis, CashFlowArc will suspend ordinary deletion only for the minimum data and time necessary. The Privacy Officer or designated counsel must approve the hold, document its scope and expiration/review date, and release the data to the standard deletion queue when the hold ends. 9. ROLES AND ACCOUNTABILITY --------------------------- Privacy Officer / Security Owner * Owns this policy, approves exceptions, oversees requests and review, maintains the retention register, and escalates legal questions. Engineering / Operations * Implements and tests deletion, purge, backup, recovery, and provider removal controls; promptly remediates failure alerts. All personnel and service providers * Follow this policy, use approved systems only, and report suspected retention or deletion failures immediately. 10. PERIODIC REVIEW ------------------- Yes. This policy is reviewed at least once every 12 months by the Privacy Officer / Security Owner and sooner when any of the following occur: * a material change to CashFlowArc products, data categories, providers, jurisdictions, hosting, backups, or security architecture; * a change in applicable privacy, financial-services, consumer-protection, or records-retention law; * a material incident, deletion failure, audit finding, complaint, or regulator inquiry; or * a merger, acquisition, new vendor, or new use of personal information. Each review must record the date, reviewer, changes considered, approved retention schedule, test results, exceptions, and next review date. Material changes require documented management approval and employee/vendor notice or training where appropriate. 11. REFERENCE POINTS FOR LEGAL REVIEW ------------------------------------- * GDPR, Article 5(1)(e), requires personal data to be kept in identifiable form no longer than necessary for the processing purpose (storage limitation): https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng * The California Attorney General describes CCPA/CPRA rights to know, delete, correct, limit sensitive-information use, and non-discrimination, subject to legal exceptions: https://oag.ca.gov/privacy/ccpa * FTC guidance recommends a written retention policy that specifies what is retained, secured, retained for how long, and securely disposed of when no longer needed: https://www.ftc.gov/business-guidance/resources/protecting-personal-information-guide-business APPROVAL -------- Approved by: ________________________________ Date: _______________ Title: ______________________________________ Next scheduled review: ______________________