Comprehensive data governance framework covering classification, retention, deletion, and data subject access request (DSAR) workflows. Privacy-by-design from day one.
Four-tier classification system governing access controls, encryption requirements, and handling procedures.
Examples: Marketing materials, public documentation, blog content
Handling: No restrictions on sharing. Standard access controls.
Examples: Internal processes, employee directories, non-sensitive configs
Handling: Access limited to authenticated employees. No external sharing without approval.
Examples: Customer data, financial records, API keys, audit reports
Handling: Encrypted at rest and in transit. Role-based access. Audit logging required.
Examples: PHI, PII, credentials, encryption keys, penetration test results
Handling: Maximum encryption. Least-privilege access. MFA required. Immutable audit trail.
| Data Category | Retention Period | Legal / Business Basis |
|---|---|---|
| Platform Usage Logs | 90 days | Operational necessity |
| Security Event Logs | 1 year | Compliance (SOC 2, HIPAA) |
| Customer Account Data | Duration of contract + 30 days | Contractual |
| Health Engagement Data | Per BAA / customer policy | Regulatory (HIPAA) |
| Backup Archives | 30 days after source deletion | Business continuity |
| Employee Records | Duration of employment + 7 years | Legal obligation |
| Audit Trails | 3 years | Compliance (multiple frameworks) |
| Marketing Analytics | 24 months | Legitimate interest |
Retention periods are configurable per customer contract and regulatory requirements.
Data deletion follows documented internal procedures; the platform audit log records deletion events, and no third-party certification is claimed.
Soft Deletion
Data marked for deletion with 30-day recovery window. Immediately inaccessible to application layer.
Hard Deletion
Permanent removal from primary storage after the recovery window.
Backup Purge
Deleted data purged from backup systems within 30 days of hard deletion.
Audit Trail
Deletion events recorded in the platform audit log — who requested, when executed, and what was removed.
Confirmation
Deletion confirmation is provided to the data controller on request; no third-party deletion certificate is issued today.
Data Subject Access Requests processed within 30 calendar days, with 48-hour acknowledgment SLA.
DSAR received via the secure privacy contact form or platform portal. Acknowledged within 48 hours.
SLA: 48hRequester identity verified through multi-factor authentication to prevent unauthorized disclosure.
SLA: 24hRequest categorized (access, deletion, portability, rectification, restriction) and data systems identified.
SLA: 3 daysRelevant data located, extracted, and compiled across platform systems with audit trail.
SLA: 10 daysResponse reviewed for completeness, third-party data redacted, legal exemptions applied if applicable.
SLA: 5 daysResponse delivered to requester in structured, portable format. Deletion confirmation provided where applicable.
SLA: Total ≤30 daysDSAR contact: Submit through the secure privacy contact form. Enterprise customers can also submit DSARs through the admin portal or designated account manager.
Our privacy and compliance team is available for DPA reviews, DSAR inquiries, and data governance assessments.
This summary is informational. Data governance terms are governed by executed agreements (DPA/BAA). CUBE OneCare is not a medical provider.