Data Retention Policy

1. Purpose

This Data Retention Policy outlines the guidelines for retaining and deleting data held by One Start LLC. The policy ensures that the organization manages its data efficiently, remains compliant with legal obligations, and protects the privacy of data subjects by retaining personal identifiable information (PII) and other data only for periods necessary for operational, legal, and compliance purposes.

2. Scope

This policy applies to all employees, contractors, and third-party service providers of One Start LLC who handle, access, or manage company data. It covers all data stored on our servers, including electronic records, databases, and backups.

3. Data Retention Schedule

Personal Identifiable Information (PII)

  • PII is retained for a maximum of 30 days after its collection or processing date. After this period, PII must be securely deleted unless subject to a specific legal requirement for a longer retention period.

Other Information

  • Non-PII data is retained for a period of 5 years from the date of its collection or last activity. After this period, the data will be securely deleted or anonymized, so it no longer constitutes personally identifiable information.

4. Data Storage and Security

  • All data, including PII and other information, is stored on secure servers that are not directly accessible from the internet. Access to these servers is restricted to authorized personnel only and is controlled through secure authentication mechanisms.
  • Data stored on our servers is protected by state-of-the-art security measures to prevent unauthorized access, disclosure, alteration, or destruction.

5. Data Backup

  • Data is backed up twice a week to ensure its availability and integrity. These backups are encrypted and stored in geographically diverse regions to protect against data loss due to natural disasters, system failures, or other unforeseen events.
  • Backup data is subject to the same retention periods and deletion protocols as primary data storage.

6. Data Deletion

  • Upon reaching the end of its retention period, data is securely deleted using methods that prevent its recovery or unauthorized access. This includes physical destruction of any hard copies and secure electronic deletion of digital records.
  • A record of the deletion will be maintained for audit purposes.

7. Compliance and Monitoring

  • One Start LLC is committed to complying with applicable data protection laws and regulations regarding data retention.
  • Regular audits will be conducted to ensure compliance with this policy and to identify and rectify any issues with data retention practices.

8. Policy Review and Updates

  • This Data Retention Policy will be reviewed annually or as required by changes in law or operational practices. Any amendments to this policy will be communicated to all staff and relevant third parties.

9. Contact Information

For questions or concerns about this Data Retention Policy, please contact:

  • Data Protection Officer: Umut Yusuf Tontus
  • Email: umut.tontus@onestartlabs.com
  • Phone: +90 542 598 3123