Data Retention & Disposal Policy

Last Updated: March 16, 2026

Policy Review Frequency: Annually (next review: March 2027)

1. Purpose

This Data Retention and Disposal Policy ("Policy") establishes the requirements and procedures for the retention, management, and secure disposal of data collected and processed by Procomm 360 ("Company," "we," "us," or "our"). This Policy ensures compliance with applicable data privacy laws, including the California Consumer Privacy Act (CCPA), the Gramm-Leach-Bliley Act (GLBA), and other relevant federal and state regulations governing the handling of personal and financial data.

2. Scope

This Policy applies to all data collected, processed, and stored by Procomm 360 in connection with our services, including but not limited to:

  • Personal information (names, email addresses, phone numbers, addresses)
  • Business information (company names, tax IDs, business license details)
  • Financial data (bank account information, transaction data, processing statements, payment card data)
  • Financial account data accessed through third-party providers such as Plaid Inc.
  • Documents and files uploaded by clients or consumers
  • Employment application data (resumes, contact information)
  • Communication records (emails, SMS messages, contact form submissions)
  • Automatically collected data (IP addresses, browser data, cookies, usage analytics)

This Policy applies to all employees, contractors, and service providers who handle data on behalf of Procomm 360.

3. Data Classification

Data is classified into the following categories based on sensitivity:

ClassificationDescriptionExamples
Highly SensitiveFinancial and identity data requiring maximum protectionSSN, bank account numbers, routing numbers, payment card data, driver's license numbers, Plaid access tokens
SensitivePersonal and business data with privacy implicationsTax IDs, transaction history, account balances, processing statements, business financial records
InternalBusiness operational dataContact information, email addresses, phone numbers, business names, uploaded documents
PublicNon-sensitive dataPublished website content, marketing materials, publicly available business information

4. Retention Schedule

Data is retained only for as long as necessary to fulfill the purpose for which it was collected, to comply with legal obligations, or as required by contractual agreements.

Data TypeRetention PeriodLegal Basis
Merchant application data7 years from last activityIRS/Bank Secrecy Act compliance
Financial account data (Plaid)Duration of service + 90 days, or until deletion requestedContractual necessity / consent
Payment transaction records7 yearsIRS requirements / PCI DSS
Processing statements & analysis3 years from analysis dateBusiness purpose / contractual
Invoice and billing records7 yearsTax and accounting requirements
Client contact informationDuration of relationship + 3 yearsLegitimate business interest
Uploaded documentsDuration of service + 1 yearContractual necessity
Employment applications2 years from submissionEEOC / DFEH compliance
Contact form submissions1 yearLegitimate business interest
SMS/communication records1 year from last communicationTCPA compliance / consent
Website analytics / cookies26 monthsLegitimate business interest
System access logs1 yearSecurity / audit requirements

5. Data Disposal Procedures

5.1 Secure Deletion Standards

When data reaches the end of its retention period or when a valid deletion request is received, disposal is carried out using the following methods based on data classification:

  • Highly Sensitive Data: Cryptographic erasure or secure overwrite (NIST SP 800-88 compliant). Database records are permanently purged, not merely soft-deleted. Access tokens (e.g., Plaid) are revoked at the provider level.
  • Sensitive Data: Permanent deletion from all production databases and backup systems within 30 days of the retention expiry.
  • Internal Data: Standard database record deletion with removal from backups within 90 days.
  • Public Data: Removed from active systems; no special disposal procedures required.

5.2 Consumer Deletion Requests

Consumers may request deletion of their personal data by emailing admin@procomm360.com or calling (866) 405-5838. Upon receipt of a verified request:

  • We acknowledge receipt within 10 business days
  • We verify the requestor's identity
  • Applicable data is deleted within 30 days
  • We confirm deletion in writing to the requestor
  • We direct third-party service providers (including Plaid) to delete the consumer's data

Exceptions: We may retain data beyond the requested deletion date where required by law (e.g., tax records, fraud prevention, ongoing legal proceedings, or regulatory requirements).

5.3 Third-Party Data Disposal

We require all third-party service providers and data processors to adhere to equivalent data disposal standards through contractual obligations. Upon termination of a third-party relationship, we verify that all Procomm 360 data held by the provider has been securely destroyed or returned.

6. Financial Data (Plaid) Specific Provisions

Financial account data obtained through Plaid is subject to additional safeguards:

  • Plaid access tokens are stored encrypted and are revoked immediately when no longer needed or when a consumer revokes consent
  • Raw financial account data (balances, transactions) is retained only for the duration of the active service engagement plus 90 days
  • Consumers may revoke Plaid access at any time via my.plaid.com or by contacting us
  • Upon revocation or deletion request, Plaid tokens are revoked and associated financial data is purged within 30 days
  • Aggregated, anonymized data derived from financial accounts may be retained for analytics but cannot be linked back to individual consumers

7. Roles and Responsibilities

  • Data Protection Officer (Operations Manager): Oversees compliance with this Policy, conducts periodic reviews, and handles deletion requests and data breach response.
  • IT / Development Team: Implements technical data disposal procedures, manages encryption and access controls, and maintains secure system configurations.
  • All Employees: Comply with this Policy in their daily operations, report potential data incidents, and participate in annual data protection training.

8. Policy Review and Updates

This Policy is reviewed and updated as follows:

  • Annual Review: A comprehensive review is conducted annually by the Operations Manager and leadership team to ensure continued compliance with evolving privacy laws and business needs.
  • Triggered Reviews: Additional reviews are conducted when there are material changes in applicable laws, business operations, data processing activities, or following a data security incident.
  • Version Control: All versions of this Policy are retained for audit purposes. The "Last Updated" date on this page reflects the most recent revision.

9. Enforcement

Violations of this Policy by employees or contractors may result in disciplinary action, up to and including termination of employment or contract. Violations by third-party service providers may result in termination of the service agreement. Any suspected violations should be reported immediately to the Operations Manager at admin@procomm360.com.

10. Applicable Laws and Regulations

This Policy is designed to comply with the following laws and regulations:

  • California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
  • Gramm-Leach-Bliley Act (GLBA)
  • Payment Card Industry Data Security Standard (PCI DSS)
  • Bank Secrecy Act (BSA)
  • IRS record retention requirements (26 CFR § 1.6001-1)
  • Equal Employment Opportunity Commission (EEOC) recordkeeping requirements
  • Telephone Consumer Protection Act (TCPA)
  • NIST Special Publication 800-88 (Guidelines for Media Sanitization)

11. Contact Information

For questions about this Policy, data deletion requests, or to report a concern:

Procomm 360 — Data Protection

Email: admin@procomm360.com

Phone: (866) 405-5838

Address: 6524 Lonetree Blvd, Rocklin CA 95765