Data Retention & Deletion Policy
Enterprise Data Retention & Deletion Policy
Classification: Global Governance Standard
Compliance Standards: SOC 2 Type II (CC6.5), GDPR (Art. 5(1)(e)), HIPAA (§ 164.316(b))
Effective Date: October 8, 2026
LookAtMe is committed to verifiable data lifecycle governance. This policy defines our standard data retention windows, automated pruning schedules, tenant-controlled purge options, and secure cryptographic wiping mechanisms.
1. Retention Schedules by Data Category
| Data Classification | Description & Examples | Standard Retention Window | Tenant Configurable? |
|---|---|---|---|
| High-Frequency Telemetry | Active window title logs, WPM cadence, CPU/RAM telemetry | 90 Days (Rolling) | Yes (30 to 365 Days) |
| Biometric & Keystrokes | Keystroke dynamics, cadence counters (Redacted PII) | 60 Days (Rolling) | Yes (15 to 180 Days) |
| Visual Artifacts | Compressed workstation screenshots, Office TV frames | 30 Days (Rolling) | Yes (7 to 90 Days) |
| DLP & Security Incidents | Blocked USB insertions, confidential clipboard alerts | 365 Days (1 Year) | Yes (180 to 2555 Days) |
| Attendance & Timesheets | Punch in/out timestamps, GPS coordinates, geofence logs | 7 Years (Statutory) | No (Statutory minimum) |
| Financial & Invoicing | Billed invoices, CPQ proposals, tax filing records | 7 Years (Financial Law) | No (Statutory requirement) |
| Universal Audit Logs | Administrative logins, permissions mutations, API calls | 3 Years (Immutable) | Yes (1 to 7 Years) |
2. Automated Pruning & Cold Storage Archiving
2.1. Cron Pruning Engine: The LookAtMe backend runs daily scheduled cron jobs that automatically identify and purge records exceeding tenant retention thresholds.
2.2. S3 Object Lifecycle Policies: Binary artifacts (compressed screenshots, audio logs) stored in MinIO/AWS S3 buckets inherit programmatic lifecycle rules transitioning data to Glacier cold storage or executing hard multi-part deletion.
3. Cryptographic Erasure & Hardware Decommissioning
3.1. NIST SP 800-88 Compliance: All database storage and attached block volumes undergo cryptographic erasure matching NIST SP 800-88 Rev 1 guidelines.
3.2. Multi-Tenant Isolation: Soft-deleted tenant data is zeroized in MySQL 8.4 via automated cascaded deletes, preventing forensic data recovery.
4. Right to Erasure ("Right to be Forgotten")
In accordance with GDPR Article 17, verified data subjects or organization administrators may issue a cryptographic purge request through the Super Admin or Tenant Security portal. Once approved:
- Workstation telemetry for the specified employee is deleted within 72 business hours.
- Encrypted backups age out and are permanently overwritten within standard backup rotation windows (30 days).
- A cryptographically signed Certificate of Data Destruction is generated for audit verification.
Compliance Officer Inquiries: privacy@lookatme.com | compliance@lookatme.com