Data Retention & Protection Policy
1. Introduction
This Policy provides for the systematic review, retention and destruction of documents received or created by Day AI in connection with the transaction of its business. This Policy covers all records and documents, regardless of physical form (including electronic documents), contains guidelines for how long certain documents should be kept and how records should be destroyed. The Policy is designed to ensure compliance with federal and state laws and regulations, to eliminate accidental or innocent destruction of records and to facilitate Day AI’s operations by promoting efficiency and freeing up valuable storage space. This Policy covers all data processed or in Day AI’s custody or control in whatever medium such data is contained in, including cloud hosted databases and static file storage.
2. Definitions
A. “Anonymisation” is the process of turning Data into a form which does not identify individuals. It is a type of information sanitization whose intent is privacy protection.
B. “Archiving” is the process of moving Data that is no longer actively used to a separate storage device or location for retention.
C. “Data” is Record and Document.
D. “Destruction” is defined as physical or technical destruction sufficient to render the information contained in the Document irretrievable by ordinary commercially available means.
E. “Document” as used in this Policy, is any medium which holds Information used to support an effective and efficient organizational operation.
F. “Litigation Hold Order” means a “hold order” issued by the Office of the General Counsel to IT and any relevant division to preserve all information relative to threatened or pending litigation, regulatory action or government order.
G. “Personal Data” (also “Personally Identifiable Information”) is any information relating to an identified or identifiable natural person (the “Data Subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
H. “Record” is any medium which holds information or evidence about a past event.
3. Data Classification
Data shall be classified as follows:A. Public: This information is public information, and can be openly shared on our website, discussed in public and with anyone. Public information as the name implies, is public, and does not require any additional controls when used.
B. Internal: Internal information is company-wide and should be protected with limited controls. Internal information may include the Employee Handbook, various policies and company-wide memos. If disclosed, Internal information has a minimal impact to the business.
C. Confidential: Confidential information is team-wide and its use should be contained within the business. This information may include pricing, marketing materials, or contact information. If disclosed, Confidential information could negatively affect the business and the brand.
D. Restricted: Restricted information is highly sensitive and its use should be limited on a need-to-know basis. Restricted information includes trade secrets and personally identifiable information (PII). If disclosed, there would be a significant financial or legal impact to the business.
4. Data Retention Periods
Data shall be retained for as long as required by the purpose they have been collected for. Therefore:
A. Personal information collected for purposes related to the performance of a contract between you and Day AI shall be retained until such contract has been fully performed.
B. Personal information collected for the purposes of Day AI’s legitimate interests shall be retained as long as needed to fulfill such purposes.
C. Day AI may be allowed to retain personal information for a longer period whenever you have given consent to such processing, as long as such consent is not withdrawn.
D. We may retain the data for a longer period if required for compliance with a legal obligation according to applicable law (e.g., to meet tax or commercial law retention obligations) or to the extent required for establishment, exercise, or defense of legal claims.
E. Once the retention period expires, the applicable personal information shall be deleted. Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
5. Data Storage and Security
A. Storage Methods
Cloud-Based Storage: All Data is stored in secure and encrypted cloud-hosted databases and static cloud file storage to ensure reliable and scalable storage solutions. Specific third-party providers are chosen based on stringent evaluation criteria but are not disclosed as part of our security protocols.
B. Access Controls
Employee Access: Access to stored Data is tightly controlled. Employees are granted only the access and permissions necessary to perform their specific job functions. Permissions are periodically reviewed and revoked if no longer needed.
Runtime Processes: All runtime processes are granted permissions using Identity and Access Management (IAM), ensuring that each process only has the minimal necessary permissions to perform its specific tasks.
C. Security Measures
Encryption: All restricted Data is encrypted at rest using industry-standard encryption algorithms. Encryption keys are securely managed, and secrets are held securely and are unrecoverable by any human.
Access Authentication: IT assets are protected by robust authentication mechanisms, including password protection and biometric security where feasible.
Regular Scanning: IT assets are regularly scanned for viruses and malware and encrypted to enhance protection against unauthorized access.
Monitoring and Logging: Continuous monitoring and logging are implemented to detect any unauthorized access or anomalous activities related to Data storage.
D. Data Handling
Data at Rest: All Data is stored encrypted at rest, ensuring that it is never human-readable by any employee or third-party.
Data in Transit: Secure protocols are utilized for Data transmission, ensuring that Data remains encrypted and protected during transit.
Data Lifecycle Management: Policies are in place to manage the lifecycle of Data, including secure deletion protocols for Data no longer needed.
6. Data Archiving
A. All archived Data must be encrypted or locked and continuously safeguarded to avoid data breaches.
B. Electronic Records shall be archived in accordance with Day AI’s Security Policy (conditionally available by request via privacy@day.ai) for access controls and in a format which is appropriate to secure the confidentiality, integrity and accessibility of such records. After the archival period has expired, records shall be destroyed in accordance with section 7.
C. If archival is outsourced, the vendor must first be assessed to ensure they comply with the standards set forth in the Day AI Security Policy and appropriate contracts with data protection and information security clauses must be implemented.
D. The possibility that data media used for archiving will wear out shall be considered. If electronic storage media are chosen, any procedures and systems ensuring that the information can be accessed during the retention period (both with respect to the information carrier and the readability of formats) shall also be stored in order to safeguard the information against loss as a result of future technological changes. The responsibility for the storage falls to the IT Manager or equivalent in charge of the storage function.
7. Data Deletion and Disposal
A. Personal Data or confidential or restricted information must be disposed of as confidential waste and be subject to secure electronic deletion or Anonymisation.
B. Some expired or superseded contracts may only warrant in-house shredding.
C. Paper Documents shall be shredded using secure, locked consoles designated in each office from which waste shall be periodically picked up by security screened personnel for disposal.
D. IT shall maintain and enforce a detailed list of approved destruction methods appropriate for each type of information archived whether in physical storage media such as CD-ROMs, DVDs, backup tapes, hard drives, mobile devices, portable drives or in database records or backup files.
E. IT shall fully document and approve the destruction process. The applicable statutory requirements for the destruction of information, particularly requirements under applicable data protection laws, shall be fully observed.
F. The specific deletion or destruction process may be carried out either by an employee or by an internal or external service provider that IT subcontracts for this purpose. All external service providers must be thoroughly vetted and reviewed to ensure their full compliance with data protection requirements, and all data disposal is subject to applicable provisions under relevant data protection laws and the Day AI Security Policy.
G. IT shall verify that deletion/disposal has been carried out correctly.
8. Roles and Responsibilities
A. Each Supervisor is responsible for the Data its department creates, uses, stores, processes and destroys. Each Supervisor shall be responsible for implementing procedures for the retention, Archiving and Destruction of Data in accordance with this Policy, communicating the terms of this Policy to the relevant employees and enforcing compliance. Each Supervisor shall be responsible for submitting exception requests to the process, including consulting and receiving legal advice if necessary to justify making an exception request under section 10.
B. The Office of the General Counsel may audit compliance with this Policy from time to time and provide recommendations to be reviewed by the President of the Company and by the other relevant senior management. The Office of the General Counsel shall provide guidance with regard to this Policy.
C. Each employee shall be responsible for returning Records and Documents in their possession or control to Day AI upon separation or retirement. Final disposition of such Records and Documents shall be determined by the immediate Supervisor in accordance with this Policy.
9. Legal and Regulatory Compliance
Breaches of this Policy may have serious legal and reputation repercussions and could cause material damage to Day AI. Consequently, breaches can potentially lead to disciplinary action that could include summary dismissal and to legal sanctions, including criminal penalties.
All employees are expected to promptly and fully report any breaches of the Policy. A report may be made to the employee’s Supervisor or the General Counsel. Reports made in good faith by someone who has not breached this Policy will not reflect badly on that person or their career at Day AI. Reports may be made using the following e-mail address: privacy@day.ai.
10. Exceptions and Special Cases
A. Exception requests may be made on account of a client requirement, business requirement, legal requirement or vital historical purpose. Exception Request Forms shall be reviewed and approved by the Office of the General Counsel and routed to IT to enforce.
B. Documents for which the Office of the General Counsel has issued a Litigation Hold Order shall be archived, retained and only destroyed as specified by the Office of the General Counsel. A Litigation Hold Order shall appoint a custodian of records and specify a location for storage and review of documentation.
11. Monitoring and Auditing
Documented procedures and evidence of practice should be in place for this operational Policy. Examples of effective organizational management, audit controls, and employee practices include: (i) documented record retention schedules and archival information; (ii) documented encryption and decryption strategies that allow for retrieval of archival electronic records; (iii) regular employee procedures and anecdotal documentation of record management and archival processes; and (iv) direct observation of archival records organization and storage. Ongoing monitoring and periodic auditing processes shall be designed to ensure compliance with this Policy.
12. Training and Awareness
Training and communication plans shall be routinely undertaken in accordance with best practices to ensure understanding and compliance across the organization.
13. Review and Update
Regular review and updating of the Policy shall be undertaken in accordance with best practices to reflect changes in laws, technologies, or business practices.