Data Retention and Deletion Policy
This policy defines how LEF retains and securely deletes data processed during client projects.
| Owner | Information Security Officer |
| Contact | infra@lef.tec.br |
| Version | 1.1 |
| Last updated | 2025-03-26 |
| Review cadence | Annual (or per contractual/legal changes) |
1. Purpose
Section titled “1. Purpose”Define how LEF handles the storage, retention, and secure deletion of personal data processed as part of client projects, in alignment with privacy laws and client expectations.
2. Scope
Section titled “2. Scope”Applies to all personal data collected, processed, or stored by LEF in the context of projects, partnerships, or client engagements.
This policy distinguishes between project-related personal data and operational client records (such as contact and contract details).
3. Retention Guidelines
Section titled “3. Retention Guidelines”- Project data: Personal data processed on behalf of clients as part of a project is retained only for the duration of the contract or project lifecycle.
- Client records (e.g., company name, contact person, contract information): These are retained for administrative, legal, and business continuity purposes, and are not subject to project-based deletion.
- A short retention extension (typically up to 12 months) may be applied to project data for support, legal, or audit purposes if agreed upon.
4. Data Deletion and Disposal
Section titled “4. Data Deletion and Disposal”- Upon project or contract completion, access to systems and project documents is revoked for all involved users.
- Project-related data is deleted from:
- Microsoft 365 (Teams, OneDrive, SharePoint)
- EVEO private cloud storage
- SQL databases and backup folders (if applicable)
- Deleted data is removed securely, including from trash/recycle bins and version history when feasible.
- Client records (contracts, contact details) are retained in LEF’s administrative systems and are not deleted unless required by law or upon formal request.
5. Roles and Responsibilities
Section titled “5. Roles and Responsibilities”- Project Leads: Confirm project completion and initiate the offboarding and cleanup process.
- Information Security Officer: Ensures revocation of access and deletion procedures are followed.
- IT/Infra: Executes deletion on cloud platforms or local systems when required.
6. Exceptions
Section titled “6. Exceptions”- Data retention may be extended if required by law, regulation, or written agreement with the client.
- If clients request earlier deletion of project data, LEF will comply promptly and confirm the action.
7. Contact
Section titled “7. Contact”For questions or requests regarding data deletion or retention: infra@lef.tec.br
Records / evidence
Section titled “Records / evidence”- Project completion/offboarding trigger:
- Deletion confirmations (per system):
- Retention exceptions approvals: