Data retention and protection policy
This policy describes retention and protection practices for data processed by NorthCoast DevOps LLC (ncdLabs) products and operations. Product-specific schedules may be stricter; they cannot be looser where this policy sets a maximum without a documented exception.
Protection
- Sensitive credentials stored by ncdLabs products are encrypted at rest; encryption keys are held as platform secrets.
- Access to production data stores is limited to authorized operators and application service roles.
- Backups, logs, and exports are treated as sensitive when they may contain customer or personal data.
- See also the security policy and privacy policy.
Company operational defaults
- Support and inquiry email — retained as needed to complete the request and for ordinary business records, then deleted or archived per mailbox practice.
- Billing records — retained as required for tax, accounting, and dispute handling (often multi-year); payment card data is handled by the payment processor.
- Security and incident records — retained for investigation and improvement, typically up to 24 months unless a longer legal hold applies.
- Marketing analytics — governed by analytics provider settings and the privacy policy; not used as a long-term PII warehouse.
Multi-tenant SaaS products (example: AttendeeSync)
Unless a customer agreement states otherwise, typical application retention includes:
- Delivery / sync ledger rows: about 90 days after last update
- Job execution detail logs: about 90 days
- Audit events: about 365 days
- Notification outbox: about 30 days after terminal status
- Encrypted connector credentials: until the customer deletes them or the account is offboarded
Account offboarding pauses sync, removes credential ciphertext, and schedules purge of account-scoped operational data after a short delay (on the order of days) so mistaken cancellations can be caught.
Customer-hosted products
Plugins and software that run primarily on customer infrastructure keep data under the customer’s control. ncdLabs retains only what is needed for licensing, updates, purchase fulfillment, or optional cloud features the customer enables.
Deletion requests
Privacy and deletion requests: privacy@ncdlabs.com. We verify the requestor’s authority before deleting account data.