Aureon Financial LLC
(Applies to Aureon Financial LLC and any affiliates and related entities processing borrower, client, partner, and employee data.)
This policy establishes a structured framework for:
This policy operationalizes retention and deletion controls aligned with:
This policy applies to:
| Classification | Description | Examples | Protection Level |
|---|---|---|---|
| Restricted | Highly sensitive personal/financial data | SSN, DOB, bank data, credit reports, loan agreements | Maximum encryption & strict retention |
| Confidential | Business-sensitive information | Contracts, underwriting notes, partner agreements | Encrypted & access-controlled |
| Internal | Non-public operational data | Internal emails, SOPs | Access-controlled |
| Public | Public-facing information | Marketing materials | No retention limits |
| Record Type | Retention Period | Rationale |
|---|---|---|
| Funded loan agreements | 7 years after loan payoff | Statute of limitations + regulatory audit |
| Loan applications (approved) | 7 years after funding | Compliance and dispute defense |
| Loan applications (denied/withdrawn) | 25 months minimum | ECOA/Reg B compliance |
| Credit bureau reports | 2 years max | Risk minimization |
| Underwriting files | 7 years | Regulatory defense |
| Data Type | Retention Period |
|---|---|
| Marketing leads (no application) | 24 months from last activity |
| Loyalty program member records | Duration of membership + 5 years |
| Email marketing lists | Until opt-out or 24 months inactivity |
| Record Type | Retention Period |
|---|---|
| Tax records | 7 years |
| Accounting records | 7 years |
| Shareholder agreements | Permanent |
| Board minutes | Permanent |
| Compliance policies | Superseded version + 5 years |
| Record Type | Retention Period |
|---|---|
| Personnel files | 7 years after termination |
| Payroll records | 7 years |
| Background checks | 5 years |
| Access logs | 2 years |
| Record Type | Retention |
|---|---|
| System access logs | 24 months |
| Security event logs | 24 months |
| Incident reports | 7 years |
| Backup archives | Rolling 90 days (unless under legal hold) |
When litigation, audit, investigation, or regulatory inquiry is anticipated or active:
Only General Counsel or Executive Management may lift a legal hold.
6.1 Digital Records
Aureon shall use:
Deletion must render data irrecoverable.
6.2 Cloud & SaaS Platforms
Vendors must:
Vendor compliance must be reviewed annually.
6.3 Physical Records
For jurisdictions recognizing data rights:
Individuals may request:
If deletion conflicts with regulatory retention requirements, Aureon will:
| Role | Responsibility |
|---|---|
| Executive Management | Policy approval |
| Compliance Officer | Oversight & enforcement |
| IT Security Lead | Technical deletion implementation |
| Operations | Ensure CRM/Lending compliance |
| Third-Party Vendors | Contractual compliance |
Any deviation must be remediated within 30 days.
Improper retention or unauthorized deletion may result in:
This policy shall be reviewed annually or upon:
This policy ensures Aureon: