Shine

Data Deletion and Retention Policy

Introduction

This Data Retention and Deletion Policy outlines the principles, guidelines, and procedures for managing and protecting data within SHINE SOLUTION. The policy ensures that data is retained and deleted in compliance with applicable laws and regulations while supporting the operational and business requirements of the organization.

1. Scope

This policy applies to all types of data, whether in electronic or physical form, that are collected, stored, or processed by SHINE SOLUTION. This includes data related to customers, employees, suppliers, and other stakeholders.

2. Data Categories

2.1 Personal Data

Information that identifies individuals including names, addresses, contact information, and other sensitive personal details.

2.2 Financial Data

Information related to financial transactions such as payment details, invoices, and financial statements.

2.3 Operational Data

Information used for day-to-day operations including emails, communication logs, and project-related data.

2.4 Legal / Compliance Data

Information required to meet legal and regulatory obligations such as contracts, tax documentation, and compliance records.

3. Data Retention Periods

3.1 Personal Data

Personal data is retained only for the time required to fulfill the purpose for which it was collected or as required by law. After the retention period, the data is securely deleted.

3.2 Financial Data

Financial data is retained according to applicable financial and tax regulations. Once the retention period expires, it is securely deleted.

3.3 Operational Data

Operational data is retained for a reasonable period necessary to support business activities. When no longer required, the data is securely removed.

3.4 Legal / Compliance Data

Legal and compliance data is retained as required by law or regulation. After the specified retention period, it is securely deleted.

4. Data Deletion Procedures

Data deletion refers to the secure and permanent removal of data from all relevant storage systems. The process includes:

5. Responsibilities

5.1 Data Owner

The Data Owner is responsible for determining appropriate data retention periods and initiating deletion requests when required.

5.2 IT Department

The IT Department is responsible for executing data deletion procedures and ensuring that the data is permanently and securely removed from systems.

6. Training and Awareness

SHINE SOLUTION provides training and awareness programs for employees to ensure compliance with this policy. Training includes data protection, privacy, and best practices for managing and retaining data.

7. Monitoring and Enforcement

SHINE SOLUTION regularly monitors compliance with this policy. Any violation may result in disciplinary action as per company policies and applicable laws.