Skip to main content

Security and trust

Data Retention and Disposal Policy

What we keep, how long we keep it, and how it is destroyed. Every category of data in Ledger has a stated retention period and a stated disposal method, and a customer can ask for deletion at any time.

Version 1.0 · Effective August 28, 2026 · Next review August 28, 2027 · Owner: David Boruchowitz, Owner

Back to the security and trust page

Download Word

1. Purpose and scope

This policy states how long BreathEasy Administrative Services LLC keeps the data held in BreathEasy | Ledger, the accounting application published at ledger.breatheasy.net, and how that data is disposed of when the retention period ends. It is a companion to the Information Security Policy and Procedures and the Access Controls Policy, and it carries the same authority.

The scope covers customer bookkeeping records, financial account data received from an aggregator such as Plaid, uploaded statements and receipts, account and authentication records, application and security logs, backups, marketing and quote-request contacts, and any copy of that data held on a company device or in a vendor system.

The policy applies to every owner, employee, and contractor with access to company systems, and to every vendor that processes customer data on our behalf.

2. Governing principles

  • Collect the minimum. We collect only the data needed to keep books, produce reports, and support the account. We do not collect government identification numbers, and we never receive or store bank usernames and passwords.
  • Keep it only as long as it is needed. Each category below has a stated retention period tied to a business, contractual, or legal reason.
  • Delete on request. A customer may ask for deletion at any time, and we complete it inside the timeframe stated in this policy.
  • Dispose securely. Deletion means the record is removed from the live system and aged out of backups, not merely hidden from view.
  • Never repurpose. Customer financial data is used to operate the service for that customer. It is not sold, rented, or used for advertising, and it is not used to train third-party models.
  • Prove it. Deletion requests, disposal events, and the annual retention review are recorded and retained as evidence.

3. Roles and responsibilities

RoleHeld byResponsibility
Data OwnerDavid Boruchowitz, OwnerOwns this policy, approves exceptions and legal holds, handles deletion requests, and runs the annual retention review.
System AdministratorDavid BoruchowitzExecutes deletions, verifies backup expiry, and records disposal evidence.
Workspace administrator (customer side)The customer's designated administratorDecides what their workspace uploads and keeps, and requests export or deletion on the customer's behalf.
Vendors and subprocessorsHosting, database, email, and aggregation providersHonor deletion instructions and their own contractual retention limits, as listed on the trust page.

4. Retention schedule

The following schedule states the default retention period for each category of data. Where a customer contract or a tax authority requires a longer period, the longer period governs for that customer.

Data categoryRetention periodReason
Bookkeeping records: transactions, categories, splits, rules, chart of accounts, reportsLife of the account, then 30 days after account closure unless the customer asks for immediate deletionThe customer needs their books available, and tax records commonly must be reproducible for prior years.
Uploaded statements, CSV imports, and receipt imagesLife of the account, deletable by the customer at any timeSupporting documentation for entries the customer has posted.
Financial account data from an aggregator: transactions, balances, account ownershipDeleted with the connection, immediately on disconnectAccess ends when the customer withdraws permission.
Aggregator access tokensDeleted immediately on disconnect or account closureA token has no purpose once the connection ends, and holding one is a standing risk.
Account and profile records: name, work email, role, workspace membershipLife of the account, then 30 daysNeeded to operate access control, and briefly afterward to complete offboarding.
Authentication records: password hashes, passkey public keys, factor enrollmentsDeleted with the accountNo purpose once the login is removed. Passwords are stored only as salted hashes and are never recoverable.
Security and access logs: sign-ins, failures, administrative actions12 monthsInvestigation, incident response, and access review evidence.
Application error and performance logs90 daysDebugging and reliability. Scrubbed of financial detail.
Cookie-free site analytics: page path, timestamp, referrer domain, device type, daily-rotating anonymous hash25 months, aggregated monthlyYear-over-year traffic comparison. No cookies, no IP storage, no personal data.
Quote requests and sales inquiries24 months from last contact, or immediately on requestFollowing up on an active inquiry, and honoring opt-outs.
Email delivery records and marketing suppression listDelivery records 12 months; suppression entries retained indefinitelyDeliverability troubleshooting, and a permanent record so an unsubscribed address is never emailed again.
Security program evidence: risk register, access reviews, policy acknowledgments, incident records3 years minimumGovernance and diligence evidence.
Encrypted database backupsRolling 30 days, then automatically expiredRecovery from failure or error, without becoming a shadow archive.
Contracts, invoices, and accounting records of the business itself7 yearsTax and corporate recordkeeping obligations.

5. Customer-initiated deletion and export

  • A workspace administrator can delete individual records, uploaded files, and bank connections from inside the application at any time, and that deletion takes effect immediately in the live system.
  • A customer may request deletion of the entire workspace by writing to the address at the end of this policy. We confirm the request with a known administrator on the account before acting, so an impostor cannot destroy a customer's books.
  • Confirmed full-account deletion is completed in the live system within 30 days, and the data ages out of encrypted backups within a further 30 days.
  • Before deletion we offer an export of the customer's records in CSV and PDF form, so the customer retains what they need for taxes.
  • After deletion we retain only what the law or an open dispute requires, plus the minimum record that the deletion occurred: the date, the requester, and the scope.
  • A customer may ask for a written confirmation of deletion, which we provide within 5 business days of completion.

6. Disposal methods

MediumMethodVerification
Database recordsPermanent deletion with cascading removal of dependent rows. No soft-delete flag is used as a substitute for disposal.Post-deletion query confirming zero remaining rows for the workspace.
Object storage: uploads and receiptsObject deletion through the storage provider, including any versioned copies.Listing of the prefix returning empty.
BackupsExpiry on the rolling schedule. Backups are encrypted and are not selectively edited, so disposal is completed by expiry rather than by extraction.Backup inventory confirming the last copy containing the data has aged out.
LogsAutomatic expiry at the stated retention period.Retention setting recorded in the annual review.
Company laptops and mobile devicesFull-disk encryption throughout life, then cryptographic erase or a certified wipe at end of life. Devices are not resold or donated without a completed wipe.Disposal entry in the machine register with date and method.
PaperCross-cut shredding. Customer financial data is not printed except when a customer asks for a printed report.Destruction noted in the disposal log.
Vendor-held copiesWritten deletion instruction to the vendor, relying on the deletion terms in the vendor agreement.Vendor confirmation retained with the disposal record.

7. Legal holds and exceptions

If we receive a lawful preservation request, a subpoena, or notice of a claim, the Data Owner places the relevant data under legal hold. A hold suspends routine deletion for the data in question, is recorded with a date and a reason, and is lifted in writing once the matter closes. Deletion resumes on the normal schedule at that point.

Any other deviation from the retention schedule requires written approval from the Data Owner, a stated reason, and an expiry date. Approved exceptions are recorded in the risk register and revisited at each annual review.

8. Review, evidence, and enforcement

  • The Data Owner reviews this policy and the retention schedule at least annually, and after any change to the systems, vendors, or legal obligations that would affect it.
  • The review confirms that automatic expiry settings match the schedule, that no orphaned copies of customer data exist on devices or in vendor systems, and that recorded deletion requests were completed on time.
  • Deletion requests, disposal events, legal holds, and review records are retained for at least three years as evidence.
  • Failure to follow this policy may result in removal of access and, for employees and contractors, termination of the relationship.

Deletion requests, export requests, and questions about this policy go to sales@breatheasy.net. We acknowledge within 2 business days.

Request an export or a deletion

Write to the policy owner from an address on the account. We confirm the request with a known administrator before acting, offer an export of your records first, and send written confirmation once the deletion is complete.

sales@breatheasy.net

BreathEasy Administrative Services LLC · 201 Lupin Street, Pahrump, Nevada 89048