Backpack Works logo
All policies
Version: 1.0Last updated: December 2025Owner: Security Lead

Data Retention & Disposal Policy

1. Purpose

To define how long Backpack Works retains data and how it is securely disposed of or returned.

2. Principles

  • We retain data only as long as needed for the purpose it was collected or as required by contract or law.
  • Client data is returned or deleted at the end of an engagement, per the client agreement.

3. Retention

  • Client project data: retained for the duration of the engagement plus an agreed wind-down period, then deleted or returned.
  • Business records: retained per legal and tax requirements.
  • Logs: retained for a defined period sufficient for security investigation.

4. Secure disposal

  • Electronic data is deleted using methods that prevent recovery.
  • Cloud data is removed from active systems and backups age out per backup retention.
  • Physical media, if any, is securely wiped or destroyed.

5. Review

This policy is reviewed at least annually.