Important:
This document is a professional draft, not legal advice. It must be reviewed against elyXion’s final legal entity details, implemented controls, suppliers, customer contracts, and actual operating practices before publication.
1. Purpose
This policy defines principles for retaining and disposing of elyXion information and personal data.
2. Principle
Information is retained only as long as necessary for legitimate business, contractual, security, operational or legal purposes.
3. Retention Criteria
Periods consider Dutch and EU legal obligations, contracts, service needs, accounting and tax requirements, investigations, disputes, customer instructions and backup architecture.
4. Customer Data
Customer Data is retained according to the Agreement, DPA, service design and documented Customer instructions.
5. Logs and Backups
Security and operational logs are retained according to purpose and risk. Deleted information may remain in protected backups until normal expiry and is not intended for ordinary processing.
6. Disposal
At the end of retention, information should be securely deleted, anonymised or otherwise rendered inaccessible according to sensitivity and technical context.
Detailed schedules must be reconciled with actual systems and legal obligations before publication.
| Owner: | elyXion |
| Version: | 1.0 |
| Last updated: | 11 Aug 2026 |
| Status: | Draft for legal and operational review |
