Data Retention Policy

Important:

This document is a professional draft, not legal advice. It must be reviewed against elyXion’s final legal entity details, implemented controls, suppliers, customer contracts, and actual operating practices before publication.

1. Purpose

This policy defines principles for retaining and disposing of elyXion information and personal data.

2. Principle

Information is retained only as long as necessary for legitimate business, contractual, security, operational or legal purposes.

3. Retention Criteria

Periods consider Dutch and EU legal obligations, contracts, service needs, accounting and tax requirements, investigations, disputes, customer instructions and backup architecture.

4. Customer Data

Customer Data is retained according to the Agreement, DPA, service design and documented Customer instructions.

5. Logs and Backups

Security and operational logs are retained according to purpose and risk. Deleted information may remain in protected backups until normal expiry and is not intended for ordinary processing.

6. Disposal

At the end of retention, information should be securely deleted, anonymised or otherwise rendered inaccessible according to sensitivity and technical context.

Detailed schedules must be reconciled with actual systems and legal obligations before publication.

Owner: elyXion
Version: 1.0
Last updated: 11 Aug 2026
Status: Draft for legal and operational review