Data Security & Retention Policy
Last updated: August 8, 2026
This Policy describes, at a level that does not itself create risk, how LeadQuarry secures information and how long it keeps it. Detailed architecture, vendors, keys, thresholds and configurations are deliberately not published.
Governance
We maintain a written, risk-based information-security programme proportionate to our size, systems, data and legal obligations. A designated owner reports material risks to leadership, reviews the programme at least annually and after any material change, and tracks remediation to closure.
Controls
Data and system inventory, classification, ownership and flow mapping.
Minimization and purpose limitation, including deliberate exclusion of unnecessary high-risk fields. Personal information at rest is protected by database-level encryption and TLS in transit rather than application-layer field encryption, a deliberate trade-off that keeps search, scoring and deduplication working.
Role-based least privilege, unique accounts, multi-factor authentication on the administrative consoles used to operate the Services, and periodic access review. Row-level access is scoped by branch and by assignment.
Secure management of secrets, keys, endpoints, backups and configuration. Required secrets are validated at boot and the service fails closed if one is missing or is still a development placeholder.
Logging of administrative access, exports, data deliveries, privacy actions and security events. Every mutation of sensitive fields — phone numbers, email addresses, mailing addresses, do-not-contact status and consent — is written to an immutable audit log.
Vulnerability management, patching, secure development, change control, code review and risk-based testing.
Workforce confidentiality obligations, onboarding, recurring training and prompt offboarding.
Resilient backups, restoration testing, business continuity and disaster recovery.
Incident detection, triage, containment, investigation, evidence preservation, notification assessment and lessons learned.
Secure deletion or irreversible de-identification once retention ends.
Retention Schedule
Raw source snapshots — 30 to 180 days, or shorter where a source requires it.
Active Lead Data — while current and needed, generally 90 to 365 days by category.
Customer account and transaction records — the contract term plus 7 years for tax, accounting, dispute and legal needs.
Consent evidence — the life of the use plus the longest applicable claim and record-keeping period, and never less than 5 years. Consent records are archived immutably, survive deletion of the underlying lead, and are never touched by a retention purge. The TCPA limitations window is approximately four years, and no retention rule is permitted to delete consent or contact evidence inside it.
Do-not-call, opt-out and suppression records — as long as needed to keep honouring the request, held in minimized form and isolated from active marketing data.
Privacy-request identity evidence — deleted promptly after verification; the request and response record is kept for 24 months or longer where required.
Telemarketing and email campaign audit data — at least the longest applicable federal or state period, with 5 years as the contractual baseline.
Security logs — 12 to 24 months, adjusted to risk and capacity.
Backups — a rolling 35 to 90 day cycle, with deletions ageing out through the cycle.
Unsuccessful applicant and prospect data — 12 to 24 months.
Legal holds — until released by counsel.
Retention is a ceiling, not a promise to retain. We may delete earlier where lawful.
Incident Response
Suspected incidents are reported immediately to [email protected]. We activate an incident team, contain without destroying evidence, determine the affected systems, people, jurisdictions and data, coordinate counsel and forensics where warranted, meet our contractual and statutory notice duties, document decisions, remediate, and review lessons learned.
If you experience an incident involving data obtained from the platform, notify us within one business day.