Data Retention, Deletion and Secure Destruction Policy
Document control
Policy title: Data Retention, Deletion and Secure Destruction Policy
Organisation: flowprofiler® Pty Ltd
Policy owner: Rebecca Chalmers, Executive Sponsor
Operational lead: Rebecca Chalmers, Data Protection Lead
Assurance lead for AI systems and agents: Bronwyn, AI Agent Compliance, Governance and Assurance Manager
Version: 1.0
Effective date: 20 July 2026
Review date: July 2027, or earlier following a material change (see Section 24)
1. Purpose
flowprofiler® Pty Ltd is committed to retaining personal information and confidential business information only for as long as it is reasonably required, and to deleting, destroying or de-identifying it securely when it is no longer needed.
This policy explains how we manage the end of the information lifecycle, including:
– regular review of retained information
– deletion from active systems
– de-identification
– disposal of paper records
– sanitisation or destruction of electronic media and equipment
– management of cloud systems and backups
– use of specialist destruction providers
– legal and contractual holds
– client-controlled assessment information
– evidence that destruction has been completed
This policy should be read with our Privacy Policy, Data Protection Policy and Data Retention and Destruction Schedule.
2. Who we are
flowprofiler® Pty Ltd provides workplace psychometric assessments, behavioural profiles, reports, training, coaching, professional development and related technology.
Privacy contact
flowprofiler® Pty Ltd
33 Oxley Crescent, Mollymook Beach, 2539 Australia
Email: hello@flowprofiler.com
3. Scope
This policy applies to personal information and confidential information held or processed by flowprofiler® Pty Ltd in any format, including information held in:
– assessment and survey platforms
– client and participant accounts
– reports and document repositories
– websites and online forms
– customer relationship and marketing systems
– email and approved collaboration systems
– learning and training platforms
– accounting and payment systems
– employment and contractor records
– support systems
– development, test and production environments
– approved artificial intelligence systems
– system and security logs
– cloud-storage and software services
– backups and archives
– computers, mobile devices and removable media
– paper files and handwritten records
The policy applies to directors, employees, contractors, trainers, consultants, authorised practitioners, system administrators, suppliers and any other person handling information for or on behalf of flowprofiler® Pty Ltd.
4. Our roles
Our responsibilities depend on whether flowprofiler® Pty Ltd acts as a controller or processor.
Where flowprofiler® acts as controller
flowprofiler® Pty Ltd generally determines retention and destruction requirements for information relating to:
– its websites and enquiries
– direct customers and client contacts
– contracts, invoices and business records
– trainers, practitioners and suppliers
– marketing preferences
– job applicants, employees and contractors
– security and access records
– privacy requests and complaints
– governance and compliance
– its own approved research and product-development activities
Where flowprofiler® acts as processor
Where an employer, client or other organisation commissions an assessment, survey or programme, that organisation will generally determine why the participant information is processed and how long it should be retained.
In those circumstances, flowprofiler® Pty Ltd will normally:
– follow the client’s documented and lawful retention instructions
– apply the applicable Data Processing Agreement
– retain information only for the agreed service period
– return, delete or de-identify information as agreed
– preserve information where a lawful hold applies
– manage relevant subprocessors
– provide reasonable evidence that deletion has been completed
A client instruction will not be followed where it would require flowprofiler® Pty Ltd to breach applicable law.
5. Retention principles
flowprofiler® Pty Ltd applies the following principles.
5.1 Purpose-based retention
Information must be retained only while it is reasonably needed for an identified:
– service-delivery purpose
– client instruction
– contractual obligation
– legal or regulatory requirement
– accounting or taxation obligation
– professional or certification record
– security purpose
– dispute or claim
– approved research purpose
– other documented and lawful business purpose
Information must not be retained indefinitely merely because it may be useful in the future.
5.2 Data minimisation
Systems and records should contain only the information reasonably required for their authorised purpose.
Duplicate, obsolete, temporary and unnecessary copies should be removed as soon as reasonably practicable.
5.3 Defined retention periods
Retention periods and their starting points are documented in the flowprofiler® Data Retention and Destruction Schedule.
The schedule identifies, where relevant:
– the record category
– the purpose for which it is retained
– whether flowprofiler® acts as controller or processor
– the event that starts the retention period
– the default retention period
– the system or location
– the responsible owner
– the disposal method
– any applicable legal-hold requirements
5.4 Regular review
Retention arrangements must be reviewed:
– at least annually
– when a new product or system is introduced
– when a supplier changes
– when a client contract changes
– when information is moved or migrated
– following a relevant privacy or security incident
– when legal requirements change
– when the original processing purpose ends
6. When information will be deleted, destroyed or de-identified
Personal information will be considered for secure deletion, destruction or de-identification when:
– the applicable retention period expires
– the purpose for which it was collected has ended
– a client lawfully instructs flowprofiler® Pty Ltd to delete or return it
– an account or service relationship ends
– information was collected unintentionally and is not required
– information is duplicated or obsolete
– a valid deletion request applies
– consent is withdrawn and no other lawful reason for retention applies
– a system or supplier is retired
– equipment or storage media is to be reused, transferred or disposed of
– a review determines that continued retention is no longer necessary or proportionate
Deletion will not proceed where information must lawfully be retained.
7. Circumstances that may delay or prevent deletion
Information may be retained beyond its ordinary period where reasonably necessary because of:
– a legal or regulatory obligation
– a court, tribunal or regulator requirement
– an actual or anticipated legal claim
– an insurance matter
– a contractual dispute
– a privacy request or complaint
– an active personal data breach investigation
– an internal investigation
– a client’s lawful instruction
– a requirement to establish, exercise or defend legal rights
– fraud or security monitoring
– an approved research or statistical purpose using appropriate safeguards
– another documented legal hold
A legal or operational hold must be:
– authorised
– documented
– limited to the relevant information
– reviewed periodically
– released when the reason for the hold no longer applies
Once a hold is released, the information returns to its normal retention and destruction process.
No person may delete, conceal, alter or destroy information because a complaint, access request, investigation, dispute or legal proceeding has been made or is reasonably anticipated.
8. Secure deletion from active systems
Deleting a record must remove it from ordinary operational use and prevent unauthorised recovery using methods appropriate to the system and risk.
Depending on the system, secure deletion may include:
– deletion through an approved administrative function
– deletion from databases and document repositories
– removal of accounts and access rights
– deletion of exported or downloaded copies
– expiration of secure links
– deletion from synchronised devices
– deletion from local recycle bins or deleted-item folders
– deletion through a supplier’s verified deletion process
– cryptographic erasure
– deletion of encryption or access keys
– secure overwrite or sanitisation
– physical destruction of the storage medium
Merely hiding a record, removing a shortcut or deactivating an account does not necessarily constitute deletion.
The responsible system owner must understand what the relevant system’s deletion function actually does.
9. Cloud services and software providers
Where information is stored or processed through a cloud or software provider, flowprofiler® Pty Ltd will take reasonable steps to establish:
– where the information is stored
– whether deletion removes the information from active systems
– whether deleted information remains in replicas, caches or archives
– the provider’s backup-retention period
– how account closure is handled
– whether exports or local copies exist
– whether subprocessors retain copies
– whether deletion can be verified
– what happens to information when the supplier agreement ends
Where flowprofiler® Pty Ltd acts as processor, supplier deletion must also be consistent with applicable client instructions and contractual commitments.
A supplier must not be treated as having deleted information merely because flowprofiler® has lost access to the supplier account.
10. Backups and disaster-recovery copies
Backups are maintained for security, resilience and service-recovery purposes and may not permit selective deletion of an individual record without affecting the integrity of the backup.
Where immediate removal from a backup is not reasonably practicable:
– the information must be deleted from active systems
– the backup must remain protected and access restricted
– the information must not be restored to ordinary operational use
– any restoration must reapply applicable deletion instructions
– the backup must expire or be overwritten according to the approved backup cycle
– the backup period must not be extended merely to preserve information that should otherwise be deleted
Backups must not be used as an alternative archive or as a means of avoiding approved retention periods. Backup cycles and restoration procedures must be documented and periodically tested.
11. De-identification
Removing a person’s name alone does not necessarily de-identify information. Information will be treated as personal information where an individual remains reasonably identifiable from the information itself or when it is combined with other reasonably available information.
Information may be retained in de-identified form where:
– continued use has a legitimate and authorised purpose
– identifiable information is no longer required
– de-identification is appropriate for the information and intended use
– direct identifiers are removed or transformed
– linkage keys are destroyed or separately protected
– unnecessary variables are removed or generalised
– small groups and unusual combinations are considered
– the likelihood of re-identification is assessed
– access and use remain appropriately controlled
De-identified information used for psychometric validation, norming, benchmarking or research must be subject to documented governance approval.
12. Assessment and survey information
Assessment and survey information must be destroyed or de-identified in accordance with:
– the applicable client agreement
– the Data Processing Agreement
– the Participant Notice
– the Data Retention and Destruction Schedule
– product-specific requirements
– applicable privacy law
The following must be considered separately because they may require different retention periods or disposal methods:
– participant identity and contact information
– assessment invitations
– raw item responses
– scores and dimension results
– generated reports
– 360-degree rater identities
– rater comments
– team or organisational reports
– report-download links
– client exports
– support copies
– de-identified research or benchmark data
A client’s downloaded copy of a report is under the client’s control after lawful delivery. flowprofiler® Pty Ltd remains responsible for copies retained within its own systems and for ensuring clients receive appropriate information about secure retention and disposal.
13. Artificial intelligence systems
Personal information, assessment content and client-confidential information may be processed only through an approved artificial intelligence system and for an authorised purpose.
When an AI-supported task is complete, prompts, attachments, retrieved information and outputs must be retained only for the approved period.
Where deletion is required, the process must consider:
– conversation history
– uploaded files
– temporary working data
– vector or retrieval stores
– logs
– tool outputs
– local exports
– provider retention
– provider model-training settings
– connected systems
Deleting a visible conversation does not necessarily establish that every provider or connected-system copy has been deleted.
AI-agent permissions must not override retention, deletion, legal-hold or destruction controls.
14. Paper records
Paper containing personal or confidential information must be:
– stored securely until no longer required
– kept out of ordinary waste and recycling bins
– destroyed using cross-cut shredding or another approved secure-destruction method
– protected during collection and transport
– handled only by authorised personnel
– disposed of in an environmentally responsible manner after secure destruction
Small quantities may be destroyed using an approved internal shredder.
Bulk or highly confidential paper records should be destroyed by an appropriately assessed specialist provider.
Paper records must not be left unattended in unsecured destruction bins, vehicles or public areas.
15. Electronic media and equipment
Electronic media and equipment must be sanitised or destroyed before it is:
– reused
– reassigned
– returned to a supplier
– donated
– sold
– recycled
– discarded
– otherwise released from flowprofiler® control
This includes:
– desktop and laptop computers
– internal and external drives
– solid-state drives
– mobile telephones and tablets
– removable USB media
– memory cards
– optical media
– backup tapes
– network and storage equipment
– printers or scanners with internal storage
– any other device capable of retaining information
The disposal method must take account of:
– the type of media
– the sensitivity of the information
– whether the equipment will be reused
– the effectiveness of available sanitisation methods
– whether encryption was properly implemented
– the ability to verify the result
– the consequences of unsuccessful sanitisation
Equipment may be reused only where sanitisation has been completed and verified. Where reliable sanitisation cannot be completed or verified, the media must be physically destroyed through an approved process.
16. Sanitisation methods
Sanitisation methods may include:
– Clear: Logical methods that protect against ordinary non-invasive recovery and allow the media to remain usable.
– Purge: Stronger methods intended to make recovery infeasible using advanced technical methods while potentially allowing the media to be reused.
– Destroy: Physical destruction that makes the media unusable and makes recovery of the information infeasible.
The selected method must be appropriate to the media, information classification and intended destination.
Formatting a device or using an ordinary delete command will not be treated as sufficient unless the system owner has verified that the method provides an appropriate level of sanitisation for the relevant technology and risk.
17. Lost, damaged or inaccessible equipment
A device or storage medium that is:
– lost
– stolen
– damaged
– inaccessible
– unable to complete sanitisation
– returned without confirmation of deletion
– unaccounted for during disposal
must be reported immediately to the Data Protection Lead and Technical Owner.
The incident must be assessed under the Data Breach Response Plan. Disposal must not be treated as complete merely because equipment is broken or no longer functions.
18. Third-party destruction providers
A specialist destruction or recycling provider may be used where appropriate.
Before appointment, flowprofiler® Pty Ltd will conduct due diligence proportionate to the information and risk.
The review may consider:
– the provider’s experience and reputation
– security and privacy controls
– collection and transport arrangements
– chain-of-custody controls
– personnel access
– subcontracting
– destruction and recycling methods
– facility security
– incident-response arrangements
– insurance
– certifications or independent assurance
– evidence of destruction
– the countries in which information or equipment will be handled
A written agreement must address, where relevant:
– confidentiality
– authorised processing
– security requirements
– incident notification
– subcontractors
– transport and custody
– return or destruction
– evidence and audit rights
– compliance with applicable privacy and environmental requirements
19. Chain of custody
Where records, equipment or media are transferred for destruction, reasonable chain-of-custody controls must be maintained.
These may include:
– a disposal authorisation
– asset or batch identifiers
– an inventory
– sealed containers
– authorised collection
– transfer records
– receipt confirmation
– tracking
– controlled storage
– destruction confirmation
– reconciliation of exceptions
Any unexplained discrepancy must be investigated immediately.
20. Evidence of destruction
Material or high-risk destruction activities must be recorded in the Destruction and Disposal Log.
The record should include, where applicable:
– the disposal date
– the record category or asset
– the system or location
– the authorised retention decision
– the relevant date range or batch
– the destruction or de-identification method
– the person who authorised the activity
– the person or provider who completed it
– evidence of completion
– any exception or failure
– verification that the process was completed
A certificate of destruction should be obtained from a specialist provider where appropriate.
A certificate does not remove flowprofiler® Pty Ltd’s responsibility to select and oversee the provider appropriately.
The destruction record must not reproduce the personal information that has been destroyed.
21. Individual requests for deletion
Individuals may have rights to request deletion or erasure in certain circumstances. Those rights are not absolute.
Before acting on a request, flowprofiler® Pty Ltd will consider:
– whether it acts as controller or processor
– whether the relevant client must decide the request
– the applicable legal basis
– contractual and statutory retention requirements
– legal claims and holds
– third-party rights
– security requirements
– the technical systems involved
– whether deletion, restriction or de-identification is the appropriate response
Where flowprofiler® Pty Ltd acts solely as processor, the request will normally be referred to the relevant client controller and flowprofiler® will provide reasonable assistance.
22. Roles and responsibilities
The Data Protection Lead is responsible for:
– overseeing this policy
– maintaining or supervising the retention schedule
– advising on legal holds and deletion requests
– reviewing material exceptions
– coordinating privacy and breach matters
– approving high-risk destruction arrangements
– monitoring compliance
The Technical Owner is responsible for:
– maintaining secure deletion and sanitisation procedures
– documenting cloud and backup deletion behaviour
– confirming that system settings support the retention schedule
– removing access and credentials
– verifying device sanitisation
– managing technical suppliers
– escalating failures or discrepancies
Record and system owners are responsible for:
– identifying records within their control
– applying the approved retention period
– preventing unauthorised deletion
– initiating disposal when the period expires
– confirming legal holds
– maintaining appropriate evidence
– reporting any problem promptly
Everyone handling flowprofiler® information must:
– use approved systems
– avoid unnecessary local copies
– delete temporary working information when no longer required
– use secure disposal methods
– never place confidential information in ordinary waste
– report lost equipment or failed deletion
– comply with legal holds
– cooperate with audits and investigations
23. Failure or suspected disclosure during destruction
Any actual or suspected:
– loss of records or equipment
– unauthorised access
– incomplete destruction
– misdirected collection
– chain-of-custody failure
– recovery of information thought to have been deleted
– supplier failure
– unexpected restoration of deleted information
– unauthorised disclosure during disposal
must be reported immediately and handled under the Data Breach Response Plan. Destruction activity must be suspended where continuing could increase the risk or compromise evidence.
24. Monitoring and review
Compliance with this policy may be monitored through:
– retention reviews
– system and supplier audits
– deletion testing
– backup-restoration testing
– asset reconciliation
– sampling of disposal records
– review of destruction certificates
– access-log review
– incident analysis
– review of client deletion instructions
Material findings must be assigned an owner and completion date.
This policy will be reviewed:
– at least annually
– following a significant deletion or destruction failure
– following a material change to systems, suppliers or processing
– when entering a new jurisdiction
– following a relevant legal change
– when monitoring identifies that the policy no longer reflects actual practice
25. Non-compliance
Failure to comply with this policy may result in:
– withdrawal of access
– corrective training
– disciplinary action
– termination of a contract or supplier relationship
– notification to a client
– regulatory notification
– recovery of reasonable losses
– legal action
depending on the circumstances and applicable law.
No person will be penalised for reporting a genuine concern in good faith.
26. Related documents
This policy should be read with:
– Privacy Policy
– Data Protection Policy
– Data Retention and Destruction Schedule
– Data Processing Agreement
– Data Breach Response Plan
– Subject Access and Individual Rights Procedure
– Data Protection Complaints Procedure
– Information Security Policy
– Acceptable Use Policy
– Secure Development and Change Management Policy
– Supplier and Subprocessor Register
– AI Governance Policy
– AI Agent Permissions Register
27. Contact
Questions, deletion requests or concerns relating to information retention or destruction may be directed to:
Data Protection Lead
flowprofiler® Pty Ltd
Email: hello@flowprofiler.com
