When a subject rights request is received, information must be collected in order to respond to the request. To maintain an auditable log of received requests and the responses they received, non-personal record data, including the unique request identifier, request dates, status, and the actions taken, is retained indefinitely.
Information that may fall into the category of personal information is subject to the retention limits below. Retaining it for the full period allows the requester to appeal a decision and to continue accessing the secure messaging portal, and allows Osano's customers to demonstrate how a request was handled.
Information Collected | Retention Limit |
Requester Email | 730 Days |
Requester First Name | 730 Days |
Requester Last Name | 730 Days |
Requester Phone Number | 730 Days |
Requester Type (Customer, Employee, etc.) | 730 Days |
Request Description | 730 Days |
Requester Country of Residence | 730 Days |
Requester State/Province/Territory | 730 Days |
Requester PII – Custom Field | 730 Days |
Requester Sensitive PII – Custom Field | 730 Days |
Requester non-PII – Custom Field | 730 Days |
Requester Proof of Identity/Other Attachments | 730 Days |
Requester Secure Messaging Portal Attachments | 730 Days |
Subject Rights Manager Secure Messaging Portal Attachments | 730 Days |
Subject Rights Manager Request Attachments | 730 Days |
Subject Rights Manager Attachments on Action Items | 730 Days |
Subject Rights Assignee Attachments on Action Items | 730 Days |
Automated Data Store Summary Files on Action Items | 730 Days |
Automated Data Store Deletion Files on Action Items | 730 Days |
Reporting Dashboard Metrics (aggregate, non-identifying) | Indefinitely |
Unique Request Identifier (non-identifying) | Indefinitely |
Note: Data processing and storage occur in AWS (Virginia, US).
Once the 730-day period is reached, all personal information listed above is permanently deleted from the platform. All attachments listed above are deleted on the same schedule.
The only element retained after deletion is the unique number assigned to identify the request within the Osano platform. This identifier contains no personal information and is kept indefinitely to preserve the auditable log of requests received and responses given.