# Data Handling & Retention Policy **Effective:** 2026-03-15 **Owner:** Engineering & Operations ## Purpose Define how TowerOps stores, processes, backs up, and disposes of customer data to ensure reliability, compliance, and trust. ## Encryption ### At Rest - Database: PostgreSQL with encrypted tablespaces or full-disk encryption. - Secrets (API keys, SNMP communities, integration tokens): encrypted using application-level encryption (`Cloak` or equivalent) before storage. - Backups: encrypted before writing to storage. ### In Transit - All external connections over TLS 1.2+. - Internal service-to-service: TLS or encrypted tunnel (Cloudflare Tunnel, WireGuard). - SNMP v3 preferred where supported; v1/v2c community strings treated as secrets. ## Backups - Database: daily automated backups with point-in-time recovery. - Backup retention: 30 days. - Backup restoration tested quarterly. - Backups stored in a separate location from primary data. ## Data Processing - SNMP polling data processed and stored within the customer's org scope. - No cross-org data aggregation without explicit anonymization. - Metrics downsampled after retention window (raw → hourly → daily). - Background jobs operate within org context; job payloads contain `org_id`. ## Data Disposal - Deleted records soft-deleted for 30-day grace period, then hard-purged. - Purge jobs run nightly to remove expired soft-deleted records. - Customer account deletion triggers full data purge after grace period. - Credentials from revoked integrations deleted immediately (no grace period). ## Access Controls - Role-based access: `owner`, `admin`, `member`, `viewer`. - API tokens scoped to organization; cannot access other orgs. - Token rotation supported; old tokens invalidated on rotation. - Session timeout: 24 hours idle, 7 days absolute. ## Audit Trail - All data mutations logged: who (user/agent), what (action), when (timestamp), context (org, resource). - Audit logs immutable — append-only, no deletion. - Retained for 1 year minimum.