Data management policy
1. Purpose
To ensure that information is classified, protected, retained, and securely disposed of in accordance with its importance to the organization.
2. Scope
All Posted data, information, and information systems, including the user data Posted processes through Google APIs and the financial data derived from it.
3. Policy
Posted classifies data and information systems in accordance with legal requirements, sensitivity, and business criticality in order to ensure that information is given the appropriate level of protection. Data owners are responsible for identifying any additional requirements for specific data or exceptions to standard handling requirements.
Information systems and applications shall be classified according to the highest classification of data that they store or process.
4. Data classification
To help the Posted team easily understand requirements associated with different kinds of information, three classes of data are used.
Confidential
Highly sensitive data requires the highest levels of protection. Access is restricted to specific team members or roles, and these records can only be passed to others with approval from the data owner or management. Examples include:
User data, including email content and attachments accessed through Gmail, files stored through Google Drive, and the financial data derived from them
Personally identifiable information
Company financial and banking data
Salary, compensation, and payroll information
Authentication credentials
Secrets and private keys
Source code
Litigation data
Contracts
Google user data is always confidential and is additionally subject to the Limited Use requirements of the Google API Services User Data Policy, as described in the Posted privacy policy.
Restricted
Proprietary information requiring thorough protection. Access is restricted to team members with a need to know based on business requirements. This data can only be distributed outside the company with approval. This is the default for all company information unless stated otherwise. Examples include:
- Internal policies
- Legal documents
- Internal reports
- Slack messages
- Product roadmap
Public
Documents intended for public consumption which can be freely distributed outside the company. Examples include:
- Marketing materials
- Product descriptions
- External facing policies
5. Data handling
Confidential data handling
Confidential data is subject to the following protection and handling requirements:
Access is restricted to specific team members, roles, or departments
Confidential systems shall not allow unauthenticated or anonymous access
Confidential user data shall not be used or stored in non-production systems or environments
Confidential data shall be encrypted in transit over public networks
Mobile device hard drives containing confidential data, including laptops, shall be encrypted
Mobile devices storing or accessing confidential data shall be protected by a log-on password or passcode and shall be configured to lock the screen after five minutes of non-use
Backups shall be encrypted
Confidential data shall not be stored on personal phones or devices or removable media including USB drives, CDs, or DVDs
Hard drives and mobile devices used to store confidential information must be securely wiped prior to disposal or physically destroyed
Transfer of confidential data to people or entities outside the company shall only be done in accordance with a legal contract or arrangement, and the explicit written permission of management or the data owner, and, for Google user data, only within the limits of the Google user data section of the Posted privacy policy
Human access to user Gmail or Google Drive data is limited to the narrow cases set out in the Posted privacy policy: the user's clear agreement, for example to help with a support issue, security, or legal compliance. Access shall be revoked when no longer needed
Restricted data handling
Restricted data is subject to the following protection and handling requirements:
Access is restricted to users with a need to know based on business requirements
Restricted systems shall not allow unauthenticated or anonymous access
Transfer of restricted data to people or entities outside the company or authorized users shall require management approval and shall only be done in accordance with a legal contract or arrangement, or the permission of the data owner
Hard drives and mobile devices used to store restricted information must be securely wiped prior to disposal or physically destroyed
Public data handling
No special protection or handling controls are required for public data. Public data may be freely distributed.
6. Data retention
Posted shall retain data as long as there is a need for its use, or to meet regulatory or contractual requirements. Once data is no longer needed, it shall be securely disposed of or archived. Retention periods shall be documented in the data retention matrix in appendix B to this policy.
7. Data and device disposal
Data classified as restricted or confidential shall be securely deleted when no longer needed.
All restricted and confidential data shall be securely deleted from company devices prior to, or at the time of, disposal.
8. Annual data review
Management shall review data retention requirements during the annual review of this policy. Data shall be disposed of in accordance with this policy.
9. Legal requirements
Under certain circumstances, Posted may become subject to legal proceedings requiring retention of data associated with legal holds, lawsuits, or other matters as stipulated by Xero Legal. Such records and information are exempt from any other requirements specified within this data management policy and are to be retained in accordance with requirements identified by Xero Legal. All such holds and special retention requirements are subject to annual review with Xero Legal to evaluate continuing requirements and scope.
10. Policy compliance
Compliance with this policy will be measured and verified through various methods, including but not limited to business tool reports and both internal and external audits.
11. Exceptions
Requests for an exception to this policy must be submitted to and authorized by an engineering manager for approval. Exceptions shall be documented.
12. Violations and enforcement
Any known violations of this policy should be reported to the product lead. Violations of this policy can result in immediate withdrawal or suspension of system and network privileges and disciplinary action in accordance with company procedures, up to and including termination of employment.
Appendix A: internal retention and disposal procedure
The engineering managers are responsible for setting and enforcing the data retention and disposal procedures for Posted managed accounts. Posted team devices are Xero managed devices, and device collection, reprovisioning, and secure erasure follow Xero IT procedures.
User accounts
User data shall be deleted within 30 days:
1. Upon request by the user, or
2. If the user's account is deleted.
When a user revokes Posted's access to their Google account, ingestion of Google user data stops immediately. Previously ingested data remains subject to the standard retention rules and is deleted on user request or account deletion, except where retention is required by law.
Account deletion deletes the account's entire ledger, including all journals, rather than redacting individual entries.
Deleted data may persist in encrypted backups for up to 90 days after deletion, after which it is purged as backups cycle.
Devices
1. Team member devices will be collected within 1 business day upon a team member's departure.
2. Collected devices will be cleared to be reprovisioned and securely erased in accordance with Xero IT procedures.
3. Device images may be retained at the discretion of management for business purposes.
Destroying devices or electronic media
In cases where a device is damaged in a way that prevents access to erase the drive, an e-waste service that includes data destruction with a certificate may be used. Certificates of destruction will be kept on record for one year. Physical destruction can be optional if it is verified that the device is encrypted with full disk encryption, which would negate the risk of data recovery.
Management will review this procedure at least annually.
Appendix B: data retention matrix
Posted production service (GCP) | User data, including Google user data, derived financial data, books, and journals | 30 days after user deletion request or account deletion, except where retention is required by law. Encrypted backups purge within 90 days
Posted logs and telemetry | Application, security, and audit log data | 12 months
Support mailbox (support@posted.ai) | Support requests and cases | 24 months after case resolution
Rootly | Incident records and timelines | Indefinite, reviewed in the annual data review |
GitHub | Source code and resolution tags | Indefinite
Waitlist and marketing list | Waitlist signups and marketing preferences | Until opt-out or 24 months of inactivity
