Data Retention and Disposal Policy
Movik, Inc. · Information Security Program
- Document
- Data Retention and Disposal Policy
- Version
- 1.0
- Effective date
- August 19, 2026
- Owner
- Security Program Owner (CEO)
- Review cycle
- Annually, and on material change
- Classification
- Internal — shareable with partners
1Purpose
This policy defines how long Movik retains data, the basis for each period, and how data is disposed of when that period ends. It exists to satisfy two obligations that pull in opposite directions: Movik must keep financial records long enough to meet its regulatory and contractual duties, and must not keep personal or financial information longer than those duties require. Retaining data without a basis increases the impact of any breach and is itself treated as a risk.
2Scope
This policy applies to all data Movik controls or processes, in every location it is held: the production database, object storage for uploaded documents, backups, application and security logs, transactional messaging systems, support and email correspondence, internal business records, and data held on Movik’s behalf by the third-party providers listed in clause 9. It applies to all personnel and contractors.
3Regulatory context
Movik provides freight invoice financing to commercial motor carriers and brokers. Most of the data Movik holds is business-to-business commercial information, but the records necessarily include personal information about owner-operators, business owners and guarantors. Retention periods in clause 5 are set against the following obligations, as applicable to a given record:
- The Gramm-Leach-Bliley Act Safeguards Rule, including its requirement to dispose of customer information that is no longer necessary.
- The Fair Credit Reporting Act and the FTC Disposal Rule, governing the handling and destruction of consumer report information where a consumer report is obtained.
- Federal and state tax and accounting recordkeeping requirements applicable to financial transactions and executed agreements.
- Federal Motor Carrier Safety Administration recordkeeping expectations for freight documentation such as bills of lading, rate confirmations and delivery receipts.
- The Telephone Consumer Protection Act, for records evidencing messaging consent and opt-out.
- State consumer privacy laws conferring deletion rights, including the California Consumer Privacy Act as amended, to the extent they apply to a given individual and record.
- Contractual retention and deletion obligations owed to Movik’s banking, data and platform partners.
Where more than one obligation applies to the same record, the longest applicable period governs, and the record is disposed of when that period expires.
4Principles
- Collect the minimum. Movik requests the information a financing decision and the resulting servicing require, and no more.
- Every record has a class and a period. Data without an assigned retention period is treated as a defect and classified at the next review.
- Disposal is the default at expiry. Retention beyond a stated period requires a legal hold under clause 7 or an exception under clause 12.
- Disposal must be irreversible. A record is disposed of when it cannot be reconstructed from any system Movik controls, including backups, once the window in clause 6.4 has elapsed.
5Retention schedule
Periods run from the trigger stated in each row. “Relationship end” means the date the customer account is closed and all outstanding advances are settled.
| Data | Retention period | Basis | Disposal |
|---|---|---|---|
| Account, contact and business identity records | 5 years after relationship end | GLBA Safeguards; commercial recordkeeping | Database deletion |
| Identity verification records and government ID images | 5 years after relationship end | GLBA Safeguards; anti-fraud | Object storage deletion; provider deletion request |
| Business verification records | 5 years after relationship end | GLBA Safeguards; anti-fraud | Database deletion; provider deletion request |
| Executed agreements and signed authorizations | 7 years after termination of the agreement | Contract enforceability; tax and accounting | Database and provider deletion |
| Funding, invoice, settlement and payment records | 7 years from the transaction date | Tax and accounting recordkeeping | Database deletion |
| Bank account connection tokens | Deleted on customer disconnection, or at relationship end | Data minimization; partner obligation | Token revoked with the provider and deleted from Movik systems |
| Bank transaction data retrieved for underwriting | 24 months rolling, or relationship end if earlier | Data minimization; partner obligation | Database deletion |
| Commercial credit assessments and credit reports | 25 months from the date obtained | FCRA / FTC Disposal Rule alignment | Database deletion; secure destruction of any derived copy |
| Load documents — rate confirmations, bills of lading, delivery receipts | 3 years after delivery | FMCSA recordkeeping | Object storage deletion |
| Messaging consent and opt-out records | 4 years after opt-out | TCPA limitation period | Database deletion |
| Support and customer correspondence | 3 years from last contact | Dispute resolution | Deletion in the mail and support systems |
| Application, access and security logs | 12 months | Incident investigation; access review evidence | Automatic log expiry |
| Access review records and offboarding evidence | 3 years | Access Controls Policy clause 11 | Deletion from internal storage |
| Database backups | 35 days (point-in-time recovery window) | Business continuity | Automatic expiry |
| Marketing and prospect contact data | Until opt-out, then 2 years | Suppression-list maintenance | Deletion, except the minimum suppression record |
| Declined or abandoned applications | 25 months from decision | FCRA alignment; anti-fraud | Database and object storage deletion |
6Disposal methods
6.1 Structured data
Records in the production database are deleted, not flagged as inactive. Where a record must be retained in part for a longer-lived obligation, the fields that are no longer required are cleared and the remaining record is reduced to what the obligation needs.
6.2 Documents and files
Uploaded documents are held in private object storage with no public read path, and are deleted from storage at expiry. Because storage is encrypted at rest under AWS-managed keys, deletion of the object together with expiry of the encryption context renders the content unrecoverable.
6.3 Physical media
Movik operates no data centers and stores no customer data on removable media. Where printed material containing Confidential or Restricted data is produced, it is cross-cut shredded. Company devices are encrypted at rest and are cryptographically erased before disposal or reassignment.
6.4 Backups
Deletion of a live record does not immediately remove it from backups. Backups exist to recover from failure and are not selectively editable, so a deleted record persists in backup media until the backup retention window in clause 5 elapses, after which it is no longer recoverable from any Movik system. Movik does not restore a backup for the purpose of recovering data that has been deleted under this policy, and where a restore is performed for continuity reasons, deletions that had already been applied are reapplied to the restored environment.
7Legal hold
Where Movik becomes aware of actual or reasonably anticipated litigation, a regulatory inquiry, a subpoena, or an internal investigation, the Security Program Owner places the relevant data under legal hold. Data under hold is exempt from scheduled disposal and from deletion requests under clause 8, for the duration of the hold and no longer. Holds are recorded with their scope, the reason, the date imposed and the date released.
8Deletion requests
Individuals may request deletion of their personal information by writing to support@movik.us. Movik verifies the identity of the requester before acting, so that a request cannot be used to destroy or expose another party’s records.
- Movik acknowledges a request promptly and completes it within the period required by applicable law, and in any event without undue delay.
- Where a record is subject to a retention obligation in clause 5 or a hold under clause 7, Movik deletes what it can, retains only what the obligation requires, and tells the requester which categories were retained and on what basis.
- A completed request is passed to the providers in clause 9 that hold the same data on Movik’s behalf.
- Requests, the verification performed, the action taken and the date are recorded as evidence of compliance.
Customers may disconnect a linked bank account at any time from within the application, which revokes the access token immediately and independently of any broader deletion request.
9Third-party providers
Movik uses specialist providers for bank account connectivity, identity verification, business verification, document execution, commercial credit data and transactional messaging. Each holds only the data its function requires.
- Provider agreements require the provider to delete or return Movik data on termination, and to process it only on Movik’s instruction.
- Where a provider holds data subject to a deletion request or to expiry under clause 5, Movik issues a deletion instruction to that provider and records the confirmation.
- Provider retention practices are examined when the provider is onboarded and at each periodic reassessment. A provider that cannot meet the obligations in this policy is not used for data in scope of it.
- Movik does not sell customer data.
10Roles and responsibilities
- The Security Program Owner owns this policy, approves the retention schedule, places and releases legal holds, and confirms that scheduled disposal has occurred.
- Engineering implements retention and disposal in the systems that hold the data, including automatic expiry where the platform supports it, and reports any data class found without an assigned period.
- All personnel handle data according to its classification, do not create unmanaged copies of Confidential or Restricted data, and route deletion requests to the process in clause 8.
11Verification
Disposal is verified rather than assumed. At least annually, and as part of the review in clause 13, the Security Program Owner samples data classes from clause 5 and confirms that records past their retention period are no longer present in the live systems, that automatic expiry mechanisms are operating, and that provider deletion confirmations were received where instructions were issued. Findings are tracked to closure in the risk register.
12Exceptions
Retention beyond a period in clause 5, other than under a legal hold, requires written approval from the Security Program Owner and is recorded in the risk register with the reason, the data affected, a compensating control, an owner and an expiry date. Exceptions are reviewed at each cycle and are not renewed by default.
13Review and enforcement
This policy and the retention schedule are reviewed at least annually by the Security Program Owner, and additionally whenever Movik adds a data class, changes a provider, enters a new jurisdiction, or becomes subject to a new regulatory or contractual obligation. Personnel are made aware of this policy on hire and at each material revision, and non-compliance may result in disciplinary action up to termination. Revisions are versioned, and the effective date in the document control block above reflects the current version.
Questions about this policy, or to make a deletion request: support@movik.us.