Data Retention and Disposal Policy

Choose Save as PDF as the destination

Movik, Inc. · Information Security Program

Document
Data Retention and Disposal Policy
Version
1.0
Effective date
August 19, 2026
Owner
Security Program Owner (CEO)
Review cycle
Annually, and on material change
Classification
Internal — shareable with partners

1Purpose

This policy defines how long Movik retains data, the basis for each period, and how data is disposed of when that period ends. It exists to satisfy two obligations that pull in opposite directions: Movik must keep financial records long enough to meet its regulatory and contractual duties, and must not keep personal or financial information longer than those duties require. Retaining data without a basis increases the impact of any breach and is itself treated as a risk.

2Scope

This policy applies to all data Movik controls or processes, in every location it is held: the production database, object storage for uploaded documents, backups, application and security logs, transactional messaging systems, support and email correspondence, internal business records, and data held on Movik’s behalf by the third-party providers listed in clause 9. It applies to all personnel and contractors.

3Regulatory context

Movik provides freight invoice financing to commercial motor carriers and brokers. Most of the data Movik holds is business-to-business commercial information, but the records necessarily include personal information about owner-operators, business owners and guarantors. Retention periods in clause 5 are set against the following obligations, as applicable to a given record:

  • The Gramm-Leach-Bliley Act Safeguards Rule, including its requirement to dispose of customer information that is no longer necessary.
  • The Fair Credit Reporting Act and the FTC Disposal Rule, governing the handling and destruction of consumer report information where a consumer report is obtained.
  • Federal and state tax and accounting recordkeeping requirements applicable to financial transactions and executed agreements.
  • Federal Motor Carrier Safety Administration recordkeeping expectations for freight documentation such as bills of lading, rate confirmations and delivery receipts.
  • The Telephone Consumer Protection Act, for records evidencing messaging consent and opt-out.
  • State consumer privacy laws conferring deletion rights, including the California Consumer Privacy Act as amended, to the extent they apply to a given individual and record.
  • Contractual retention and deletion obligations owed to Movik’s banking, data and platform partners.

Where more than one obligation applies to the same record, the longest applicable period governs, and the record is disposed of when that period expires.

4Principles

  • Collect the minimum. Movik requests the information a financing decision and the resulting servicing require, and no more.
  • Every record has a class and a period. Data without an assigned retention period is treated as a defect and classified at the next review.
  • Disposal is the default at expiry. Retention beyond a stated period requires a legal hold under clause 7 or an exception under clause 12.
  • Disposal must be irreversible. A record is disposed of when it cannot be reconstructed from any system Movik controls, including backups, once the window in clause 6.4 has elapsed.

5Retention schedule

Periods run from the trigger stated in each row. “Relationship end” means the date the customer account is closed and all outstanding advances are settled.

DataRetention periodBasisDisposal
Account, contact and business identity records5 years after relationship endGLBA Safeguards; commercial recordkeepingDatabase deletion
Identity verification records and government ID images5 years after relationship endGLBA Safeguards; anti-fraudObject storage deletion; provider deletion request
Business verification records5 years after relationship endGLBA Safeguards; anti-fraudDatabase deletion; provider deletion request
Executed agreements and signed authorizations7 years after termination of the agreementContract enforceability; tax and accountingDatabase and provider deletion
Funding, invoice, settlement and payment records7 years from the transaction dateTax and accounting recordkeepingDatabase deletion
Bank account connection tokensDeleted on customer disconnection, or at relationship endData minimization; partner obligationToken revoked with the provider and deleted from Movik systems
Bank transaction data retrieved for underwriting24 months rolling, or relationship end if earlierData minimization; partner obligationDatabase deletion
Commercial credit assessments and credit reports25 months from the date obtainedFCRA / FTC Disposal Rule alignmentDatabase deletion; secure destruction of any derived copy
Load documents — rate confirmations, bills of lading, delivery receipts3 years after deliveryFMCSA recordkeepingObject storage deletion
Messaging consent and opt-out records4 years after opt-outTCPA limitation periodDatabase deletion
Support and customer correspondence3 years from last contactDispute resolutionDeletion in the mail and support systems
Application, access and security logs12 monthsIncident investigation; access review evidenceAutomatic log expiry
Access review records and offboarding evidence3 yearsAccess Controls Policy clause 11Deletion from internal storage
Database backups35 days (point-in-time recovery window)Business continuityAutomatic expiry
Marketing and prospect contact dataUntil opt-out, then 2 yearsSuppression-list maintenanceDeletion, except the minimum suppression record
Declined or abandoned applications25 months from decisionFCRA alignment; anti-fraudDatabase and object storage deletion

6Disposal methods

6.1 Structured data

Records in the production database are deleted, not flagged as inactive. Where a record must be retained in part for a longer-lived obligation, the fields that are no longer required are cleared and the remaining record is reduced to what the obligation needs.

6.2 Documents and files

Uploaded documents are held in private object storage with no public read path, and are deleted from storage at expiry. Because storage is encrypted at rest under AWS-managed keys, deletion of the object together with expiry of the encryption context renders the content unrecoverable.

6.3 Physical media

Movik operates no data centers and stores no customer data on removable media. Where printed material containing Confidential or Restricted data is produced, it is cross-cut shredded. Company devices are encrypted at rest and are cryptographically erased before disposal or reassignment.

6.4 Backups

Deletion of a live record does not immediately remove it from backups. Backups exist to recover from failure and are not selectively editable, so a deleted record persists in backup media until the backup retention window in clause 5 elapses, after which it is no longer recoverable from any Movik system. Movik does not restore a backup for the purpose of recovering data that has been deleted under this policy, and where a restore is performed for continuity reasons, deletions that had already been applied are reapplied to the restored environment.

7Legal hold

Where Movik becomes aware of actual or reasonably anticipated litigation, a regulatory inquiry, a subpoena, or an internal investigation, the Security Program Owner places the relevant data under legal hold. Data under hold is exempt from scheduled disposal and from deletion requests under clause 8, for the duration of the hold and no longer. Holds are recorded with their scope, the reason, the date imposed and the date released.

8Deletion requests

Individuals may request deletion of their personal information by writing to support@movik.us. Movik verifies the identity of the requester before acting, so that a request cannot be used to destroy or expose another party’s records.

  • Movik acknowledges a request promptly and completes it within the period required by applicable law, and in any event without undue delay.
  • Where a record is subject to a retention obligation in clause 5 or a hold under clause 7, Movik deletes what it can, retains only what the obligation requires, and tells the requester which categories were retained and on what basis.
  • A completed request is passed to the providers in clause 9 that hold the same data on Movik’s behalf.
  • Requests, the verification performed, the action taken and the date are recorded as evidence of compliance.

Customers may disconnect a linked bank account at any time from within the application, which revokes the access token immediately and independently of any broader deletion request.

9Third-party providers

Movik uses specialist providers for bank account connectivity, identity verification, business verification, document execution, commercial credit data and transactional messaging. Each holds only the data its function requires.

  • Provider agreements require the provider to delete or return Movik data on termination, and to process it only on Movik’s instruction.
  • Where a provider holds data subject to a deletion request or to expiry under clause 5, Movik issues a deletion instruction to that provider and records the confirmation.
  • Provider retention practices are examined when the provider is onboarded and at each periodic reassessment. A provider that cannot meet the obligations in this policy is not used for data in scope of it.
  • Movik does not sell customer data.

10Roles and responsibilities

  • The Security Program Owner owns this policy, approves the retention schedule, places and releases legal holds, and confirms that scheduled disposal has occurred.
  • Engineering implements retention and disposal in the systems that hold the data, including automatic expiry where the platform supports it, and reports any data class found without an assigned period.
  • All personnel handle data according to its classification, do not create unmanaged copies of Confidential or Restricted data, and route deletion requests to the process in clause 8.

11Verification

Disposal is verified rather than assumed. At least annually, and as part of the review in clause 13, the Security Program Owner samples data classes from clause 5 and confirms that records past their retention period are no longer present in the live systems, that automatic expiry mechanisms are operating, and that provider deletion confirmations were received where instructions were issued. Findings are tracked to closure in the risk register.

12Exceptions

Retention beyond a period in clause 5, other than under a legal hold, requires written approval from the Security Program Owner and is recorded in the risk register with the reason, the data affected, a compensating control, an owner and an expiry date. Exceptions are reviewed at each cycle and are not renewed by default.

13Review and enforcement

This policy and the retention schedule are reviewed at least annually by the Security Program Owner, and additionally whenever Movik adds a data class, changes a provider, enters a new jurisdiction, or becomes subject to a new regulatory or contractual obligation. Personnel are made aware of this policy on hire and at each material revision, and non-compliance may result in disciplinary action up to termination. Revisions are versioned, and the effective date in the document control block above reflects the current version.

Questions about this policy, or to make a deletion request: support@movik.us.