Purpose & Scope
This policy governs how Kisner Media Solutions LLC ("the Company") retains, minimizes, and deletes personal and business data across all of its systems — the marketing site, the Client Portal, the internal operations platform (HR, Finance, Legal), and connected third-party services (for example, Stripe, PayPal, a connected business bank via Plaid, Resend, and Cloudflare). It covers data about clients, prospects, employees, and contractors, in any format. For what we collect and why, see our Privacy Policy; to exercise your rights, see Data Deletion.
Principles
Data minimization. We collect only what we need for a defined purpose. Purpose limitation. Data is kept only while that purpose — or a specific legal, tax, or dispute obligation — remains active. Storage limitation. When the retention period ends, data is deleted or irreversibly anonymized. Security by default. Sensitive data is encrypted at rest and access is restricted to authorized personnel for as long as it is retained.
Retention Schedule
We retain each category of data for the period below, after which it is deleted or anonymized. Where a legal obligation (such as tax recordkeeping) requires a longer period, that obligation controls.
| Data Category | What It Includes | Retention Period | Basis |
|---|---|---|---|
| Client account & project data | Portal accounts, project files, deliverables, messages | Engagement + 30 days | Contract / service delivery |
| Contact & lead data | Name, email, phone, company from forms & the Website Audit | Until deletion, or 24 mo. inactive | Consent / legitimate business |
| Advertising / analytics events | Hashed (SHA-256) conversion events sent to Meta Pixel / CAPI | Per Meta; opt-out anytime | Consent (cookie banner) |
| Payment & transaction records | Invoices, Stripe/PayPal charges, bank transaction records | 7 years | Tax & audit law |
| Payroll & tax records | W-2 / 1099 records, SSNs, compensation records | 7 years after tax year | IRS / state recordkeeping |
| Employee HR records | Personnel files, policy acknowledgments, onboarding docs | Employment + 4 years | Federal recordkeeping |
| Authentication credentials | Password hashes (PBKDF2), enrolled passkeys / WebAuthn keys | Life of account | Security / account access |
| Session tokens | Login sessions and short-lived tokens | Auto-purged on expiry | Security |
| Security & audit logs | Access logs, SSN-reveal audit, admin action records | ≈ 90 days (longer if under investigation) | Security / accountability |
| Support & communications | Email threads, support tickets, chat history | Relationship + 24 months | Service & dispute records |
Periods are maximums, not commitments to hold data for the full term; we delete sooner when the purpose ends or on a valid deletion request, except where law requires otherwise.
Secure Deletion, Disposal & Enforcement
Retention and deletion are enforced by real controls, not just intent:
Cascading deletion. Deleting a client or account removes the associated records from our primary database and purges the out-of-band stores that database cannot reach — uploaded files in object storage (R2) and cached entries in our key-value store (KV). Automatic expiry. A scheduled maintenance job continuously purges expired login sessions. Post-engagement purge. Client project data is permanently purged 30 days after a project ends. Encryption & access control. Passwords are stored only as salted PBKDF2 hashes; sensitive credentials and tokens are AES-256-GCM encrypted at rest; access to sensitive fields (such as SSNs) is restricted and every reveal is logged to an audit trail. Verified requests. Deletion requests are verified and fulfilled within 30 days.
Your Rights & Requests
You may request access to, correction of, or deletion of your personal information, and you may opt out of non-essential tracking at any time. To make a request, follow the steps on our Data Deletion page or email reply@kisnermediasolutions.com. There is no cost, and we confirm when the request is complete. We may retain the minimum information the law requires (for example, tax or transaction records) and anonymized data that no longer identifies you.
Legal Basis
Kisner Media Solutions LLC operates in the United States and serves U.S. clients, so this policy is written to comply with the California Consumer Privacy Act (CCPA/CPRA) and applicable U.S. federal and state recordkeeping law (including IRS and Department of Labor retention requirements). We do not knowingly target or establish operations in the EU/UK, so the GDPR does not apply; even so, our minimization, deletion, and security practices are designed to meet a high standard. This policy is informational and not legal advice.
Review & Governance
This policy is owned by Kisner Media Solutions LLC and is reviewed at least annually— and whenever a material change to our systems, data flows, or applicable law occurs. Each review is recorded by updating the version number and the "Last Reviewed" / "Next Review" dates at the top of this page. Version 1.0 — last reviewed July 2026; next scheduled review July 2027. Questions about this policy: reply@kisnermediasolutions.com.