Lynq Legal Back to app

Lynq Data Retention Policy

Effective date: 08/20/2026

Last updated: 08/20/2026

This Data Retention Policy explains how Lynq retains, deletes, restores, and backs up customer data.

This document is a business draft and should be reviewed by legal counsel before publication.

1. Purpose

Lynq stores operational business records for commercial real estate risk management. This policy is designed to:

  • Preserve active customer records needed for business operations.
  • Support auditability and recovery from accidental deletion or data loss.
  • Reduce unnecessary retention of obsolete data.
  • Clarify how backups, trash, audit logs, and tenant data are handled.

2. Scope

This policy applies to:

  • Company tenant records
  • Users and role assignments
  • Properties, policies, claims, lawsuits, acquisitions, proposals, and related notes
  • Documents, email originals, email attachments, chat attachments, logos, and signature images
  • Imported Outlook conversations and metadata
  • Tasks, messages, calendar items, deadlines, reports, and audit logs
  • Database backups and Blob Storage backups

3. General Retention Rule

Customer Data is retained for as long as the customer account remains active, unless:

  • The customer deletes it.
  • The customer requests deletion.
  • Lynq purges it under this policy.
  • A legal, security, contractual, or operational reason requires longer retention.

4. Active Records

Active business records are retained while the customer account is active.

Examples:

  • Properties
  • Policies
  • Claims
  • Lawsuits
  • Documents
  • Saved emails
  • Tasks
  • Calendar items
  • Messages
  • Acquisition and proposal records

Customers should not use Lynq as the only place to store legally required original documents unless their internal policies allow it.

5. Trash And Soft-Deleted Records

When supported by the app, deleted records are first moved to Trash instead of immediately destroyed.

Default trash retention:

  • Minimum suggested retention: 30 days
  • Recommended business retention: 90 days
  • Final value: 90 days

Admins may restore deleted records during the trash retention period. Admins may also permanently delete records if that control is enabled.

Some linked data may need separate restoration. For example, restoring a deleted property may also require restoring related folder records, document metadata, email metadata, and Blob Storage files.

6. Uploaded Files And Blob Storage

Uploaded files and binary objects are stored in private Azure Blob Storage.

Examples:

  • Uploaded documents
  • Email `.eml` originals
  • Email attachments
  • Chat attachments
  • Company branding images
  • Email signature images

Blob Storage may use:

  • Soft delete
  • Versioning
  • Point-in-time restore
  • Azure Backup for Blobs

Blob restore capability depends on Azure configuration, backup policy, and retention settings.

7. Database Backups

Lynq production records are stored in Azure PostgreSQL.

Database protection includes:

  • Azure PostgreSQL point-in-time restore, currently configured for up to 35 days where supported.
  • Scheduled `pg_dump` exports to private Azure Blob Storage.
  • Restore drill workflows to confirm backups are usable.

Database backups contain all tenants in the database at the time of backup. Restoring from database backup creates or uses a restored copy of the database. It should not overwrite production until data is verified.

8. Tenant-Specific Recovery

For a single company data-loss incident, the preferred recovery process is selective tenant restore:

  1. Identify the affected tenant, records, and approximate incident time.
  2. Restore the database to a temporary server or database from before the incident.
  3. Connect to the restored database from inside the Azure private network.
  4. Locate the missing tenant records.
  5. Export only the affected tenant records or record set.
  6. Restore any needed Blob Storage files.
  7. Import the recovered data into production.
  8. Verify in Lynq with the customer admin.
  9. Delete the temporary restore resources after validation.

Full production rollback should be reserved for system-wide corruption or catastrophic failure.

9. Audit Logs

Audit logs are retained to support security, compliance, troubleshooting, and accountability.

Default audit log retention:

  • Recommended minimum: 1 year
  • Recommended business retention: 3 to 7 years depending on customer requirements
  • Final value: 7 years

Admins may have tools to search audit logs by date range and item name. Clearing audit history should be restricted to authorized admins and should itself create an audit entry where practical.

10. Authentication And Security Logs

Authentication, API, system, diagnostic, and security logs may be retained separately from business records.

Default operational log retention:

  • Application logs: 90 days
  • Security logs: 1 year
  • Error monitoring events: 90 days

These logs may include user identifiers, tenant identifiers, IP addresses, request metadata, and error details. They should not intentionally contain passwords, secrets, or full sensitive document contents.

11. Microsoft 365 Data

Lynq stores Microsoft 365 data only as needed for enabled features.

Examples:

  • Imported Outlook conversations
  • Email metadata and attachments saved into Lynq
  • Microsoft message IDs used to sync already-saved conversations
  • Calendar event IDs used to update Outlook calendar items

If a company disconnects Microsoft 365 integrations, already-imported Lynq records may remain in Lynq unless deleted by the customer or removed under this policy.

12. Account Termination

After customer termination, Lynq may retain customer data for a limited transition period to support export, billing, legal obligations, security review, and recovery.

Default termination retention:

  • Export window: 30 days
  • Backup retention after termination: 90 days, subject to backup cycles
  • Final deletion target: 90 days after termination, unless legally required to retain longer

Customers should request exports before the end of the export window.

13. Legal Holds

If data is subject to a legal hold, investigation, dispute, subpoena, regulatory request, or preservation obligation, Lynq may suspend deletion until the hold is released.

Legal holds override normal retention periods.

14. Backup Limitations

Backups are designed for recovery, not routine browsing.

Important limitations:

  • Database backups may contain all tenants, so access must be restricted.
  • Blob backups and database backups may have different timestamps.
  • Restoring a file may require restoring both the database metadata and the Blob Storage object.
  • Some deleted data may remain in backups until backup retention expires.
  • Selective restore may require engineering or administrator assistance.

15. Secure Disposal

When data reaches the end of its retention period and is not subject to a legal hold or operational exception, Lynq will delete or purge it using the deletion tools available in the relevant system.

Final deletion from backups occurs according to backup expiration schedules and cloud provider retention behavior.

16. Customer Responsibilities

Customers are responsible for:

  • Deciding what data to place in Lynq.
  • Maintaining their own legal record-retention requirements.
  • Reviewing deleted records before permanent deletion.
  • Promptly reporting accidental deletion, unauthorized access, or missing records.
  • Exporting data before termination if required.

17. Review Schedule

This policy should be reviewed at least annually and whenever Lynq materially changes its storage, backup, tenant, Microsoft 365, or deletion architecture.