Lynq Data Retention Policy
Effective date: 08/20/2026
Last updated: 08/20/2026
This Data Retention Policy explains how Lynq retains, deletes, restores, and backs up customer data.
This document is a business draft and should be reviewed by legal counsel before publication.
1. Purpose
Lynq stores operational business records for commercial real estate risk management. This policy is designed to:
- Preserve active customer records needed for business operations.
- Support auditability and recovery from accidental deletion or data loss.
- Reduce unnecessary retention of obsolete data.
- Clarify how backups, trash, audit logs, and tenant data are handled.
2. Scope
This policy applies to:
- Company tenant records
- Users and role assignments
- Properties, policies, claims, lawsuits, acquisitions, proposals, and related notes
- Documents, email originals, email attachments, chat attachments, logos, and signature images
- Imported Outlook conversations and metadata
- Tasks, messages, calendar items, deadlines, reports, and audit logs
- Database backups and Blob Storage backups
3. General Retention Rule
Customer Data is retained for as long as the customer account remains active, unless:
- The customer deletes it.
- The customer requests deletion.
- Lynq purges it under this policy.
- A legal, security, contractual, or operational reason requires longer retention.
4. Active Records
Active business records are retained while the customer account is active.
Examples:
- Properties
- Policies
- Claims
- Lawsuits
- Documents
- Saved emails
- Tasks
- Calendar items
- Messages
- Acquisition and proposal records
Customers should not use Lynq as the only place to store legally required original documents unless their internal policies allow it.
5. Trash And Soft-Deleted Records
When supported by the app, deleted records are first moved to Trash instead of immediately destroyed.
Default trash retention:
- Minimum suggested retention: 30 days
- Recommended business retention: 90 days
- Final value: 90 days
Admins may restore deleted records during the trash retention period. Admins may also permanently delete records if that control is enabled.
Some linked data may need separate restoration. For example, restoring a deleted property may also require restoring related folder records, document metadata, email metadata, and Blob Storage files.
6. Uploaded Files And Blob Storage
Uploaded files and binary objects are stored in private Azure Blob Storage.
Examples:
- Uploaded documents
- Email `.eml` originals
- Email attachments
- Chat attachments
- Company branding images
- Email signature images
Blob Storage may use:
- Soft delete
- Versioning
- Point-in-time restore
- Azure Backup for Blobs
Blob restore capability depends on Azure configuration, backup policy, and retention settings.
7. Database Backups
Lynq production records are stored in Azure PostgreSQL.
Database protection includes:
- Azure PostgreSQL point-in-time restore, currently configured for up to 35 days where supported.
- Scheduled `pg_dump` exports to private Azure Blob Storage.
- Restore drill workflows to confirm backups are usable.
Database backups contain all tenants in the database at the time of backup. Restoring from database backup creates or uses a restored copy of the database. It should not overwrite production until data is verified.
8. Tenant-Specific Recovery
For a single company data-loss incident, the preferred recovery process is selective tenant restore:
- Identify the affected tenant, records, and approximate incident time.
- Restore the database to a temporary server or database from before the incident.
- Connect to the restored database from inside the Azure private network.
- Locate the missing tenant records.
- Export only the affected tenant records or record set.
- Restore any needed Blob Storage files.
- Import the recovered data into production.
- Verify in Lynq with the customer admin.
- Delete the temporary restore resources after validation.
Full production rollback should be reserved for system-wide corruption or catastrophic failure.
9. Audit Logs
Audit logs are retained to support security, compliance, troubleshooting, and accountability.
Default audit log retention:
- Recommended minimum: 1 year
- Recommended business retention: 3 to 7 years depending on customer requirements
- Final value: 7 years
Admins may have tools to search audit logs by date range and item name. Clearing audit history should be restricted to authorized admins and should itself create an audit entry where practical.
10. Authentication And Security Logs
Authentication, API, system, diagnostic, and security logs may be retained separately from business records.
Default operational log retention:
- Application logs: 90 days
- Security logs: 1 year
- Error monitoring events: 90 days
These logs may include user identifiers, tenant identifiers, IP addresses, request metadata, and error details. They should not intentionally contain passwords, secrets, or full sensitive document contents.
11. Microsoft 365 Data
Lynq stores Microsoft 365 data only as needed for enabled features.
Examples:
- Imported Outlook conversations
- Email metadata and attachments saved into Lynq
- Microsoft message IDs used to sync already-saved conversations
- Calendar event IDs used to update Outlook calendar items
If a company disconnects Microsoft 365 integrations, already-imported Lynq records may remain in Lynq unless deleted by the customer or removed under this policy.
12. Account Termination
After customer termination, Lynq may retain customer data for a limited transition period to support export, billing, legal obligations, security review, and recovery.
Default termination retention:
- Export window: 30 days
- Backup retention after termination: 90 days, subject to backup cycles
- Final deletion target: 90 days after termination, unless legally required to retain longer
Customers should request exports before the end of the export window.
13. Legal Holds
If data is subject to a legal hold, investigation, dispute, subpoena, regulatory request, or preservation obligation, Lynq may suspend deletion until the hold is released.
Legal holds override normal retention periods.
14. Backup Limitations
Backups are designed for recovery, not routine browsing.
Important limitations:
- Database backups may contain all tenants, so access must be restricted.
- Blob backups and database backups may have different timestamps.
- Restoring a file may require restoring both the database metadata and the Blob Storage object.
- Some deleted data may remain in backups until backup retention expires.
- Selective restore may require engineering or administrator assistance.
15. Secure Disposal
When data reaches the end of its retention period and is not subject to a legal hold or operational exception, Lynq will delete or purge it using the deletion tools available in the relevant system.
Final deletion from backups occurs according to backup expiration schedules and cloud provider retention behavior.
16. Customer Responsibilities
Customers are responsible for:
- Deciding what data to place in Lynq.
- Maintaining their own legal record-retention requirements.
- Reviewing deleted records before permanent deletion.
- Promptly reporting accidental deletion, unauthorized access, or missing records.
- Exporting data before termination if required.
17. Review Schedule
This policy should be reviewed at least annually and whenever Lynq materially changes its storage, backup, tenant, Microsoft 365, or deletion architecture.