GOOD LIFE GAMES
Data Retention Policy
Policy Owner: CEO/DPO | Next Review Date: January 1, 2027
1. Purpose and Scope
Good Life Games is committed to retaining personal data and business records only for as long as necessary to fulfill the purposes for which they were collected, comply with applicable legal and regulatory obligations, resolve disputes, and enforce our agreements. This policy establishes clear, documented standards for how long different categories of data are retained, how they are deleted, and who is responsible for managing retention compliance.
This policy applies to all data in any format — digital and physical — including data stored on Company servers, cloud infrastructure, third-party processors, employee devices, backup systems, and paper records.
Objectives
- Minimize data retention risk and comply with GDPR, CCPA/CPRA, CAN-SPAM, and other applicable laws
- Establish consistent, auditable retention standards across the organization
- Ensure personal data is not retained beyond its useful life
- Define clear deletion, anonymization, and legal hold procedures
- Assign accountability for retention policy compliance
2. Legal and Regulatory Framework
This policy is informed by the following legal requirements and frameworks:
- General Data Protection Regulation (GDPR) — Article 5(1)(e): Data must not be kept in a form that permits identification of data subjects for longer than is necessary for the purposes for which it is processed (the “storage limitation” principle).
- California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA): requires disclosure of retention periods and honoring deletion requests.
- CAN-SPAM Act: requires retention of consent and opt-out records sufficient to demonstrate compliance.
- Internal Revenue Service (IRS) / State Tax Requirements: generally require 7 years of financial transaction records.
- Nebraska State Law: applicable state data protection and recordkeeping obligations.
- Contractual Obligations: agreements with payment processors (e.g., PCI DSS) and other service providers may impose retention requirements.
3. Data Retention Schedule
Note: "Anonymization" means irreversibly transforming data so it can no longer be attributed, directly or indirectly, to a specific individual.
| Data Category | Retention Period | Legal / Business Basis | Deletion Method | Exceptions |
|---|---|---|---|---|
| Account Registration Data | Duration of account + 90 days post-closure | Contract performance; legal compliance | Secure overwrite / anonymization | Legal hold; fraud investigation |
| Subscription & Billing Records | 7 years from transaction date | Tax law; financial recordkeeping (IRS, state) | Secure deletion | Active dispute or audit |
| Authentication & Session Logs | 12 months from event date | Security; fraud prevention | Automated log rotation | Active security incident |
| Usage & Engagement Data | 24 months from event date | Service improvement | Aggregated / anonymized | None standard |
| Support & Communication Records | 3 years from ticket close date | Legal defense; service quality | Secure deletion | Active legal proceeding |
| Marketing Records | 5 years from last interaction | CAN-SPAM; GDPR audit trail | Secure deletion | Regulatory audit |
| Backup & Recovery Copies | Maximum 90 days rolling | Business continuity | Overwritten by rotation | Legal hold extension |
| Legal Hold Data | Duration of hold + 1 year post-resolution | Legal obligation | Reviewed and deleted post-hold | Hold supersedes all schedules |
4. Deletion and Destruction Procedures
4.1 Digital Data: Upon expiration of the applicable retention period, digital data shall be permanently and securely deleted using methods that prevent recovery. Acceptable deletion methods include: Secure overwrite (minimum single-pass overwrite); Cryptographic erasure; Physical destruction of storage media where necessary. Deletion must cascade across primary systems, backup copies, and archived data.
4.2 Physical Records: Physical records (if any) containing personal information shall be destroyed via cross-cut shredding or equivalent secure destruction method. Physical destruction should be documented by a Certificate of Destruction.
4.3 Third-Party Processors: All third-party data processors engaged by Good Life Games must be contractually required to adhere to retention periods consistent with this policy.
4.4 Backups: Backup copies of data are subject to a rolling 90-day maximum retention cycle. Automated backup rotation must be configured to overwrite or delete backups exceeding this threshold.
5. Responding to User Deletion Requests
Users may submit a request to delete their personal data at any time by contacting info@goodlifegames.co. Upon receipt of a verified deletion request, we will:
- Acknowledge receipt within 5 business days
- Verify the identity of the requestor before processing
- Complete deletion from all active systems within 30 days
- Identify and document any data retained beyond the request due to a legal exception (e.g., financial recordkeeping)
6. Legal Hold Procedures
A Legal Hold suspends the normal deletion or modification of data when that data may be relevant to litigation, regulatory investigation, or other legal proceeding.
6.1 Triggering a Legal Hold: Holds may be triggered by receipt of a subpoena, court order, notice of lawsuit, or internal decision by management that a proceeding is reasonably anticipated.
6.2 Hold Process: All automated deletion processes and backup rotation are suspended for in-scope data immediately upon issuance of a Legal Hold Notice. Custodians must confirm in writing that data is preserved.
6.3 Releasing a Legal Hold: A legal hold is released only by written authorization from legal counsel. Upon release, data is returned to the standard retention schedule.
7. Roles and Responsibilities
| Role | Responsibilities |
|---|---|
| Policy Owner (CEO / DPO) | Overall accountability; annual review; legal hold authority; regulatory communications. |
| IT / Systems Administrator | Implementing automated deletion; backup rotation; maintaining audit logs of deletions. |
| Finance / Accounting | Maintaining financial record retention per IRS; flagging records under financial hold. |
8. Audit, Review, and Compliance
8.1 Annual Review: This policy shall be reviewed at least annually and updated to reflect changes in practices or law.
8.2 Retention Audit: An internal audit shall be conducted annually to verify retention schedules are followed and legal holds are properly documented.
8.3 Documentation: The Company shall maintain records of deletion activities, user deletion requests, and legal holds.
8.4 Non-Compliance: Violations of this policy may result in disciplinary action up to and including termination of employment or contract.
9. International Data Transfers
Where data is transferred outside the US, Good Life Games ensures adequate protections consistent with GDPR Standard Contractual Clauses.
10. Contact Information
Good Life Games — Policy Owner10842 Old Mill Road, Suite 1, Omaha, NE 68154
Email: info@goodlifegames.co