DATA RETENTION & SECURITY POLICY

This Data Retention & Security Policy (“Policy”) outlines the principles and procedures followed by Creed Financial Crimes Compliance Firm, LLC (“Creed”, “we”, “our”, or “us”) regarding the collection, retention, storage, protection, and disposal of personal and sensitive data. This policy ensures our compliance with applicable state, federal, and international laws—including the Maryland Personal Information Protection Act (PIPA), Gramm-Leach-Bliley Act (GLBA), GDPR, and other relevant data security frameworks.

1. Purpose

The purpose of this policy is to:

2. Scope

This Policy applies to:

3. Legal & Regulatory Compliance

Creed’s data retention and security practices are designed to comply with:

4. Data Categories & Retention Periods

#

Data Category

Examples

Retention Period

1

Client Identifiable Data (CID)

Name, email, phone, address, consultation notes

7 years from last activity or engagement

2

Financial Transaction Records

Invoices, payments, wire confirmations

7 years (IRS and audit compliance)

3

Compliance Data (AML/KYC)

ID documents, risk assessments, reports

5–10 years depending on jurisdiction

4

Employment Applications

Resumes, background checks, references

2 years if not hired

5

Employee Records

Contracts, payroll, benefits, performance reviews

7 years post-employment

6

Website Analytics & Cookies

IP addresses, session data, traffic logs

12–26 months, per GDPR/analytics config

7

Marketing & CRM Data

Newsletters, contact forms, outreach interactions

Until opt-out or 5 years inactivity

8

Legal Correspondence

Notices, claims, contracts, litigation records

10 years from final resolution

Note: If required by law or litigation hold, data may be retained longer.

5. Secure Storage and Access Controls

Creed maintains a multi-layered information security architecture designed to ensure:

5.1. Technical Safeguards

5.2. Physical Safeguards

5.3. Organizational Safeguards

6. Third-Party Access and Cloud Storage

We only share personal and sensitive data with trusted, vetted third-party service providers under binding contracts that:
Examples include:

7. Data Disposal & Destruction

When data retention periods expire—or when requested by the data subject under valid legal grounds—we permanently delete or destroy data using industry-standard methods.

8. Breach Notification and Incident Response

In the event of a data breach, Creed will:

9. Your Rights Under Applicable Laws

Depending on your jurisdiction, you may have the right to:
To exercise these rights, email us at info@creedfinancialcrimescompliancefirm.com.

10. Policy Review and Updates

This policy is reviewed annually or upon changes in law, data practices, or company operations. Major updates will be posted on our website and communicated via email where appropriate.
Last updated:6/23/2025
Scroll to Top