Data Security & Retention Policy

Last Updated: June 15, 2025
Effective Date: June 15, 2025
Scope: All Aevum News Users & Subscribers

1. Introduction

Aevum News is committed to protecting the confidentiality, integrity, and availability of your personal and usage data. This policy outlines the technical and organizational measures we implement to safeguard your information, as well as our data retention, processing, and deletion practices.

Our Commitment We treat data protection as a core editorial and operational value. Every system, process, and third-party integration is evaluated against strict security and privacy benchmarks before deployment.

2. Security Infrastructure

Our digital infrastructure is engineered to prevent unauthorized access, data breaches, and service disruptions. Key security controls include:

3. Encryption & Protection

All sensitive data is encrypted both in transit and at rest using industry-standard cryptographic protocols:

Data State Encryption Standard Key Management
In Transit TLS 1.3 / HTTPS Automated certificate rotation (Let's Encrypt / DigiCert)
At Rest AES-256-GCM HSM-backed keys, separated from data storage
Backups AES-256 + Hash Verification Geo-redundant, immutable storage with 30-day versioning

4. Data Retention Schedule

We retain personal and usage data only for as long as necessary to fulfill the purposes outlined in our Privacy Policy, comply with legal obligations, and resolve disputes. Retention periods are strictly enforced via automated lifecycle management:

Data Category Retention Period Storage Location
Account & Profile Data Duration of account + 12 months Primary EU/US Cloud Regions
Subscription & Payment Records 7 years (tax/legal compliance) Encrypted financial ledger
Reading History & Preferences 24 months of activity Analytics cluster (aggregated after 6 months)
Server & Security Logs 90 days SIEM platform (read-only access)
Customer Support Tickets 3 years Secure helpdesk database

5. Data Deletion & Anonymization

When data reaches the end of its retention period, or upon valid user request, it undergoes one of the following processes:

  1. Secure Deletion: Overwritten using cryptographic erasure standards (NIST SP 800-88 Rev. 1). Database records are permanently purged, and backup copies are marked for exclusion during the next restoration cycle.
  2. Anonymization: Where legally permissible, data may be transformed into anonymized datasets for editorial analytics, trend reporting, or system optimization. Re-identification is technically and procedurally prevented.
  3. Archival Exceptions: Data subject to legal holds, ongoing investigations, or regulatory requirements is segregated and retained until the obligation expires.

6. User Rights & Controls

Under GDPR, CCPA, and equivalent frameworks, you have the following rights regarding your data:

Self-Service Portal Most data rights can be exercised instantly through your privacy dashboard. No account representative is required for standard requests.

7. Compliance & Audits

Aevum News maintains compliance with global data protection standards through continuous governance:

Our compliance reports are reviewed quarterly by an independent data governance board. Summary findings are published annually in our Transparency Report.

8. Contact & Support

For questions regarding this policy, data requests, or security concerns, please reach out to our dedicated Data Protection team:

Data Protection Officer

Email: dpo@aevumnews.com

Security Hotline: security@aevumnews.com

Response Time: Within 2 business days for inquiries, 30 days for data requests