Overview
MetalCore Manufacturing is committed to protecting the personal and business data of our clients, employees, suppliers, and business partners. This Data Retention Policy outlines how we determine how long data is kept, under what conditions it is stored, and when and how it is securely disposed of.
Our policy is designed to ensure compliance with applicable data protection laws including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and industry-specific regulations governing aerospace, medical, and automotive manufacturing data.
Key Principle: We only retain data for as long as necessary to fulfill the purpose for which it was collected, meet legal and regulatory obligations, resolve disputes, and establish, exercise, or defend legal claims. Once the retention period expires, data is securely destroyed or anonymized.
Scope of This Policy
This policy applies to all data processed by MetalCore Manufacturing, including:
- Personal Data: Names, contact information, identification documents, and employment records
- Business Data: Contracts, purchase orders, invoices, and project specifications
- Technical Data: CAD files, engineering drawings, quality reports, and inspection records
- Communication Data: Emails, meeting notes, and customer correspondence
- System Data: IT logs, access records, and network security data
- Financial Data: Payment records, banking details, and tax documentation
Data We Collect
We collect data through our manufacturing operations, customer relationships, and internal processes. The types of data we collect depend on your relationship with us and the services you engage.
For Customers & Clients
- Contact information (name, email, phone, mailing address)
- Company details and business registration information
- Project specifications, CAD files, and engineering requirements
- Procurement records, purchase orders, and contract terms
- Payment and billing information
- Quality feedback and inspection results
- Communication history and support tickets
For Employees & Contractors
- Personal identification and background verification
- Employment contracts and compensation records
- Training certifications and compliance records
- Access control and badge records
- Health and safety incident reports
For Suppliers & Vendors
- Business registration and compliance certificates
- Material certifications and test reports
- Quality audit results and corrective action records
- Payment and invoicing history
Data Minimization: We follow the principle of data minimization β we only collect data that is strictly necessary for our manufacturing and business operations. We regularly review our data collection practices to ensure we are not retaining more data than required.
Data Retention Periods
The table below outlines the standard retention periods for different categories of data processed by MetalCore Manufacturing. These periods are determined by legal requirements, industry standards, and business necessity.
| Data Category | Retention Period | Basis | Classification |
|---|---|---|---|
| Customer Contact Records | Duration of business relationship + 7 years | Business & Legal | Long-term |
| Contracts & Agreements | 10 years after termination | Legal Requirement | Long-term |
| Purchase Orders & Invoices | 7 years after completion | Tax & Financial | Long-term |
| Engineering Drawings & CAD Files | Product lifecycle + 10 years | Business Necessity | Long-term |
| Quality Inspection Reports | 15 years (aerospace) / 7 years (general) | Regulatory (AS9100, ISO 9001) | Regulatory |
| Material Certifications | Duration of product lifecycle | Traceability Requirement | Regulatory |
| Employee Records | 7 years after employment ends | Legal Requirement | Long-term |
| Employee Safety Records | 30 years | OSHA Requirement | Regulatory |
| Email Communications | 3 years from date | Business Practice | Medium |
| IT System Logs | 1 year | Security Monitoring | Short-term |
| Security Camera Footage | 30 days | Facility Security | Short-term |
| Website Analytics Data | 26 months | Operational Analytics | Medium |
| Marketing Consent Records | Until consent withdrawn + 2 years | GDPR Compliance | Medium |
| Supplier Quality Audits | 5 years after last audit | ISO 9001 Requirement | Medium |
| Warranty Claims | Warranty period + 3 years | Contractual Obligation | Medium |
Legal Hold: If we are involved in litigation, a regulatory investigation, or a government subpoena, we may suspend our standard retention periods and preserve all relevant data under a legal hold until the matter is resolved. You will be notified if a legal hold affects your data.
Data Lifecycle Management
Every piece of data we process goes through a structured lifecycle from collection to secure disposal. This ensures consistency, accountability, and compliance at every stage.
Collection
Data collected with clear purpose and consent
Categorization
Data classified and assigned retention schedule
Secure Storage
Encrypted storage with access controls
Usage & Access
Monitored access with audit trails
Review
Regular audits of data necessity
Disposal
Secure destruction or anonymization
Secure Disposal Methods
When data reaches the end of its retention period, we ensure it is disposed of securely using the following methods:
- Digital Data: Secure deletion using NIST 800-88 compliant methods, including cryptographic erasure and overwriting
- Physical Documents: Cross-cut shredding by certified destruction vendors with certificates of destruction
- Storage Media: Physical destruction (degaussing, shredding, incineration) of hard drives, tapes, and removable media
- Cloud Data: Permanent deletion from all cloud infrastructure with confirmation from service providers
Anonymization Alternative: In some cases, rather than destroying data, we may anonymize it for statistical analysis, quality improvement studies, or industry benchmarking. Anonymized data cannot be used to identify individuals and is no longer considered personal data under GDPR.
Security Measures
Protecting retained data is as important as managing how long it is kept. MetalCore Manufacturing implements comprehensive security controls across all data storage systems.
Technical Security Controls
- Encryption at Rest: All stored data encrypted using AES-256 encryption standard
- Encryption in Transit: TLS 1.3 encryption for all data transfers across networks
- Access Controls: Role-based access control (RBAC) with multi-factor authentication (MFA)
- Audit Logging: Comprehensive logging of all data access, modifications, and transfers
- Network Segmentation: Production systems isolated from corporate networks
- Vulnerability Management: Regular penetration testing and automated vulnerability scanning
- Backup & Recovery: Encrypted backups with tested disaster recovery procedures
Organizational Security Measures
- Annual security awareness training for all employees
- Background checks for employees with data access privileges
- Strict confidentiality agreements for all staff and contractors
- Regular internal and external security audits
- Incident response plan with defined escalation procedures
- Clear desk and clear screen policies across all facilities
Certifications: Our information security management system is certified under ISO 27001, and our manufacturing processes comply with AS9100 (aerospace), IATF 16949 (automotive), and ISO 13485 (medical devices) requirements for data integrity.
Your Data Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data held by MetalCore Manufacturing:
Right to Access
Request a copy of all personal data we hold about you, including details of how it is processed.
Right to Rectification
Request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure
Request deletion of your personal data when it is no longer necessary for the original purpose.
Right to Restrict Processing
Request that we temporarily stop processing your data in certain circumstances.
Right to Data Portability
Receive your data in a structured, machine-readable format for transfer to another organization.
Right to Object
Object to processing of your data for direct marketing or other legitimate interest purposes.
Right to Withdraw Consent
Withdraw consent at any time where processing is based on your consent.
Right to Lodge a Complaint
File a complaint with a supervisory authority if you believe your data rights have been violated.
Important Note: Some retention periods are mandated by law (e.g., tax records, safety records, aerospace quality documentation). In these cases, we may not be able to delete your data immediately upon request, but we will restrict its processing and confirm the applicable legal obligation.
Third-Party Data Sharing
We may share data with third-party service providers who assist in our manufacturing and business operations. All third parties are contractually bound to protect your data and process it only according to our instructions.
Categories of Third-Party Recipients
- Cloud Infrastructure Providers: AWS, Microsoft Azure (hosting and data storage)
- ERP & Business Systems: SAP, Oracle (order management and financial processing)
- Logistics & Shipping Partners: Freight carriers and customs brokers for delivery
- Quality Testing Laboratories: Accredited labs for material testing and certification
- Payroll & HR Service Providers: Employee compensation and benefits administration
- IT Security Vendors: Managed security service providers and monitoring tools
- Legal & Accounting Professionals: External advisors providing professional services
International Transfers: Some of our service providers operate outside your country. Where personal data is transferred internationally, we ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission and other legally recognized transfer mechanisms.
Regulatory Compliance
MetalCore Manufacturing's data retention practices are designed to comply with the following laws, regulations, and standards:
- GDPR (EU General Data Protection Regulation): Comprehensive data protection for EU residents, including rights to access, erasure, and portability
- CCPA / CPRA (California Consumer Privacy Act): Privacy rights for California residents including right to know, delete, and opt-out
- FERPA & State Records Laws: Applicable state and federal records retention requirements
- ITAR / EAR (Export Controls): Data handling requirements for defense-related manufacturing
- AS9100 Quality Standard: Aerospace quality management system requiring defined document and record retention
- IATF 16949: Automotive quality management requirements for production part approval and traceability
- OSHA 29 CFR 1910.1020: Employee exposure and medical records retention (30 years for safety data)
- SOC 2 Type II: Service organization controls for security, availability, and confidentiality
Ongoing Compliance Reviews: Our Data Protection Officer and legal team conduct quarterly reviews of this policy and our data practices to ensure ongoing compliance with evolving regulations. Significant changes are communicated to all stakeholders.
Contact Our Data Protection Officer
If you have questions about this Data Retention Policy, wish to exercise your data rights, or need to submit a formal data request, please contact our Data Protection team.
Data Protection Team
Our dedicated team is available to assist with data-related inquiries, subject access requests, and compliance questions. We respond to all requests within 30 days as required by applicable law.
Submitting a Data Request
To submit a formal request regarding your data, please include:
- Your full name and contact information
- Description of the request (access, correction, deletion, etc.)
- Details of the data in question (if known)
- Proof of identity (for verification purposes)
Data Breach Notification: In the unlikely event of a data breach affecting your information, we will notify affected individuals within 72 hours of becoming aware of the breach, as required by GDPR and applicable state laws. You will receive details of what happened, what data was affected, and what steps we are taking.
Policy Updates
MetalCore Manufacturing may update this Data Retention Policy periodically to reflect changes in our operations, technology, or applicable laws. When we make significant changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify registered users via email
- Post a prominent notice on our website
- Provide updated policy documents to business partners upon request
Version History: v3.2 (Jan 2025) β Updated CCPA/CPRA compliance provisions; v3.1 (Jul 2024) β Revised retention periods for IT logs; v3.0 (Jan 2024) β Major overhaul with new data lifecycle framework; v2.8 (Mar 2023) β Added medical device regulatory requirements.