Data Governance, Retention, and Deletion Policy
Applies to H2H Technologies
Effective Date: October 24, 2025
Purpose
This Data Protection & Retention Policy describes how H2H Technologies (“H2H Technologies,” “we,” “us,” or “our”) manages the collection, retention, protection, and deletion of data processed through the YouNegotiate platform.
Scope
This policy applies to all personal, financial, operational, and system data processed or stored by H2H Technologies via the YouNegotiate platform, including data related to consumers, creditors, vendors, and platform users.
Data Categories
H2H Technologies may process the following categories of data:
- Personal identifiers (name, email, phone number, address)
- Account and balance information provided by creditors
- Payment-related metadata (processed via third-party providers)
- Communication records and audit logs
- Uploaded documents and correspondence
- System, device, and usage information
- Data Protection Principles
H2H Technologies applies the following principles to data processing:
- Data minimization – collecting only data necessary to provide services
- Purpose limitation – using data only for legitimate business purposes
- Access restriction – limiting access based on role and necessity
- Security safeguards – protecting data against unauthorized access or disclosure
- Data Retention Periods
H2H Technologies retains data for defined periods based on operational, legal, and compliance needs:
- Account and communication records – retained for compliance and audit purposes
- Payment metadata – retained as required by financial and tax regulations
- Security and access logs – retained for monitoring and incident investigation
- Backup data – retained according to business continuity requirements
Retention periods may vary based on contractual obligations, regulatory requirements, or litigation holds.
Data Deletion and Disposal
When data is no longer required, H2H Technologies follows secure deletion or anonymization practices designed to prevent unauthorized recovery. Deletion may be delayed when required by law or legal holds.
User Rights and Requests
Depending on applicable law, users may request access to, correction of, or deletion of personal data. Requests are handled in accordance with H2H Technologies’ Privacy Policy and applicable legal requirements.
Data Transfers and Storage
Data is stored and processed primarily in the United States. Third-party service providers may be used for hosting, processing, or communications and are contractually required to protect data.
Incident Response and Breach Handling
In the event of a data security incident involving personal information, H2H Technologies follows its Incident Response procedures and will provide notifications as required by applicable law.
Regulatory Alignment
This policy supports compliance with applicable U.S. laws and standards, including GLBA, state privacy laws such as CCPA/CPRA, and industry security best practices.
Policy Updates
This policy may be updated periodically to reflect changes in operations, technology, or regulatory requirements. Updates will be communicated as appropriate.