Trust & Security
Data Management Policy
Version 1.0 · Effective: July 16, 2026 · Reviewed annually · Public edition — certain internal operational details have been generalized for publication.
1. Purpose
This policy defines the rules Penusila Digital Solutions LLC ("we," "us," "our") follows for handling data throughout its entire lifecycle: collection, classification, storage, access, sharing, retention, backup, and secure deletion. Its goal is to protect the confidentiality, accuracy (integrity), availability, and privacy of the data entrusted to us — by our customers, our partners, and our own team — across all of our products, including DAF Connect, KLAW, and KlawConnect.
2. Scope
This policy applies to all data created, received, stored, or transmitted by the company — in our products, our internal systems, and our cloud infrastructure — and to every employee, contractor, and service provider who handles that data, wherever they work.
3. Collection
- Data minimization. We collect only the data a product or process actually needs to work. If we don't need it, we don't ask for it, and we don't keep it.
- Transparency. When we collect personal data, we say what we collect and why — in the product and in the applicable privacy policy.
- Lawful basis. Collection of personal data always rests on a lawful basis (consent, contract, or legitimate interest) appropriate to the jurisdiction.
4. Classification
All data is classified into one of four levels, which determine how it must be handled:
- Restricted — data whose exposure would cause serious harm: credentials and keys, financial/banking details, government identifiers, health-related data. Encrypted at rest and in transit, access on strict need-to-know, never in email or chat.
- Confidential — customer records, personal data, contracts, internal security documentation. Encrypted, access-controlled, shared only under agreement.
- Internal — day-to-day business information not intended for the public. Kept within company systems.
- Public — information approved for publication (marketing copy, public documentation).
When in doubt, data is treated at the higher classification until confirmed otherwise.
5. Storage
- Production data lives in approved cloud infrastructure — Amazon Web Services (AWS) for compute and storage, Cloudflare for edge network, DNS, TLS termination, and DDoS/WAF protection, and Base44, our managed application platform (whose backend runs on AWS-based infrastructure) — in data centers independently audited under SOC 2 Type II and ISO 27001.
- All data is encrypted at rest (AES-256 or provider-equivalent) and in transit (TLS 1.2+). No exceptions.
- Company data must not be stored in personal cloud accounts, personal email, or on unencrypted devices or media.
- Local copies of production data are prohibited unless explicitly approved, time-limited, encrypted, and deleted after use.
6. Access
- Least privilege. People get access to the data their role requires — nothing more.
- Multi-factor authentication is required on every system that touches Confidential or Restricted data, including cloud consoles and admin panels.
- Named accounts only. Shared logins are prohibited. Administrative access is limited to named individuals and logged.
- Reviews and revocation. Access rights are reviewed at least annually and revoked immediately on role change or departure.
7. Sharing
- Confidential or Restricted data is shared externally only when there is a business need and an appropriate agreement in place (contract, DPA, or NDA).
- Third-party processors and sub-processors — including our hosting and infrastructure providers (Amazon Web Services, Cloudflare, and Base44) — are vetted for security posture before any data reaches them, and re-reviewed periodically.
- We do not sell personal data. Ever.
- Data shared internally stays inside approved company systems — never personal channels.
8. Retention
- Data is kept only as long as it is needed for the purpose it was collected for, or as long as law or contract requires.
- Each data category has a defined retention period documented in our internal retention schedule; when the period ends, data is securely deleted or anonymized.
- Customers may request deletion of their personal data as described in the applicable privacy policy; verified requests are honored within the legally required timeframe.
9. Backup
- Production data is backed up automatically on a defined schedule, and backups are encrypted with the same standards as live data.
- Backups are stored redundantly within our cloud providers' infrastructure and access to them is restricted and logged.
- Restoration procedures are tested periodically so that backups actually work when needed — availability is a promise, not an assumption.
- Backups expire on the same retention schedule as the data they contain.
10. Secure Deletion
- Digital data is deleted using the provider's secure deletion mechanisms; cryptographic erasure (destroying the keys) is used where supported.
- Devices and drives leaving service are securely wiped or physically destroyed before disposal, resale, or recycling.
- Physical documents containing Confidential or Restricted information are cross-cut shredded — never discarded in regular trash.
- Deletion obligations extend to backups and to data held by processors on our behalf.
11. Incidents
Suspected loss, exposure, or corruption of data must be reported internally within 24 hours. We investigate promptly, contain the issue, and notify affected customers and authorities as required by applicable law.
12. Enforcement & Review
Violations of this policy may result in disciplinary action up to and including termination of employment or contract. This policy is reviewed at least annually and whenever our products, providers, or legal obligations change materially.
13. Contact
Questions about this policy can be sent to hello@penusiladigitalsolutions.org. See also our related policies — Physical Security and Remote Work — and our Security & Data Protection overview.