SOLUTION · SPOTLIGHT Technical SEO & Organic Growth. Crawl architecture, Core Web Vitals, migrations. Bench capacity for teams carrying an open seat. See the capability
Legal

Data Retention Policy

How long we hold client data, how we dispose of it, and how we prove it.

Last updated: September 13, 2026

Purpose and scope

This policy sets out how Innovative Design, LLC, doing business as Innovative Group, retains and disposes of data, including data received from or processed on behalf of clients. It applies to every officer and independent contractor performing work for us, to every system and device used for that work, and to all formats including electronic files, cloud storage, messaging and printed material.

Retention is governed by a single principle. We hold client data for no longer than we need it to deliver the service, and we can evidence its deletion.

Data classification

  • Client Confidential: data received from or generated for a client under a services agreement, such as system extracts, account plans, campaign data and strategy documents.
  • Personal Data: information identifying an individual, whether in a business or personal capacity, such as name, job title, business email and business telephone.
  • Internal: our own operating material containing no client data, such as templates and methods.
  • Public: material intended for publication.

We do not accept or process special category or sensitive personal information, consumer financial account data, lending records, biometric data or precise geolocation data unless expressly agreed in writing in advance.

Retention schedule

  • Client Confidential data, all formats: duration of the engagement plus 90 days.
  • Client system access credentials: duration of the engagement. Surrendered on the final day.
  • Working extracts and analysis files: duration of the engagement plus 90 days.
  • Deliverables issued to the client: duration of the engagement plus 90 days. The client retains its own copy.
  • Contracts and statements of work: seven years from the end of the engagement.
  • Invoices and financial records: seven years.
  • Contractor agreements and attestations: four years after the relationship ends.
  • Security training completion records: three years.
  • Website visitor data: as set out in our Privacy Policy.

Where a client agreement specifies a shorter retention period than the schedule above, the client agreement governs.

Method of disposal

  • Electronic files are deleted from the primary location and from the provider recycle or trash area, so the provider retention window begins immediately.
  • Cloud deletions propagate through provider backup cycles. We confirm the standard backup retention window has elapsed before certifying deletion.
  • Local copies on endpoints are deleted by the individual, who confirms deletion in writing.
  • Printed material is cross-cut shredded.
  • Devices that have held Client Confidential data are cryptographically erased before disposal, transfer or reassignment.

Certification of deletion

On written request, and in any event where a client agreement requires it, we provide a signed certificate of deletion within ten business days of completing disposal. The certificate states the client, the engagement, the categories of data deleted, the date and the systems involved, and is signed by an officer.

As an alternative to deletion, a client may elect return of its data in a usable electronic format, after which deletion proceeds as above.

Legal hold

Where we become aware of actual or reasonably anticipated litigation, regulatory investigation, subpoena or audit, the retention schedule is suspended for the affected records. A legal hold is issued in writing by an officer, records the scope and the reason, and is communicated to everyone holding relevant records. Deletion of records under hold is prohibited until the hold is lifted in writing.

Responsibilities

  • Officer: owns this policy, issues legal holds, signs deletion certificates, reviews annually.
  • Engagement lead: maintains the record of what client data is held and where, initiates disposal at the end of the retention period, collects written confirmation.
  • Contractors: hold the minimum data necessary, store it only in approved locations, delete local copies when instructed and confirm in writing.

Review

This policy is reviewed annually, and on any material change to our services, systems, sub-processors or applicable law.

Entity Information

Innovative Group is a doing business as (DBA) name of Innovative Design, LLC, a California limited liability company, California Entity Number 202102910867. Innovative Design, LLC is the contracting entity for all client engagements.

Registered office: 907 Willow Glen Way, San Jose, CA 95125
Correspondence: 1153 Lincoln Ave E, San Jose, CA 95125
Email: info@innovativegroup.io
Phone: (408) 316-6946