Privacy

Global Data Retention & Deletion Policy

How FanSynQ collects, retains, manages, and permanently deletes personal data and sensitive information.

VersionEffective DateReview CycleClassification
2.0January 1, 2025AnnualPublic

1. Purpose and Scope

This Global Data Retention and Deletion Policy establishes the principles, obligations, and procedures governing how FanSynQ collects, retains, manages, and permanently deletes personal data and other sensitive information. It is designed to ensure full compliance with applicable data protection laws across every jurisdiction in which we operate.

1.1 Purpose

The primary objectives of this Policy are to:

  • Ensure compliance with global privacy and data protection legislation, including but not limited to the GDPR, CCPA/CPRA, PIPL, LGPD, DPDPA, POPIA, PIPA, PDPA, APPI, PIPEDA, nFADP, PDPL, Privacy Act 1988, and all applicable US state privacy laws.
  • Define clear retention periods for each category of personal data, grounded in documented legal bases or legitimate business necessity.
  • Protect the rights of data subjects — including the right to erasure, the right to access, and the right to portability — in accordance with applicable law.
  • Minimize data storage costs, privacy risks, and security exposure by disposing of data that no longer serves its original, documented purpose.
  • Establish a consistent, auditable framework for responding to deletion requests, regulatory inquiries, and litigation holds.

1.2 Scope

This Policy applies to:

  • All personal data and sensitive personal information collected, processed, or stored by FanSynQ in any form — digital, physical, or otherwise.
  • All employees, contractors, consultants, vendors, and third-party processors acting on behalf of FanSynQ.
  • All systems, platforms, databases, cloud environments, backup media, and physical records under FanSynQ's control.
  • All geographic locations and legal entities within the FanSynQ group.

This Policy does NOT override applicable law. Where a specific legal obligation requires longer retention, that obligation takes precedence. Where law requires shorter retention or immediate deletion, that requirement applies.

2. Key Definitions

Personal Data
Any information relating to an identified or identifiable natural person ('data subject'), including name, ID number, location data, online identifiers, or factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity.
Sensitive Personal Data
A special category of personal data requiring heightened protection, including racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, sex life or sexual orientation, and (in some jurisdictions) financial data, precise geolocation, and children's data.
Retention Period
The defined period during which data must be kept based on legal obligation, contractual need, or documented business purpose.
Deletion / Erasure
The permanent, irreversible removal of personal data such that it cannot be reconstructed, accessed, or read by any means. Includes secure overwriting, cryptographic erasure, degaussing, and physical destruction.
Anonymization
An irreversible process of altering data such that the data subject can no longer be identified, directly or indirectly. Anonymized data falls outside the scope of most data protection laws.
Pseudonymization
Replacing directly identifying information with artificial identifiers ('pseudonyms'). Pseudonymized data remains personal data and is subject to this Policy.
Litigation Hold
A legally mandated suspension of normal data deletion processes when litigation, regulatory investigation, or other legal proceedings are reasonably anticipated or have commenced.
Data Subject
The natural person whose personal data is being processed. Includes customers, employees, prospects, suppliers' personnel, and any other identified or identifiable individuals.
Controller
The entity that determines the purposes and means of processing personal data. FanSynQ is typically the controller of data it collects.
Processor
An entity that processes personal data on behalf of the controller. Third-party vendors are often processors subject to Data Processing Agreements (DPAs).
Legal Basis
The lawful ground under which personal data is processed, such as consent, contract performance, legal obligation, vital interests, public task, or legitimate interests.
Right to Erasure
A data subject's right to request deletion of their personal data under qualifying circumstances defined by applicable law.
Records of Processing Activities (RoPA)
A mandatory register under GDPR Article 30 documenting all data processing activities, including purposes, categories, retention periods, and security measures.

3. Governing Regulations and Jurisdictional Framework

FanSynQ is subject to data protection obligations under the laws set out below. This table is not exhaustive and will be updated as new laws come into force. All references to penalties reflect the statutory maximums; actual penalties depend on the nature, gravity, and duration of the infringement.

RegulationJurisdictionKey RightsRetention RequirementsMax Penalty
GDPR (2018)EU / EEA (& UK via UK GDPR)Access, Erasure, Portability, ObjectNo longer than necessary; explicit justification required€20M or 4% global annual turnover
CCPA / CPRA (2020/2023)California, USAKnow, Delete, Opt-Out, Correct, LimitDisclose retention periods in Privacy Policy$2,500–$7,500 per intentional violation
CPRA (2023 amendment)California, USAExpanded sensitive data & contractor obligationsRetention schedules must be publishedSame as CCPA + civil action
PIPL (2021)ChinaAccess, Correction, Deletion, ExplanationDelete when purpose fulfilled; no unnecessary storageUp to ¥50M or 5% annual revenue
LGPD (2020)BrazilAccess, Correction, Anonymization, DeletionRetention for legal obligation or consent period onlyUp to 2% Brazil annual revenue (R$50M cap)
PIPA (2011, amended 2023)South KoreaAccess, Correction, Erasure, WithdrawalDestroy immediately when retention period expiresUp to ₩100M + criminal sanctions
PDPA (2019)ThailandAccess, Erasure, Restriction, PortabilityRetain only as long as necessary for stated purposeUp to THB 5M + criminal liability
APPI (amended 2022)JapanDisclosure, Correction, DeletionDelete when no longer needed; annual disclosure requiredUp to ¥100M organizational fine
PIPEDA / Law 25 (Canada)Canada (federal & Quebec)Access, Correction, ComplaintKeep only as long as needed; defined retention schedulesUp to CAD $100,000 per violation
POPIA (2020)South AfricaAccess, Correction, Object, DeletionNo longer than necessary; records destruction requiredZAR 10M or 10 years imprisonment
DPDPA (2023)IndiaAccess, Correction, Erasure, GrievanceErase when consent withdrawn or purpose servedUp to ₹250 crore per violation
Privacy Act 1988 (amended)AustraliaAccess, Correction, ComplaintReasonable steps to destroy when no longer neededUp to AUD $50M per serious breach
nFADP (2023)SwitzerlandAccess, Portability, Deletion, ObjectDestroy or anonymize when purpose fulfilledUp to CHF 250,000 (personal liability)
PDPL (2021)Saudi Arabia (NDMO)Access, Correction, ErasureDelete after purpose fulfilled; document retention justificationUp to SAR 5M + imprisonment
TDPSA (2024)Texas, USAAccess, Deletion, Portability, Opt-OutReasonable retention schedules requiredUp to $7,500 per violation

Additionally, the following US state laws are applicable or anticipated: Virginia CDPA (2023), Colorado CPA (2023), Connecticut CTDPA (2023), Utah UCPA (2023), Iowa ICDPA (2025), Montana MCDPA (2024), Oregon OCPA (2024), Delaware DPDPA (2025), New Hampshire NHPA (2025), New Jersey NJDPA (2025), and Indiana IDPL (2026). FanSynQ monitors state privacy law developments on an ongoing basis.

4. Data Retention Schedule

Retention periods below represent minimum and maximum standards derived from applicable law, industry standards, and documented business necessity. All periods run from the later of: (a) the date data is collected, (b) the end of the customer/employment relationship, or (c) the last interaction, as noted below.

Data CategoryRetention PeriodLegal BasisDeletion MethodExceptions
Customer account dataDuration of relationship + 7 yearsContract / Legal obligationSecure erasure + audit logActive disputes, regulatory hold
Transaction & payment records7 years (US) / 10 years (EU)Legal obligation (tax/accounting)Cryptographic erasurePending audit or litigation
Employee & HR dataEmployment + 7 yearsLegal obligation / ContractSecure wipe + shred physicalOngoing claims or appeals
Website & app usage logs13 monthsLegitimate interest / ConsentAutomated purgeSecurity investigations
Marketing & consent records3 years post last interactionConsent records (legal basis)Secure erasureActive consent in force
Health & biometric dataAs required + 10 yearsExplicit consent / LegalCertified destructionMedical necessity
Children's data (under 13/16)Minimum necessary / consent periodExplicit consent (parental)Immediate on requestNone – strict deletion
CCTV / surveillance footage30 days (standard)Legitimate interestAutomated overwriteActive incident investigation
Legal & contract records10 years post expiryLegal obligationSecure destructionActive litigation hold
Backup & archived dataPer primary data schedule +90 daysLegal obligation / ContractSecure media destructionDisaster recovery cycles

Important Note on Backup and Archive Data

Data stored in backup systems is subject to the same retention schedules as primary data. Backup purge cycles must be engineered to ensure that data deleted from live systems is also removed from all backups within 90 days (or earlier where required by law).

Where technical constraints prevent real-time backup deletion, the data must be flagged for deletion in the next scheduled purge cycle and access must be restricted.

Logs of deletions performed — but not the deleted data itself — must be retained for audit purposes for a minimum of 7 years.

6. Data Deletion Procedures

All deletion must be performed in accordance with a method appropriate to the sensitivity of the data and the nature of the storage medium. The choice of method must be documented.

6.1 Deletion Methods

MethodDescriptionAppropriate ForStandard
Secure OverwriteMultiple-pass overwriting of storage media with random data patterns, rendering original data irrecoverableHDDs, SSDs, USB drives, on-premise serversNIST SP 800-88, DoD 5220.22-M
Cryptographic ErasureDestruction of encryption keys rendering encrypted data permanently inaccessible without overwritingCloud storage, encrypted databases, mobile devicesNIST SP 800-188
Physical DestructionDegaussing, shredding, disintegration, or incineration of physical mediaPhysical documents, decommissioned hardware, optical mediaISO 21964 / DIN 66399
Database PurgeAutomated scripts that permanently delete records from all tables, views, indexes, logs, and cachesRDBMS, NoSQL databases, data warehousesInternal DBA procedures + audit trail
AnonymizationIrreversible stripping of identifiers such that re-identification is not technically feasibleAnalytics datasets where aggregated data has ongoing valueISO 29101, Art. 29 WP guidance
Certified Vendor DestructionThird-party certified media destruction with chain-of-custody documentation and certificate of destructionEnd-of-life hardware, outsourced storageISO 27001, SOC 2 Type II vendor

6.2 Automated Deletion Schedule

The IT and Data Engineering teams must maintain automated deletion pipelines that:

  • Trigger deletion when retention period expiry dates are reached, without manual intervention.
  • Generate an immutable audit log entry recording: data category, deletion date, method used, responsible system, and authorizing policy section.
  • Cover all environments including production, staging, development, analytics, data lakes, and all backup tiers.
  • Send exception reports to the CPO/DPO within 24 hours when automated deletion fails for any reason.
  • Be tested at least semi-annually and after any major system change.

6.3 Responding to Data Subject Deletion Requests

Where a data subject exercises their right to erasure (right to be forgotten), the following procedure applies:

  1. Verify the identity of the requestor using at least two pieces of identifying information before acting on any request.
  2. Log the request in the Data Subject Request Register, including requestor identity (hashed), date received, request type, and assigned handler.
  3. Acknowledge receipt within 3 business days (or sooner as required by applicable law).
  4. Conduct a legal hold check: verify no active litigation hold, regulatory inquiry, legal obligation, or overriding public interest prevents deletion.
  5. If deletion is permissible, execute deletion across all systems (primary, backup, logs, third-party processors) within the timeframe required by applicable law (typically 30 days under GDPR; 45 days under CCPA/CPRA).
  6. Notify all sub-processors and third-party processors of the deletion requirement and obtain written confirmation of compliance.
  7. Notify the requestor of completion, including a summary of systems from which data was deleted.
  8. Where deletion is refused (e.g., due to legal obligation), provide the data subject with a written explanation and their right to complain to the relevant supervisory authority.
  9. Retain the audit log of the completed request (not the personal data) for 7 years.

6.4 Third-Party and Vendor Deletion

All Data Processing Agreements (DPAs) must include contractual provisions requiring vendors to:

  • Comply with FanSynQ's retention schedules for data processed on our behalf.
  • Delete or return all personal data upon termination of the agreement within 30 days.
  • Confirm deletion in writing, including the method used, within 14 days of completing destruction.
  • Permit FanSynQ to audit deletion procedures on reasonable notice.
  • Notify FanSynQ within 48 hours if they are unable to comply with a deletion instruction for any reason.

8. Data Subject Rights and Response Framework

FanSynQ respects and facilitates the exercise of data subject rights in accordance with applicable law. The following rights are recognized under one or more applicable regulations:

RightDescriptionApplicable LawsResponse Deadline
Right of AccessRequest a copy of personal data held, the purposes of processing, recipients, and retention periodsGDPR, CCPA, PIPL, LGPD, POPIA, all30 days (GDPR); 45 days (CCPA)
Right to ErasureRequest deletion of personal data where no overriding legal basis for retention existsGDPR, CCPA/CPRA, PIPL, LGPD, DPDPA, POPIA30 days (GDPR); 45 days (CCPA)
Right to Rectification / CorrectionRequest correction of inaccurate or incomplete personal dataGDPR, CCPA/CPRA, PIPL, LGPD, POPIA, all30 days (GDPR); 45 days (CCPA)
Right to Data PortabilityReceive personal data in a structured, machine-readable format for transfer to another controllerGDPR, CCPA/CPRA, PIPL, LGPD30 days (GDPR); 45 days (CCPA)
Right to Object / Opt-OutObject to processing for direct marketing or profiling; opt out of sale or sharing of personal dataGDPR, CCPA/CPRA, PIPL, POPIA, allImmediately (opt-out of sale); 30 days (object)
Right to Restrict ProcessingRequest that processing be limited while accuracy is contested or a legitimate interest objection is assessedGDPR, LGPD, POPIA30 days
Right to Non-DiscriminationNot to receive differential service, pricing, or quality for exercising privacy rightsCCPA/CPRA, TDPSA, Virginia CDPA, othersImmediate / ongoing obligation
Right to Withdraw ConsentWithdraw previously given consent at any time; withdrawal does not affect prior lawful processingGDPR, PIPL, PDPA, DPDPA, all consent-based lawsImmediate effect; deletion within 30 days

All data subject requests must be submitted through FanSynQ's designated privacy portal, email address, or written request process. We will verify the requestor's identity before processing any request. Requests may be extended by an additional 30 days (or as permitted by applicable law) for complex or high-volume requests, with written notification to the data subject.

9. Roles and Responsibilities

Effective data retention and deletion requires clear ownership across all organizational levels. The following table defines accountability:

RoleResponsibilitiesAccountability
Board of Directors / Executive LeadershipApprove this policy; ensure adequate resources for compliance; receive annual compliance reportsUltimate legal and fiduciary accountability
Chief Privacy Officer (CPO) / DPOOwn this policy; maintain Records of Processing Activities (RoPA); respond to regulator inquiries; conduct DPIAsRegulatory point of contact under GDPR Art. 37; accountable for breach notifications
Chief Information Security Officer (CISO)Implement and verify secure deletion technologies; maintain audit trails; oversee encryption and key managementTechnical accountability for secure erasure compliance
Legal & Compliance TeamIdentify applicable laws by jurisdiction; manage litigation holds; update policy for law changes; review contractsAccountable for legal obligation mapping and hold management
IT / Data EngineeringExecute automated deletion schedules; maintain backup purge cycles; decommission data systems securelyOperational accountability for deletion execution
Human ResourcesManage employee data retention and destruction; enforce this policy in HR systems; conduct staff trainingAccountable for workforce data compliance
Business Unit / Department HeadsMaintain departmental data inventories; enforce retention schedules within their teams; escalate exceptionsFirst-line accountability for data in their control
All Employees & ContractorsHandle personal data per this policy; report potential breaches; complete mandatory privacy training annuallyIndividual accountability under employment agreements

10. Data Security During Retention and at Deletion

10.1 Security During the Retention Period

While data is retained, it must be protected in accordance with FanSynQ's Information Security Policy and the following minimum standards:

  • All personal data must be encrypted at rest using AES-256 or equivalent, and in transit using TLS 1.2 or higher.
  • Access to personal data must be governed by role-based access control (RBAC) on a need-to-know basis, reviewed quarterly.
  • Sensitive personal data (health, biometric, financial) must be subject to additional access controls, including multi-factor authentication and privileged access management (PAM).
  • All access to personal data must be logged and logs must be retained for a minimum of 12 months (security) and 7 years (audit).
  • Data processing environments must be assessed via Data Protection Impact Assessments (DPIAs) prior to any new high-risk processing activity, as required under GDPR Article 35 and equivalent provisions.

10.2 Security at Deletion

When deleting personal data, the following controls must be applied:

  • Deletion must be performed by a method appropriate to the data sensitivity classification (see Section 6.1).
  • For cloud-stored data, cryptographic erasure (key destruction) supplemented by provider-confirmed deletion is acceptable.
  • Physical media containing personal data must be destroyed by a certified vendor, with a certificate of destruction retained.
  • Prior to disposal or re-use of any hardware, a certified data erasure process must be completed and documented.
  • Employees must not use personal devices or unauthorized cloud services to store personal data subject to this Policy.

11. Cross-Border Data Transfers and Deletion

Where personal data is transferred to processors or sub-processors outside the country of collection, the following additional requirements apply to retention and deletion:

  • Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or equivalent transfer mechanisms must include deletion obligations consistent with this Policy.
  • Where a jurisdiction prohibits or restricts cross-border transfer (e.g., China under PIPL, Russia under Federal Law No. 242-FZ), data must be localized and deletion procedures must be executed within that jurisdiction.
  • Transfer Impact Assessments (TIAs) must evaluate whether the destination country's laws prevent effective deletion or compliance with data subject rights — this includes government access laws and mandatory data retention regulations.
  • Upon termination of any cross-border processing arrangement, the receiving entity must confirm deletion in writing within 30 days.
  • FanSynQ maintains a cross-border transfer register documenting all international transfers, legal mechanisms relied upon, and deletion confirmation records.

12. Data Breach Procedures Relating to Retained Data

The volume and sensitivity of retained data directly affects breach risk and regulatory notification obligations. This section addresses the intersection of data breach management and retention practices.

12.1 Notification Timelines

RegulationNotification WindowAuthority NotificationIndividual Notification
GDPR72 hoursTo lead supervisory authority (DPA) within 72 hours of awarenessWithout undue delay if high risk to individuals
CCPA/CPRANo defined windowAttorney General enforcement; cure period may applyExpedient notification to affected CA residents
PIPL (China)Immediately / promptTo cybersecurity authority promptlyNotify individuals if risk to rights/interests
LGPD (Brazil)No specific periodTo ANPD within reasonable timeframeTo affected individuals when relevant
DPDPA (India)As prescribedTo Data Protection Board as prescribed by RulesTo affected data principals as prescribed
POPIA (South Africa)As soon as reasonably possibleTo Information RegulatorTo affected data subjects
PIPA (S. Korea)Without delay / 72 hoursTo PIPC within 72 hours for large breachesNotify data subjects without delay
Privacy Act (Australia)30 days to assessTo OAIC if eligible data breachTo affected individuals if serious harm likely

Following any confirmed data breach, FanSynQ must conduct a Post-Incident Review within 30 days that specifically assesses whether: (a) the breached data should have already been deleted under this Policy; (b) retention periods for the affected data category should be shortened; and (c) security controls during retention were adequate.

13. Training and Awareness

All personnel with access to personal data must complete training on data retention and deletion obligations. Training requirements by role are:

AudienceTraining ContentFrequencyCompletion Requirement
All employees and contractorsGeneral data protection awareness; this Policy overview; how to respond to data subject requests; breach reportingAnnually + onboardingWithin 30 days of hire; annually thereafter
IT / Data EngineeringSecure deletion techniques; automated purge systems; encryption and key management; backup purge cyclesAnnually + on system changeRole-specific certification required
Legal & ComplianceJurisdiction-specific law updates; litigation hold procedures; cross-border transfer rules; regulatory changesSemi-annuallyContinuing legal education credit eligible
HR professionalsEmployee data retention rules; subject access request handling; biometric and health data requirementsAnnuallyHR data handler certification
CPO / DPO / Privacy teamAdvanced regulatory developments; enforcement trends; DPIA methodology; international transfer mechanismsQuarterly briefingsOngoing professional development
Executive leadershipBoard-level privacy accountability; regulatory penalty landscape; reputational risk of non-complianceAnnuallyExecutive briefing completion

Training completion records must be retained for a minimum of 5 years as evidence of compliance.

14. Audit, Monitoring, and Compliance Verification

14.1 Internal Audit

The Privacy and Compliance team must conduct a comprehensive internal audit of this Policy's implementation at least annually. The audit must verify:

  • Accuracy and completeness of the Records of Processing Activities (RoPA) and data inventory.
  • That automated deletion pipelines are functioning correctly across all environments.
  • That data subject deletion requests were completed within required timeframes, with documented outcomes.
  • That litigation holds were properly issued, maintained, and released.
  • That third-party processors have confirmed compliance with deletion obligations.
  • That training completion rates meet the thresholds set out in Section 13.
  • That any deviations from retention schedules are documented, justified, and authorized.

14.2 Audit Documentation

Audit reports must be presented to the Board of Directors or Audit Committee annually. Reports must include: findings, risk ratings, remediation actions, owners, and target completion dates. Audit records must be retained for 7 years.

14.3 Key Performance Indicators

KPITargetMeasurement Method
Data subject deletion requests completed on time100%Data Subject Request Register
Automated deletion pipeline success rate>99.5%IT exception reports
Staff privacy training completion rate>98%LMS completion records
Third-party deletion confirmations received100% within 45 daysVendor management system
Litigation hold issuance time after triggering event<24 hoursLegal hold register timestamps
DPIA completion rate for new high-risk processing100%DPIA register
Data inventory accuracy (audit verified)>95%Annual data mapping audit

15. Policy Governance, Review, and Updates

15.1 Review Cycle

This Policy must be formally reviewed at least annually by the CPO/DPO and Legal team. An expedited review must be triggered by:

  • Enactment of a new applicable data protection law or significant regulatory guidance.
  • A material change to FanSynQ's data processing activities, systems, or geographic footprint.
  • A significant data breach or enforcement action by a regulatory authority.
  • Findings from an internal audit, external audit, or data subject complaint.

15.2 Version Control

VersionDateAuthorSummary of Changes
1.0January 1, 2024Privacy TeamInitial policy adoption covering GDPR, CCPA/CPRA, and PIPL.
1.5July 1, 2024Privacy TeamAdded DPDPA (India), TDPSA (Texas), updated US state law table.
2.0January 1, 2025CPO / LegalComprehensive global update; added breach notification table; revised deletion methods; expanded roles matrix.

15.3 Policy Hierarchy

This Policy operates within the following governance framework:

  • Information Security Policy — governs data security controls during retention.
  • Privacy Notice / Privacy Policy — public-facing disclosure of retention periods and rights.
  • Data Processing Agreements (DPAs) — contractual retention and deletion obligations for processors.
  • Records of Processing Activities (RoPA) — operational record of processing purposes and periods.
  • Incident Response Policy — governs breach response and notification procedures.
  • Employee Handbook — incorporates employee data handling obligations.

In the event of conflict between this Policy and a more specific operational document, the more protective standard applies unless legal counsel determines otherwise.

16. Exceptions and Deviation Process

Deviations from the retention periods set out in Section 4 are permitted only in the following circumstances and must be formally authorized:

Exception TypeJustification RequiredAuthorization LevelMaximum Duration
Extended Retention – Legal ObligationCitation to specific law, regulation, or court order requiring extended retentionLegal counsel + CPODuration of obligation
Extended Retention – Business NeedDocumented business justification; DPIA if special category data involved; LIA if legitimate interest basisCPO + relevant Business Head + Legal1 year (renewable)
Shortened RetentionEvidence that original basis no longer applies; no litigation hold; no regulatory obligationCPOImmediate effect
Litigation Hold ExtensionWritten assessment from Legal that matter remains active or resolution is uncertainGeneral CounselDuration of matter
Research / Archiving ExceptionEthics board approval; appropriate safeguards (anonymization/pseudonymization); documented public interestCPO + Ethics CommitteePer research timeline

All approved exceptions must be recorded in the Exception Register and reviewed at each annual policy review. Exceptions not renewed within their authorized duration must revert to the standard schedule.

17. Consequences of Non-Compliance

Failure to comply with this Policy may result in:

  • Disciplinary action up to and including termination of employment or contract, in accordance with applicable employment law and FanSynQ's disciplinary procedures.
  • Civil or criminal liability under applicable data protection law, which may be imposed personally on individuals as well as FanSynQ.
  • Regulatory investigation, enforcement action, and fines by data protection authorities — up to the maxima set out in Section 3.
  • Reputational damage to FanSynQ, resulting in loss of customer trust, business relationships, and market value.
  • Litigation costs, court sanctions, and adverse judgments resulting from spoliation of evidence or failure to respect data subject rights.
  • Mandatory remediation orders, processing bans, or temporary restrictions on data processing activities.

FanSynQ does not indemnify employees or contractors against personal liability arising from intentional or grossly negligent violations of this Policy.

Questions?

If you have questions or concerns regarding this Policy, please contact us.

Email support@fansynq.com