← Vortoc

Data Security & Retention Policy

1. Governance


Vortoc maintains a written, risk-based information-security program appropriate to its size, systems, data, and legal obligations. A designated security owner reports material risks to leadership, reviews the program at least annually and after material changes, and tracks remediation to closure.


2. Minimum controls


The program includes data and system inventory, classification, ownership, and flow mapping; minimization and purpose limitation, including exclusion of unnecessary high-risk fields; role-based least privilege, unique accounts, multifactor authentication for privileged and remote access, and periodic access review; encryption in transit and at rest using current, appropriate methods; secure secrets, key, endpoint, backup, and configuration management; logged administrative access, exports, data deliveries, privacy actions, and security events; vulnerability management, patching, secure development, change control, code review, and risk-based testing; vendor diligence, contractual safeguards, access limits, incident notice, and deletion verification; workforce confidentiality, onboarding, recurring training, and prompt offboarding; resilient backups, restoration tests, business continuity, and disaster recovery; incident detection, triage, containment, investigation, evidence preservation, notification assessment, and lessons learned; and secure deletion or irreversible deidentification when retention ends.


Personal information at rest is protected by database-level encryption together with transport encryption rather than application-layer field encryption. Every change to a sensitive field, including phone numbers, email addresses, mailing addresses, do-not-contact status, and consent, is written to an audit log.


Detailed architecture, vendors, keys, thresholds, and configurations are deliberately not published, because publishing them would increase attack risk.


3. Baseline retention schedule


Raw source snapshots: 30 to 180 days, or shorter where a source or right requires it.


Active Lead Data: while current and needed, generally 90 to 365 days by category.


Customer account and transaction records: the contract term plus 7 years for tax, accounting, dispute, and legal needs.


Consent evidence: the life of the use plus the longest applicable claim and recordkeeping period, and never less than 5 years. Consent records are archived immutably, survive deletion of the related record, and are never removed by a retention purge. The TCPA limitations window is approximately four years, and no retention rule may delete consent or contact evidence inside it.


Do-not-call, opt-out, and suppression records: as long as needed to honor the request, stored in minimized form and isolated from active marketing data.


Privacy-request identity evidence: deleted promptly after verification, retaining the request and response record for 24 months or longer if required.


Telemarketing and email campaign audit data: at least the longest applicable federal or state period, with 5 years as the default contractual baseline.


Security logs: 12 to 24 months, adjusted to risk and capacity.


Backups: a rolling 35 to 90 day cycle, with deletions aging through the cycle.


Unsuccessful applicant or prospect data: 12 to 24 months.


Legal holds: until released by counsel.


Retention is a ceiling, not a promise to retain. Vortoc may delete earlier when lawful.


4. Incident response


Personnel must report suspected incidents immediately to [email protected]. Vortoc will activate an incident team; contain without destroying evidence; determine affected systems, people, states, and data; coordinate counsel and forensics; meet contractual and statutory notice duties; document decisions; remediate; and review lessons learned. Customers must notify Vortoc within one business day of incidents involving Vortoc data.

TermsPrivacyYour Privacy ChoicesCookiesData UseData SourcesAcceptable UseTCPA / DNCEmail PolicySMS ConsentFCRA NoticeData AccuracySecurity

Vortoc is an independent data-intelligence and lead-management technology provider — not a lender, broker, real-estate company, law firm, insurance agency, financial institution, consumer reporting agency, or government entity. Public-record-derived leads are not consumer inquiries or consent to contact. Customers are independently responsible for lawful use.

© 2026 — © 2026 VORTOC. Intelligence, Amplified. All rights reserved.