Effective Date: August 5, 2026
At Merrimack Technology, we are committed to protecting the confidentiality, integrity, and availability of the information entrusted to us. This Data Retention Policy explains how long we retain personal information and business records, the reasons for retaining them, and how they are securely disposed of when they are no longer needed.
Purpose
We retain information only for as long as necessary to:
- Provide our managed IT, cybersecurity, and technology services
- Fulfill contractual obligations
- Respond to customer support requests
- Maintain network security and system integrity
- Meet legal, regulatory, accounting, and tax requirements
- Resolve disputes and enforce agreements
Once information is no longer required, it is securely deleted, destroyed, or anonymized using industry-accepted methods appropriate for the type of information.
GDPR-Compliant Data Retention & Erasure
Purpose and Principles
Where applicable, Merrimack Technology processes personal data in accordance with the General Data Protection Regulation (GDPR). In compliance with the GDPR principles of Storage Limitation and Data Minimization, personal data is collected only for specified, explicit, and legitimate business purposes and retained only for as long as necessary to fulfill those purposes or comply with applicable legal obligations. When personal data is no longer required, it is securely deleted or permanently anonymized.
Retention Schedule & Lawful Bases
| Data Category | Retention Period | Lawful Basis |
|---|---|---|
| Customer account information | Duration of the customer relationship plus up to seven (7) years | Article 6(1)(b) Contract Article 6(1)(c) Legal Obligation |
| Website contact forms and sales inquiries | Up to twenty-four (24) months unless a business relationship is established | Article 6(1)(f) Legitimate Interest |
| Support tickets and service records | Up to five (5) years following the last service interaction | Article 6(1)(b) Contract Article 6(1)(f) Legitimate Interest |
| Security logs, authentication records, and system monitoring logs | Ninety (90) days to two (2) years, depending on operational and security requirements | Article 6(1)(f) Legitimate Interest |
| Contracts, invoices, tax, and financial records | Seven (7) years or longer where required by law | Article 6(1)(c) Legal Obligation |
| Marketing communications | Until consent is withdrawn or the individual unsubscribes | Article 6(1)(a) Consent |
| Website analytics data | According to the configured retention settings of the applicable analytics platform | Article 6(1)(f) Legitimate Interest |
| Backup and disaster recovery data | Thirty (30) to three hundred sixty-five (365) days, depending on backup schedules | Article 6(1)(f) Legitimate Interest |
Secure Storage
Information retained by Merrimack Technology is protected through administrative, technical, and physical safeguards appropriate to the sensitivity of the data. These safeguards may include:
- Role-based access controls
- Encryption where appropriate
- Secure cloud infrastructure
- Multi-factor authentication
- Network monitoring and logging
- Regular security reviews
- Secure backup and disaster recovery systems
Right to Erasure (“Right to Be Forgotten”)
Data Subject Rights
Where the GDPR applies, individuals may request access to, correction of, restriction of processing, portability of, or deletion of their personal data in accordance with applicable law.
Compliance & Execution Timelines
Upon receipt of a valid Right to Erasure request, Merrimack Technology will verify the identity of the requesting individual and, where required by law, permanently delete or irreversibly anonymize applicable personal information without undue delay and, where feasible, within one (1) calendar month.
Where personal information has been shared with trusted service providers processing data on our behalf, Merrimack Technology will take reasonable steps to communicate applicable deletion requests consistent with our contractual obligations and applicable Data Processing Agreements (DPAs).
Exceptions
The right to erasure is not absolute. Merrimack Technology may retain personal information where necessary to:
- Fulfill an active contractual obligation or ongoing service.
- Comply with applicable legal, regulatory, tax, or accounting requirements.
- Detect, investigate, or prevent fraud, cybersecurity incidents, or unauthorized activity.
- Establish, exercise, or defend legal claims.
- Protect the security, integrity, and availability of systems and services.
Data Disposal & System Controls
Secure Disposal
At the conclusion of the applicable retention period, Merrimack Technology securely deletes, destroys, or permanently anonymizes personal information using methods appropriate for the storage medium. Physical records are securely destroyed, and electronic records are securely erased from production systems whenever practical.
Data Anonymization
Where operational records are retained for reporting, cybersecurity analysis, trend identification, service improvement, capacity planning, or statistical purposes, personal identifiers are removed or irreversibly anonymized so that individuals can no longer be identified.
Backups & Disaster Recovery
GDPR storage limitation principles extend to backup systems. When personal information reaches the end of its retention period or a valid Right to Erasure request is fulfilled, records are removed from production systems and scheduled for deletion from backup media according to Merrimack Technology’s established backup retention schedule.
Personal information may remain in encrypted backup media until those backups naturally expire as part of the organization’s standard backup lifecycle. Backup data is maintained solely for disaster recovery and business continuity purposes and is securely overwritten or destroyed according to established retention schedules. Deleted data is not restored except when necessary to recover from a verified system failure or cybersecurity incident.
Legal & Regulatory Requirements
Certain records may be retained for longer periods where required by:
- Applicable federal, state, or international laws
- Tax and accounting regulations
- Contractual obligations
- Court orders or legal proceedings
- Ongoing investigations or cybersecurity incidents
Your Rights
Depending on applicable privacy laws, including the GDPR where applicable, you may have the right to:
- Access your personal information.
- Correct inaccurate or incomplete information.
- Request deletion of your personal information.
- Restrict or object to certain processing activities.
- Request a copy of your personal information in a portable format.
- Withdraw consent where processing is based on consent.
Requests will be reviewed and processed in accordance with applicable legal requirements.
Policy Updates
Merrimack Technology may update this Data Retention Policy periodically to reflect changes in our services, legal obligations, security practices, or business operations. The updated version will be posted on this page with a revised Effective Date.
Contact Us
If you have questions regarding this Data Retention Policy or our information handling practices, please contact us through the information provided on our Contact page.