Effective Date: August 5, 2026

At Merrimack Technology, we are committed to protecting the confidentiality, integrity, and availability of the information entrusted to us. This Data Retention Policy explains how long we retain personal information and business records, the reasons for retaining them, and how they are securely disposed of when they are no longer needed.

Purpose

We retain information only for as long as necessary to:

  • Provide our managed IT, cybersecurity, and technology services
  • Fulfill contractual obligations
  • Respond to customer support requests
  • Maintain network security and system integrity
  • Meet legal, regulatory, accounting, and tax requirements
  • Resolve disputes and enforce agreements

Once information is no longer required, it is securely deleted, destroyed, or anonymized using industry-accepted methods appropriate for the type of information.

GDPR-Compliant Data Retention & Erasure

Purpose and Principles

Where applicable, Merrimack Technology processes personal data in accordance with the General Data Protection Regulation (GDPR). In compliance with the GDPR principles of Storage Limitation and Data Minimization, personal data is collected only for specified, explicit, and legitimate business purposes and retained only for as long as necessary to fulfill those purposes or comply with applicable legal obligations. When personal data is no longer required, it is securely deleted or permanently anonymized.

Retention Schedule & Lawful Bases

Data Category Retention Period Lawful Basis
Customer account information Duration of the customer relationship plus up to seven (7) years Article 6(1)(b) Contract
Article 6(1)(c) Legal Obligation
Website contact forms and sales inquiries Up to twenty-four (24) months unless a business relationship is established Article 6(1)(f) Legitimate Interest
Support tickets and service records Up to five (5) years following the last service interaction Article 6(1)(b) Contract
Article 6(1)(f) Legitimate Interest
Security logs, authentication records, and system monitoring logs Ninety (90) days to two (2) years, depending on operational and security requirements Article 6(1)(f) Legitimate Interest
Contracts, invoices, tax, and financial records Seven (7) years or longer where required by law Article 6(1)(c) Legal Obligation
Marketing communications Until consent is withdrawn or the individual unsubscribes Article 6(1)(a) Consent
Website analytics data According to the configured retention settings of the applicable analytics platform Article 6(1)(f) Legitimate Interest
Backup and disaster recovery data Thirty (30) to three hundred sixty-five (365) days, depending on backup schedules Article 6(1)(f) Legitimate Interest

Secure Storage

Information retained by Merrimack Technology is protected through administrative, technical, and physical safeguards appropriate to the sensitivity of the data. These safeguards may include:

  • Role-based access controls
  • Encryption where appropriate
  • Secure cloud infrastructure
  • Multi-factor authentication
  • Network monitoring and logging
  • Regular security reviews
  • Secure backup and disaster recovery systems

Right to Erasure (“Right to Be Forgotten”)

Data Subject Rights

Where the GDPR applies, individuals may request access to, correction of, restriction of processing, portability of, or deletion of their personal data in accordance with applicable law.

Compliance & Execution Timelines

Upon receipt of a valid Right to Erasure request, Merrimack Technology will verify the identity of the requesting individual and, where required by law, permanently delete or irreversibly anonymize applicable personal information without undue delay and, where feasible, within one (1) calendar month.

Where personal information has been shared with trusted service providers processing data on our behalf, Merrimack Technology will take reasonable steps to communicate applicable deletion requests consistent with our contractual obligations and applicable Data Processing Agreements (DPAs).

Exceptions

The right to erasure is not absolute. Merrimack Technology may retain personal information where necessary to:

  • Fulfill an active contractual obligation or ongoing service.
  • Comply with applicable legal, regulatory, tax, or accounting requirements.
  • Detect, investigate, or prevent fraud, cybersecurity incidents, or unauthorized activity.
  • Establish, exercise, or defend legal claims.
  • Protect the security, integrity, and availability of systems and services.

Data Disposal & System Controls

Secure Disposal

At the conclusion of the applicable retention period, Merrimack Technology securely deletes, destroys, or permanently anonymizes personal information using methods appropriate for the storage medium. Physical records are securely destroyed, and electronic records are securely erased from production systems whenever practical.

Data Anonymization

Where operational records are retained for reporting, cybersecurity analysis, trend identification, service improvement, capacity planning, or statistical purposes, personal identifiers are removed or irreversibly anonymized so that individuals can no longer be identified.

Backups & Disaster Recovery

GDPR storage limitation principles extend to backup systems. When personal information reaches the end of its retention period or a valid Right to Erasure request is fulfilled, records are removed from production systems and scheduled for deletion from backup media according to Merrimack Technology’s established backup retention schedule.

Personal information may remain in encrypted backup media until those backups naturally expire as part of the organization’s standard backup lifecycle. Backup data is maintained solely for disaster recovery and business continuity purposes and is securely overwritten or destroyed according to established retention schedules. Deleted data is not restored except when necessary to recover from a verified system failure or cybersecurity incident.

Legal & Regulatory Requirements

Certain records may be retained for longer periods where required by:

  • Applicable federal, state, or international laws
  • Tax and accounting regulations
  • Contractual obligations
  • Court orders or legal proceedings
  • Ongoing investigations or cybersecurity incidents

Your Rights

Depending on applicable privacy laws, including the GDPR where applicable, you may have the right to:

  • Access your personal information.
  • Correct inaccurate or incomplete information.
  • Request deletion of your personal information.
  • Restrict or object to certain processing activities.
  • Request a copy of your personal information in a portable format.
  • Withdraw consent where processing is based on consent.

Requests will be reviewed and processed in accordance with applicable legal requirements.

Policy Updates

Merrimack Technology may update this Data Retention Policy periodically to reflect changes in our services, legal obligations, security practices, or business operations. The updated version will be posted on this page with a revised Effective Date.

Contact Us

If you have questions regarding this Data Retention Policy or our information handling practices, please contact us through the information provided on our Contact page.