Data Retention & Disposal Policy
Last Updated: September 10, 2026
This Data Retention & Disposal Policy defines the mandatory retention schedules and secure destruction procedures for data collected, processed, and stored by Under One Roof Property Manager LLC ("Under One Roof"). It balances statutory corporate compliance under state common interest development acts (e.g., California Davis-Stirling Act, Civil Code §§ 5200, 5855) with resident privacy protections.
1. Purpose & Scope
This policy applies to all active community workspaces, registered member profiles, financial ledger feeds, uploaded CC&R legal files, work order records, voting ballots, and internal communications hosted on our infrastructure.
2. Mandatory Data Retention Schedules
We enforce explicit data lifecycles based on regulatory requirements and data sensitivity:
- 7-Year Statutory Audit Retention (Corporate & Fiduciary):
The following corporate records are retained in encrypted cold storage for seven (7) years to satisfy state corporate oversight, tax compliance, and association financial audit requirements:- Official Board of Directors meeting minutes, agendas, and resolutions.
- Digital secret ballot logs and quorum audit trail certifications.
- Plaid dual-ledger banking transactions, assessment receipts, and fee schedules.
- Approved contractor invoices, proof-of-work photos, and payment payout receipts.
- Statutory disciplinary hearing notices, member responses, and written Notices of Decision issued pursuant to California Civil Code § 5855(c).
- 90-Day Ephemeral Neighbor Chat Purge (Privacy First):
Informal, peer-to-peer communications are ephemeral by design. Casual direct unit-to-unit messages, maintenance coordination chatter, and temporary amenity reservation check-ins are automatically and permanently purged from production databases ninety (90) days after generation. This ensures neighbors can communicate freely without creating permanent surveillance records. - 14-Day Notice Board Expiration:
General community announcements and seasonal notices posted to the community feed auto-expire and archive after fourteen (14) days unless explicitly designated as pinned permanent records by an authorized Board Officer. - 24-Hour Financial Token Revocation:
Depository bank access tokens provided via Plaid, temporary session keys, and single-use amenity PIN codes are cryptographically destroyed within twenty-four (24) hours of account disconnection, credential revocation, or reservation expiration. - 30-Day Workspace Termination Purge:
When a community subscription concludes or a workspace deletion request is executed, all active production records, member directories, and unarchived files are permanently deleted across all application databases within thirty (30) days.
3. Data Disposal & Destruction Procedures
Decommissioned data is destroyed using industry-standard cryptographic and physical overwriting protocols:
- NoSQL Document Databases (Google Cloud Firestore): Record deletion commands execute immediate cryptographic unlink operations, followed by automated block overwriting during standard garbage collection. Rolling automated cloud snapshots expire within thirty (30) days.
- Secure Object Storage (Google Cloud Storage): PDF documents, uploaded CC&R scans, and work order photos are purged via standard Cloud Storage APIs, rendering raw disk sectors unreadable and reclaiming underlying storage.
- Secret & Token Deletion: API secrets, Webhook signing keys, and Plaid access tokens are shredded from Google Secret Manager with immediate key invalidation.
4. Annual Policy Review & Compliance Contact
This policy is audited annually to ensure alignment with CCPA/CPRA, state HOA statutory retention rules, and banking integration security standards. Inquiries regarding data retention or data deletion requests may be directed to:
Under One Roof Property Manager LLC
Data Governance & Security Office
455 Market St Ste 1940
San Francisco, CA 94105-2448 US
Email: info@underoneroofpm.com