← Return to Nexus

DATA RETENTION & DISPOSAL POLICY

Effective Date: June 28, 2026
Document Version
1.0
Owner
Drew Thomas Ernst, Owner / Systems Engineer
Contact
dte.solutions.llc@gmail.com
Review Cycle
Annual or upon material change

1. Purpose and Scope

This Data Retention and Disposal Policy defines the minimum and maximum periods for which Drew Ernst, sole proprietor, doing business as DTE Solutions. retains consumer data, and the standards by which data is securely disposed of when retention periods expire or when consumers request deletion.

This policy applies to all consumer data processed by Drew Ernst, sole proprietor, doing business as DTE Solutions. through the Pulse AI platform, including financial data received from the Plaid API, account metadata, transaction history, and behavioral analytics.

2. Legal and Regulatory Basis

Data retention and disposal practices comply with the following applicable frameworks and regulations:

Regulation Applicability
CCPA / CPRA California Consumer Privacy Act — consumers have the right to deletion
GDPR (where applicable) EU General Data Protection Regulation — right to erasure
GLBA Gramm-Leach-Bliley Act — data safeguarding for financial information
COPPA DTE does not knowingly collect data from users under 13

3. Data Categories and Retention Periods

Data Category Description Retention Period Legal Basis
Consumer Account Data Name, email address, authentication credentials Duration of account + 30 days post-deletion Service delivery
Financial Transaction Data Transaction records retrieved from Plaid API 24 months from date of ingestion Service delivery / behavioral analysis
Behavioral Analytics Spending velocity, drift, baseline metrics 24 months or until account deletion Service delivery
Access / Audit Logs Server-side API request logs, authentication events 90 days Security and incident response
Session Tokens JWT session tokens Expiry defined in token (short-lived) Authentication
Plaid Access Tokens OAuth tokens used to retrieve consumer financial data Duration of active Plaid connection or until consumer revokes Plaid integration
Support Communications Any communications with consumers for support purposes 12 months Legitimate interest
Marketing / Pre-Order Data Email addresses collected for early-access programs Until opt-out or program conclusion, max 24 months Consent

4. Data Deletion Procedures

4.1 Consumer-Initiated Deletion

Consumers may request deletion of their data at any time by:

  • Submitting a deletion request to dte.solutions.llc@gmail.com with the subject line "Data Deletion Request"
  • Using any in-app account deletion functionality where available

Upon receiving a verified deletion request:

  1. All personal data, financial data, and behavioral analytics associated with the consumer's account are permanently deleted from the production database (Supabase PostgreSQL) within 30 days.
  2. Plaid access tokens associated with the consumer are revoked via the Plaid API.
  3. Any residual data in backups is overwritten or purged within the next scheduled backup rotation cycle (maximum 90 days from request).
  4. Confirmation of deletion is sent to the consumer's registered email address.

4.2 Automated Retention Enforcement

  • Consumer data that has exceeded its defined retention period is flagged for deletion through periodic data hygiene reviews.
  • Retention enforcement is reviewed at minimum quarterly.
  • Automated deletion pipelines are implemented where technically feasible.

4.3 Secure Disposal Standards

All data disposal follows these standards:

Storage Medium Disposal Method
PostgreSQL Database Records Hard DELETE with no soft-delete shadow; row is permanently removed
Backups Encrypted backups are purged on schedule; no recovery of deleted data is possible after the backup rotation cycle completes
Plaid Tokens Revoked via Plaid /item/remove API endpoint
Server Logs Log files are rotated and permanently deleted after 90-day retention period

5. Data Minimization

Drew Ernst, sole proprietor, doing business as DTE Solutions. collects only the data necessary to provide the Pulse AI behavioral finance service. Financial data received from the Plaid API is:

  • Not sold to third parties
  • Not used for advertising or profiling beyond the direct service
  • Not shared with any party except as required to deliver the service (e.g., the authenticated consumer's own data displayed in the Pulse UI)

6. Cross-Border Data Transfers

Consumer data is stored on Supabase's PostgreSQL infrastructure and processed on Vercel's globally distributed edge network. Where data may transit or be processed outside the consumer's jurisdiction, Drew Ernst, sole proprietor, doing business as DTE Solutions. relies on the data transfer mechanisms and compliance certifications maintained by these providers (Supabase and Vercel, both SOC 2 Type II compliant).

7. Policy Review

This policy is reviewed:

  • Annually at minimum
  • Upon any material change to DTE's data processing activities, technology stack, or applicable law
  • Following any data incident that implicates retention or disposal practices

8. Contact for Data Requests

All data retention and deletion requests should be directed to:

Drew Thomas Ernst, Owner, Drew Ernst, sole proprietor, doing business as DTE Solutions.
Email: dte.solutions.llc@gmail.com | drew.t.ernst@gmail.com

Authorized Signature
Drew Thomas Ernst
Owner, Drew Ernst, sole proprietor, doing business as DTE Solutions.
June 28, 2026
© 2026 Drew Ernst, sole proprietor, doing business as DTE Solutions. // Engineered with Intention