Policies and Procedures: Data Retention and Destruction

Prev Next

The purpose of this policy is to outline the destruction process and purpose for the retention of data (when applicable). Ripple Treasury utilizes and stores information from various sources that is confidential, including cardholder information, financial information and data access information. When media storing this data is no longer required it must be securely disposed of to ensure the integrity of the client data is encrypted while in transit and while at rest. Ripple Treasury will retain client data through the life of the agreement with the customer.  Upon receipt of client cardholder data, incoming sensitive information will be encrypted immediately. 

Deletion of Application Data

Application data will only be deleted upon receipt of the client’s written request (other than due to the regular deletion processes available within the application). Client requests should specify exact data and time periods to be deleted. 

The Ripple Treasury Data Retention & Deletion Policy governs the retention and/or deletion of all client data including PCI (Payment Card Industry) and non-PCI related information, along with data regulations such as GDPR.

Deletion of Marketing Data

Marketing Data will be retained for as long as is necessary for business purposes. Requests for the removal of data from the marketing database should be sent to the Ripple Treasury marketing team (treasury-sales@ripple.com). 

Purpose for Retention

Ripple Treasury will retain client data unless a request is received to delete in order to have the data available to the client or Ripple Treasury for the following purposes:

  • Legal actions

  • Regulatory requirements

  • Business purposes

Upon termination of a client’s agreement with Ripple Treasury, Ripple Treasury will return data to the client.  Ripple Treasury will retain the client’s data for 30 days, upon which time it will be deleted (unless agreed in writing with the client). 

Disposal of Paper Based Data

All paper-based media must be securely disposed of using a shredder or secure shred bin. Any media containing cardholder information or cryptographic key components must be destroyed using a crosscut shredder or be disposed of within a secure shred bin. This includes any documents containing sensitive information.

Users should make every effort to securely dispose of documents via either a shred bin and/or cross-cut shred any printed material containing confidential or sensitive information once no longer needed.