Legal / Trust
Data Retention Policy
This schedule explains what website-related information Lapemo Systems LLC keeps, why it is needed, the event that starts each retention period, and what happens when the period ends. A maximum period is not a minimum: information is deleted or anonymized earlier when its purpose has ended.
Last updated: 2026-08-06
1. Governing Rules
Retention decisions follow the principles of lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability.
Personal information is not retained indefinitely or merely because it may be useful later. Every extension must have a current purpose, lawful basis, documented owner, review date, and access boundary.
- Know what information is held and why
- Use the shortest justified period
- Correct or erase inaccurate information
- Delete or anonymize information when no longer needed
- Protect retained information and limit access
- Keep evidence that the schedule is followed
2. Standards and Guidance
The schedule is designed around GDPR and UK GDPR storage-limitation, purpose-limitation, data-minimization, accuracy, security, accountability, and erasure principles. These sources do not prescribe one universal retention duration; they require periods that are purpose-based, justified, documented, reviewed, and followed in practice.
3. Website Retention Schedule
Ordinary Contact inquiries
- Data: name, email, company, role, inquiry type, and message.
- Purpose: respond to and follow up on the inquiry.
- Clock starts: last substantive interaction.
- Maximum: 12 months, with earlier deletion when no longer needed.
- End action: delete from active Web3Forms and operational email records or irreversibly anonymize the non-identifying business insight.
Privacy-rights correspondence
- Data: request, verification material when necessary, response, and resolution.
- Purpose: respond to the request and document its resolution.
- Clock starts: request closure.
- Maximum: 12 months unless a documented legal obligation or dispute requires a scoped extension.
- End action: delete correspondence and retain no more than a non-identifying completion record where operational evidence is still needed.
Aggregate website analytics
- Provider: Plausible Analytics.
- Scope: aggregate pageviews and broad traffic categories; no analytics cookies, form content, custom visitor properties, or advertising profiles.
- Purpose: understand overall website use and improve navigation and content.
- Review: every six months and whenever analytics configuration changes.
- End action: remove the tracker and delete the Plausible site data when aggregate measurement is no longer needed.
Hosting and security request logs
- Scope: request and security information processed by the selected hosting or protection provider.
- Purpose: delivery, reliability, abuse prevention, and incident investigation.
- Period: the shortest provider-supported period justified for those purposes; the provider and configured period must be recorded before production use.
- End action: automatic deletion or anonymization under the provider configuration, subject to a documented incident hold.
- Launch boundary: this schedule must be updated if the final provider materially changes the information or period.
Unconfigured submission
- If the Contact access key is not configured, the website does not submit or store any information; the visitor sees an inline error and may retry.
- No message, draft, or record is created until a submission is successfully delivered through Web3Forms.
Newsletter subscriptions
- Subscriptions occur directly on Substack; this website does not collect the subscription address.
- Substack's published privacy and retention terms govern information submitted there.
- A visitor may use Substack's unsubscribe and privacy controls or contact Substack directly.
4. Early Deletion, Accuracy, and Individual Rights
The stated periods are maximums. Records are reviewed for continued necessity and may be deleted or anonymized earlier. If information is shown to be inaccurate or misleading, reasonable steps are taken to correct or erase it without delay.
Requests for access, correction, restriction, objection, or erasure may be made verbally or in writing. Identity verification is limited to what is reasonably necessary. Erasure is not absolute, but any refusal or limitation must be tied to an applicable legal basis and explained to the requester.
Send requests to privacy@largepeoplemodel.com. Do not send identity documents unless they are specifically and lawfully requested.
5. Extensions and Legal Holds
A retention period may be extended only for an active business relationship or a specific legal obligation, dispute, fraud or abuse investigation, security incident, or establishment, exercise, or defense of legal claims.
An extension must identify the affected records, purpose, legal or operational justification, accountable owner, restricted access group, and next review date. A hold does not authorize unrelated reuse. Records are deleted or anonymized when the hold is released and no other justified purpose remains.
- No blanket or indefinite holds
- Narrow record scope
- Restricted access
- Review at least every 90 days
- Documented release and disposal
6. Deletion, Anonymization, and Backups
Deletion removes information from active systems and instructs applicable processors to delete their active copies. If immediate removal from a protected backup is not technically possible, the information is placed beyond ordinary use, remains protected, is not restored except for disaster recovery, and expires through the backup cycle.
Anonymization must be irreversible in the circumstances. Pseudonymized or key-coded information remains personal information and continues to follow this schedule.
7. Processor and Sharing Controls
Service providers are limited to the information and period needed for their assigned purpose. Provider settings and contracts should support deletion, return, or anonymization when processing ends. Where information has been shared, each relevant copy must be addressed rather than treating deletion from one system as complete.
- Web3Forms: configured Contact submissions
- Operational email provider: sent and received correspondence
- Plausible: aggregate website measurement
- Substack: direct newsletter relationship
- Hosting and security providers: request delivery and protection
8. Governance and Review
The privacy owner reviews this schedule at least every six months and whenever a purpose, form field, provider, system, legal requirement, or analytics configuration changes. The review confirms that categories, purposes, periods, deletion actions, processor settings, and public disclosures still match actual practice.
Operational evidence should record the review date, decisions, completed deletions or anonymizations, unresolved exceptions, and the next review date without recreating the personal information that was deleted.
- Policy owner: Lapemo Systems LLC privacy function
- Routine review: every six months
- Event-driven review: before any material processing change
- Deletion check: at least monthly for expired Contact and rights-request records
- Public update: when a material practice or period changes
9. Contact
Questions, challenges to retention, and requests to exercise privacy rights may be sent to privacy@largepeoplemodel.com. Business location: Kansas, United States.
Questions
