Data Retention Policy
How Reyman Pty Ltd retains and destroys personal and business information — kept only for as long as it is needed, and no longer.
1. Scope
This policy applies to personal information and business records held by Reyman Pty Ltd, including client and project records, supplier and subcontractor records, employment information, support and communications logs, and website and analytics data. It should be read with our Privacy Policy, which sets out how personal information is collected, used, and disclosed under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
2. Retention Principles
- Only what is needed — we collect and hold the minimum information required for the purpose.
- Only for as long as needed — records are kept while they serve the purpose for which they were collected.
- Lawful obligations first — where law or regulation requires longer retention (for example taxation and record-keeping obligations), those requirements prevail.
- Contract governs client data — for client and project data, retention is governed by the engagement terms and the client's own requirements, and never exceeds what the contract allows.
- Destroy or de-identify — when information is no longer needed, we take reasonable steps to destroy it or de-identify it.
3. Retention of Business Records
The table below describes how long categories of records are generally kept. Periods are indicative and governed by the principles above; specific contractual or legal obligations always take precedence.
| Record category | Indicative retention |
|---|---|
| Client & project records (contracts, scope, delivery records) | Duration of engagement + post-engagement period agreed in the contract, then securely deleted |
| Financial, invoicing & taxation records | As required by applicable law (e.g. taxation record-keeping obligations) |
| Employment & contractor records | For the period required by applicable employment law, then securely deleted |
| Supplier & subcontractor records | For the life of the relationship and any contractual or legal obligations after it |
| Support tickets, communications & enquiry logs | For the period needed to resolve and verify the matter, then deleted |
| Website & analytics data | As described in our Privacy Policy; aggregated data is de-identified |
4. Data Destruction
- Secure deletion — digital records are deleted using secure methods that prevent recovery, including verified deletion of backups.
- Client-initiated erasure — clients may request erasure of project data and system teardowns at any time; upon authorisation we securely purge the associated data in accordance with the engagement terms.
- Certification on request — where a client's obligations require it, we can provide written confirmation of data destruction.
- Physical records — any physical records are shredded or securely destroyed when no longer needed.
5. Government Information
Where we hold or process information for or on behalf of an Australian government agency, retention and destruction are governed by the contract and the agency's own requirements, including any applicable records management and security obligations. We do not retain government information beyond what the engagement permits, and we support agency-led audits of what we hold. See our data sovereignty and information security pages for how government data is protected.
6. Access, Correction & Enquiries
You may request access to, or correction of, the personal information we hold about you, or ask us about our retention practices. Contact our Privacy Contact at privacy@axisonic.com and we will respond within a reasonable period.
7. Review
This policy is reviewed periodically — and at least annually — and updated as our operations, legal obligations, and client requirements evolve.