Skip to main content

TierSphere

Data Return and Destruction Procedure

This procedure describes the default handling process when a customer agreement ends or a district requests return, deletion, or both for protected data.

1. Confirm Scope and Instruction

  • Confirm the requesting party is authorized to issue the return or deletion instruction.
  • Confirm the scope of data involved, requested export format, target delivery channel, and timing requirements.
  • Review any customer-specific agreement terms that override the default workflow below.

2. Return Data When Requested

  • Prepare an export in a mutually agreed format such as CSV or JSON where technically appropriate.
  • Deliver the export through a secure channel approved by the customer.
  • Record the data sets included, export date, delivery method, and receiving contact.

3. Delete Active Customer Data

  • After confirmed return, or after a direct deletion instruction when no return is requested, remove active customer data from the application environment within 30 days unless the agreement requires a different timeline.
  • Remove associated active object-storage files and other directly linked customer data within the same workflow where technically feasible.

4. Backup Handling

  • Operational backups retained for disaster recovery are not restored for normal business use after contract termination.
  • Backup copies age out according to the normal retention cycle and are deleted in the ordinary course.

5. Completion Record

  • Record the date the request was received.
  • Record the export or deletion completion date.
  • Record the responsible operator and any exceptions.
  • Confirm completion back to the customer when required by agreement.

Related Policies

Review our Student Data Privacy and Privacy Policy pages for broader privacy commitments.