GOOD LIFE GAMES

Data Retention Policy

Effective Date: January 1, 2025 Last Updated: February 20, 2026 Version: 1.0

Policy Owner: CEO/DPO | Next Review Date: January 1, 2027

This Data Retention Policy applies to all personal data and business records collected, processed, or stored by Good Life Games in connection with its subscription-based gaming platform and related operations. It applies to all employees, contractors, and third-party service providers acting on behalf of Good Life Games.

1. Purpose and Scope

Good Life Games is committed to retaining personal data and business records only for as long as necessary to fulfill the purposes for which they were collected, comply with applicable legal and regulatory obligations, resolve disputes, and enforce our agreements. This policy establishes clear, documented standards for how long different categories of data are retained, how they are deleted, and who is responsible for managing retention compliance.

This policy applies to all data in any format — digital and physical — including data stored on Company servers, cloud infrastructure, third-party processors, employee devices, backup systems, and paper records.

Objectives

  • Minimize data retention risk and comply with GDPR, CCPA/CPRA, CAN-SPAM, and other applicable laws
  • Establish consistent, auditable retention standards across the organization
  • Ensure personal data is not retained beyond its useful life
  • Define clear deletion, anonymization, and legal hold procedures
  • Assign accountability for retention policy compliance

2. Legal and Regulatory Framework

This policy is informed by the following legal requirements and frameworks:

  • General Data Protection Regulation (GDPR) — Article 5(1)(e): Data must not be kept in a form that permits identification of data subjects for longer than is necessary for the purposes for which it is processed (the “storage limitation” principle).
  • California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA): requires disclosure of retention periods and honoring deletion requests.
  • CAN-SPAM Act: requires retention of consent and opt-out records sufficient to demonstrate compliance.
  • Internal Revenue Service (IRS) / State Tax Requirements: generally require 7 years of financial transaction records.
  • Nebraska State Law: applicable state data protection and recordkeeping obligations.
  • Contractual Obligations: agreements with payment processors (e.g., PCI DSS) and other service providers may impose retention requirements.

3. Data Retention Schedule

Note: "Anonymization" means irreversibly transforming data so it can no longer be attributed, directly or indirectly, to a specific individual.

Data Category Retention Period Legal / Business Basis Deletion Method Exceptions
Account Registration Data Duration of account + 90 days post-closure Contract performance; legal compliance Secure overwrite / anonymization Legal hold; fraud investigation
Subscription & Billing Records 7 years from transaction date Tax law; financial recordkeeping (IRS, state) Secure deletion Active dispute or audit
Authentication & Session Logs 12 months from event date Security; fraud prevention Automated log rotation Active security incident
Usage & Engagement Data 24 months from event date Service improvement Aggregated / anonymized None standard
Support & Communication Records 3 years from ticket close date Legal defense; service quality Secure deletion Active legal proceeding
Marketing Records 5 years from last interaction CAN-SPAM; GDPR audit trail Secure deletion Regulatory audit
Backup & Recovery Copies Maximum 90 days rolling Business continuity Overwritten by rotation Legal hold extension
Legal Hold Data Duration of hold + 1 year post-resolution Legal obligation Reviewed and deleted post-hold Hold supersedes all schedules

4. Deletion and Destruction Procedures

4.1 Digital Data: Upon expiration of the applicable retention period, digital data shall be permanently and securely deleted using methods that prevent recovery. Acceptable deletion methods include: Secure overwrite (minimum single-pass overwrite); Cryptographic erasure; Physical destruction of storage media where necessary. Deletion must cascade across primary systems, backup copies, and archived data.

4.2 Physical Records: Physical records (if any) containing personal information shall be destroyed via cross-cut shredding or equivalent secure destruction method. Physical destruction should be documented by a Certificate of Destruction.

4.3 Third-Party Processors: All third-party data processors engaged by Good Life Games must be contractually required to adhere to retention periods consistent with this policy.

4.4 Backups: Backup copies of data are subject to a rolling 90-day maximum retention cycle. Automated backup rotation must be configured to overwrite or delete backups exceeding this threshold.

5. Responding to User Deletion Requests

Users may submit a request to delete their personal data at any time by contacting info@goodlifegames.co. Upon receipt of a verified deletion request, we will:

  • Acknowledge receipt within 5 business days
  • Verify the identity of the requestor before processing
  • Complete deletion from all active systems within 30 days
  • Identify and document any data retained beyond the request due to a legal exception (e.g., financial recordkeeping)

6. Legal Hold Procedures

A Legal Hold suspends the normal deletion or modification of data when that data may be relevant to litigation, regulatory investigation, or other legal proceeding.

6.1 Triggering a Legal Hold: Holds may be triggered by receipt of a subpoena, court order, notice of lawsuit, or internal decision by management that a proceeding is reasonably anticipated.

6.2 Hold Process: All automated deletion processes and backup rotation are suspended for in-scope data immediately upon issuance of a Legal Hold Notice. Custodians must confirm in writing that data is preserved.

6.3 Releasing a Legal Hold: A legal hold is released only by written authorization from legal counsel. Upon release, data is returned to the standard retention schedule.

7. Roles and Responsibilities

Role Responsibilities
Policy Owner (CEO / DPO) Overall accountability; annual review; legal hold authority; regulatory communications.
IT / Systems Administrator Implementing automated deletion; backup rotation; maintaining audit logs of deletions.
Finance / Accounting Maintaining financial record retention per IRS; flagging records under financial hold.

8. Audit, Review, and Compliance

8.1 Annual Review: This policy shall be reviewed at least annually and updated to reflect changes in practices or law.

8.2 Retention Audit: An internal audit shall be conducted annually to verify retention schedules are followed and legal holds are properly documented.

8.3 Documentation: The Company shall maintain records of deletion activities, user deletion requests, and legal holds.

8.4 Non-Compliance: Violations of this policy may result in disciplinary action up to and including termination of employment or contract.

9. International Data Transfers

Where data is transferred outside the US, Good Life Games ensures adequate protections consistent with GDPR Standard Contractual Clauses.

10. Contact Information

Good Life Games — Policy Owner
10842 Old Mill Road, Suite 1, Omaha, NE 68154
Email: info@goodlifegames.co

Approval and Sign-Off

Approved By (Name):
Title:
Signature:
Date:
Next Scheduled Review: January 1, 2027