Employee Center Data Minimization and Sensitive Data Handling Policy
No Raw Database Data Claim
For clarity, this document does not claim that Quintin N. Mahan owns raw facts, raw database rows, independent outside source records, CRS-owned operational records, customer-owned records, third-party-owned records, or customer relationships merely because such information is entered into, stored in, processed by, displayed through, backed up with, or exported from EC.
This document protects EC Protected Materials: the application, software, source code, schemas, database design, data model, relationships, indexes, workflows, dashboards, reports, queries, automations, integrations, APIs, access controls, credentials, hardware, infrastructure, legal records, certificate records, hashes, metadata systems, audit systems, methods, processes, techniques, trade secrets, documentation, and EC-created structural organization.
Version: 1.0
Effective Date: June 1, 2026
Platform: Employee Center / EC
Owner: Quintin N. Mahan
Legal Hub: /legal
Policies Hub: /legal/policies
Policy URL: /legal/policies/policies/data-minimization-sensitive-data-handling-policy
1. Purpose
This policy explains that users should avoid entering unnecessary sensitive data into EC and should handle sensitive data carefully.
2. Data Minimization
Users should submit only information reasonably needed for authorized EC-related purposes.
Users should avoid adding unnecessary Social Security numbers, payment card numbers, bank credentials, passwords, private medical details, identity documents, personal disputes, unrelated photos, or unrelated confidential records.
3. Sensitive Data
Sensitive data may include personal identifiers, payment information, credentials, employee records, customer records, legal records, security records, medical details, financial records, and private attachments.
4. User Responsibility
Users are responsible for avoiding unnecessary sensitive uploads and for following EC policies when handling sensitive data.
5. Owner/Admin Review
Quintin N. Mahan may restrict, remove, archive, preserve, encrypt, redact, or limit access to sensitive records based on owner/admin judgment, legal holds, or security needs.
6. No Credential Storage
Users should not store passwords, private keys, API secrets, customer credentials, or payment card numbers in ordinary EC notes or attachments unless a feature is specifically designed and authorized for secure handling.
7. Retention
Sensitive data may be retained where needed for legal, operational, evidence, audit, security, evidence preservation and authorized transition support, or owner/admin purposes.
8. Reporting
Users should promptly report accidental sensitive-data uploads or suspected exposure.
Changes to This Policy
Quintin N. Mahan may update this policy by publishing a new active version in EC.
The current active version will be displayed through the Legal hub or Policies hub.
Older versions may remain stored in Postgres for audit, evidence, legal history, and historical review.
Contact / Owner
Employee Center is owned by Quintin N. Mahan.
Legal and policy documents are available from:
/legal
Policy documents may be organized at:
/legal/policies
The current Terms and Conditions are available from:
/legal/terms-and-conditions
End of Employee Center Data Minimization and Sensitive Data Handling Policy.