← Back

EC Data Minimization Sensitive Data Handling Policy

03_policy_library/ec_data_minimization_sensitive_data_handling_policy.md

Employee Center Data Minimization and Sensitive Data Handling Policy

No Raw Database Data Claim

For clarity, this document does not claim that Quintin N. Mahan owns raw facts, raw database rows, independent outside source records, CRS-owned operational records, customer-owned records, third-party-owned records, or customer relationships merely because such information is entered into, stored in, processed by, displayed through, backed up with, or exported from EC.

This document protects EC Protected Materials: the application, software, source code, schemas, database design, data model, relationships, indexes, workflows, dashboards, reports, queries, automations, integrations, APIs, access controls, credentials, hardware, infrastructure, legal records, certificate records, hashes, metadata systems, audit systems, methods, processes, techniques, trade secrets, documentation, and EC-created structural organization.

Version: 1.0
Effective Date: June 1, 2026
Platform: Employee Center / EC
Owner: Quintin N. Mahan
Legal Hub: /legal
Policies Hub: /legal/policies

Policy URL: /legal/policies/policies/data-minimization-sensitive-data-handling-policy


1. Purpose

This policy explains that users should avoid entering unnecessary sensitive data into EC and should handle sensitive data carefully.

2. Data Minimization

Users should submit only information reasonably needed for authorized EC-related purposes.

Users should avoid adding unnecessary Social Security numbers, payment card numbers, bank credentials, passwords, private medical details, identity documents, personal disputes, unrelated photos, or unrelated confidential records.

3. Sensitive Data

Sensitive data may include personal identifiers, payment information, credentials, employee records, customer records, legal records, security records, medical details, financial records, and private attachments.

4. User Responsibility

Users are responsible for avoiding unnecessary sensitive uploads and for following EC policies when handling sensitive data.

5. Owner/Admin Review

Quintin N. Mahan may restrict, remove, archive, preserve, encrypt, redact, or limit access to sensitive records based on owner/admin judgment, legal holds, or security needs.

6. No Credential Storage

Users should not store passwords, private keys, API secrets, customer credentials, or payment card numbers in ordinary EC notes or attachments unless a feature is specifically designed and authorized for secure handling.

7. Retention

Sensitive data may be retained where needed for legal, operational, evidence, audit, security, evidence preservation and authorized transition support, or owner/admin purposes.

8. Reporting

Users should promptly report accidental sensitive-data uploads or suspected exposure.


Changes to This Policy

Quintin N. Mahan may update this policy by publishing a new active version in EC.

The current active version will be displayed through the Legal hub or Policies hub.

Older versions may remain stored in Postgres for audit, evidence, legal history, and historical review.


Contact / Owner

Employee Center is owned by Quintin N. Mahan.

Legal and policy documents are available from:

/legal

Policy documents may be organized at:

/legal/policies

The current Terms and Conditions are available from:

/legal/terms-and-conditions

End of Employee Center Data Minimization and Sensitive Data Handling Policy.