Storage model
- Easy Social accounts run in a shared app with tenant-scoped Postgres data and row-level security.
- Generated assets, PDFs, uploads, audit archives, and backups live under configured Easy Social data directories, not in tracked source files.
- Secrets are held in environment or vault-backed runtime configuration and must not be committed to source control.
Retention and deletion
Account records are retained while needed to provide the service, meet audit obligations, support users, or satisfy legal and accounting requirements. When an account is closed, Easy Social deletes or de-identifies personal information within a reasonable operational window unless it must be retained for legal, tax, dispute, security, or backup reasons.
Backups
Backup scripts and backup storage paths are part of the platform. Offsite encrypted backup status and restore evidence should be verified before making stronger disaster-recovery commitments in procurement material.
Data export
Users can request an export of account, profile, generated content references, and service data where legally and technically appropriate. Some settings are directly editable in the app.
Incident response
- Contain suspected incidents by revoking access, rotating secrets, disabling affected routes, or isolating affected services.
- Assess what happened, what data is affected, which users or clients are affected, and whether serious harm is likely.
- Notify affected people and the Office of the Privacy Commissioner where required by the New Zealand Privacy Act 2020.
- Fix the root cause, record the incident, and update controls or documentation to reduce recurrence.