This Data Storage, Security & Retention Policy explains how Barry Law collects, stores, protects, and removes client data. It covers intake materials such as text, documents, audio, and video and describes hosting region, encryption methods, access controls, backup procedures, and retention schedules. The policy applies to client files managed by the firm and related services, and it describes how requests to shorten or extend retention are handled under contract, legal holds, or applicable law.
This policy reflects our commitment to safeguarding client information while meeting legal and contractual obligations. It explains our use of United States primary hosting, secure transport and storage encryption, separation of tenant data, and measures like multi-factor authentication and role-based access controls. It also outlines how we work with subprocessors, handle incident response and breach notification, and provide contact information for questions or requests about data handling and retention scheduling.
A clear policy ensures predictable handling of client information, reduces legal risk, and supports compliance with retention obligations. It gives clients transparency about where data is stored, how long it is kept, and the safeguards in place to prevent unauthorized access. Strong retention rules help limit unnecessary data exposure while preserving records needed for ongoing matters, litigation, or regulatory requirements. This balance helps protect client privacy and the firm’s operational integrity.
Barry Law serves clients from Bloomington, Minnesota and focuses on business, tax, real estate, and bankruptcy matters. The firm prioritizes disciplined data practices that align with legal and contractual duties. Our approach combines secure hosting, access controls, routine reviews, and documented procedures to maintain confidentiality and availability of client records. Clients can contact the firm directly at [email protected] for questions about how their information is handled and retained.
This section describes practical aspects of storage, segmentation, encryption, and retention that clients should expect when engaging with Barry Law. It explains default retention periods for account records, security logs, intake materials, and multimedia, along with options to modify retention based on client instruction or legal holds. The policy clarifies responsibilities for data access, subprocessors engaged for service delivery, and procedures for responding to incidents that could impact personal information.
Clients will find information about where data is hosted, typical safeguards that protect data in transit and at rest, and how backups and disaster recovery are handled. The firm also explains logging practices, access reviews, and the contractual obligations subprocessors must meet. This transparency supports informed decisions about retention needs and helps clients request adjustments to default schedules consistent with law firm instructions or legal requirements.
Terms used throughout this policy include ‘intake materials’ for text and documents provided by clients, ‘matter life’ to indicate the duration of an open client matter, ‘subprocessor’ for third-party service providers, and ‘retention schedule’ for default holding periods. Knowing these definitions helps clients understand what types of data are subject to specific retention rules, how data moves through systems, and what triggers deletion or extended retention under legal hold or litigation circumstances.
Key elements include hosting region selection, TLS for data in transit, industry-standard encryption at rest, tenant-aware segregation to isolate client data, role-based permissions, and options for single sign-on with multi-factor authentication. Operational processes encompass routine vulnerability scanning, patch management, secure change control, documented backup and restoration testing, and periodic reviews of access rights. These controls are supplemented by employee confidentiality measures and background screening where permitted.
This glossary provides clear definitions for terms that appear in the policy so clients can interpret retention schedules and security measures with confidence. It covers the types of data we store, common retention concepts, and roles that control access. The glossary also clarifies what constitutes a legal hold, how backup retention differs from primary storage retention, and what clients can expect when requesting deletion or data export under contract or applicable law.
Intake materials include client-provided text, documents, forms, and structured data used to open and manage a matter. These items are retained for the life of the matter and may be kept for an additional period consistent with firm policy or client direction. Access to intake materials is limited by role-based permissions, and the firm will follow specific deletion or retention instructions provided by the client or required by law.
A subprocessor is a third-party service provider engaged by the firm to perform data processing functions on behalf of the firm. Subprocessors operate under written agreements that require confidentiality, security measures, and deletion of data at the end of their services. The firm maintains a material subprocessor list available on request and evaluates subprocessor controls before onboarding them to ensure alignment with contractual security expectations.
A legal hold is an instruction to preserve specific records beyond normal retention periods because they may be relevant to ongoing litigation or regulatory matters. When a legal hold is issued, affected data is prevented from being deleted or altered until the hold is lifted. The firm coordinates legal holds with clients to ensure that required documents remain accessible for the duration of any dispute or regulatory review.
A retention schedule lists default retention periods for categories of data, such as billing records, security logs, website analytics, intake files, and multimedia recordings. The schedule explains when data will be deleted automatically and when it may be archived or aggregated for analysis. Clients may request adjustments to retention periods in writing, and retention may be extended for legal holds, litigation, or specific contractual obligations.
Organizations and law firms can choose limited retention approaches that keep only operational data for short periods, or comprehensive approaches that store full matter records for longer terms to satisfy legal and business needs. Limited retention reduces storage footprint and exposure, while comprehensive retention preserves a complete record for legal defenses, tax, or regulatory requirements. The appropriate choice depends on the client’s priorities, legal obligations, and the nature of the matter being handled.
A limited retention strategy may be suitable when regulatory or business needs require short-term access to operational records and there is no obligation to retain full matter histories. In such circumstances, retaining only essential billing, compliance, and minimal intake details for a concise period can reduce exposure and storage costs. Clients should confirm the specific retention requirements that apply to their industry before choosing a reduced retention plan.
Adopting shorter retention periods can lower the risk associated with storing sensitive data over long durations. When matters are straightforward and unlikely to trigger future disputes or audits, a limited approach that removes or anonymizes records sooner can reduce the surface area for incidents. Clients must weigh this benefit against potential needs for historical records in tax, regulatory, or future litigation scenarios.
Extended retention is often necessary to meet legal, tax, or regulatory obligations that require maintaining records for several years. Matters involving real estate transactions, bankruptcy filings, or complex business disputes may require a full archive of communications, documents, and multimedia. Preserving a detailed record supports compliance and enables thorough responses to inquiries or disputes that arise after a matter has closed.
Keeping comprehensive records preserves context and evidence that may be important later. Full retention of documents, intake notes, and recordings ensures that the history of a matter is available if unexpected issues, audits, or litigation arise. For clients who anticipate possible disputes or long-term obligations, maintaining a complete archive provides the strongest position for responding to future needs without losing critical information.
A comprehensive retention program balances legal compliance with operational readiness. It ensures required documents are available for audits, litigation, and tax matters while documenting decisions about data lifecycle management. When properly implemented, comprehensive retention reduces the likelihood of accidental deletion, enables efficient discovery processes, and provides clear records that support dispute resolution and regulatory reporting obligations.
Comprehensive retention also supports continuity of representation and client service by preserving matter histories and evidence. This approach allows the firm to access prior communications and documents when advising clients about follow-up matters or long-term obligations. Clear policies and transparent schedules also build client trust by demonstrating that data is managed consistently with legal responsibilities and firm practice.
One key benefit of comprehensive retention is better alignment with legal and regulatory timelines, which reduces the risk of penalties or evidence gaps. Maintaining records according to a documented schedule ensures that documents are available when needed for audits, filings, or dispute resolution. This documentation provides defensible retention practices and clear guidance for when records can be deleted under normal circumstances.
A robust retention program preserves institutional memory and the factual context of past engagements, enabling smoother transitions and informed decision-making. When matters span years or involve complex transactions, having access to prior documents and recordings supports consistent client service. Archival processes and tested restoration procedures also ensure that data can be recovered reliably in the event of system failures or accidental deletions.
Evaluate legal, tax, and regulatory retention requirements at the outset of any matter to determine appropriate retention periods. Early review helps avoid unnecessary retention of sensitive materials and ensures that critical records are preserved. Clients should inform the firm of any industry-specific rules or contractual obligations so retention schedules can be adjusted accordingly. Planning retention up front reduces later disruption and supports consistent recordkeeping.
Keep an up-to-date list of subprocessors and review their contractual obligations periodically to ensure they meet confidentiality and security requirements. Clients may request a list of material subprocessors to understand where data is processed and stored. Verifying subprocessor practices reduces risk and supports transparent decision-making about data transfers and contract terms, especially when cross-border processing could apply.
A formal data policy reduces ambiguity about how client records are handled, retained, and deleted, which helps both clients and the firm meet legal obligations. It supports predictable responses to discovery requests, audits, and regulatory inquiries. By documenting hosting locations, encryption practices, subprocessors, and retention schedules, a policy gives clients confidence in how sensitive information is managed throughout the lifecycle of a matter.
Adopting a formal policy also helps allocate responsibility between the firm and clients for retention decisions and legal holds. Clear procedures minimize the risk of accidental data loss and help streamline incident response. Clients benefit from knowing how long various categories of records will be maintained and the process for modifying retention timelines, requesting exports, or asking for secure deletion in accordance with contracts or applicable law.
Scenarios that commonly require documented retention practices include real estate closings, bankruptcy proceedings, tax audits, mergers and acquisitions, and disputes likely to trigger discovery. In these circumstances, preserving full matter histories and related communications is often essential. A documented policy helps ensure that relevant records remain available for the necessary period and that any legal holds are implemented consistently.
When litigation is possible or ongoing, retention policies should be adjusted to ensure that all relevant documents and communications are preserved. This includes intake notes, emails, transactional documents, and multimedia recordings that could be material. Implementing holds and cataloging affected custodians ensures that preservation obligations are met and reduces the risk of spoliation or incomplete discovery responses.
Regulatory examinations and tax audits often require access to historical records that span several years. Retention schedules should reflect these potential needs by preserving financial records, correspondence, and transaction documents for the period required by applicable rules. Proper archival and indexing practices make retrieval more efficient when responding to audit requests or compliance inquiries.
Complex transactions such as mergers or large real estate deals may unfold over a long period and require comprehensive records to support due diligence and post-closing obligations. Keeping a complete set of documents, communications, and recordings helps resolve future questions about transaction terms or performance. Retention planning for long-term transactions ensures that important records remain intact and accessible when needed.
Barry Law combines practical legal services with documented approaches to data protection and retention, tailored to business, tax, real estate, and bankruptcy matters. The firm provides transparent information about where data is stored, the safeguards applied, and the default retention periods that guide record lifecycle decisions. Clients benefit from clear procedures for legal holds, subprocessors, and incident notification.
The firm maintains secure hosting practices and works with vetted service providers under written agreements that require confidentiality and data deletion at the end of service. Regular reviews, logging, and access controls help ensure that client data is handled consistently and that any changes to storage or processing are documented and communicated to affected clients in a timely manner.
Barry Law offers direct contact for data questions and maintains a posted retention schedule for certain sensitive categories such as biometric identifiers when used. Clients receive clear instructions for requesting retention changes or exports and can rely on documented incident response procedures should a security event occur that affects personal information.
Our process begins with secure intake and the classification of matter-related data, followed by storage in a tenant-segregated environment with encrypted backups and access logging. Throughout the matter lifecycle we conduct periodic access reviews, apply changes through secured change control, and maintain tested restoration procedures. At matter closing we follow the retention schedule unless the client requests different handling or a legal hold requires longer preservation.
During intake we collect required information and classify data by category so appropriate protection and retention rules can be applied. This step establishes matter identifiers and defines which records are subject to longer retention or immediate deletion upon request. Classification supports task-specific permissions and makes it easier to locate records for discovery, audits, or client requests.
Intake documentation is stored under secure controls and linked to matter records that determine retention timelines. Assigning matter identifiers and categorizing documents at setup reduces ambiguity about what is kept and for how long. The firm secures intake data in transit and at rest and limits access to roles necessary to perform legal work while logging access for auditability.
At matter inception the firm confirms default retention settings and invites clients to provide instructions that modify retention periods or flag materials that should be excluded from routine deletion. This early dialogue ensures retention aligns with client expectations, regulatory needs, or contractual provisions. Any client-directed changes are documented and applied to the matter record.
Throughout the matter lifecycle, systems perform encrypted backups, vulnerability scans, and periodic restorations to verify recovery capability. Access is governed by role-based permissions and reviewed periodically. Logging and alerting provide visibility into system events, and change management procedures ensure updates are applied safely. The combined controls aim to preserve confidentiality, integrity, and availability of client records.
Backups are encrypted and tested for restoration against documented recovery time and recovery point objectives. The firm maintains procedures for backup retention, secure transfer, and restoration to reduce downtime and data loss risk. Regular testing ensures that restoration processes function as expected, supporting continuity of service for client matters even after significant system events.
The firm applies regular vulnerability scanning and patch updates to systems that store or process client data. Change control and approval processes ensure modifications are planned, tested, and documented. These management practices reduce the risk of exploitation and maintain a secure operational environment for matter-related information and communications.
At matter conclusion the firm applies the retention schedule to determine whether files are archived, deleted, or retained for an extended period due to legal holds or client direction. Where deletion is appropriate, processes ensure secure removal of data from primary systems and mandated deletion from subprocessors at the end of their services. Clients can request exports or earlier deletion in writing.
Retention schedules are applied to each matter to determine how long documents, billing records, logs, and multimedia are kept. The policy lists default retention periods for common categories, and the firm documents any deviations requested by clients or required by law. Applying these schedules consistently helps maintain predictable records management and simplifies compliance with requests and audits.
When data reaches the end of its retention period, secure deletion procedures are employed to remove it from active systems. Subprocessors are contractually required to delete client data at the end of their engagement. The firm documents deletion requests and confirmations so clients can verify that material has been removed or retained only as instructed for legal holds or other specified reasons.
Seasoned, flat-fee counsel you can count on.
Barry Rosenzweig has served Minnesota and Arizona for three decades, guiding 3,000 clients through bankruptcy, real estate, estate planning, tax resolution and business matters with clear communication and practical strategies.
From first call to final signature, we keep the process simple, predictable and affordable. Most matters can be handled remotely or in one short meeting, and you’ll always know your next step and your cost before you decide.
At Rosenzweig Law in Minnesota, we provide full-service probate guidance to help families settle estates with clarity and care. From asset inventory and administration to creditor notices and distribution, we handle every step efficiently. Our team works to minimize costs, avoid conflicts, and protect your family’s inheritance throughout the process.
Client data is primarily hosted in the United States, with region-specific options available contractually when needed. Data in transit is protected with TLS, and data at rest uses industry-standard encryption. Tenant-aware segmentation and role-based access controls limit access to authorized personnel, and options such as single sign-on with multi-factor authentication can be applied to further reduce unauthorized access risks. Backups are encrypted and stored according to documented procedures, and subprocessors are bound by agreements that require confidentiality and secure handling. The firm maintains logging and monitoring to detect anomalous activity and conducts periodic reviews of access controls to maintain a secure environment for client information.
Default retention periods are set for common categories: account and billing records are retained for seven years, audit and security logs for 24 months, and website analytics up to 26 months before aggregation. Intake text and documents are generally retained for the life of the matter plus up to three years unless otherwise instructed by the law firm or client requirements. Audio and video recordings follow a similar schedule tied to matter life plus up to three years, and biometric identifiers, if used, are retained only until the purpose is satisfied or up to three years after last interaction. Retention may be shortened or extended by written client request or legal hold.
Backups are performed on an encrypted basis with documented recovery time and recovery point objectives. The firm tests restorations regularly to ensure that backups can be recovered reliably and that data integrity is maintained. These tests are part of a broader disaster recovery plan designed to minimize downtime and data loss in the event of system incidents. Testing includes restoration of representative datasets to confirm that processes work end to end. Documentation of these tests and their outcomes is maintained so that the firm can demonstrate recovery capability and adjust procedures as necessary to meet operational requirements.
Barry Law maintains a written incident response plan with escalation procedures and 24/7 availability for handling incidents. If a security incident affects personal information, the firm will investigate promptly, take steps to contain and remediate the issue, and notify affected customers or individuals without unreasonable delay under applicable law and contract. Notification will include relevant details and recommended next steps when required by law. Response steps include identifying the scope of the incident, preserving evidence, communicating with affected parties, and implementing measures to prevent recurrence. The firm coordinates with subprocessors to ensure they also follow incident response obligations under contractual agreements.
Clients may request export or deletion of their data before standard retention periods expire by submitting a written request that identifies the matter and the specific data categories. The firm will review requests and take action consistent with contractual obligations, any applicable legal holds, and legal requirements. Some deletions may be constrained by obligations to retain records for regulatory or litigation reasons. When deletion is feasible, the firm will follow secure deletion procedures and ensure that subprocessors remove data at the end of their services. Export requests will be handled to provide clients with their records in a common, machine-readable format where practicable.
Subprocessors are third-party service providers retained to perform data processing tasks on behalf of the firm. They are vetted through due diligence that evaluates security controls, confidentiality practices, and compliance with contractual obligations. Written agreements require subprocessors to implement appropriate safeguards and to delete or return data at the end of their services. The firm maintains a list of material subprocessors upon request so clients can review where and how data is processed. Ongoing oversight includes periodic reassessments and contractual provisions that align subprocessors’ responsibilities with the firm’s data protection commitments.
Primary storage is in the United States, but where cross-border transfers occur they are governed by appropriate safeguards determined by applicable law and contractual arrangements. The firm evaluates transfer mechanisms and implements protections such as data processing agreements and required contractual clauses to protect data during cross-border processing. Clients with specific localization requirements should raise those needs when engaging the firm so that hosting region options and contractual arrangements can be reviewed. The firm aims to provide transparency about transfer practices and to employ safeguards that meet legal and contractual obligations.
To request a legal hold, contact the firm with the matter identifier and a description of the records that must be preserved. The firm will document the hold, identify custodians and data sources, and suspend routine deletion for affected materials until the hold is lifted. Clear communication helps ensure that all relevant data remains available for the duration of the matter. The firm coordinates with clients to define the scope and duration of legal holds and maintains records of holds for auditability. When a hold is no longer necessary, clients should confirm with the firm so normal retention schedules can resume.
Clients may request a copy of the retention schedule or a list of material subprocessors by contacting the firm. The firm provides these materials to help clients understand how different categories of data are handled and to support informed decisions about retention and processing preferences. Requests should include the client’s name and matter identifiers to expedite response. The firm maintains current documentation and will provide reasonable access to the information needed to confirm where data is processed, the default retention timelines, and the contractual commitments subprocessors make to protect client information. This aids transparency and supports client oversight.
For questions about this policy or to make requests related to retention, export, or deletion, contact Barry Law at [email protected]. For written requests, include the matter identifier and specific instructions or categories of data that your request concerns to ensure a prompt and precise response. The firm’s physical mailing address is 3800 American Blvd W Suite 1500, Bloomington, MN 55431. The firm will respond to inquiries in a timely manner and coordinate with clients to implement reasonable requests consistent with contractual terms and applicable law.
"*" indicates required fields