Effective Date: September 13, 2026
Last Updated: September 13, 2026
BRAIDAN Business Solutions ("BRAIDAN," "we," "us," or "our") recognizes that bookkeeping and related business services may require access to confidential financial and business information.
This Policy describes the principles BRAIDAN follows regarding access, protection, retention, transfer, and secure disposal of information processed in connection with bookkeeping and related services.
BRAIDAN seeks to collect, access, and retain only information reasonably necessary to provide authorized services, maintain appropriate records, comply with applicable obligations, and protect legitimate business and legal interests.
Depending on the services provided, protected information may include:
The Client retains ownership of its underlying financial records, documents, accounting data, and other Client-provided information.
BRAIDAN's access to or possession of Client information for purposes of providing services does not transfer ownership of that information to BRAIDAN.
Whenever reasonably possible, the Client should remain the primary owner or administrator of its accounting and financial-platform accounts.
BRAIDAN will seek to use only the level of access reasonably necessary to perform the contracted service.
Where a platform offers different permission levels, BRAIDAN will favor the least-privileged access appropriate for the work being performed.
Access to confidential financial information should be limited to persons with a legitimate business need.
BRAIDAN will not request that Clients send online-banking passwords or full banking login credentials through:
Where available, BRAIDAN will favor:
BRAIDAN will use multi-factor authentication where reasonably available for systems containing confidential Client financial information.
This may include:
BRAIDAN will favor providers and systems that use appropriate security measures, including encrypted transmission and storage where reasonably available.
Sensitive financial documents should not routinely be transmitted through unsecured channels when a secure accounting platform, portal, or other appropriate method is reasonably available.
Confidential bookkeeping documents should be stored in approved business systems.
BRAIDAN will avoid using personal email accounts, personal cloud-storage accounts, SMS, WhatsApp, or unprotected personal devices as permanent repositories for Client financial records.
If a Client sends a sensitive document through an ordinary communication method, BRAIDAN may move it to an approved system and remove unnecessary copies when reasonably practicable.
Employees or contractors will receive access to Client financial information only when reasonably necessary for their assigned work.
Access should be individual rather than shared whenever reasonably possible.
Persons with access to confidential information should be required to maintain confidentiality and follow applicable BRAIDAN security procedures.
Access should be removed promptly when it is no longer required.
BRAIDAN may use reputable third-party service providers to deliver bookkeeping and related services.
These may include:
BRAIDAN will seek to use providers reasonably capable of protecting the information entrusted to them and will limit disclosure to information reasonably necessary for the relevant service.
While bookkeeping services remain active, BRAIDAN may retain information reasonably necessary to:
BRAIDAN does not intend to retain sensitive financial information indefinitely merely because storage is available.
When bookkeeping services end, BRAIDAN will take reasonable steps to:
Ending bookkeeping services does not mean that financial records will automatically be deleted immediately.
BRAIDAN's normal operational transition period for bookkeeping information that is no longer actively needed may be up to approximately 90 days after the bookkeeping relationship ends.
This period is intended to allow for:
The 90-day period is an operational BRAIDAN policy and does not mean that every category of information must legally be retained for exactly 90 days.
Some information may be retained beyond the normal transition period when reasonably necessary because of:
Information retained for one of these purposes will be kept only as long as reasonably necessary for that purpose or applicable requirement.
Clients remain responsible for maintaining records necessary for their own tax filings, payroll obligations, regulatory requirements, audits, and business operations.
BRAIDAN's internal retention practices do not replace the Client's own legal, accounting, or tax recordkeeping obligations.
When BRAIDAN no longer has a legitimate or legally required reason to retain confidential Client information, BRAIDAN will take reasonable measures to dispose of that information securely.
Depending on the system, this may include:
BRAIDAN does not promise instantaneous deletion from every backup or disaster-recovery system where information may remain temporarily until the normal backup lifecycle expires.
BRAIDAN will periodically review access to systems containing confidential financial information.
Access should also be reviewed when:
Devices used to access confidential Client financial information should use reasonable security safeguards where available, including:
BRAIDAN personnel should avoid permanently storing Client financial records in unsecured local folders when an approved business system is available.
BRAIDAN will maintain a process for responding to suspected loss, unauthorized access, disclosure, or misuse of confidential Client information.
Depending on the circumstances, the response may include:
BRAIDAN will comply with applicable breach-notification requirements when a security incident meets the legal conditions requiring notification.
Whether a particular event requires notification depends on the information involved, the circumstances of the event, applicable law, and other relevant factors.
BRAIDAN will not represent that every security event automatically constitutes a legally reportable data breach.
BRAIDAN will use reasonable safeguards appropriate to the nature of the information it handles.
However, no internet-connected system, financial platform, cloud provider, accounting application, or other technology can guarantee absolute security.
Nothing in this Policy should be interpreted as a guarantee that a security incident can never occur.
BRAIDAN may review and update this Policy as its services, technology, providers, staffing, data practices, or legal obligations change.
Questions regarding bookkeeping data retention, confidentiality, or security may be directed to:
BRAIDAN Business Solutions
Email: [BUSINESS EMAIL — PENDING]
Phone: (951) 334-2399
Mailing Address: [BUSINESS ADDRESS — PENDING]