LKP Privacy policy

Public privacy, data-protection, retention, and DSAR handling terms for Locksmith Key Pricer.

Legal Terms Privacy
Back to app
LKP-PP-001 | Effective June 28, 2026 Rendered from the current approved policy source stored in the repo.
# LKP Privacy & Data Protection Policy

**Document ID:** LKP-PP-001  
**Version:** 1.0  
**Effective Date:** June 28, 2026  
**Classification:** Public  
**Owner:** Joshua Rivera, Founder & Principal Developer  
**Entity:** Digital Auction House LLC dba LKP  
**Parent Company:** Digital Auction House LLC ("DAH")  
**State of Formation:** South Carolina  
**Contact:** support@locksmithkeypricer.com

---

## Table of Contents

1. [Introduction & Scope](#1-introduction--scope)
2. [Definitions](#2-definitions)
3. [Data Classification Map](#3-data-classification-map)
4. [Data We Collect](#4-data-we-collect)
5. [How We Use Your Data](#5-how-we-use-your-data)
6. [Legal Bases for Processing](#6-legal-bases-for-processing)
7. [Data Sharing & Disclosure](#7-data-sharing--disclosure)
8. [FTC & ROSCA Compliance](#8-ftc--rosca-compliance)
9. [South Carolina Specific Provisions](#9-south-carolina-specific-provisions)
10. [GDPR / UK GDPR Rights](#10-gdpr--uk-gdpr-rights)
11. [CCPA / CPRA Rights](#11-ccpa--cpra-rights)
12. [Unified DSAR Process](#12-unified-dsar-process)
13. [Data Retention Schedule](#13-data-retention-schedule)
14. [Legal Hold Procedure](#14-legal-hold-procedure)
15. [Data Security](#15-data-security)
16. [Children's Privacy](#16-childrens-privacy)
17. [International Data Transfers](#17-international-data-transfers)
18. [Changes to This Policy](#18-changes-to-this-policy)
19. [Contact Information](#19-contact-information)
20. [Document Control](#20-document-control)

---

## 1. Introduction & Scope

### 1.1 Who We Are

Digital Auction House LLC dba LKP ("LKP," "we," "us," or "our") is a South Carolina limited liability company that operates the LKP platform — a Software-as-a-Service (SaaS) application for automotive locksmith professionals. LKP is a subsidiary of Digital Auction House LLC ("DAH"), which serves as the parent development and intellectual property holding entity.

### 1.2 What This Policy Covers

This Privacy & Data Protection Policy describes how we collect, use, store, share, and protect personal information when you:

- Visit our website at locksmithkeypricer.com
- Use the LKP mobile application or web application
- Create an account or participate in the LKP beta program
- Contact us for support or business inquiries
- Interact with our services in any other way

### 1.3 Jurisdictional Scope

This policy is designed to comply with applicable privacy laws in the jurisdictions where we operate or where our users reside. The following jurisdictions receive specific treatment in this policy:

| Jurisdiction | Applicability | Trigger |
|-------------|--------------|---------|
| **United States (Federal)** | Applies | LKP is a U.S. entity; all users are currently U.S.-based |
| **South Carolina** | Applies | LKP is formed and headquartered in South Carolina |
| **California (CCPA/CPRA)** | Conditional | Triggered if LKP collects covered personal information of California residents AND meets statutory thresholds |
| **European Union (GDPR)** | Conditional | Triggered if an EU individual creates an account, or if LKP processes personal data of EU residents |
| **United Kingdom (UK GDPR)** | Conditional | Triggered if a UK individual creates an account, or if LKP processes personal data of UK residents |

**Current status:** As of the effective date, LKP operates an invite-only beta program with approximately ten (10) U.S.-based users. GDPR and UK GDPR provisions are included proactively but are not currently triggered. CCPA/CPRA provisions are included proactively but LKP does not currently meet the statutory thresholds for applicability.

---

## 2. Definitions

| Term | Definition |
|------|-----------|
| **Personal Information / Personal Data** | Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household |
| **Processing** | Any operation performed on personal data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure, or destruction |
| **Data Subject** | An identified or identifiable natural person whose personal data is processed |
| **Controller** | The entity that determines the purposes and means of processing personal data. For purposes of this policy, the controller is Digital Auction House LLC dba LKP |
| **Processor** | An entity that processes personal data on behalf of the controller |
| **DSAR** | Data Subject Access Request — a request by an individual to exercise their privacy rights |
| **Covered Personal Information** | As defined under CCPA/CPRA: personal information collected by a business from the consumer |
| **Service Provider** | A third party that processes personal information on behalf of LKP pursuant to a written contract |

---

## 3. Data Classification Map

LKP classifies all personal and operational data into five (5) classes. Each class has a defined legal basis, default handling, and retention period.

### Class 1: Authentication & Account Metadata

| Attribute | Value |
|-----------|-------|
| **Data Elements** | Email address, hashed password, MFA enrollment data, account creation timestamp, invitation token, professional verification status, role assignment |
| **Legal Basis (GDPR)** | Contract performance (Art. 6(1)(b)) — necessary to provide the service |
| **Legal Basis (CCPA)** | Business purpose — maintaining accounts and providing the service |
| **Default Handling** | Encrypted at rest (Neon PostgreSQL encryption); hashed passwords (bcrypt); MFA secrets encrypted with application key |
| **Retention** | Indefinitely (LKP maintains a strict indefinite data retention policy for transactional integrity and historical pricing index preservation) |
| **DSAR Impact** | Subject to access and deletion requests; deletion triggers account termination |

### Class 2: Search & Pricing Operations

| Attribute | Value |
|-----------|-------|
| **Data Elements** | Search queries (Year/Make/Model, keyway, VIN prefix), search timestamps, result sets viewed, price comparisons accessed |
| **Legal Basis (GDPR)** | Legitimate interest (Art. 6(1)(f)) — product improvement and service optimization |
| **Legal Basis (CCPA)** | Business purpose — improving and debugging the service |
| **Default Handling** | Stored in operational database; associated with user account for personalization; aggregated for analytics |
| **Retention** | Indefinitely (LKP does not delete any searches or data entered into the system) |
| **DSAR Impact** | Subject to access requests; individual events subject to deletion; aggregated data not subject to deletion (anonymized) |

### Class 3: Billing References

| Attribute | Value |
|-----------|-------|
| **Data Elements** | Stripe customer ID, subscription plan, billing cycle, payment status, invoice references. **LKP does not store credit card numbers, bank account numbers, or any payment card data.** |
| **Legal Basis (GDPR)** | Contract performance (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) — tax and financial record-keeping |
| **Legal Basis (CCPA)** | Business purpose — processing payments and maintaining financial records |
| **Default Handling** | Stripe handles all payment card data; LKP stores only reference identifiers and subscription metadata |
| **Retention** | Minimum 2 years after last transaction (tax and financial record-keeping requirements) |
| **DSAR Impact** | Subject to access requests; deletion may be limited by legal record-keeping obligations |

### Class 4: Admin / Owner Operational Logs

| Attribute | Value |
|-----------|-------|
| **Data Elements** | Admin action logs (crawl job management, product match approvals, user management actions), system configuration changes, deployment logs |
| **Legal Basis (GDPR)** | Legitimate interest (Art. 6(1)(f)) — security, audit, and operational integrity |
| **Legal Basis (CCPA)** | Business purpose — security and fraud detection |
| **Default Handling** | Stored in operational database; access restricted to admin role |
| **Retention** | Minimum 1 year |
| **DSAR Impact** | Access requests may be limited to the extent logs contain information about other individuals; security logs may be exempt from deletion |

### Class 5: Support Artifacts

| Attribute | Value |
|-----------|-------|
| **Data Elements** | Support tickets, email correspondence, bug reports, feature requests, screenshots provided by users |
| **Legal Basis (GDPR)** | Legitimate interest (Art. 6(1)(f)) — product support and improvement |
| **Legal Basis (CCPA)** | Business purpose — providing customer support |
| **Default Handling** | Stored in support system (email); may be transferred to issue tracker (redacted) |
| **Retention** | Minimum 1 year after ticket resolution |
| **DSAR Impact** | Subject to access and deletion requests |

---

## 4. Data We Collect

### 4.1 Information You Provide Directly

- **Account registration:** Email address, password, professional credentials for verification
- **Profile information:** Business name, license numbers (for verification only — not stored after verification unless required)
- **Support communications:** Content of emails, bug reports, feature requests
- **Feedback:** Product feedback, survey responses, beta testing observations

### 4.2 Information We Collect Automatically

- **Usage data:** Search queries, pages viewed, features used, timestamps
- **Device information:** Device type, operating system, browser type and version (for mobile app: device model, OS version)
- **Network information:** IP address, approximate geographic location (derived from IP)
- **Performance data:** Page load times, error rates, API response times

### 4.3 Information We Receive from Third Parties

- **Stripe:** Payment status, subscription events, invoice status (no payment card data)
- **Render.com:** Deployment status, health check results, infrastructure metrics (no personal data)
- **Neon:** Database performance metrics (no personal data)

### 4.4 Information We Do NOT Collect

- Credit card numbers, bank account numbers, or payment card data (handled entirely by Stripe)
- Social Security numbers or government-issued ID numbers
- Biometric data
- Health or medical information
- Precise geolocation (GPS coordinates) | Not currently collected (May be collected in the future to map quotes/dealers for routing) |
- Voice recordings or video
- Data from children under 18

---

## 5. How We Use Your Data

| Purpose | Data Classes Used | Legal Basis |
|---------|-------------------|------------|
| Provide and maintain the LKP platform | 1, 2, 3 | Contract performance |
| Process payments and manage subscriptions | 1, 3 | Contract performance |
| Verify professional credentials | 1 | Contract performance; legitimate interest |
| Improve search results and product matching | 2 | Legitimate interest |
| Provide customer support | 1, 5 | Contract performance; legitimate interest |
| Detect and prevent fraud and abuse | 1, 2, 4 | Legitimate interest |
| Comply with legal obligations | 1, 3, 4 | Legal obligation |
| Send service-related communications | 1 | Contract performance |
| Analyze usage patterns (aggregated) | 2 | Legitimate interest |
| Enforce terms of service | 1, 2, 4 | Legitimate interest; contract performance |

---

## 6. Legal Bases for Processing

### 6.1 Under GDPR (when applicable)

| Legal Basis | Article | When Used |
|-------------|---------|-----------|
| **Contract performance** | Art. 6(1)(b) | Account creation, service delivery, payment processing |
| **Legal obligation** | Art. 6(1)(c) | Tax record-keeping, data breach notification, law enforcement requests |
| **Legitimate interest** | Art. 6(1)(f) | Security, fraud prevention, product improvement, analytics |
| **Consent** | Art. 6(1)(a) | Marketing communications (if implemented in the future); not currently used |

### 6.2 Under U.S. Law

U.S. privacy law does not generally require a "legal basis" for data processing in the GDPR sense. However, LKP adheres to the following principles:

- **Notice:** This policy provides clear notice of our data practices
- **Choice:** Users can exercise opt-out rights where applicable
- **Access:** Users can request access to their data
- **Security:** We implement reasonable security measures
- **Enforcement:** We commit to resolving privacy complaints

---

## 7. Data Sharing & Disclosure

### 7.1 Service Providers

We share personal information with the following categories of service providers, each bound by contractual obligations to process data only as directed:

| Provider | Data Shared | Purpose |
|----------|-------------|---------|
| **Stripe** | Email, billing references | Payment processing and subscription management |
| **Render.com** | Application logs (may contain IP addresses) | Infrastructure hosting and deployment |
| **Neon** | Encrypted database contents | Database hosting |
| **Vercel** | None (static content hosting) | Frontend hosting |

### 7.2 Legal Disclosures

We may disclose personal information when required to:

- Comply with applicable law, regulation, legal process, or governmental request
- Enforce our Terms of Service or other agreements
- Protect the rights, property, or safety of LKP, our users, or the public
- Detect, prevent, or address fraud, security, or technical issues

### 7.3 No Sale of Personal Information

**We do not sell personal information.** We have not sold personal information in the preceding twelve (12) months, and we have no plans to sell personal information.

### 7.4 No Sharing for Cross-Context Behavioral Advertising

We do not share personal information for cross-context behavioral advertising as defined under the CPRA.

---

## 8. FTC & ROSCA Compliance

### 8.1 FTC Act — Unfair or Deceptive Practices

LKP commits to the following practices under Section 5 of the FTC Act (15 U.S.C. § 45):

- **Truthful advertising:** All descriptions of the LKP platform are accurate and not misleading
- **Privacy promises kept:** We honor the commitments made in this Privacy Policy
- **Data security:** We implement reasonable security measures appropriate to the sensitivity of the data we process
- **No deceptive data practices:** We do not collect, use, or share data in ways that contradict the representations in this policy

### 8.2 ROSCA — Restore Online Shoppers' Confidence Act (15 U.S.C. § 8401 et seq.)

When LKP transitions from beta to paid subscriptions, we will comply with ROSCA requirements:

#### 8.2.2 Express Informed Consent

LKP will obtain the consumer's express informed consent before charging for any subscription. This means:

- The consumer must take an affirmative action (e.g., clicking a clearly labeled "Subscribe" button)
- The consent mechanism must be separate from any other consent (e.g., not bundled with Terms of Service acceptance)
- The consumer must have an opportunity to review all material terms before consenting

#### 8.2.3 Click-to-Cancel

In compliance with the FTC's Click-to-Cancel rule and 15 U.S.C. § 8401:

- Consumers can cancel their subscription through the same medium they used to subscribe (e.g., if they subscribed online, they can cancel online)
- The cancellation mechanism is at least as simple as the subscription mechanism
- No mandatory phone calls, chat sessions, or multi-step procedures are required to cancel
- Cancellation takes effect within 1 business day of the request
- A confirmation of cancellation is provided via email

---

## 9. South Carolina Specific Provisions

### 9.1 SaaS Tax Treatment

Under South Carolina law, SaaS is treated as taxable pursuant to:

- **S.C. Code Ann. § 12-36-910(B)(3):** Defines "tangible personal property" to include "computer software" regardless of delivery method
- **SC Revenue Ruling #16-2:** Clarifies that SaaS is subject to sales and use tax in South Carolina

**Tax rate:** 6% state sales tax plus 1–3% local option tax (varies by county/municipality)

LKP will collect and remit applicable South Carolina sales and use tax on all paid subscriptions for South Carolina-based customers. Out-of-state tax obligations will be assessed based on economic nexus thresholds in each state.

### 9.2 SC Data Breach Notification Act

LKP is subject to the South Carolina Data Breach Notification Act:

- **S.C. Code Ann. § 39-1-90:** Requires businesses to notify South Carolina residents of security breaches involving their personal identifying information
- **S.C. Code Ann. § 1-11-490:** Applies to state agencies and their contractors (relevant if LKP contracts with SC government entities)

**Notification obligations:**

| Requirement | Detail |
|-------------|--------|
| **Who must be notified** | Any South Carolina resident whose personal identifying information was, or is reasonably believed to have been, acquired by an unauthorized person |
| **Timing** | Without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system |
| **Method** | Written notice, electronic notice (if consistent with E-SIGN Act), or substitute notice (if cost > $250,000 or affected class > 500,000) |
| **Content** | The incident in general terms, the type of personal identifying information subject to the unauthorized access, what the business has done to protect the data, what the individual can do to protect themselves, contact information |
| **Consumer Protection Division** | Notify the SC Department of Consumer Affairs if notification is provided to more than 1,000 persons |

### 9.3 Personal Identifying Information (South Carolina Definition)

Under SC law, "personal identifying information" includes:

- Social Security number
- Driver's license number or state ID number
- Financial account number (with security code, access code, or password)
- Credit/debit card number (with security code, access code, or password)
- Other information that can be used to access a person's financial accounts

**LKP's exposure:** LKP does not collect Social Security numbers, driver's license numbers, or financial account numbers. Credit card data is processed entirely by Stripe. LKP's breach notification obligations are limited to email addresses and hashed passwords (which may not meet SC's threshold for "personal identifying information" unless combined with other identifying elements).

---

## 10. GDPR / UK GDPR Rights

**Applicability:** This section applies only when GDPR or UK GDPR is triggered by the processing of personal data of EU/UK residents.

### 10.1 Your Rights Under GDPR

If GDPR applies to our processing of your data, you have the following rights:

| Right | Description | How to Exercise |
|-------|-------------|-----------------|
| **Right of Access** (Art. 15) | You have the right to obtain confirmation of whether we process your personal data and, if so, access to that data and information about the processing | Submit a DSAR to support@locksmithkeypricer.com |
| **Right to Rectification** (Art. 16) | You have the right to have inaccurate personal data corrected and incomplete data completed | Submit a correction request to support@locksmithkeypricer.com |
| **Right to Erasure** (Art. 17) | You have the right to have your personal data deleted in certain circumstances (e.g., data is no longer necessary, consent withdrawn, unlawful processing) | Submit a deletion request to support@locksmithkeypricer.com |
| **Right to Restriction** (Art. 18) | You have the right to restrict processing in certain circumstances (e.g., you contest accuracy, processing is unlawful) | Submit a restriction request to support@locksmithkeypricer.com |
| **Right to Data Portability** (Art. 20) | You have the right to receive your personal data in a structured, commonly used, machine-readable format | Submit a portability request to support@locksmithkeypricer.com |
| **Right to Object** (Art. 21) | You have the right to object to processing based on legitimate interest | Submit an objection to support@locksmithkeypricer.com |
| **Right re: Automated Decision-Making** (Art. 22) | You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects | Contact support@locksmithkeypricer.com |

### 10.2 Response Timelines (GDPR)

- **Acknowledgment:** Within 1 business day of receipt
- **Substantive response:** Within 30 calendar days of receipt (extendable by 60 days for complex requests, with notice)
- **Format:** Electronic, unless otherwise requested

### 10.3 Data Protection Officer

LKP has not appointed a Data Protection Officer (DPO) as it does not meet the mandatory appointment criteria under Art. 37 GDPR. All privacy inquiries should be directed to support@locksmithkeypricer.com.

---

## 11. CCPA / CPRA Rights

**Applicability:** This section applies when CCPA/CPRA is triggered by the collection of covered personal information of California residents and LKP meets statutory thresholds.

### 11.1 Your Rights Under CCPA/CPRA

| Right | Description |
|-------|-------------|
| **Right to Know** | You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose, and the categories of third parties with whom we share it |
| **Right to Delete** | You have the right to request deletion of personal information we have collected, subject to exceptions (e.g., completing a transaction, detecting security incidents, complying with legal obligations) |
| **Right to Correct** | You have the right to request correction of inaccurate personal information |
| **Right to Opt-Out of Sale** | You have the right to opt out of the sale of your personal information. **LKP does not sell personal information.** |
| **Right to Opt-Out of Sharing** | You have the right to opt out of sharing your personal information for cross-context behavioral advertising. **LKP does not share personal information for this purpose.** |
| **Right to Limit Use of Sensitive Information** | You have the right to limit the use and disclosure of sensitive personal information. **LKP does not collect sensitive personal information as defined by CPRA.** |
| **Right to Non-Discrimination** | We will not discriminate against you for exercising your CCPA/CPRA rights |

### 11.2 "Do Not Sell or Share My Personal Information"

**LKP does not sell or share personal information** as those terms are defined under the CCPA/CPRA. We have not sold or shared personal information in the preceding twelve (12) months. No opt-out mechanism is required at this time, but we will implement a "Do Not Sell or Share My Personal Information" link on our website if our data practices change.

### 11.3 DSAR Methods (CCPA)

California residents may submit requests through:

- **Email:** support@locksmithkeypricer.com
- **In-app:** (when available) Through the account settings page

### 11.4 Authorized Agents

California residents may designate an authorized agent to submit requests on their behalf. We will require written authorization from the consumer and verification of the agent's identity.

### 11.5 Response Timelines (CCPA)

- **Acknowledgment:** Within 10 business days of receipt
- **Substantive response:** Within 45 calendar days of receipt (extendable by an additional 45 days with notice)

---

## 12. Unified DSAR Process

Regardless of jurisdiction, LKP follows a unified Data Subject Access Request (DSAR) process for all privacy rights requests.

### 12.1 DSAR Workflow

```
Step 1: INTAKE
    │   Receive request via email (support@locksmithkeypricer.com)
    │   or in-app submission
    │   Log request with: timestamp, requestor identity, request type
    │   Acknowledge receipt within 1 business day
    │
    ▼
Step 2: IDENTITY VERIFICATION
    │   Verify requestor's identity using at least two factors:
    │     - Email address on file
    │     - Account credentials (if active account)
    │     - Government-issued ID (last resort, for non-account holders)
    │   If verification fails: request additional information
    │   If verification cannot be completed: deny request with explanation
    │
    ▼
Step 3: CLASSIFY REQUEST
    │   Determine request type:
    │     - Access (what data do you have about me?)
    │     - Deletion (delete my data)
    │     - Correction (fix inaccurate data)
    │     - Portability (give me my data in machine-readable format)
    │     - Restriction (stop processing my data)
    │     - Objection (I object to specific processing)
    │   Determine applicable jurisdiction(s) and response timeline
    │
    ▼
Step 4A: ACCESS RESPONSE          Step 4B: DELETION WITH LEGAL-HOLD CHECK
    │   Compile all personal            │   Identify all data stores
    │   data across all data            │   containing requestor's data
    │   stores (Classes 1–5)            │
    │                                   │   Check for active legal holds
    │   Format response:                │     - If hold exists: exclude
    │     - Structured data as JSON     │       held data from deletion;
    │     - Narrative summary           │       notify requestor
    │     - Categories and sources      │     - If no hold: proceed
    │                                   │       with full deletion
    │   Deliver to requestor via        │
    │   secure method (encrypted        │   Execute deletion across
    │   email or secure download)       │   all affected systems
    │                                   │
    │                                   │   Verify deletion complete
    │                                   │   (spot-check each data store)
    │
    ▼
Step 5: COMPLETION WITH EVIDENCE
    │   Log completion: timestamp, actions taken, data stores affected
    │   Send confirmation to requestor
    │   Retain DSAR log entry for 3 years (audit evidence)
    │   Close request
    │
    ▼
    DONE
```

### 12.2 Response Timelines Summary

| Jurisdiction | Acknowledgment | Substantive Response | Extension |
|-------------|---------------|---------------------|-----------|
| General (U.S.) | 1 business day | 30 calendar days | Case-by-case |
| GDPR | 1 business day | 30 calendar days | +60 days with notice |
| CCPA/CPRA | 10 business days | 45 calendar days | +45 days with notice |

LKP applies the **shortest applicable timeline** when multiple jurisdictions apply. In practice, all requests receive an initial acknowledgment within 1 business day and a substantive response within 30 calendar days.

---

## 13. Data Retention Schedule

### 13.1 Retention Periods by Data Type

| Data Type | Class | Minimum Retention | Maximum Retention | Basis |
|-----------|-------|-------------------|-------------------|-------|
| Authentication & session events | 1 | 180 days | Account duration + 30 days | Security audit; fraud prevention |
| Admin action logs | 4 | 1 year | Indefinite (during beta) | Audit trail; compliance evidence |
| Monitoring alerts & health check logs | 4 | 180 days | 1 year | Operational debugging |
| Billing references (Stripe IDs, invoices) | 3 | 2 years after last transaction | 7 years | Tax record-keeping; financial audit |
| Support artifacts (tickets, emails) | 5 | 1 year after resolution | 3 years | Service improvement; legal defense |
| Search telemetry (individual queries) | 2 | 90 days | 180 days | Product improvement |
| Search analytics (aggregated) | 2 | Indefinite | Indefinite | Anonymized; no personal data |
| AI workflow evidence (match suggestions, approvals) | 4 | 180 days | 1 year | AI governance audit |
| Account data (email, profile) | 1 | Account duration | Account duration + 30 days | Service delivery |
| Professional verification records | 1 | Account duration | Account duration + 1 year | Regulatory compliance |

### 13.2 Deletion Procedure

When data reaches the end of its retention period:

1. The automated retention cleanup job identifies eligible records
2. Records are checked against active legal holds (see Section 14)
3. Records not subject to legal hold are permanently deleted (not merely soft-deleted)
4. Deletion is logged in the audit trail
5. Deletion is verified by spot-checking affected data stores

### 13.3 User-Initiated Deletion

When a user requests account deletion:

1. Account is immediately deactivated (no further login possible)
2. Within 30 days: all personal data is permanently deleted, subject to:
   - Legal hold exceptions (see Section 14)
   - Legal record-keeping obligations (billing references retained per schedule)
   - Aggregated/anonymized data (retained indefinitely; no longer personal data)
3. Confirmation of deletion sent to user's email (last communication before email deletion)

---

## 14. Legal Hold Procedure

### 14.1 When a Legal Hold Is Required

A legal hold is required when LKP reasonably anticipates litigation, regulatory investigation, or other legal proceedings that may involve data subject to the retention schedule. Examples include:

- Receipt of a litigation hold notice or preservation demand
- Knowledge of a pending or threatened lawsuit
- Receipt of a regulatory inquiry or subpoena
- Discovery of a data breach (preserve evidence for investigation)
- Receipt of a law enforcement request

### 14.2 Legal Hold Process

```
Step 1: RECORD HOLD
    │   Document: hold reason, legal matter identifier, hold owner,
    │   scope (which data types, which users, which time periods)
    │   Assign a unique hold ID
    │
    ▼
Step 2: IDENTIFY AFFECTED SYSTEMS
    │   Map hold scope to specific data stores:
    │     - Operational database (which tables, which records)
    │     - Public database (which tables, which records)
    │     - Log files (which date ranges)
    │     - Email/support systems (which threads)
    │     - Stripe records (which customers)
    │
    ▼
Step 3: SUSPEND DELETION
    │   Apply legal hold flag to affected records
    │   Automated retention cleanup job skips held records
    │   Manual deletion requests checked against active holds
    │   If DSAR deletion request conflicts with hold:
    │     - Notify requestor that specific data is subject to legal hold
    │     - Delete all non-held data per normal process
    │     - Document the exception
    │
    ▼
Step 4: DOCUMENT LOCATION
    │   Record exact locations of held data (database, table, record IDs)
    │   Record preservation method (database flag, backup, export)
    │   Ensure held data is included in regular backup processes
    │
    ▼
Step 5: REMOVE HOLD (ONLY WITH OWNER APPROVAL)
    │   Hold owner (Joshua Rivera or legal counsel) provides written
    │   closure approval
    │   Legal hold flag removed from affected records
    │   Records resume normal retention lifecycle
    │   Hold closure documented with: date, approver, reason
    │
    ▼
    HOLD COMPLETE
```

### 14.3 Legal Hold Register

All active and closed legal holds are tracked in a register containing:

| Field | Description |
|-------|-------------|
| Hold ID | Unique identifier (format: `HOLD-YYYY-NNN`) |
| Hold reason | Brief description of the legal matter |
| Hold owner | Person responsible for the hold (Joshua Rivera or legal counsel) |
| Hold scope | Data types, users, and time periods covered |
| Created date | Date the hold was initiated |
| Affected systems | List of data stores containing held data |
| Status | Active or Closed |
| Closure date | Date the hold was removed (if closed) |
| Closure approver | Person who approved closure |
| Closure reason | Reason for removing the hold |

---

## 15. Data Security

### 15.1 Technical Measures

| Measure | Implementation |
|---------|---------------|
| **Encryption in transit** | All data transmitted over HTTPS (TLS 1.2+); no HTTP access permitted |
| **Encryption at rest** | Neon PostgreSQL encrypts all data at rest; Render encrypts environment variables |
| **Password hashing** | bcrypt with appropriate cost factor |
| **MFA** | Required for all accounts |
| **Access control** | Role-based access control; admin functions require re-authentication |
| **Input validation** | Parameterized queries; Zod schema validation on all API inputs |
| **Rate limiting** | Authentication endpoints rate-limited to prevent brute force |
| **Dependency security** | Automated vulnerability scanning via npm audit |
| **Infrastructure as Code** | All infrastructure defined in render.yaml; changes tracked in Git |

### 15.2 Organizational Measures

| Measure | Implementation |
|---------|---------------|
| **Principle of least privilege** | Users receive minimum permissions necessary for their role |
| **Invite-only access** | No public registration; each user individually vetted |
| **Incident response plan** | Documented in Operations Manual (LKP-OPS-001) |
| **Security control verification** | 14 automated control scripts (see Compliance Controls Report, LKP-CCR-001) |
| **Vendor assessment** | Critical vendors assessed for security practices |

---

## 16. Children's Privacy

LKP is a professional tool for licensed automotive locksmiths and is not directed at individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have inadvertently collected personal information from a child under 18, we will take steps to delete that information promptly.

If you believe we have collected personal information from a child under 18, please contact us at support@locksmithkeypricer.com.

---

## 17. International Data Transfers

### 17.1 Current Data Locations

All LKP data is currently stored and processed in the United States:

| Component | Provider | Data Center Location |
|-----------|----------|---------------------|
| Application servers | Render.com | United States |
| Databases | Neon PostgreSQL | United States |
| Frontend | Vercel | United States (edge CDN may serve from other locations) |
| Payment processing | Stripe | United States |

### 17.2 GDPR Transfer Safeguards

If GDPR applies and data is transferred outside the EU/EEA to the United States, LKP will ensure appropriate safeguards are in place, which may include:

- Standard Contractual Clauses (SCCs) approved by the European Commission
- The EU-U.S. Data Privacy Framework (if LKP certifies under the framework)
- Derogations under Art. 49 GDPR (e.g., explicit consent, contract necessity)

---

## 18. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

1. Update the "Effective Date" at the top of this document
2. Provide notice through the LKP application (in-app notification)
3. For material changes affecting user rights: provide direct email notification at least 30 days before the changes take effect
4. Maintain a revision history in Section 20

Your continued use of the LKP platform after the effective date of a revised policy constitutes your acceptance of the revised policy.

---

## 19. Contact Information

For all privacy-related inquiries, requests, and complaints:

**Digital Auction House LLC dba LKP**  
**Email:** support@locksmithkeypricer.com  
**Subject Line:** Privacy Inquiry — [Your Name]

**Response commitment:** We will acknowledge all privacy inquiries within 1 business day and provide a substantive response within the timelines specified in Section 12.

---

## 20. Document Control

### 20.1 Revision History

| Version | Date | Author | Description |
|---------|------|--------|-------------|
| 1.0 | June 28, 2026 | Joshua Rivera | Initial release |

### 20.2 Review Schedule

This policy shall be reviewed and updated:

- At least annually
- Within 30 days of any material change to data practices
- Within 30 days of entering a new jurisdiction (e.g., onboarding EU/UK users)
- Upon legal counsel review or regulatory inquiry

### 20.3 Related Documents

| Document ID | Title | Relationship |
|-------------|-------|-------------|
| LKP-OPS-001 | Operations Manual | Infrastructure, monitoring, and incident response |
| LKP-CCR-001 | Compliance Controls Report | Security controls and compliance readiness |
| LKP-DS-001 | Data Sourcing Methodology | Data collection practices for vehicle/supplier data |
| LKP-TOS-001 | Beta Terms of Service | User agreement and acceptable use |

---

**END OF DOCUMENT**

*Digital Auction House LLC dba LKP — A Digital Auction House LLC Company*  
*© 2026 Digital Auction House LLC. All rights reserved.*