Data Processing & Security Policy
Entity: Hashtag Thrift LLC d/b/a Flexiflock | Website: www.flexiflock.com
Effective Date: October 5, 2026 | Last Updated: October 5, 2026
1.0 Purpose
1.1 This Data Processing & Security Policy ("Security Policy") supplements the Privacy Policy by detailing how Hashtag Thrift LLC d/b/a Flexiflock ("Flexiflock") collects, classifies, processes, stores, protects, and disposes of data. Designed to satisfy Fla. Stat. § 501.171 (FIPA) and applicable federal data security requirements.
2.0 Data Classification
- Public — marketing content, published blog posts, publicly posted policies.
- Internal — internal communications, operational workflows, vendor contracts.
- Confidential — client intake forms, payment records, legal documents prepared for clients.
- Restricted — personally identifiable information (PII), health information, financial account details; access limited to authorized personnel only.
3.0 Data Processing Principles
- Lawfulness, Fairness, and Transparency.
- Purpose Limitation — data used only for stated, legitimate purposes.
- Data Minimization — only necessary data is collected.
- Accuracy and Rectification — reasonable steps to correct or delete inaccurate data.
- Storage Limitation per the retention schedule below.
- Integrity and Confidentiality — protection against unauthorized access, loss, or damage.
4.0 Technical Security Measures
- TLS Encryption in Transit (TLS 1.2+); HTTP redirected to HTTPS.
- AES-256 Encryption at Rest for sensitive personal data.
- Multi-Factor Authentication (MFA) for administrative and sensitive-data access.
- Firewalls and Intrusion Detection/Prevention Systems.
- Regular Vulnerability Scanning and security assessments.
- Secure Coding Practices (input validation, output encoding, OWASP Top 10 protections).
5.0 Organizational Security Measures
- Least-Privilege Access Controls.
- Annual Staff Training on data protection and incident reporting.
- Vendor Due Diligence and mandatory data processing agreements.
- Written Incident Response Plan covering detection, escalation, containment, notification, and remediation.
6.0 Data Breach Notification (Fla. Stat. § 501.171)
6.1 Internal escalation required within twenty-four (24) hours of discovery.
6.2 Affected Florida residents notified within thirty (30) calendar days of determination.
6.3 Breaches affecting 500+ Florida residents trigger simultaneous notification to the Florida Attorney General.
6.4 Notifications include incident description, affected categories/individuals, mitigation steps, protective recommendations, and contact information.
7.0 Data Retention Schedule
- Client engagement records — 7 years after engagement conclusion.
- Financial and accounting records — 5 years from close of relevant fiscal year.
- Marketing and prospect data — 2 years from last interaction.
- Security and access logs — 1 year, rolling.
- Data subject rights requests and correspondence — 3 years from resolution.
8.0 International Data Transfers
8.1 Personal data is primarily stored and processed within the United States; Flexiflock does not intentionally transfer data abroad without appropriate legal safeguards.
8.2 Cloud vendors processing data in multiple jurisdictions are evaluated for compliance, with contractual security commitments required.
© 2026 Hashtag Thrift LLC d/b/a Flexiflock | www.flexiflock.com | Confidential – Legal Use Only