The Principle
Data has a beginning, a purpose, and an end. The beginning is the moment data enters the Ariana Nexus environment — whether through a client engagement, a contact form submission, an interpreter session, or an AI annotation task. The purpose is the specific, documented reason for which the data was collected and the contractual, legal, or operational basis that authorizes its processing. The end is the point at which the data has served its purpose, the retention period has elapsed, and the data is securely destroyed or returned to the client.
Between the beginning and the end, data moves through a governed lifecycle — classified, encrypted, access-controlled, monitored, retained according to documented schedules, and ultimately destroyed through verified procedures. At no point in this lifecycle is data ungoverned. At no point is data retained without justification. At no point is data accessible without authorization.
This page documents how Ariana Nexus governs data through every phase of its lifecycle — from creation to destruction — across all four operational domains: Healthcare, AI & Technology, Government & Public Sector, and Research & Education.
Data Lifecycle Framework
Ariana Nexus governs data through seven distinct lifecycle phases. Each phase has defined controls, responsible parties, and audit mechanisms:
Phase 1: Data Creation and Collection
What happens: Data enters the Ariana Nexus environment through one of four channels: client engagement data (PHI, CUI, PII, AI training data provided by clients), website visitor data (contact form submissions, cookie consent choices, analytics), personnel and subcontractor data (employee and contractor records), or internally generated data (reports, analysis, documentation, correspondence).
Governance controls:
- Purpose specification: Every data collection activity has a documented purpose linked to a lawful basis (consent, contractual necessity, legitimate interest, legal obligation, or vital interest).
- Data minimization: Only the data strictly necessary for the specified purpose is collected. No supplementary data is gathered without documented justification and Privacy Review Gate approval.
- Classification at creation: Data is classified immediately upon entry into the environment using the four-tier framework (Public, Internal, Confidential, Restricted). Microsoft Purview Sensitivity Labels are applied at the point of creation or receipt.
- Consent documentation: Where consent is the lawful basis for processing, the consent is recorded with timestamp, scope, and method of collection. Finsweet Consent Pro manages website consent. Engagement-specific consent is documented in the applicable agreement.
- Source documentation: For client-provided data, the source, delivery method, date of receipt, and responsible recipient are logged.
Phase 2: Data Ingestion and Classification
What happens: Data received from external sources is ingested into the Microsoft 365 environment and formally classified.
Governance controls:
- Engagement-specific storage: Client data is stored in dedicated SharePoint document libraries or Teams channels configured with engagement-specific Security Groups. Data from different clients is never commingled.
- Sensitivity Label application: The receiving team member applies the appropriate Sensitivity Label based on the data's content and the applicable regulatory classification. For data containing PHI: Restricted. For CUI: Restricted. For AI training data with PII: Restricted. For client proposals and contracts: Confidential. For internal operations: Internal.
- Default classification: If a team member fails to apply a Sensitivity Label, the system applies the default label of Internal, preventing unclassified data from being treated as Public.
- Automated classification (planned): Microsoft Purview trainable classifiers are on the roadmap to automatically detect and classify PHI, PII, and CUI patterns, supplementing manual classification. Target: Q4 2026.
- Data inventory registration: All new data processing activities are registered in the Record of Processing Activities (ROPA) with the data categories, purpose, lawful basis, data subjects, recipients, retention period, and security measures.
Phase 3: Data Storage and Protection
What happens: Data resides in the Microsoft 365 environment under continuous protection.
Governance controls:
- Encryption at rest: AES-256 encryption applied to all data in SharePoint, OneDrive, Exchange, and Teams. Document-level encryption via Azure RMS for Confidential and Restricted data.
- Encryption on devices: BitLocker (Windows) and FileVault (macOS) enforced on all enrolled devices via Intune.
- Access control: Role-Based Access Control (RBAC) via Microsoft Entra ID Security Groups. Least privilege enforced. Access granted only to personnel with documented need-to-know for the specific engagement.
- DLP enforcement: Microsoft Purview DLP policies monitor all data surfaces (Exchange, SharePoint, OneDrive, Teams, endpoint) for unauthorized movement of classified data. Confidential and Restricted data is blocked from external transmission by default.
- Audit logging: All access, modification, sharing, and label change events are logged in the Microsoft 365 Unified Audit Log. Logs are retained for audit and investigation purposes.
- Backup: Third-party backup solution provides independent, encrypted backup of all Microsoft 365 data. Daily incremental, weekly full. Backup data stored in geographically separate, encrypted environment.
Phase 4: Data Processing and Use
What happens: Data is actively used for its intended purpose — interpretation, translation, annotation, validation, training, analysis, or communication.
Governance controls:
- Purpose limitation: Data is processed only for the purposes specified in the applicable Engagement Agreement, Data Processing Agreement, or Business Associate Agreement. No secondary use without explicit client authorization.
- Minimum necessary access: Personnel access only the data required for their specific task. Interpreters access the PHI relevant to their assigned encounter. Annotators access the dataset relevant to their assigned task. Translators access the documents relevant to their assigned project.
- Processing records: For GDPR-covered processing, the ROPA documents each processing activity. For HIPAA-covered processing, access logs record each instance of PHI access.
- Quality assurance: QA processes that involve data review are conducted by authorized personnel within the same access-controlled environment. QA findings are documented without unnecessary reproduction of personal data.
- Subcontractor governance: Subcontractors who process data are subject to the same access controls, DLP policies, audit logging, and training requirements as employees. Subcontractor access is engagement-specific and time-bound.
Phase 5: Data Sharing and Transfer
What happens: Data is shared with authorized recipients — clients, co-workers, subcontractors, or regulatory authorities.
Governance controls:
- Internal sharing: Governed by Sensitivity Labels and Security Group membership. Confidential and Restricted data can only be shared within authorized Security Groups.
- External sharing (to clients): Governed by the Engagement Agreement. Deliverables are transmitted through encrypted channels (OME, Sensitivity Label encryption, secure SharePoint links with access restrictions). External sharing of Confidential and Restricted data requires Tier 1 administrator approval.
- External sharing (to subcontractors): Governed by the Subcontractor Agreement, NDA, and applicable BAA or DPA. Subcontractors access data through their managed Entra ID accounts within the Ariana Nexus M365 environment — data is not exported to subcontractor personal systems.
- Cross-border transfers: For personal data transferred from the EU/UK to the United States, transfers are governed by Standard Contractual Clauses (SCCs), UK IDTA, and Transfer Impact Assessments as documented in the Global Privacy & Data Protection Pack and the Privacy Policy.
- Regulatory disclosures: Data disclosed to regulatory authorities (HHS, OCR, ICO, state attorneys general, DC3) is provided only as required by law, in the minimum amount necessary, through secure channels, and documented in the incident response or compliance records.
- DLP enforcement: All sharing actions are monitored by Purview DLP policies. Attempted violations are blocked, logged, and escalated per the DLP incident workflow.
Phase 6: Data Retention
What happens: Data is retained for the period required by law, regulation, contract, or operational necessity — and no longer.
Governance controls:
Documented retention periods aligned with specific regulatory requirements:
Client engagement records — Duration + 7 years. Governing requirement: Tax, audit, contractual. Purview Policy: Automated retention label.
Protected Health Information (PHI) — 6 years from creation or last effective date. Governing requirement: HIPAA 45 CFR § 164.530(j). Purview Policy: Automated retention label.
Controlled Unclassified Information (CUI) — 3 years after final contract payment. Governing requirement: FAR 4.703. Purview Policy: Automated retention label.
Government contract records — 3 years after final payment (or per agency). Governing requirement: FAR 4.703, agency-specific. Purview Policy: Automated retention label.
AI training data (client-provided) — Per Data Processing Agreement. Governing requirement: Client-specific. Purview Policy: Automated engagement-specific policy.
Employee and contractor records — Duration + 7 years. Governing requirement: Employment law, tax. Purview Policy: Automated retention label.
Website visitor data (analytics) — Maximum 26 months. Governing requirement: GDPR, CCPA/CPRA. Purview Policy: Automated platform configuration.
Contact form submissions — 2 years (unless leads to engagement). Governing requirement: Privacy Policy. Purview Policy: Automated retention label.
Audit logs and compliance records — 7 years. Governing requirement: Industry best practice, SOC 2. Purview Policy: Automated retention label.
Legal hold / litigation records — Duration of hold + applicable SOL. Governing requirement: Legal obligation. Purview Policy: Manual legal hold applied, automated retention suspended.
- Automated enforcement: Microsoft Purview retention labels and retention policies are configured to enforce retention schedules automatically. When the retention period expires and no legal hold applies, data is flagged for disposition review or automatically deleted based on the policy configuration.
- No indefinite retention: Ariana Nexus does not retain data indefinitely. Every data category has a defined retention period. When the purpose is fulfilled and the retention period has elapsed, data proceeds to the deletion phase.
- Legal hold override: When data is subject to a legal hold (litigation, regulatory investigation, audit), the retention policy is suspended for the affected data until the hold is released. Legal holds are documented, scoped to the minimum data necessary, and reviewed quarterly.
Phase 7: Data Deletion and Destruction
What happens: Data that has served its purpose and completed its retention period is permanently destroyed.
Governance controls:
- Automated disposition: For data governed by Purview retention policies with auto-delete enabled, data is automatically purged upon retention period expiration. Purged data is removed from all primary storage, recycle bins, and second-stage recycle bins.
- Manual disposition: For data requiring human review before deletion (e.g., complex engagement data, data with multiple retention requirements), a disposition review workflow notifies the responsible team member to confirm deletion eligibility.
- Cryptographic erasure: For Restricted-tier data (PHI, CUI, AI data with PII), the preferred destruction method is cryptographic erasure — destroying the encryption keys that protect the data, rendering the encrypted data permanently unreadable.
- Physical media destruction: If data has been stored on physical media (USB drives, external hard drives, printed documents), destruction follows NIST SP 800-88 Rev. 1 (Guidelines for Media Sanitization) — cross-cut shredding for paper, degaussing or physical destruction for magnetic media, cryptographic erasure for solid-state media.
- Backup data destruction: Backup data is subject to the same retention schedules. Backup retention periods align with primary data retention. Upon expiration, backup data is purged from the third-party backup environment.
- Destruction certification: A record of destruction is maintained documenting the data destroyed, method of destruction, date, and responsible individual. Destruction certification is provided to clients upon request.
Data Inventory and Records of Processing Activities (ROPA)
Data Inventory
Ariana Nexus maintains a formal data inventory that catalogs all categories of personal and sensitive data the organization holds. The inventory includes:
- Data category: Description of the data type (PHI, CUI, PII, AI training data, employee data, website visitor data, etc.).
- Data subjects: Categories of individuals whose data is processed (patients, clients, employees, subcontractors, website visitors, data subjects in AI training sets).
- Source: How the data was obtained (client-provided, directly collected, publicly sourced, internally generated).
- Purpose: The specific, documented purpose for processing.
- Lawful basis: The legal basis for processing under GDPR (and equivalent basis under other applicable laws).
- Storage location: The Microsoft 365 service and specific SharePoint site, mailbox, or Teams channel where the data resides.
- Access authorization: The Security Groups and individuals authorized to access the data.
- Retention period: The applicable retention period and governing requirement.
- Security measures: The Sensitivity Label, encryption status, DLP policies, and other controls applied.
- Cross-border transfer: Whether the data is transferred internationally, and the transfer mechanism used.
ROPA Maintenance
The ROPA is maintained as required by GDPR Article 30 and is updated: when a new client engagement involving personal data is onboarded, when a new data processing activity is initiated, when an existing processing activity changes in nature, scope, or purpose, when a new sub-processor is engaged, and during the annual privacy review cycle.
The ROPA is available for review by supervisory authorities (upon lawful request) and by clients (under NDA, as part of engagement due diligence or audit rights).
Engagement Data Exit Procedures
Client Data Return
When a client engagement ends, Ariana Nexus executes documented data exit procedures:
Step 1 — Engagement Closure Notification: The engagement lead confirms the engagement end date and initiates the data exit process. The client is notified that data exit procedures will begin.
Step 2 — Data Inventory Confirmation: The engagement lead confirms the scope of client data held within the Ariana Nexus environment, including SharePoint libraries, Exchange mailboxes, Teams channels, OneDrive files, and backup data.
Step 3 — Client Data Return: If the client requests data return, Ariana Nexus provides all client data in a structured, commonly used, machine-readable format (or the original format in which it was received) through a secure, encrypted transfer mechanism. The data return is documented with a delivery confirmation.
Step 4 — Data Deletion: Following data return (or if the client elects deletion without return), Ariana Nexus permanently deletes all client data from all systems: SharePoint libraries (content deleted and purged from recycle bin and second-stage recycle bin), Exchange (engagement-specific email deleted and purged), Teams (channel content deleted), OneDrive (engagement-specific files deleted and purged), backup systems (client data purged from the third-party backup environment within the next backup rotation cycle), and subcontractor systems (subcontractors confirm in writing that all client data in their possession has been returned or destroyed).
Step 5 — Destruction Certification: Ariana Nexus provides a Certificate of Data Destruction to the client, documenting the data destroyed, systems purged, method of destruction, date of destruction, and responsible individual. The certificate is retained in Ariana Nexus compliance records for seven (7) years.
Step 6 — Access Revocation: All engagement-specific access (Security Group memberships, Teams channel access, SharePoint permissions) is revoked for employees and subcontractors. Subcontractor Entra ID accounts associated solely with the ended engagement are disabled.
Exceptions to Deletion
Data may be retained beyond the engagement end date only in the following circumstances:
- Legal hold: Data subject to litigation hold, regulatory investigation, or audit preservation order.
- Regulatory retention requirement: Data subject to minimum retention periods (HIPAA 6 years, FAR 3 years, etc.) that extend beyond the engagement duration.
- Client request: Client requests extended retention, documented in writing with a defined retention end date.
- Anonymized/aggregated data: Data that has been irreversibly anonymized or aggregated such that it no longer constitutes personal data may be retained for statistical or operational improvement purposes, unless the client agreement prohibits this.
All exceptions are documented, scoped, and reviewed quarterly. When the exception condition ends, data proceeds to deletion.
Sector-Specific Data Lifecycle Governance
Healthcare (PHI Lifecycle)
Collection: BAA required before any PHI receipt; classification as Restricted immediate upon receipt.
Ingestion: Dedicated SharePoint library per healthcare engagement; PHI-specific Security Group.
Storage: AES-256 encryption; Azure RMS document-level encryption; DLP with PHI detection patterns.
Processing: Minimum necessary standard (45 CFR § 164.502(b)); interpreter/translator access scoped to encounter.
Sharing: TLS 1.2+ in transit; OME for external email; no external sharing without client authorization.
Retention: 6 years minimum (HIPAA); Purview retention label enforced.
Destruction: Cryptographic erasure preferred; destruction certification provided to Covered Entity.
Government (CUI Lifecycle)
Collection: Engagement agreement with CUI handling provisions; classification as Restricted immediate.
Ingestion: Dedicated SharePoint environment; U.S.-based personnel access only.
Storage: AES-256 with FIPS-validated encryption; no storage outside U.S. borders.
Processing: NIST SP 800-171 controls applied; access restricted to vetted, need-to-know personnel.
Sharing: TLS 1.2+; no transfer outside U.S. without government authorization; DLP blocks external sharing.
Retention: 3 years after final payment (FAR 4.703); agency-specific extensions honored.
Destruction: Cryptographic erasure or NIST 800-88 media sanitization; DC3 notification if incident-driven.
AI & Technology (AI Data Lifecycle)
Collection: Data Processing Agreement defines permitted use; provenance and consent chain documented.
Ingestion: Client data isolation; Restricted classification for data containing PII; annotator access scoped.
Storage: AES-256 encryption; engagement-specific SharePoint with named Security Group.
Processing: Purpose limitation per DPA; no repurposing without authorization; inter-annotator agreement QA.
Sharing: Deliverables (validation reports, annotated data) encrypted; client-only delivery.
Retention: Per DPA terms; Purview retention label per engagement.
Destruction: Client data deleted upon engagement completion and confirmation; destruction certification.
Sensitive Populations (Diaspora Data Lifecycle)
Collection: Heightened purpose justification; no collection beyond absolute necessity.
Ingestion: Restricted classification regardless of legal minimum; enhanced access restriction.
Storage: Maximum encryption; named-individual access only; no broad Security Group.
Processing: Enhanced monitoring for access anomalies; any unauthorized access treated as Critical incident.
Sharing: No disclosure to foreign governments; no transfer to sanctioned territories; OFAC screening.
Retention: Shortest defensible period; engagement-specific retention with accelerated deletion.
Destruction: Cryptographic erasure; destruction certification; verification that no copies remain.
Alignment with Data Governance Frameworks
Ariana Nexus's data lifecycle governance is designed in alignment with the following recognized frameworks and standards:
GDPR (Articles 5, 13, 17, 25, 30) — Data lifecycle principles, ROPA, right to erasure, PbD. Aligned — all articles addressed through lifecycle governance.
HIPAA (45 CFR § 164.530(j)) — PHI retention (6 years). Compliant — retention schedule enforced via Purview.
FAR 4.703 — Government contract records retention (3 years). Compliant — retention schedule enforced.
NIST SP 800-171 Rev. 2 / Rev. 3 — Media Protection (MP), System and Information Integrity (SI). Aligned — lifecycle controls cover MP and SI families (Rev. 2 current; Rev. 3 transition planned per DoD rulemaking).
NIST SP 800-88 Rev. 1 — Media sanitization. Aligned — destruction methods follow NIST 800-88.
ISO 27001:2022 — Annex A.8.10 (Information Deletion), A.8.11 (Data Masking), A.5.33 (Record Protection). Aligned — deletion, masking, and record governance documented.
SOC 2 (TSC) — CC6 (Logical/Physical Access), CC9 (Risk Mitigation). Aligned — lifecycle controls support CC6 and CC9.
EU AI Act (Article 10) — Data governance for AI training data. Aligned — AI data lifecycle with provenance, quality, and retention.
CCPA/CPRA — Data deletion rights, purpose limitation, minimization. Compliant — deletion honored; minimization practiced.
NIST Privacy Framework — Control-P, Protect-P functions. Aligned — lifecycle controls implement both functions.
ISO/IEC 27701:2019 — PIMS lifecycle management. Roadmap (2028) — certification planned.
CJIS Security Policy — Media Protection (Policy Area 8). Aligned — encryption, device controls, destruction procedures.
What Data Lifecycle Governance Means for Our Clients and Partners
For procurement officers: Every piece of data entering the Ariana Nexus environment is classified at receipt, encrypted at storage, access-controlled during processing, encrypted in transit during sharing, retained per documented schedules with automated enforcement, and destroyed through verified procedures with certification. We can produce data inventory reports, retention compliance evidence, and destruction certificates on demand.
For CISOs: Our lifecycle governance is automated through Microsoft Purview retention labels and policies — not dependent on human memory or manual processes. DLP policies enforce classification boundaries at every phase. Audit logging captures every access and modification event. Backup data follows the same retention schedules as primary data.
For compliance officers: Our ROPA documents every processing activity with purpose, lawful basis, data subjects, recipients, retention period, and security measures. Engagement exit procedures include data return, verified deletion across all systems including backup, subcontractor confirmation, and destruction certification. We can provide the ROPA, retention policy configuration, and destruction records for your audit.
For government contracting officers: CUI lifecycle governance satisfies NIST SP 800-171 MP and SI families. Retention follows FAR 4.703. Destruction follows NIST 800-88. Data residency is U.S.-only for CUI. All lifecycle controls are documented for the System Security Plan.
If your organization requires data lifecycle documentation, retention compliance evidence, ROPA review, or destruction certification, contact privacy@ariananexus.com or +1 (202) 771-0224.
Maturity Roadmap
Ariana Nexus views data lifecycle governance as a multi-year discipline. The following roadmap reflects our planned maturation path:
Phase 1: Foundation (Current — 2026) — Operational
Seven-phase lifecycle governance operational. ROPA maintained. Purview automated retention labels. Documented engagement exit procedures with destruction certification. Four-tier classification enforced at creation. Third-party backup with aligned retention. DLP enforcement across all lifecycle phases.
Phase 2: Hardening (Q3–Q4 2026) — In Planning
Purview trainable classifiers for automated PHI/PII/CUI detection. Enhanced disposition review workflows. Data inventory dashboard. Quarterly ROPA review cycle formalization.
Phase 3: Certification (2027) — Planned
ISO 27001 certification (Annex A.8.10, A.5.33). SOC 2 Type II (lifecycle-relevant controls). CMMC Level 2 MP domain certification. Automated ROPA generation from M365 metadata.
Phase 4: Advanced (2028) — Planned
Purview Data Lifecycle Management automation. Adaptive retention policies based on engagement classification. Cross-system data lineage tracking. ISO 27701 PIMS certification.
Phase 5: Autonomous (2030+) — Vision
AI-driven data lifecycle optimization. Real-time data residency and sovereignty compliance. Automated regulatory retention mapping for emerging laws. Blockchain-verified destruction records.
Limitation of Liability and Disclaimers
No Guarantee Against Data Loss. Ariana Nexus implements commercially reasonable data lifecycle governance measures. However, no data management system can guarantee absolute prevention of data loss, unauthorized retention, or incomplete deletion. Ariana Nexus expressly disclaims any warranty of absolute data lifecycle integrity.
Automated Retention Limitations. Purview retention policies operate within the Microsoft 365 platform. Automated retention and deletion are subject to Microsoft platform capabilities, limitations, and processing schedules. Ariana Nexus does not control Microsoft's retention policy execution engine.
Backup Data Timing. Deletion of backup data may not be instantaneous. Backup purging occurs within the next backup rotation cycle following primary data deletion. During this interval, deleted data may exist in encrypted backup storage.
Client-Specific Obligations. Specific data lifecycle obligations for individual engagements are defined in the applicable Engagement Agreement, DPA, or BAA. In the event of conflict, the Engagement Agreement controls.
Roadmap Items. The maturity roadmap reflects current plans as of the Effective Date. Roadmap items are forward-looking statements, not binding commitments.
Limitation of Liability. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, ARIANA NEXUS'S TOTAL AGGREGATE LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATED TO DATA LIFECYCLE GOVERNANCE SHALL NOT EXCEED THE AMOUNTS SET FORTH IN THE APPLICABLE ENGAGEMENT AGREEMENT, OR, WHERE NO ENGAGEMENT AGREEMENT EXISTS, ONE HUNDRED DOLLARS ($100). ARIANA NEXUS SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES ARISING FROM OR RELATED TO DATA RETENTION, DELETION, DESTRUCTION, OR LIFECYCLE MANAGEMENT. NOTHING IN THIS SECTION SHALL LIMIT OR EXCLUDE ARIANA NEXUS'S LIABILITY FOR: (A) FRAUD OR FRAUDULENT MISREPRESENTATION; (B) DEATH OR PERSONAL INJURY CAUSED BY NEGLIGENCE; OR (C) ANY OTHER LIABILITY THAT CANNOT BE EXCLUDED OR LIMITED BY APPLICABLE LAW, INCLUDING BUT NOT LIMITED TO LIABILITY UNDER THE UK UNFAIR CONTRACT TERMS ACT 1977, THE UK CONSUMER RIGHTS ACT 2015, OR GDPR.
Dispute Resolution. Any dispute arising out of or relating to this page shall be subject to the dispute resolution provisions in the Terms of Use, Section 18.