How ClosePack handles information.
Altiteck LLC, California, United States, operates ClosePack. Contact odymov@altiteck.com for privacy, access, export or account-deletion requests. ClosePack coordinates recurring client document collection, human review and delivery for firms.
Information and purposes
We process firm, client and legal-entity names; contact addresses and sign-in identifiers; checklists, deadlines and coverage dates; original uploaded documents and integrity hashes; reviews, including staff-only notes; exceptions; delivery receipts; and closure and audit history. We also process Microsoft Marketplace purchaser, beneficiary and subscription identifiers, verified subscription state, support correspondence and security records.
We use this information to provide and protect collection, review, delivery, support and subscription access, and to carry out authorized export and deletion instructions. Customers retain their rights in submitted records. The customer terms do not grant Altiteck a right to sell customer documents or use them for unrelated advertising. The document review workflow does not use an LLM to judge or accept documents.
Access and customer instructions
Firm staff have access within their authorized firm workspace. Client contacts have access only to explicitly assigned entities and requests. Staff-only review notes are not visible to client contacts. The firm defines its collection instructions, authorizes users, and is responsible for required notices and permissions concerning client records.
Altiteck assists with verified requests as required by applicable law and its role. Where an additional data-processing or transfer agreement is required, it must be in place before the affected processing. This notice does not waive applicable privacy rights or establish a blanket international-transfer or regulatory-compliance claim.
Providers, locations and file safety
The planned production service uses Microsoft Azure application, database and private storage services, Microsoft Defender for Storage malware scanning, Microsoft identity and Marketplace services, and Microsoft Graph for delivery to the firm's SharePoint. Microsoft Azure Communication Services Email is the selected transactional email provider for invitations and reminders. Uploaded files remain private while their safety scan is pending; they are unavailable for download, review or delivery until the required checks allow those actions. A clean scan does not determine accounting correctness.
See the subprocessor inventory for provider functions and location status. The planned application region is Azure East US 2; production application deployment is still being verified. The email resources are configured with United States data storage. Microsoft may process or transmit data in other geographies, and recipients' email services process delivered messages separately. This is not a promise that every identity, commerce, email or support operation occurs exclusively in one region.
Copies delivered to the firm's SharePoint are controlled separately by the firm under its Microsoft 365 access and retention policies. A saved delivery receipt records evidence at delivery time; it does not establish the firm's later retention decisions.
Routine retention
The routine source-cleanup policy protects current versions on open requests. Non-current sources not referenced by a closed manifest ordinarily become eligible for deletion 90 days after their original upload. An unreferenced source on a closed request may also become eligible after 90 days. Sources referenced by closed manifests ordinarily remain for at least 365 days after the latest referencing closure. Pending, running or unresolved delivery can delay cleanup. Eligibility is not immediate physical erasure.
Original bytes can expire while hashes, review decisions, manifests and audit metadata remain. Those records have no automatic age-based expiry in the current service; they are included in the reviewed account-deletion process. ClosePack is not a regulatory archive and does not promise a seven-year or other statutory retention period. Expired invitation, verification and session records ordinarily become eligible for cleanup 30 days after expiry; old rate-limit counters after seven days. Cleanup requires the service worker to run.
Assisted account deletion and export
Clients should first contact their firm about access, correction, export or deletion of client records. An authorized firm administrator may request service access, export or account deletion at odymov@altiteck.com. We authenticate the administrator and verify the firm, requested scope and export instructions before carrying out the request. Do not send documents, passwords, authentication codes or purchase tokens in ordinary support email.
Our target is to complete active-service account deletion within 30 days after verification and export instructions, subject to documented lawful exceptions. This target does not postpone any earlier applicable legal deadline. We explain relevant retained records and recovery-copy expiry separately; cancellation alone does not delete stored records.
Authorized users can download individual retained source files when safety checks permit. Firm staff can export a selected closed manifest as JSON. Contact support to agree export instructions before deletion; a complete account export bundle is not currently offered. The deletion process covers the verified firm's application records and source copies. Shared sign-in identities needed by another firm are preserved. Minimal completion, security or subscription-suppression records may be retained only under a documented purpose and period. Firm-controlled SharePoint copies must be handled separately by the firm.
Backups and recovery copies
Active-service deletion and recovery-copy expiry are separate. Recovery copies are restricted to recovery handling, and approved deletion instructions must be reapplied before restored data returns to service. Planned production settings are 14-day database backups, 14-day Blob soft deletion and 30-day operational logs; these settings and actual expiry still require production verification.
Previous Blob versions are configured to become eligible for lifecycle deletion more than 14 days after their original version creation, followed by the separate soft-delete period. Lifecycle processing is asynchronous. Removing a current file does not prove all previous versions, snapshots, logs or backups have expired. We do not promise a combined 30-plus-14-day final-erasure deadline. Contact odymov@altiteck.com for the applicable status of a verified deletion request.
Security
ClosePack uses server-side access checks, private document storage, version hashes and append-only ordinary application audit actions. These controls are not a certification, a guarantee against every security incident, or a substitute for a firm's own retention duties. Report suspected unauthorized access to odymov@altiteck.com using non-sensitive identifiers.