HomeData Retention
Data Retention
Retention criteria for DPRQ processing activities.
Last updated: 2026-09-03
1. Framework
DPRQ retains information only as long as necessary for the purposes described in the Privacy Notice, to comply with law, resolve disputes, and maintain security.
This page describes retention criteria. Automatic deletion schedules may not yet be implemented for every category — technical automation requiring core backend changes needs separate owner approval.
2. Accounts and organisations
- Active account profile and membership data: retained while the account or organisation remains active.
- Closed account data: retained for a limited period after closure where needed for billing, security, or legal claims, then deleted or anonymised where feasible.
3. Products, passports, and evidence
- Product and passport records: retained while the customer maintains them and for backup/integrity purposes.
- Uploaded documents and evidence: retained while linked to active products or as required for published passport integrity.
- Deleted product/passport records: removed from primary application views; residual copies may persist briefly in backups.
4. Billing and receipts
- Payment receipts, Stripe identifiers, and subscription history: retained for accounting, tax, and dispute resolution periods required by law.
- Single DPP credit records: retained to evidence purchase and consumption.
5. Logs and security records
- Application, authentication, and security logs: retained for a limited operational period appropriate to security monitoring and incident investigation.
6. Support communications
- Support emails and privacy/account requests: retained as long as needed to handle the request and maintain an audit trail.
7. Backups
Database and storage backups may retain deleted data for the provider's backup retention window before being overwritten.