DATA LIFECYCLE

Retention and Deletion Policy

Retention is limited by operational, security, billing and legal requirements. Final periods require legal review before commercial launch.

Controlled-production policy draft dated 3 August 2026. Final legal review and jurisdiction-specific amendments are required before unrestricted paid commercial launch.

Proposed retention schedule

RecordProposed periodReason
Unused OTP challengesUp to 24 hoursAuthentication abuse detection and expiry cleanup
Revoked or expired web sessionsUp to 90 daysSecurity investigation and account history
Contact enquiriesUp to 24 monthsSupport continuity, quotations and dispute handling
Billing and webhook recordsUp to 7 years where requiredAccounting, tax, reconciliation and disputes
Tenant audit eventsSubscription term plus up to 7 yearsSecurity, compliance and file-lifecycle accountability
Connector health and operational logs30–180 daysTroubleshooting, capacity trends and incident review
BackupsAccording to documented backup rotationRecovery, disaster response and restore testing

Client file data

1ProNAS should retain only the metadata, indexes, manifests and evidence required for approved platform functions. The client remains responsible for NAS source files and independent backups. Archive destinations and retention rules are client-controlled. The service must not remove a client’s source file solely because an account or subscription is cancelled.

Account closure

After a verified closure request, active sessions and connector credentials should be revoked. The client should receive an export or documented transition period where technically and legally applicable. Operational records are deleted or anonymised after the applicable retention period, except where preservation is required for security, disputes, billing or law.

Backups and delayed deletion

Deleted database records may remain temporarily in encrypted backups until the backup expires through normal rotation. Backup copies are not restored for ordinary access requests; if restored for disaster recovery, deletion instructions must be re-applied where required.

Integrator removal

Removing or suspending an integrator immediately ends delegated access and staff assignments. It does not delete the client tenant, subscription, NAS history or audit evidence.