Data Retention Policy
This is the platform's retention register, rendered live from the system that enforces it. Every class of data TradeFinanceAI holds appears below with the period it is kept for, the lawful basis for keeping it that long, and whether removal happens automatically or on request. 11 of 14 classes are purged automatically on a schedule — the remainder are held for a statutory period and are removed by a reviewed process instead.
01The register
| Data class | What it holds | Retained | Basis | Purge |
|---|---|---|---|---|
| invoices | Issued invoices and receipts | 10 years | Legal obligation — tax and accounting (10 years) | On request |
| audit logs | Administrative and security audit trail | 7 years | Legal obligation — financial recordkeeping (7 years) | On request |
| backup runs | Backup and restore-test evidence | 3 years | Legitimate interest — disaster recovery evidence | Automatic |
| ai usage events | AI usage telemetry (tokens, cost, latency) | 2 years | Legitimate interest — service governance | Automatic |
| email deliveries | Transactional email delivery tracking | 2 years | Legal obligation — proof of notice | On request |
| security events | Detected security events and alerts | 2 years | Legitimate interest — security monitoring | Automatic |
| login history | Authentication attempts, successful and failed | 1 year | Legitimate interest — account security | Automatic |
| webhook deliveries | Payment and email provider webhook deliveries | 6 months | Legal obligation — payment reconciliation | Automatic |
| admin sessions | Expired and revoked sessions | 3 months | Legitimate interest — account security | Automatic |
| service health checks | Platform service health probe history | 3 months | Legitimate interest — service reliability | Automatic |
| download grants | Expired temporary document access grants | 1 months | Legitimate interest — access accountability | Automatic |
| rate limits | Transient abuse-prevention counters | 7 days | Legitimate interest — abuse prevention | Automatic |
| login captchas | Expired login challenges | 1 day | Legitimate interest — abuse prevention | Automatic |
| mfa challenges | Expired multi-factor challenge tickets | 1 day | Legitimate interest — account security | Automatic |
02How the periods are chosen
- Legal obligation sets the floor. Invoices, receipts and the financial audit trail are kept for the statutory tax and accounting period. We cannot shorten these, and a deletion request does not remove them.
- Security evidence — sign-in history, security events, session records — is kept long enough to investigate an incident that is discovered late, and no longer.
- Transient data — rate-limit counters, expired sign-in challenges, expired multi-factor tickets, expired download links — is purged within days, because it has no value once it has served its purpose and every extra day is extra exposure.
- Operational telemetry — health checks, AI usage — is kept for the period needed to see a trend, then removed.
03How enforcement works
Classes marked Automatic are purged by a scheduled job that runs daily and records, per class, when it last ran and how many rows it removed. That evidence is visible to our compliance staff, so "the policy is enforced" is an observation rather than an assertion. Classes marked On request are subject to a documented review before removal, because deleting them prematurely would breach a legal obligation.
04Backups
Encrypted backup snapshots are taken on a schedule and are themselves retained for a bounded period before being deleted. A record deleted from the live platform therefore persists in backups until those snapshots age out; it is not restored into the live system, and the backup retention window is the outer bound on how long any deleted record can exist anywhere.
05When you close your account
Request erasure from Settings → Privacy and your data. We respond within 30 days. Your account, profile, company details, documents, AI conversations, sessions and consents are removed. Issued invoices, receipts and the financial audit trail are retained for their statutory period, reduced to what the obligation actually requires. We tell you which category each item fell into rather than reporting a blanket deletion.
06Changes and questions
Retention periods are set by our compliance function and are versioned with this policy. Because this page reads the live register, a change is visible here as soon as it is made. Questions to privacy@tradefinanceai.com.