Back to Home

Data Retention Policy

Operated By: Sachin Rathod, operating as OuterCircle Labs

Effective Date: August 11, 2026

Version: v1.0.0

DPDP Section 8(6) compliance

Summary

Data lifecycle policy defining retention periods, deletion triggers, and cryptographic erasure procedures across profile data, consent logs, and operational telemetry.

Key Highlights

Retention Schedule Matrix

Category Examples Retention Period Basis Deletion Trigger
Account Master Data User ID, full name, email, phone, authentication metadata Active account lifetime plus 2 years post-dormancy Service provision, identity management, dispute defense Account deletion or 24 months inactivity
Address Data Saved home, office, delivery addresses Active account lifetime plus 2 years post-last usage Consent autofill and user convenience Direct address deletion or account deletion
Consent Records and Ledger App ID, scopes, timestamps, revoke status Minimum 3 years from grant or revocation event DPDP accountability and audit proof Expiry of 3-year audit window unless legal hold applies
Authentication and Security Logs Login timestamps, IP, user-agent, MFA telemetry 1 to 2 years rolling Fraud prevention and forensics Automated rotation after 730 days
API Usage and Developer Logs Request metadata, endpoint telemetry, latency 1 to 3 years Billing and rate-limit auditing Automated purge at retention boundary
Support Tickets and Correspondence Grievance emails, support tickets, chat logs 2 to 3 years from resolution Support continuity and legal defense Purge 3 years after resolution
Encrypted Disaster Recovery Backups Production datastore snapshots 30-day rolling cycle Disaster recovery and continuity Automatic cryptographic overwrite on cycle expiry
Anonymized Aggregate Telemetry Aggregate usage trends and MAU metrics Indefinite after irreversible anonymization Product analytics and benchmarking Not applicable

1. Purpose and Scope

This policy standardizes retention, archival, and secure disposal across production databases, telemetry pipelines, cloud infrastructure, and backups in line with DPDP Act Section 8(6).

2. Core Retention Principles

3. Deletion and Cryptographic Erasure Procedures

4. Legal Holds and Regulatory Exceptions

Records may be temporarily retained beyond baseline schedules for legal obligations, court orders, investigations, or imminent legal claims. Standard schedules resume once the hold is lifted.

5. Policy Governance and Periodic Review

This policy is reviewed annually by the Data Protection Officer and Legal Counsel. Updates are published with incremented versioning when legal or regulatory requirements evolve.