Data Retention Policy
Compliance
On this page
EnthiosHub — Data Retention Policy
Operating Entity: [ENTITY LEGAL NAME] · Version: 1.0 · Effective: [EFFECTIVE DATE] · privacy@enthioshub.com
This Policy explains how long EnthiosHub retains personal and transactional data and when it is deleted or anonymized. It forms part of the Privacy Policy and is implemented through the Platform's data-governance controls.
1. Principles#
1.1. We retain personal data only as long as necessary for the purposes for which it was collected, or as required by Applicable Law, after which it is deleted, anonymized, or archived.
2. Indicative Retention Periods#
| Data Category | Retention Period | Basis |
|---|---|---|
| Account & profile data | While the account is active + [12] months after closure | Service provision; dispute window |
| Event registration & attendance | Duration of Event + [24] months | Service provision; disputes |
| Financial records (payments, invoices, settlements, refunds) | Up to 8 years | Income-tax / GST / accounting law |
| KYC verification status/reference | Duration of relationship + statutory period | Fraud/AML; legal compliance |
| Consent logs | Duration of relationship + [24] months | Proof of consent (DPDP) |
| Communications / support records | [24] months | Grievance/dispute handling |
| Security & audit logs (incl. IP addresses) | [12] months (or as required) | Security, fraud prevention, legal |
| Marketing data | Until consent withdrawal + [minimal] | Consent-based |
| User-generated content | Until deletion by user or account closure, subject to legal holds | Service provision |
(Bracketed periods are configurable defaults; confirm with your advocate/accountant.)
3. Deletion & Anonymization#
3.1. On expiry of the retention period, data is deleted or anonymized. Where deletion is not feasible (e.g., data within immutable financial/audit records), data is retained only as long as legally required and then removed.
3.2. Right to erasure: Users may request deletion of their personal data (see Privacy Policy). We will comply subject to legal retention obligations (e.g., financial records) and legitimate ongoing needs (e.g., fraud prevention, pending disputes).
4. Legal Holds#
Data subject to a legal, regulatory, or investigative hold is retained until the hold is lifted, notwithstanding the periods above.
5. Backups#
Backups are retained for a limited rolling period for disaster recovery and then overwritten. Data in backups is not used for active processing.
6. Implementation#
Retention is enforced through documented retention policies and automated processes within the Platform's data-governance framework.
Review by a licensed advocate and a chartered accountant (for statutory financial-record periods) recommended before publication.