Data Retention Schedules
| Field | Value |
|---|---|
| Version | 1.0 |
| Effective Date | April 2026 |
| Review Cycle | Annual |
| Document Owner | Chief Information Security Officer (CISO) |
| Classification | CONFIDENTIAL — Internal Use Only |
| Applicable Standard | SOC 2 Type II — Security, Availability, Confidentiality |
1. Purpose and Scope
This document defines the formal data retention schedule for QA Touch, specifying how long each category of personal and operational data is retained and the disposal procedures applied when the retention period expires. Supports SOC 2 Privacy criterion P4.2 (Retention of Personal Information) and GDPR Article 5(1)(e) (storage limitation), CCPA, and PIPEDA.
ASSUMPTION: All retention periods are representative based on common SaaS regulatory practice. QA Touch legal, engineering, and compliance teams must formally confirm and approve these periods before referencing them in customer contracts, the Privacy Policy, or the DPA.
2. Retention Schedule
| Data Category | Active Period | Archive Period | Total Max | Deletion Trigger | Legal Basis |
|---|---|---|---|---|---|
| User Account Data (name, email, profile) | Account active | 90 days | Active + 90 days | Account deletion + 90-day grace period | Contract; GDPR Art. 17 |
| Password Hashes | Account active | None | Account lifetime | Account closure; password change (old hash deleted immediately) | Security necessity |
| MFA Secrets / Recovery Codes | MFA active | None | MFA active duration | MFA disabled or account closed | Security necessity |
| Session Tokens | Session duration (max 24h) | None | 24 hours | Logout; expiry; deactivation | Security necessity |
| API Keys | Until revoked | None | Until explicit revocation | Admin/user revocation; account deactivation | Contract performance |
| Workspace / Organisation Data | Subscription active | 30 days | Subscription + 30 days | Subscription end + 30-day export window | Customer contract |
| Projects, Test Cases, Runs, Defects, Requirements | Workspace active | Included in workspace retention | Workspace retention period | Workspace deletion | Customer contract |
| File Attachments | Workspace active | Included in workspace retention | Workspace retention period | Workspace deletion | Customer contract |
| Import Staging Files | Processing duration only | None | Max 24 hours | Import completion or failure (automated lifecycle policy) | Data minimisation |
| Export Package Files | 24–72 hours | None | 72 hours maximum | Automated TTL expiry; optional: immediate on first download [VERIFY] | Data minimisation |
| AI Prompt Content (in QA Touch) | Workspace active [VERIFY] | None | Workspace retention [VERIFY] | Workspace deletion [VERIFY] | Contract; minimisation |
| Audit Logs (user actions) | 12 months active | 24 months archive | 36 months total | 36 months from creation (automated) | SOC 2 evidence; contractual |
| Security Event Logs | 12 months active | 24 months archive | 36 months total | 36 months from creation | SOC 2 CC7; GDPR Art. 5 |
| Application / Error Logs | 30 days active | 60 days archive | 90 days total | 90 days from creation | Operational necessity |
| Integration Credentials | Integration active | None | Integration active duration | Integration removed by admin; token revoked | Security best practice |
| Webhook Delivery Logs | 90 days | None | 90 days | 90 days from event | Operational / debugging |
| Email Delivery Logs | 90 days | None | 90 days | 90 days from delivery | Operational / debugging |
| Database Backup Snapshots | 7 daily / 4 weekly / 12 monthly | None | 12 months maximum | Automated rotation per backup schedule | Availability commitments |
| Billing Records (invoices, payment history) | Subscription active | 7 years | Subscription + 7 years | Tax / legal hold expiry | Tax and accounting law |
| Support Ticket Content | Active + 2 years | None | 2 years post-closure | 2 years after ticket closure | Legitimate interests; dispute resolution |
| Explicit Consent Records | Account active | 3 years post-closure | Account + 3 years | 3 years after account closure | Legal accountability; GDPR Art. 5(2) |
| Data Subject Request Records (DSR) | Request active | 3 years post-completion | 3 years from completion | 3 years after request completed | Legal accountability |
| Password Reset Tokens | 60 minutes | None | 60 minutes | First use or TTL expiry | Security necessity |
3. Deletion and Disposal Procedures
3.1 Automated Deletion
- Scheduled jobs execute daily to identify and purge records that have exceeded their retention window.
- Object storage lifecycle policies enforce TTL-based deletion for import staging files, export packages, and archived log data.
- Automated deletion job completion is monitored; failure triggers a P2 operational alert.
3.2 Account and Workspace Offboarding
- Account closure: personal account data scheduled for deletion within 90 days; workspace data retained per workspace schedule if workspace continues operating.
- Workspace termination: all workspace data (projects, tests, runs, defects, users) deleted 30 days after subscription end; customer receives export opportunity during this window.
- Hard delete from primary database; data may persist in encrypted backup snapshots for the backup rotation period (maximum 30 days for daily snapshots) before permanent removal.
3.3 Data Subject Erasure Requests (Right to Erasure)
- Verified DSR: personal data deleted within 30 days (GDPR Art. 17 requires ‘without undue delay’).
- Deletion confirmation sent to data subject on completion.
- Exceptions: data required for legal obligations (tax records, active legal hold) may be retained until the legal basis expires, with the data subject notified of the reason.