Retention Period Justifications
| Field | Value |
|---|---|
| Version | 1.0 |
| Effective Date | April 2026 |
| Review Cycle | Annual |
| Document Owner | Chief Information Security Officer (CISO) |
| Classification | CONFIDENTIAL — Internal Use Only |
| Applicable Standard | SOC 2 Type II — Security, Availability, Confidentiality |
1. Purpose and Scope
This document provides the rationale, legal basis, and formal approval records for each data retention period applied to personal and operational information held by QA Touch. It serves as an internal governance record supporting SOC 2 Privacy criterion P4.2 and demonstrates that retention decisions are deliberate, proportionate, and appropriately approved.
2. Retention Justification Framework
Each retention period must be justified on one or more of the following grounds:
- Legal obligation: a specific law or regulation requires retention for a defined minimum period (e.g., tax records for 7 years).
- Contract performance: data is required to fulfil the active customer subscription and is no longer needed after termination.
- Legitimate interests: data is needed for security, fraud prevention, or audit defence beyond the contract period, and retention is proportionate to the risk.
- Consent: the data subject has consented to retention for a defined purpose and period.
- Legal hold: data may be subject to a preservation notice in connection with active or reasonably anticipated litigation.
3. Retention Period Justification Register
| Data Category | Period | Justification | Approved By | Review |
|---|---|---|---|---|
| User Account Data | Active + 90 days | 90-day post-closure window enables: resolution of billing disputes, data export by departing users, and legal hold where a claim exists. No legitimate purpose after 90 days. | CISO + Legal | 2025-01 |
| Password Hashes | Account lifetime | Security credential required for authentication. Old hash deleted on password change (replaced). No purpose after account closure. | CISO | 2025-01 |
| Audit Logs (user actions) | 36 months total | SOC 2 Type II audit evidence requires minimum 12 months per annual audit cycle; 36 months covers 3 audit cycles and typical litigation discovery windows. Industry standard for SaaS audit logs. | CISO + Legal | 2025-01 |
| Security Event Logs | 36 months total | Security incidents may not be discovered immediately. 36-month window preserves forensic evidence for incidents discovered retrospectively. Aligns with typical statutes of limitation for security-related claims. | CISO | 2025-01 |
| Application / Error Logs | 90 days total | Debugging value is highest in the first 30 days; 90-day total provides adequate overlap for delayed issue discovery. No regulatory minimum; shorter period reduces privacy risk. | VP Engineering | 2025-01 |
| Billing Records | Active + 7 years | Tax and accounting regulations in most jurisdictions (US, EU, UK) require financial records for 5–7 years. 7-year retention ensures compliance across all operating jurisdictions. | CFO + Legal | 2025-01 |
| Workspace Data | Active + 30 days | 30-day post-termination window provides customers with an export opportunity before permanent deletion. Standard SaaS industry practice; referenced in customer contracts. | Legal + CISO | 2025-01 |
| Import Staging Files | Max 24 hours | Staging files are transient by design; once import completes or fails, the file has no further purpose. Minimum viable retention reduces storage footprint and eliminates stale sensitive file risk. | VP Engineering | 2025-01 |
| Export Package Files | 24–72 hours | Sufficient window for user to download; auto-deletion reduces storage cost and eliminates risk of sensitive exported data persisting unnecessarily in object storage. | VP Engineering | 2025-01 |
| Daily Backup Snapshots | 7 days | 7-day window provides point-in-time recovery for accidental deletion or corruption, typically identified within hours to days of occurrence. | VP Engineering + CISO | 2025-01 |
| Weekly Backup Snapshots | 4 weeks | Extends recovery window to one month for scenarios where corruption is not immediately detected. | VP Engineering + CISO | 2025-01 |
| Monthly Backup Snapshots | 12 months | Annual recovery capability for long-term integrity verification and compliance purposes. | VP Engineering + CISO | 2025-01 |
| Support Ticket Content | 2 years post-closure | Retained for quality assurance and potential dispute resolution regarding support interactions. 2 years aligns with typical contractual limitation periods. | Legal + Customer Success | 2025-01 |
| Consent Records | Account + 3 years | Records must demonstrate processing was lawful at time of occurrence. 3-year post-account window covers typical limitation periods for privacy-related claims. | Legal + CISO | 2025-01 |
| DSR Records | 3 years post-completion | Regulatory bodies may audit DSR compliance; 3-year retention provides evidence of timely and lawful handling of all requests. | Legal + CISO | 2025-01 |
| AI Prompt Content | Workspace duration [VERIFY] | Retained for workspace lifecycle to enable reproducibility [VERIFY if this is intended product behaviour]. Deleted with workspace. | CPO + CISO [VERIFY] | 2025-01 |
4. Review and Approval Process
- Retention periods reviewed annually by the CISO, Legal/Compliance Officer, and relevant Data Owners.
- Reviews triggered earlier by: new regulations, business model changes, significant new data types, or regulatory/customer feedback.
- Changes to retention periods require CISO and Legal Officer approval; material changes trigger Privacy Policy update and customer notification.
- Approval records for each review cycle maintained in the compliance management system; available for SOC 2 auditor inspection.