Retention Period Justifications


FieldValue
Version1.0
Effective DateApril 2026
Review CycleAnnual
Document OwnerChief Information Security Officer (CISO)
ClassificationCONFIDENTIAL — Internal Use Only
Applicable StandardSOC 2 Type II — Security, Availability, Confidentiality

1. Purpose and Scope

This document provides the rationale, legal basis, and formal approval records for each data retention period applied to personal and operational information held by QA Touch. It serves as an internal governance record supporting SOC 2 Privacy criterion P4.2 and demonstrates that retention decisions are deliberate, proportionate, and appropriately approved.

2. Retention Justification Framework

Each retention period must be justified on one or more of the following grounds:

  • Legal obligation: a specific law or regulation requires retention for a defined minimum period (e.g., tax records for 7 years).
  • Contract performance: data is required to fulfil the active customer subscription and is no longer needed after termination.
  • Legitimate interests: data is needed for security, fraud prevention, or audit defence beyond the contract period, and retention is proportionate to the risk.
  • Consent: the data subject has consented to retention for a defined purpose and period.
  • Legal hold: data may be subject to a preservation notice in connection with active or reasonably anticipated litigation.

3. Retention Period Justification Register

Data CategoryPeriodJustificationApproved ByReview
User Account DataActive + 90 days90-day post-closure window enables: resolution of billing disputes, data export by departing users, and legal hold where a claim exists. No legitimate purpose after 90 days.CISO + Legal2025-01
Password HashesAccount lifetimeSecurity credential required for authentication. Old hash deleted on password change (replaced). No purpose after account closure.CISO2025-01
Audit Logs (user actions)36 months totalSOC 2 Type II audit evidence requires minimum 12 months per annual audit cycle; 36 months covers 3 audit cycles and typical litigation discovery windows. Industry standard for SaaS audit logs.CISO + Legal2025-01
Security Event Logs36 months totalSecurity incidents may not be discovered immediately. 36-month window preserves forensic evidence for incidents discovered retrospectively. Aligns with typical statutes of limitation for security-related claims.CISO2025-01
Application / Error Logs90 days totalDebugging value is highest in the first 30 days; 90-day total provides adequate overlap for delayed issue discovery. No regulatory minimum; shorter period reduces privacy risk.VP Engineering2025-01
Billing RecordsActive + 7 yearsTax and accounting regulations in most jurisdictions (US, EU, UK) require financial records for 5–7 years. 7-year retention ensures compliance across all operating jurisdictions.CFO + Legal2025-01
Workspace DataActive + 30 days30-day post-termination window provides customers with an export opportunity before permanent deletion. Standard SaaS industry practice; referenced in customer contracts.Legal + CISO2025-01
Import Staging FilesMax 24 hoursStaging files are transient by design; once import completes or fails, the file has no further purpose. Minimum viable retention reduces storage footprint and eliminates stale sensitive file risk.VP Engineering2025-01
Export Package Files24–72 hoursSufficient window for user to download; auto-deletion reduces storage cost and eliminates risk of sensitive exported data persisting unnecessarily in object storage.VP Engineering2025-01
Daily Backup Snapshots7 days7-day window provides point-in-time recovery for accidental deletion or corruption, typically identified within hours to days of occurrence.VP Engineering + CISO2025-01
Weekly Backup Snapshots4 weeksExtends recovery window to one month for scenarios where corruption is not immediately detected.VP Engineering + CISO2025-01
Monthly Backup Snapshots12 monthsAnnual recovery capability for long-term integrity verification and compliance purposes.VP Engineering + CISO2025-01
Support Ticket Content2 years post-closureRetained for quality assurance and potential dispute resolution regarding support interactions. 2 years aligns with typical contractual limitation periods.Legal + Customer Success2025-01
Consent RecordsAccount + 3 yearsRecords must demonstrate processing was lawful at time of occurrence. 3-year post-account window covers typical limitation periods for privacy-related claims.Legal + CISO2025-01
DSR Records3 years post-completionRegulatory bodies may audit DSR compliance; 3-year retention provides evidence of timely and lawful handling of all requests.Legal + CISO2025-01
AI Prompt ContentWorkspace duration [VERIFY]Retained for workspace lifecycle to enable reproducibility [VERIFY if this is intended product behaviour]. Deleted with workspace.CPO + CISO [VERIFY]2025-01

4. Review and Approval Process

  • Retention periods reviewed annually by the CISO, Legal/Compliance Officer, and relevant Data Owners.
  • Reviews triggered earlier by: new regulations, business model changes, significant new data types, or regulatory/customer feedback.
  • Changes to retention periods require CISO and Legal Officer approval; material changes trigger Privacy Policy update and customer notification.
  • Approval records for each review cycle maintained in the compliance management system; available for SOC 2 auditor inspection.