Skip to content

Data Retention & Disposal Policy

Field Value
Owner Puneet Gupta (Co-Founder)
Classification Internal (shareable under NDA)
Version 1.0
Effective date 2026-06-11
Next review 2027-06-11

1. Purpose

Define how long data is retained and how it is securely disposed of.

2. Retention principle

Data is retained only as long as necessary to deliver the service and to meet applicable business, legal, and regulatory requirements.

3. Retention schedule

Data type Retention Notes
Customer financial/ERP records Duration of engagement Deleted after termination (see §4)
Integration credentials (encrypted) Until integration removed or engagement ends
Audit / activity / login logs At least 180 days Supports investigation and customer export
Backups Per provider plan / PITR window See BCDR policy

(The formal retention schedule mapped line-by-line to legal/regulatory drivers is being finalized.)

4. Disposal at end of engagement

On contract termination or customer request, customer data — including PII — is deleted from the production systems. Deletion from backups occurs as backups age out of their retention window.

5. Secure disposal

  • Logical deletion removes data from active systems; tenant isolation (RLS) prevents access in the interim.
  • Physical media disposal for the hosting infrastructure is handled by the cloud provider under its certified data-destruction processes; Revzio operates no self-managed storage media holding scoped data.

Revision history

Version Date Author Change Approved by
1.0 2026-06-11 Puneet Gupta Initial draft Puneet Gupta (Co-Founder)