Data Retention & Disposal Policy¶
| Field | Value |
|---|---|
| Owner | Puneet Gupta (Co-Founder) |
| Classification | Internal (shareable under NDA) |
| Version | 1.0 |
| Effective date | 2026-06-11 |
| Next review | 2027-06-11 |
1. Purpose¶
Define how long data is retained and how it is securely disposed of.
2. Retention principle¶
Data is retained only as long as necessary to deliver the service and to meet applicable business, legal, and regulatory requirements.
3. Retention schedule¶
| Data type | Retention | Notes |
|---|---|---|
| Customer financial/ERP records | Duration of engagement | Deleted after termination (see §4) |
| Integration credentials (encrypted) | Until integration removed or engagement ends | |
| Audit / activity / login logs | At least 180 days | Supports investigation and customer export |
| Backups | Per provider plan / PITR window | See BCDR policy |
(The formal retention schedule mapped line-by-line to legal/regulatory drivers is being finalized.)
4. Disposal at end of engagement¶
On contract termination or customer request, customer data — including PII — is deleted from the production systems. Deletion from backups occurs as backups age out of their retention window.
5. Secure disposal¶
- Logical deletion removes data from active systems; tenant isolation (RLS) prevents access in the interim.
- Physical media disposal for the hosting infrastructure is handled by the cloud provider under its certified data-destruction processes; Revzio operates no self-managed storage media holding scoped data.
Revision history¶
| Version | Date | Author | Change | Approved by |
|---|---|---|---|---|
| 1.0 | 2026-06-11 | Puneet Gupta | Initial draft | Puneet Gupta (Co-Founder) |