Data Retention Schedule
OnSyra · Version 1.0 · DRAFT — requires counsel review
Retention is driven by obligation, not preference. Where a period is longer than we would choose, the reason is named.
| Data | Retained | Why |
|---|---|---|
| Account profile | 7 years after closure | Tax and AML record keeping |
| Identity verification records (CIP) | 5 years after closure | Bank Secrecy Act / FinCEN |
| Government ID images, selfies and face-match measurements (biometric data) | Destroyed 90 days after the check resolves, whatever the outcome (passed, failed, rejected, cancelled, or abandoned — an attempt idle 7 days is abandoned), and never later than 3 years; result and reference retained without biometric data. See biometric-policy.md |
Minimising the most sensitive holding; BIPA / CUBI / RCW 19.375 |
| Full taxpayer ID | Stored encrypted for the life of the account plus 7 years (with the tax records it supports). Most roles see the last 4 only; full reveal is limited to the tax/payments role, with a reason, audited. Pending counsel review | Needed to file 1099s / T4As; exposure limited by encryption and role |
| Sanctions screening results | 5 years | AML obligation |
| SARs and supporting material | 5 years from filing | Legal requirement; segregated access |
| Financial records, invoices, payouts | 7 years | Tax and audit |
| External transfer records and events | 7 years | Payment dispute and audit window |
| Work orders and contracts | 7 years | Contractual limitation periods |
| Work evidence (photos, signatures, notes) | 3 years after completion | Dispute and warranty window |
| Time logs | 3 years | Wage-claim limitation periods |
| Location pings during a job | 90 days (sent only while travelling to or on site at a job) | Shortest period that still supports a dispute; check-in/out positions are kept with the time logs |
| Check-in / check-out location | 3 years, with the work evidence | Attendance proof |
| Messages | 3 years | Dispute evidence |
| Dispute records and decisions | 7 years | Precedent and legal defence |
| Reviews and ratings | Life of the account | Marketplace trust |
| Authentication events | 2 years | Security investigation |
| In-app notifications and delivery records | 12 months | Operational only |
| Audit log | 7 years | Evidence for the financial and legal records it covers |
| Data-export downloads | 7 days after they are ready | Minimising copies of a full profile |
| Application logs | 30 days | Operational only |
| Web server access logs | 90 days | Security investigation |
| Database backups | 14 daily, 8 weekly, 12 monthly | Recovery |
| Support correspondence | 3 years | Continuity |
| Marketing consent records | 3 years after withdrawal | Proof of consent |
Deletion
On account closure, everything not in the table above is deleted within
30 days — the grace period in which the person can change their mind by
signing in again; anonymisation runs when it ends. Enforcement:
lcs:retention:prune (daily) and lcs:accounts:close-due (hourly); periods
in config/retention.php. Pending counsel review. What remains is retained under a legal obligation and is placed
beyond ordinary staff access — reachable only for the purpose that requires it.
A user asking for deletion is told specifically what is being kept, why, and when it will go.
Backups
Deletion applies to live systems immediately. Backups age out on their own cycle; a record deleted today is gone from all backups within 12 months at the latest. Backups are never mined to restore deleted personal data.
Legal hold
Where litigation or an investigation is reasonably anticipated, affected records are held beyond these periods until it concludes. A hold is recorded, scoped and lifted deliberately — never left open by neglect.