KONTYRA Legal
Data Retention Policy
This Data Retention Policy explains how KONTYRA retains, archives, and deletes information associated with its websites, products, services, accounts, operations, legal obligations, and security controls.
1. Purpose
KONTYRA retains information only for legitimate business, operational, security, legal, tax, accounting, compliance, and contractual purposes. Retention should be no longer than necessary for the purpose for which the information is maintained.
2. Scope
This policy applies to:
- Account data, user profile data, organization data, billing records, and support communications.
- Product data, project metadata, API request metadata, diagnostics, telemetry, and logs.
- Security records, audit logs, access records, incident records, vulnerability reports, and investigation materials.
- Business records, legal records, contracts, invoices, tax documents, and compliance documentation.
3. Retention Principles
- Purpose limitation: retain data for a defined business, legal, security, or operational purpose.
- Data minimization: collect and retain only what is reasonably needed.
- Security: protect retained data with safeguards appropriate to sensitivity and risk.
- Deletion: securely delete, anonymize, or archive data when retention is no longer required.
- Legal holds: suspend deletion when needed for disputes, investigations, audits, or legal obligations.
4. Retention Schedule
KONTYRA uses the following baseline retention periods unless a longer period is required by law, contract, security need, or legal hold:
- Account records: retained while the account is active and for a reasonable period after closure to support recovery, fraud prevention, dispute resolution, and legal obligations.
- Billing and tax records: retained as needed for accounting, tax, audit, and financial reporting obligations.
- Support communications: retained for service quality, troubleshooting, training, and dispute resolution.
- Security logs and audit records: retained for investigation, abuse prevention, threat detection, and compliance needs.
- Incident records: retained to document facts, decisions, remediation, lessons learned, and notification obligations.
- Marketing preferences: retained while relevant to honor communication choices and suppression requests.
5. Deletion and Anonymization
When information is no longer needed, KONTYRA may delete it, anonymize it, aggregate it, archive it, or render it inaccessible through reasonable technical and administrative measures. Backup copies may persist for a limited period until overwritten or retired through normal backup cycles.
6. User Deletion Requests
Users may request deletion of certain personal information by contacting privacy@kontyra.name.ng. KONTYRA may retain information when required or permitted for legal obligations, security, fraud prevention, billing, dispute resolution, or service integrity.
7. Legal Holds
KONTYRA may preserve information beyond normal retention periods when reasonably necessary for litigation, investigations, audits, regulatory requests, law enforcement requests, contractual disputes, or protection of rights and safety.
8. Secure Disposal
KONTYRA will use reasonable disposal methods appropriate to the data type and storage medium. Disposal may include deletion, cryptographic erasure, credential revocation, secure destruction by vendors, or removal from active systems.
9. Review
KONTYRA may review this policy periodically and update retention practices as products, legal obligations, security needs, and business operations change.