Skip to main content
Home Legal
Data Retention Schedule

Data Retention Schedule

Version 1.0 · Effective 22 August 2026

One table, one source of truth. Every other DECTIFY policy that mentions a retention period points here, so the numbers cannot drift apart.

Global DPDP s.8(7) APP 11.2 CERT-In 180 days

Storage limitation is a legal obligation in both jurisdictions we operate in: section 8(7) of the Digital Personal Data Protection Act, 2023 requires erasure once the purpose is served, and Australian Privacy Principle 11.2 requires destruction or de-identification once information is no longer needed. This schedule is how we discharge it.

1. How to read this

  • Default is what applies unless a customer changes it within the permitted range.
  • Floor is the shortest period a customer may configure. Below the floor the product stops functioning as documented.
  • Ceiling is the longest period DECTIFY will support. A customer may only exceed it where its own law compels retention, and must record the provision relied on.
  • Trigger is what starts the clock.

2. Customer Data — captures and derivations

Data classDefaultFloorCeilingTrigger
Continuous video footage30 days24 hours90 daysCapture
Facial image crops30 days24 hours90 daysCapture
Biometric templates — ambient, unmatched72 hours1 hour72 hoursCapture
Biometric templates — matched to an active watchlist entry90 days7 days90 daysMatch, or case closure if earlier
Enrolled gallery templatesEntry expiry date—12 months per entryRemoval or expiry
Plate reads — no alert30 days24 hours90 daysCapture
Plate reads — alerted90 days7 days12 monthsAlert, or case closure if earlier
Re-identification tracksSession, max 24 hours—24 hoursSession end
Crowd counts and density metrics (aggregate, non-identifying)24 months30 days36 monthsCapture
Driver-safety events (DriveCheck)90 days30 days12 monthsEvent
Traffic signal telemetry (non-identifying)24 months30 days36 monthsCapture
Aerial mission recordings (SkyResponder)30 days7 days90 daysMission end
Alerts and match-review decisions12 months90 days7 yearsDecision
Evidence exported to a case fileCustomer-set—Customer's legal obligationExport

3. Platform and account data

Data classRetentionWhy
Audit logs — searches, exports, enrolments, admin changes180 days minimum, then per customer configuration up to 7 yearsCERT-In Direction of 28 April 2022; customer accountability
Authentication and access logs180 daysSecurity investigation; CERT-In
Account administrator recordsContract term + 7 yearsCompanies Act 2013 and Income Tax Act 1961 record-keeping
Training and certification recordsContract term + 3 yearsEvidence of clause 5.3 compliance
Support tickets and correspondence36 months from closureService history and dispute resolution
Billing and tax records7 yearsStatutory in India; 5 years minimum in Australia under the Income Tax Assessment Act
Contracts and Order FormsTerm + 7 yearsLimitation Act 1963 (India); state limitation periods (Australia)
Service Data — telemetry, diagnostics, usage24 monthsCapacity planning and reliability engineering

4. Data DECTIFY controls

Data classRetentionTrigger
Website analyticsPer the Cookie Policy — up to 24 months by categoryCollection
Enquiry and demo-request records24 monthsLast contact
Marketing consent recordsConsent duration + 3 yearsWithdrawal
Unsuccessful candidate records12 monthsDecision, unless the candidate consents to a talent pool
Employee recordsEmployment + 7 yearsSeparation
Vulnerability reports36 monthsClosure
Government and law enforcement request records7 yearsResponse, for transparency reporting

5. Deletion mechanics

5.1 Rolling deletion. Time-bounded classes are deleted by a scheduled job that runs continuously, not by a periodic sweep. A record reaching its expiry is removed from production storage and from every search index within the following hour.

5.2 Backups. Deleted records persist in encrypted backups until those backups age out, within ninety (90) days. Backups are not searchable, are not restored selectively to recover deleted data, and are used only for disaster recovery of an entire system state.

5.3 Closure triggers. Where a period is expressed as "or case closure if earlier", closing the case in the HUB deletes the associated data immediately rather than waiting for expiry.

5.4 Legal hold. Where DECTIFY is served with a preservation demand it is legally required to honour, the affected data is placed on hold and excluded from automated deletion for the duration. Holds are recorded, are as narrow as the demand permits, are reviewed every ninety (90) days, and are released as soon as the obligation lapses. Customers are notified unless we are prohibited from telling them. See Government and Law Enforcement Requests.

5.5 Termination. On termination of an Order Form, Customer Data is available for export for thirty (30) days, deleted from production within a further thirty (30) days, and gone from backups within ninety (90) days after that. Biometric templates are deleted on their own accelerated schedule and are not held for the export window.

5.6 Certification. On written request DECTIFY provides a deletion certificate identifying the data set, the date of deletion and the mechanism used.

6. Changes

A change that shortens a period takes effect immediately. A change that lengthens a default or a ceiling is treated as materially adverse and takes effect at a customer's next renewal, on thirty (30) days' notice. Every change is recorded in the log at Compliance and Security Updates.

Ceilings are ceilings. DECTIFY will not extend biometric template retention beyond ninety (90) days for commercial reasons, on any tier, for any customer. A statutory obligation is the only thing that moves it, and the customer must identify the provision.

Contact

Questions about this document: legal@dectify.in

DECTIFY Technologies Pvt. Ltd., New Delhi, India