Last updated: 22 July 2026
Data Retention Policy
This starter policy is designed for the current landing page and a future KYB product. Confirm retention periods with counsel before processing regulated KYB, AML, sanctions, or beneficial ownership records.
1. Purpose
This policy describes how KYBFlow plans to retain and delete data. It supports the principle that personal data should not be kept longer than necessary for legal or business purposes.
2. Current landing-page retention
- Inbound email enquiries: retain for up to 24 months after the last interaction, unless needed for a contract, dispute, or legal obligation.
- Launch-access and sales leads: retain for up to 24 months, or until opt-out or deletion request where applicable.
- Website analytics events: retain according to Firebase/Aptabase workspace settings, preferably 14 to 26 months for early-stage funnel analysis.
- UTM attribution in browser storage: session attribution remains in session storage; first-touch attribution remains in local storage until cleared by the user or browser.
- Server logs: retain for up to 90 days unless needed for security investigation, debugging, fraud prevention, or legal reasons.
3. Future KYB product retention
If KYBFlow launches a full verification product, use a retention schedule similar to:
- KYB check records and verification reports: retain for the customer contract term plus up to 6 years, unless a different legal or customer-agreed period applies.
- UBO, director, shareholder, and authorised representative records: retain only for the active case, contract, audit, compliance, and dispute period that applies.
- Uploaded documents: delete or archive after verification and customer-agreed retention, unless required for audit or legal defence.
- Audit logs: retain for up to 6 years where needed to evidence access, changes, approvals, and compliance decisions.
- Failed or abandoned checks: retain for up to 12 months for troubleshooting, fraud prevention, and customer support.
4. Deletion and anonymisation
When the retention period expires, KYBFlow should delete, anonymise, or aggregate the data so it is no longer linked to an identifiable person, unless continued retention is required or permitted by law.
5. Backups
Data may remain in encrypted backups for a limited backup lifecycle after deletion from production systems. Backups should not be restored except for continuity, security, or disaster-recovery purposes.
6. Legal holds
KYBFlow may suspend deletion where data is needed for investigations, disputes, audits, regulatory requests, or legal proceedings.
7. Reviews
Retention periods should be reviewed at least annually and whenever KYBFlow adds a backend, database, registry provider, payment flow, or customer contract terms.
8. Contact
Questions or deletion requests can be sent to [email protected].