Data Retention Policy
This Policy explains how long Khalid Aboubakr and Sigmantic Digital Technology retain different categories of information across our websites, mobile applications, SaaS platforms, customer portals, dashboards, APIs, and any other digital service we operate. Retention periods are designed to satisfy operational, security, legal, and audit requirements while honoring the data-minimization principle — we keep information only as long as is necessary, and we dispose of it securely.
Retention principles
- Purpose limitation — every retention period is tied to a documented business or legal purpose.
- Data minimization — when a purpose is fulfilled and no legal hold applies, data moves through the deletion lifecycle.
- Integrity and availability — data is protected by encryption and access controls for the entire retention period.
- Auditability — deletion events are recorded so that auditors can verify the lifecycle.
Retention by data category
The table below summarises representative retention periods for our most common data categories. Specific products may apply shorter periods to comply with contractual commitments to a customer organization.
| Category | Default retention | Reason |
|---|---|---|
| Authentication logs (successful & failed sign-ins) | 12 months active · 12 months sealed | Account-takeover investigation, audit, and incident response. |
| Audit logs (administrative actions on production data) | 24 months | Regulatory audit, contractual SLAs, incident reconstruction. |
| Operational records (work orders, tickets, events) | For the lifetime of the account · 90 days after closure | Service continuity and contractual obligations. |
| Uploaded files and attachments | For the lifetime of the workspace · 30 days after deletion | Allows recovery from accidental deletion. |
| Support communications (tickets, email) | 24 months | Reference for repeat issues, quality assurance, dispute resolution. |
| Billing and tax records | 7 years | Statutory requirement. |
| Inactive accounts (no sign-in) | Notice at 12 months · deletion at 24 months | Reduces exposure of dormant data. |
| Platform activity / product analytics (aggregated) | 24 months | Reliability trend analysis. Personal identifiers removed. |
| Marketing contact data (opt-in only) | Until unsubscribe + 30 days | Suppression-list maintenance. |
| Backups and replicas | Up to 35 days rolling | Disaster recovery. Deleted records expire from backups within the rolling window. |
Deletion lifecycle
- Trigger — the retention period elapses, or you submit a verified deletion request, or a contractual end-of-service event occurs.
- Soft delete — the record is removed from production interfaces and APIs immediately; it can no longer be retrieved by the business.
- Sealed retention — for log-style categories, the record moves to a sealed retention area accessible only for forensic investigation under strict access controls.
- Hard delete — the record is purged from primary storage and queued for purge from backups during the rolling backup window.
- Audit confirmation — the deletion event is captured in an internal audit log so we can demonstrate the lifecycle to auditors and supervisory authorities.
Archival practices
For records subject to a statutory retention period (for example, billing and tax records), we move data into a dedicated archival store after the active operational period. Archival storage is encrypted, isolated from production environments, and accessible only to a small, audited set of administrators. Archived records are not used for any operational purpose other than the purpose that mandated their retention.
Security considerations
- All retained data — active, sealed, or archived — is encrypted at rest using AES-256 or equivalent and in transit using TLS 1.2 or higher.
- Access to sealed and archived data requires multi-factor authentication and is granted on a just-in-time basis with full audit logging.
- Cryptographic keys protecting retired data sets are rotated and revoked according to a documented key-management schedule.
Secure deletion methodology
- Database records — deleted via transactional `DELETE` or tombstone marker, followed by automatic compaction and vacuum routines that physically reclaim storage.
- Object storage (files/attachments) — deleted via the storage provider's versioned delete API; lifecycle rules expire any preserved versions within the configured retention window.
- Backups and replicas — purged through the natural expiration of the rolling backup window; emergency backup-level deletion is supported when legally required.
- Cryptographic erasure — for archived data sets, we additionally rotate or destroy the underlying encryption keys so that even residual ciphertext is rendered unreadable.
Inactive accounts
Accounts that have not signed in or interacted with the service for an extended period are flagged as inactive. We send a reminder before any action. If no action is taken, the account and associated personal data progress through the deletion lifecycle. Customer organizations can configure stricter inactivity policies that apply to their workspaces.
Legal holds and exceptions
A retention period may be extended where a legal hold has been issued (for example, in connection with litigation, government investigation, or regulatory inquiry). When the legal hold is released, the affected data resumes its normal deletion lifecycle. Records preserved under a legal hold are isolated from operational use.
Customer-configurable retention
For SaaS platforms we operate on behalf of customer organizations, administrators can configure retention windows tighter than our defaults where the underlying regulation permits, and can invoke programmatic deletion of records (for example, automatic closure of resolved tickets after a defined number of days).
Questions about retention
For specific retention questions about a product or for assistance with a data-subject request, contact contact@khalidaboubakr.com with the subject "Retention Inquiry".
Have a privacy or compliance question?
Reach out for a formal response within a few business days.