Retention & Deletion

Data Retention Policy

This Policy explains how long Khalid Aboubakr and Sigmantic Digital Technology retain different categories of information across our websites, mobile applications, SaaS platforms, customer portals, dashboards, APIs, and any other digital service we operate. Retention periods are designed to satisfy operational, security, legal, and audit requirements while honoring the data-minimization principle — we keep information only as long as is necessary, and we dispose of it securely.

Last updated: January 1, 2026Sigmantic Digital Technology · Khalid Aboubakr
Section 1

Retention principles

  • Purpose limitation — every retention period is tied to a documented business or legal purpose.
  • Data minimization — when a purpose is fulfilled and no legal hold applies, data moves through the deletion lifecycle.
  • Integrity and availability — data is protected by encryption and access controls for the entire retention period.
  • Auditability — deletion events are recorded so that auditors can verify the lifecycle.
Section 2

Retention by data category

The table below summarises representative retention periods for our most common data categories. Specific products may apply shorter periods to comply with contractual commitments to a customer organization.

CategoryDefault retentionReason
Authentication logs (successful & failed sign-ins)12 months active · 12 months sealedAccount-takeover investigation, audit, and incident response.
Audit logs (administrative actions on production data)24 monthsRegulatory audit, contractual SLAs, incident reconstruction.
Operational records (work orders, tickets, events)For the lifetime of the account · 90 days after closureService continuity and contractual obligations.
Uploaded files and attachmentsFor the lifetime of the workspace · 30 days after deletionAllows recovery from accidental deletion.
Support communications (tickets, email)24 monthsReference for repeat issues, quality assurance, dispute resolution.
Billing and tax records7 yearsStatutory requirement.
Inactive accounts (no sign-in)Notice at 12 months · deletion at 24 monthsReduces exposure of dormant data.
Platform activity / product analytics (aggregated)24 monthsReliability trend analysis. Personal identifiers removed.
Marketing contact data (opt-in only)Until unsubscribe + 30 daysSuppression-list maintenance.
Backups and replicasUp to 35 days rollingDisaster recovery. Deleted records expire from backups within the rolling window.
Section 3

Deletion lifecycle

  1. Trigger — the retention period elapses, or you submit a verified deletion request, or a contractual end-of-service event occurs.
  2. Soft delete — the record is removed from production interfaces and APIs immediately; it can no longer be retrieved by the business.
  3. Sealed retention — for log-style categories, the record moves to a sealed retention area accessible only for forensic investigation under strict access controls.
  4. Hard delete — the record is purged from primary storage and queued for purge from backups during the rolling backup window.
  5. Audit confirmation — the deletion event is captured in an internal audit log so we can demonstrate the lifecycle to auditors and supervisory authorities.
Section 4

Archival practices

For records subject to a statutory retention period (for example, billing and tax records), we move data into a dedicated archival store after the active operational period. Archival storage is encrypted, isolated from production environments, and accessible only to a small, audited set of administrators. Archived records are not used for any operational purpose other than the purpose that mandated their retention.

Section 5

Security considerations

  • All retained data — active, sealed, or archived — is encrypted at rest using AES-256 or equivalent and in transit using TLS 1.2 or higher.
  • Access to sealed and archived data requires multi-factor authentication and is granted on a just-in-time basis with full audit logging.
  • Cryptographic keys protecting retired data sets are rotated and revoked according to a documented key-management schedule.
Section 6

Secure deletion methodology

  • Database records — deleted via transactional `DELETE` or tombstone marker, followed by automatic compaction and vacuum routines that physically reclaim storage.
  • Object storage (files/attachments) — deleted via the storage provider's versioned delete API; lifecycle rules expire any preserved versions within the configured retention window.
  • Backups and replicas — purged through the natural expiration of the rolling backup window; emergency backup-level deletion is supported when legally required.
  • Cryptographic erasure — for archived data sets, we additionally rotate or destroy the underlying encryption keys so that even residual ciphertext is rendered unreadable.
Section 7

Inactive accounts

Accounts that have not signed in or interacted with the service for an extended period are flagged as inactive. We send a reminder before any action. If no action is taken, the account and associated personal data progress through the deletion lifecycle. Customer organizations can configure stricter inactivity policies that apply to their workspaces.

Section 9

Customer-configurable retention

For SaaS platforms we operate on behalf of customer organizations, administrators can configure retention windows tighter than our defaults where the underlying regulation permits, and can invoke programmatic deletion of records (for example, automatic closure of resolved tickets after a defined number of days).

Section 10

Questions about retention

For specific retention questions about a product or for assistance with a data-subject request, contact contact@khalidaboubakr.com with the subject "Retention Inquiry".

Have a privacy or compliance question?

Reach out for a formal response within a few business days.

Contact us