This document provides the rationale and approvals for the retention periods applied to each category of personal and operational data processed by DCKAP Integrator. It demonstrates that retention decisions are deliberate, justified, and reviewed.
2. Retention Period Justifications
Data Category
Retention Period
Justification
Approved By
Consumer transit data
Max 24 hours
DCKAP’s role is to transfer, not store, consumer data. 24 hours allows for immediate retry on transient failures while minimising privacy exposure.
CISO + DPO
Sync execution logs
90 days
90 days covers typical support escalation timelines and provides sufficient history for SOC 2 audit evidence without excessive data accumulation.
CISO + Engineering Lead
API request/response logs
30 days
30 days sufficient for debugging recent issues. PII is masked, reducing privacy risk. Shorter than sync logs as these are more voluminous.
CISO + Engineering Lead
Audit trail
1 year
SOC 2 Type II requires evidence of controls over the entire audit period (typically 12 months). 1 year satisfies this while balancing storage cost.
CISO + External Auditor Guidance
Security events / SIEM
1 year
Incident response investigations may cover events months in the past. 1 year aligns with industry standard and SOC 2 requirements.
CISO
Portal user account data
Account + 30 days
30-day post-deletion retention allows recovery of accidental deletions and completion of any pending support cases.
CISO + Product
Billing records
7 years
Tax regulations in multiple jurisdictions (including the US and UK) require financial records to be kept for a minimum of 6–7 years.
CFO + Legal
Customer config data
Account + 90 days
90-day post-termination retention supports customer data recovery requests during the offboarding period, a common contractual commitment.
CISO + Customer Success
3. Review and Approval History
Version
Review Date
Reviewer(s)
Outcome
1.0
June 27, 2026
CISO, DPO, CFO, Legal Counsel
Initial schedule approved — all periods justified.
1.1 (planned)
June 2027
CISO, DPO, Legal Counsel
Annual review — scheduled
4. Criteria for Retention Period Review
Change in applicable law or regulation (e.g., new data protection legislation).
Change in DCKAP’s data processing activities or product architecture.
Recommendation from external auditor or data protection authority.
Customer contract requirements that necessitate a different period.