This document specifies the retention periods for all categories of personal and operational data processed by DCKAP Integrator, along with the disposal and deletion procedures applied when retention periods expire.
2. Data Retention Schedule
Data Category
Classification
Retention Period
Basis
Disposal Method
Consumer transit data (orders, addresses)
RESTRICTED
Max 24 hours from sync completion
Data minimisation
Automated purge
Processing queue / in-flight data
CONFIDENTIAL
Until job completes (max 24h)
Operational necessity
Auto-deleted on completion
Dead-letter queue records
CONFIDENTIAL
7 days (configurable 1–30 days)
Support / replay need
Auto-purge + manual option
API request/response logs (PII masked)
INTERNAL
30 days
Debugging, SLA
Automated log rotation
Sync execution logs
INTERNAL
90 days
Support, SOC 2 audit
Automated log rotation
Security event logs / SIEM
CONFIDENTIAL
1 year
SOC 2, incident response
Automated log rotation
Portal audit trail
CONFIDENTIAL
1 year
SOC 2 CC7.2
Auto-archival, then deletion
Portal user account data
CONFIDENTIAL
Duration of account + 30 days post-deletion
Contract, legal
Secure deletion on request/termination
Customer integration configuration
INTERNAL
Duration of account + 90 days post-termination
Support during offboarding
Secure deletion after 90 days
API credentials (customer)
RESTRICTED
Until customer removes or account terminates
Service necessity
Vault deletion; crypto-shredding
Billing / invoicing records
CONFIDENTIAL
7 years
Tax / financial regulation
Archived, then secure deletion
Support tickets
INTERNAL
2 years
Support quality, SLA evidence
Anonymisation then archival
3. Disposal Procedures
3.1 Automated Disposal
All log data categories have automated retention policies enforced at the storage layer — data is automatically deleted upon expiry.
Consumer transit data is deleted by the processing engine immediately upon successful delivery confirmation.
Automated purge jobs run daily; failed purges raise an operational alert for manual review.
3.2 Customer-Triggered Disposal
Customer admins can delete their integration configurations at any time via the portal — configuration data is deleted within 90 days of account termination.
Data erasure requests from data subjects are actioned within 30 days by the DCKAP privacy team.
3.3 Cryptographic Erasure
For data stored in the encrypted secrets vault, deletion involves destroying the encryption key (crypto-shredding) in addition to deleting the ciphertext — rendering the data unrecoverable.