Data Retention Schedules

Version1.0
Effective DateApril 2026
Review CycleAnnual
Document OwnerChief Information Security Officer (CISO)
ClassificationCONFIDENTIAL — Internal Use Only
Applicable StandardSOC 2 Type II

1. Purpose

This document specifies the retention periods for all categories of personal and operational data processed by DCKAP Integrator, along with the disposal and deletion procedures applied when retention periods expire.

2. Data Retention Schedule

Data CategoryClassificationRetention PeriodBasisDisposal Method
Consumer transit data (orders, addresses)RESTRICTEDMax 24 hours from sync completionData minimisationAutomated purge
Processing queue / in-flight dataCONFIDENTIALUntil job completes (max 24h)Operational necessityAuto-deleted on completion
Dead-letter queue recordsCONFIDENTIAL7 days (configurable 1–30 days)Support / replay needAuto-purge + manual option
API request/response logs (PII masked)INTERNAL30 daysDebugging, SLAAutomated log rotation
Sync execution logsINTERNAL90 daysSupport, SOC 2 auditAutomated log rotation
Security event logs / SIEMCONFIDENTIAL1 yearSOC 2, incident responseAutomated log rotation
Portal audit trailCONFIDENTIAL1 yearSOC 2 CC7.2Auto-archival, then deletion
Portal user account dataCONFIDENTIALDuration of account + 30 days post-deletionContract, legalSecure deletion on request/termination
Customer integration configurationINTERNALDuration of account + 90 days post-terminationSupport during offboardingSecure deletion after 90 days
API credentials (customer)RESTRICTEDUntil customer removes or account terminatesService necessityVault deletion; crypto-shredding
Billing / invoicing recordsCONFIDENTIAL7 yearsTax / financial regulationArchived, then secure deletion
Support ticketsINTERNAL2 yearsSupport quality, SLA evidenceAnonymisation then archival

3. Disposal Procedures

3.1  Automated Disposal

  • All log data categories have automated retention policies enforced at the storage layer — data is automatically deleted upon expiry.
  • Consumer transit data is deleted by the processing engine immediately upon successful delivery confirmation.
  • Automated purge jobs run daily; failed purges raise an operational alert for manual review.

3.2  Customer-Triggered Disposal

  • Customer admins can delete their integration configurations at any time via the portal — configuration data is deleted within 90 days of account termination.
  • Data erasure requests from data subjects are actioned within 30 days by the DCKAP privacy team.

3.3  Cryptographic Erasure

  • For data stored in the encrypted secrets vault, deletion involves destroying the encryption key (crypto-shredding) in addition to deleting the ciphertext — rendering the data unrecoverable.

4. Placement in Product

Product LocationScreen / PageAudience
Privacy Policydckap.com/privacy → Data RetentionAll Data Subjects
Trust CenterLegal → Retention ScheduleEnterprise DPOs, Auditors
Product PortalSettings → Data & Privacy → RetentionCustomer Admins
DPASchedule 2 — Retention and DeletionCustomer Legal Teams
Compliance FolderSOC 2 Evidence → Retention ControlsExternal Auditors