1. Retention principles
Information is kept only for a defined operational, contractual, security, dispute, or legal purpose. Retention is based on data type, sensitivity, customer configuration, legal obligations, backup lifecycle, and whether an active legal hold applies.
Deletion is designed as an accountable lifecycle, not an unlogged immediate database operation. Access may be suspended first, a recoverable closure window may apply, eligible objects are deleted, and residual backups age out under the backup schedule.
2. Working schedule
- Customer project and evidence records: for the subscription term and the customer-configured retention period; the current default may be seven years where the customer has not selected another lawful period.
- Encrypted offline evidence: only until successful upload or the short offline expiry period, currently designed not to exceed seven days.
- Authentication, security, and audit records: for the period reasonably needed to investigate activity, demonstrate accountability, prevent abuse, and meet legal duties.
- Support cases: for the active relationship and a reasonable post-resolution period needed for continuity, quality review, disputes, and security.
- Registration applications: while under review and for a reasonable period afterward to document the decision, prevent duplicate applications, and meet business or legal record duties.
- Billing and tax records: for the statutory period applicable to the transaction and RestoreCheck IQ’s records.
- Backups: encrypted and access-restricted until rotation; they are not restored for ordinary access after a verified deletion except for disaster recovery, security, or legal necessity.
- Legal hold: overrides ordinary deletion only for the scope and duration reasonably required, with release and disposition recorded.
3. Requests and verification
Authorized administrators and individuals may request export, correction, account deletion, or workspace closure through account controls, support, or privacy@restorecheckiq.ca. We verify identity, organizational authority, and legal restrictions before acting.
Where a customer controls the information, individual requests may be referred to that customer. We will explain any required retention and delete or de-identify the remainder when the reason for retention ends.