Data Retention & Deletion Schedule
Effective Date: August 21, 2026 | Last Updated: August 21, 2026
Order of precedence. Where a counter-signed Order Form, Government Entity Addendum, or other executed agreement specifies a retention or deletion period different from the periods below, the executed agreement controls. Where applicable law requires a longer retention period, that law controls.
Retention Periods
| Data category | Retention period | Deletion trigger |
|---|---|---|
| Client Data held in an active Subscription Cardholder records, card templates, ID photos, custom fields, customer integration credentials | Retained for the term of the Subscription | Deleted on Client instruction, or on account closure per the row below |
| Client Data following IDMS account closure | Administrative access and most account data: within 24 hours of the deletion request. Card templates (set to private) and archived card data: 30 days from the deletion request. Where an executed agreement provides for an extended exit window — most commonly government and public sector entities — up to 90 days. | Account deletion request. Administrative access ceases immediately; card templates are set to private and issued cards are archived within 24 hours. |
| App user account data Data provided by an End User when registering. | Deleted within 24 hours | App user account deletion request. Accounts flagged for suspected identity fraud are retained for the duration of the investigation, for no longer than 12 months from the date flagged, absent an active legal hold or law enforcement request. |
| Encrypted backups Database snapshots and file storage backups | Up to 12 months | Automatic lifecycle expiry by backup classification. Backups are not selectively editable; data deleted from production ages out of backups within this window. |
| External (public) API transaction logs Public API calls used for third-party integrations | 5 Days | Automatic lifecycle expiry. Not selectively editable by the Client. |
| Internal / device API transaction logs App user and internal API calls | 10 Days | Automatic lifecycle expiry. Not selectively editable by the Client. |
| Security & system logs Internal audit and monitoring logs not tied to a specific customer account | Up to 12 months | Automatic lifecycle expiry. Internally managed, not selectively editable by the Client. |
| Customer app user notification & message logs In-app and email notifications sent to app users | Up to 2 years (default), configurable by the Client within Subscription limits | Client configuration, account closure, or automatic expiry at the maximum period |
| Account activity logs | Configurable by the Client within the limits of its Subscription, typically up to 12 months. | Client configuration, or automatic expiry at the maximum period. Import/export/sync error files (S3) inherit the retention of their associated log entry and are deleted automatically when that entry is deleted. |
| Face data processed for photo guideline validation | Not retained. Processed transiently and discarded once the check completes. | Not applicable — face data is never written to persistent storage. |
| Accounting, billing, tax and institution registration records Invoices, payment history, tax records, and institution registration & verification information (including named business, technical, and security contacts) | 7+ years | Statutory retention under applicable accounting and tax regulation. No automated deletion is applied at the 7-year mark for either financial or institution registration records. |
| Sales and marketing contact data Business contact information for prospective and current institutional customers (website enquiries, CRM records) | Retained as long as commercially useful | Commercial relevance review. Where a contact opts out of marketing communications, we retain a minimal record of that preference indefinitely to ensure the opt-out is honored and the contact is not recontacted. |
Export Before Deletion
The IDMS provides self-service export of Client Data at any time during the Subscription term. Clients are responsible for exporting a backup of their data before requesting account deletion. On written request within 30 days following termination or expiration, ID123 will extract and return remaining Client Data in a standard, non-proprietary CSV format.
Method of Deletion
When data reaches the end of its retention period it is securely and permanently deleted using disposal methods aligned with NIST and ISO/IEC 27001:2022 guidance on media sanitization. Where ID123 is unable to delete a particular copy of Client Data, that data remains subject to the confidentiality, privacy and security obligations of the Agreement and is not used for any purpose. On written request, ID123 will certify deletion in writing.
Questions about this schedule should be directed to privacy@id123.io.
