Data Retention Policy — Sustalium
Kun engelsk: Denne siden er kun tilgjengelig på engelsk. Ved spørsmål, kontakt oss på engelsk eller bruk et oversettelsesverktøy.
Last updated: August 2026
1. Purpose
To define how long Sustalium retains Personal Data and compliance assets, in accordance with GDPR and industry standards.
2. Retention Principles
- Data Minimization: Only retain data necessary for providing the service.
- Purpose Limitation: Data is retained only for the purpose it was collected.
- Security: All retained data is protected by Sustalium’s TOMs.
3. Retention Periods
| Data Type | Retention Period | Reason |
|---|---|---|
| User account data | Duration of contract + 90 days | Account closure & audit trails |
| Compliance assets & ledger anchors | 10 years minimum from the date of generation | Regulatory audit requirements |
| Audit logs | 24 months | Security & fraud detection |
| Support tickets | 12 months | Service quality |
| Backups | 30 days | Disaster recovery |
| Deleted data | 30 days | Grace period for accidental deletion |
4. Customer-Requested Deletion
Customers may request to delete:
- User accounts
- Supplier data
Deletion is immediate once processed and irreversible after the 30‑day grace period.
To preserve supply chain integrity and regulatory compliance, publicly published Compliance Assets cannot be permanently deleted by the customer, though they can be archived or marked as inactive.
5. End of Contract
Upon termination:
- Data is deleted within 90 days
- Backups containing the data expire naturally within 30 days
- Customer may request a data export before deletion