Data Retention & Deletion Policy
This Data Retention & Deletion Policy explains how ARZAQ INSIGHTS retains, deletes, and manages information associated with the centralized ARZAQ account system.
1. Purpose & 2. Scope
This policy governs how centralized identity, authentication credentials, security audit logs, billing records, subscription metadata, and session cookies are retained and purged.
Decoupled Product Scope: ARZAQ INSIGHTS does not centrally manage or routinely access operational databases inside individual products. Product-specific operational data is governed independently by each product's respective privacy and data lifecycle policies.
3. Core Data Retention Principles
4. Retention of Active Account Information
While an account remains active, profile details (name, email, phone, Passkeys, recovery methods, active subscriptions) are retained to deliver uninterrupted access across connected platforms.
5. Activity & Security Logs
Security audit trails (sign-in timestamps, IP addresses, Passkey authorizations, 2FA challenges, recovery events) are maintained to protect user accounts, investigate fraud, and troubleshoot issues.
6. Permanent Account Deletion
Users can permanently delete their ARZAQ account via account settings. Upon completion:
- The central account is permanently terminated and cannot be recovered.
- Central authentication tokens and Passkeys are immediately revoked.
- Active subscriptions linked to the account are ended.
- SSO access to all participating ecosystem products is revoked.
7. Impact on Connected Products & 8. Product Data Retention
Central account deletion cuts off identity verification. Individual applications process operational data according to their own internal deletion and archival schedules.
9. Billing, Invoices & 10. Subscription Records
Tax invoices, GST transaction records, and payment receipts are retained for the statutory period mandated by Indian accounting, tax, and commercial regulations (typically up to 8 years).
11. Payment Gateway Reconciliation Records
Payment transaction references (PayU, Razorpay, Cashfree, PhonePe) are stored for chargeback resolution, refund reconciliation, and statutory audit integrity.
12. Backup Lifecycles & Disaster Recovery
Encrypted database backups are maintained on AWS Mumbai for business continuity and disaster recovery. When an account is deleted, primary database records are purged immediately; residual backup snapshots naturally expire and are overwritten according to the standard backup rotation cycle.
13. Technical Deletion Workflow
14. Exceptions to Immediate Deletion
Limited information may be retained where strictly required for:
15. Account Recreation & 17. Data Export Before Deletion
Users can export their account activity and profile records before initiating deletion. Creating a new account in the future begins a completely fresh profile and does not restore deleted history.
19. Policy Updates & 20. Interconnected Policies
This policy should be reviewed in conjunction with our Privacy Policy and Account & Authentication Policy.