DATA PROCESSING + RETENTION / VERSION 2026-07-22-US-NC-B2B-v1
Payloads disappear. Necessary records expire.
01 / SCHEDULE
Configurable minimum periods.
| CATEGORY | DEFAULT SYSTEM BOUNDARY | REASON |
|---|---|---|
| Email-code challenge | Code expires after 10 minutes, single use; row deleted no later than 1 hour after issue | Authentication and abuse control |
| Portal session | 15-minute inactivity expiry; hard maximum 24 hours; revoked/expired rows removed promptly | Authenticated access |
| API input/full output/rejected body | Zero persistent retention | Active synchronous request only |
| Free-tool input/draft/package | Zero server receipt or retention | Local browser execution |
| Quota reservation | Active timeout up to 90 seconds; reservation metadata deleted within 7 days | Atomic billing and retry safety |
| Usage metadata | Maximum 90 days (metadata only: codes, units, timestamps; no payloads or outputs) | Quota, billing, cost, abuse, reconciliation |
| Security/admin audit metadata | Maximum 30 days | Detection, response, accountability |
| Approved manual summary/Rapid intake | Maximum 180 days, or earlier on completed engagement or verified deletion request | Customer-requested manual service |
| Legal acceptance | Maximum 7 years from acceptance, unless a longer period is legally required | Consent and contract evidence |
| Stripe/billing/tax references | Maximum 7 years from transaction, unless a longer period is legally required | Accounting, tax, refund, dispute |
| Revoked-key hash/audit metadata | Maximum 90 days after revocation or expiry | Prevent reuse and investigate abuse |
02 / EXCEPTIONS
Only documented holds delay deletion.
Exceptions are limited to required financial records, an active dispute, fraud investigation, security incident, legal hold, or applicable legal requirement. Each exception records a code and bounded review time; it does not restore API payloads or outputs that were never retained.
Deletion reverifies the email, revokes keys and sessions, requires cancellation or identification of active billing, pseudonymizes non-required operational records, removes encrypted email when no exception requires it, and preserves only approved billing, consent, dispute, fraud, incident, or legal-hold evidence. Cleanup is scheduled and production configuration fails closed if the retention schedule is invalid.
Retention controls
Verahelm configures bounded schedules for operational records and preserves only records required for an active financial obligation, dispute, fraud or security investigation, legal hold, or applicable law. Schedules are reviewed when legal, accounting, or service requirements change.