# Data Retention & Disposal Policy

**Touch2Sign Ltd**  
**Version:** 1.0  
**Effective date:** 11 July 2026  
**Owner:** [DPO / Privacy Lead]  
**Approved by:** Robert — CEO / Managing Director  
**Next review:** 11 July 2027

---

## 1. Purpose

Define how long Touch2Sign retains customer data, audit evidence, and internal records, and how data is securely disposed of when retention periods expire or accounts are deleted. Supports GDPR storage limitation (Art 5(1)(e)), eIDAS evidence requirements, and ISO 27001 A.8.10.

## 2. Scope

Applies to:

- Customer documents and signed PDFs (S3)  
- Document metadata, recipients, and audit trails (RDS)  
- Identity verification results  
- Account, billing, and support data  
- Operational logs (CloudWatch, application logs)  
- Internal business records  

## 3. Retention principles

1. Retain data only as long as necessary for the purpose collected  
2. Honour customer organisation retention settings where configurable  
3. Meet legal and regulatory minimums for electronic signature evidence  
4. Securely delete data when retention expires — not merely deactivate access  
5. Document disposal actions for audit purposes  

## 4. Default retention periods

| Data type | Default retention | Legal / business basis |
|-----------|-------------------|------------------------|
| **Signed documents & audit trails** | **7 years** from completion | eIDAS / UK electronic signature evidence; customer contract default |
| **Unsigned / draft documents** | Per org setting; **90 days** if abandoned | Storage limitation |
| **Organisation account data** | Life of contract + **90 days** after termination | Contract; backup purge |
| **IDV verification records** | **7 years** aligned with signature evidence | Dispute resolution; regulatory challenge |
| **Billing / invoices (Stripe)** | **7 years** | Tax and accounting (Ireland) |
| **Support tickets** | **3 years** after closure | Customer service; dispute |
| **Application / CloudWatch logs** | **90 days** operational | Security monitoring |
| **Security incident records** | **3 years** minimum | ISO 27001; legal hold override |
| **Access review records** | **3 years** | Compliance evidence |
| **Employee HR records** | Per employment law | HR policy |

## 5. Organisation retention settings

Touch2Sign provides configurable retention at organisation level where product supports it:

- Minimum retention cannot fall below **1 year** without Legal approval (signature evidence risk)  
- Maximum aligns with **7-year eIDAS default** unless customer contract specifies otherwise  
- Changes logged in org audit trail  
- Customer notified of retention policy in DPA and product documentation  

## 6. Account deletion

When a customer requests account deletion or contract terminates:

| Step | Action | Timeline |
|------|--------|----------|
| 1 | Verify requester authority (org admin or DPA process) | Within 5 business days |
| 2 | Export available to customer if requested (DSAR portability) | Before deletion |
| 3 | Disable login and API access | Immediate |
| 4 | Soft-delete flag in application | Day 1 |
| 5 | Purge S3 objects (documents, signed PDFs) | Within **30 days** |
| 6 | Purge RDS rows (documents, recipients, audit_log per retention) | Within **30 days** or at retention expiry |
| 7 | Remove Cognito users for org | Within **30 days** |
| 8 | Confirm deletion to customer | Upon completion |
| 9 | Retain billing records per tax retention | Up to 7 years — anonymised where possible |

Legal hold suspends deletion until hold released by Legal.

## 7. Secure disposal methods

| Medium | Disposal method |
|--------|-----------------|
| **S3 objects** | Delete all object versions; verify bucket lifecycle completion |
| **RDS records** | Hard DELETE or table purge; vacuum where applicable |
| **RDS instance decommission** | Snapshot deleted after verification; KMS key retirement per crypto policy |
| **Backups** | Allow backup retention window to expire; no restore after purge confirmation |
| **Secrets Manager** | Delete secret version; schedule key deletion |
| **Local / laptop copies** | Secure wipe (NIST 800-88 aligned) — prohibited for production data |
| **Paper** | Cross-cut shred |

Disposal events logged with: date, data category, scope (org ID / record count), executor, verification method.

## 8. eIDAS and signature evidence

For qualified and advanced electronic signatures:

- Audit trails retained to demonstrate who signed, when, and what document hash was signed  
- Retention must support potential **7-year** regulatory or contractual challenge window  
- Early deletion of signature evidence requires Legal approval and customer written consent  

## 9. Sub-processor deletion

On account deletion or retention expiry, Touch2Sign instructs sub-processors to delete data per DPA:

- AWS: data deleted from Touch2Sign-controlled buckets and RDS  
- Stripe: retained per Stripe PCI/tax obligations — payment metadata only  
- OneID / eID Easy: deletion per provider DPA and QTSP rules  
- Anthropic: no persistent storage per API terms — confirm per DPIA  

## 10. Data subject requests

Erasure requests (GDPR Art 17) processed per **DSAR Procedure**. Erasure may be limited where retention is required for legal claims or signature evidence obligations — DPO documents justification.

## 11. Related documents

- Data Classification Policy  
- DSAR Procedure  
- Data Processing Agreement  
- Cryptography & Key Management Policy  
- HIPAA Scope Policy (PHI prohibited)  

## 12. Review

Reviewed **annually** and when product retention features or legal requirements change.

---

**Approval**

| Name | Role | Signature | Date |
|------|------|-----------|------|
| Robert | CEO | Electronic | 11 July 2026 |
| | DPO / Privacy Lead | | |
