Touch2Sign Policy Library
← All policies

Data Retention & Disposal

Version 1.0 · Draft · Owner: DPO

Download .md →

Data Retention & Disposal Policy

Touch2Sign Ltd

Version: 1.0

Effective date: 11 July 2026

Owner: [DPO / Privacy Lead]

Approved by: Robert — CEO / Managing Director

Next review: 11 July 2027


1. Purpose

Define how long Touch2Sign retains customer data, audit evidence, and internal records, and how data is securely disposed of when retention periods expire or accounts are deleted. Supports GDPR storage limitation (Art 5(1)(e)), eIDAS evidence requirements, and ISO 27001 A.8.10.

2. Scope

Applies to:

  • Customer documents and signed PDFs (S3)
  • Document metadata, recipients, and audit trails (RDS)
  • Identity verification results
  • Account, billing, and support data
  • Operational logs (CloudWatch, application logs)
  • Internal business records

3. Retention principles

  1. Retain data only as long as necessary for the purpose collected
  2. Honour customer organisation retention settings where configurable
  3. Meet legal and regulatory minimums for electronic signature evidence
  4. Securely delete data when retention expires — not merely deactivate access
  5. Document disposal actions for audit purposes

4. Default retention periods

Data type Default retention Legal / business basis
Signed documents & audit trails 7 years from completion eIDAS / UK electronic signature evidence; customer contract default
Unsigned / draft documents Per org setting; 90 days if abandoned Storage limitation
Organisation account data Life of contract + 90 days after termination Contract; backup purge
IDV verification records 7 years aligned with signature evidence Dispute resolution; regulatory challenge
Billing / invoices (Stripe) 7 years Tax and accounting (Ireland)
Support tickets 3 years after closure Customer service; dispute
Application / CloudWatch logs 90 days operational Security monitoring
Security incident records 3 years minimum ISO 27001; legal hold override
Access review records 3 years Compliance evidence
Employee HR records Per employment law HR policy

5. Organisation retention settings

Touch2Sign provides configurable retention at organisation level where product supports it:

  • Minimum retention cannot fall below 1 year without Legal approval (signature evidence risk)
  • Maximum aligns with 7-year eIDAS default unless customer contract specifies otherwise
  • Changes logged in org audit trail
  • Customer notified of retention policy in DPA and product documentation

6. Account deletion

When a customer requests account deletion or contract terminates:

Step Action Timeline
1 Verify requester authority (org admin or DPA process) Within 5 business days
2 Export available to customer if requested (DSAR portability) Before deletion
3 Disable login and API access Immediate
4 Soft-delete flag in application Day 1
5 Purge S3 objects (documents, signed PDFs) Within 30 days
6 Purge RDS rows (documents, recipients, audit_log per retention) Within 30 days or at retention expiry
7 Remove Cognito users for org Within 30 days
8 Confirm deletion to customer Upon completion
9 Retain billing records per tax retention Up to 7 years — anonymised where possible

Legal hold suspends deletion until hold released by Legal.

7. Secure disposal methods

Medium Disposal method
S3 objects Delete all object versions; verify bucket lifecycle completion
RDS records Hard DELETE or table purge; vacuum where applicable
RDS instance decommission Snapshot deleted after verification; KMS key retirement per crypto policy
Backups Allow backup retention window to expire; no restore after purge confirmation
Secrets Manager Delete secret version; schedule key deletion
Local / laptop copies Secure wipe (NIST 800-88 aligned) — prohibited for production data
Paper Cross-cut shred

Disposal events logged with: date, data category, scope (org ID / record count), executor, verification method.

8. eIDAS and signature evidence

For qualified and advanced electronic signatures:

  • Audit trails retained to demonstrate who signed, when, and what document hash was signed
  • Retention must support potential 7-year regulatory or contractual challenge window
  • Early deletion of signature evidence requires Legal approval and customer written consent

9. Sub-processor deletion

On account deletion or retention expiry, Touch2Sign instructs sub-processors to delete data per DPA:

  • AWS: data deleted from Touch2Sign-controlled buckets and RDS
  • Stripe: retained per Stripe PCI/tax obligations — payment metadata only
  • OneID / eID Easy: deletion per provider DPA and QTSP rules
  • Anthropic: no persistent storage per API terms — confirm per DPIA

10. Data subject requests

Erasure requests (GDPR Art 17) processed per DSAR Procedure. Erasure may be limited where retention is required for legal claims or signature evidence obligations — DPO documents justification.

11. Related documents

  • Data Classification Policy
  • DSAR Procedure
  • Data Processing Agreement
  • Cryptography & Key Management Policy
  • HIPAA Scope Policy (PHI prohibited)

12. Review

Reviewed annually and when product retention features or legal requirements change.


Approval

Name Role Signature Date
Robert CEO Electronic 11 July 2026
DPO / Privacy Lead

Questions: security@touch2sign.com · privacy@touch2sign.com