Data Retention and Deletion Policy

Effective date: [To be confirmed]Version: Draft 1.0

This policy describes how long EscrowSign retains different categories of data, why, and what happens to your data when you close your account or request deletion. Your rights under applicable data protection law are described in our Privacy Notice.

1. Retention principles

We retain personal data only for as long as necessary to provide the Platform service and to comply with applicable legal obligations. Retention periods are determined by the legal basis for processing, the category of data, and applicable regulatory and legal requirements in the jurisdictions in which we operate.

Some data cannot be deleted even if you request it, because retention is required by law (e.g., AML/CTF regulations, tax law, financial records requirements). We will tell you when this is the case.

2. Retention periods by category

AML/CTF and identity verification records

Retained for a minimum of 5 years from the date of the transaction or the end of the business relationship, whichever is later, as required by applicable anti-money laundering regulations. [PLACEHOLDER — confirm specific periods per jurisdiction with legal counsel.]

Transaction records

Transaction data, agreed terms, payment records, audit logs, and associated documents are retained for a minimum of 7 years from transaction completion, as required by financial recordkeeping obligations. [PLACEHOLDER — confirm per jurisdiction.]

Account and profile data

Retained for the duration of your account, plus a period after account closure to allow for dispute resolution, fraud prevention, and legal proceedings. Minimum post-closure retention period: [PLACEHOLDER — to be confirmed by legal counsel, likely 5–7 years].

Communications and messages

Messages sent through the Platform are retained as part of the transaction audit trail for the duration applicable to transaction records (above). Messages that are part of a dispute record are retained until the dispute is fully resolved and the applicable retention period has expired.

Sanctions and compliance screening records

Records of sanctions screening, PEP checks, and adverse-media checks are retained as required by applicable AML/CTF regulations. These records may be retained longer where required by a court, regulatory authority, or law enforcement request.

Technical and security logs

IP addresses, session data, device fingerprints, and security logs are retained for fraud prevention and security investigation purposes. Retention period: [PLACEHOLDER — e.g., 12 months for routine logs; longer where related to a security incident or fraud investigation].

Marketing data

Marketing preferences and consent records are retained for the duration of your account, plus a period to demonstrate compliance with consent requirements. Where consent is withdrawn, processing ceases but the record of consent and withdrawal is retained.

3. Account closure and deletion

You may close your account through the account settings page. Account closure does not result in immediate deletion of all data — legally required records are retained for the applicable periods described above.

Where data is no longer required to be retained, it is deleted or anonymised in our routine data lifecycle processes. We do not retain data beyond what is required.

4. Right to erasure

You may submit a data erasure (right to be forgotten) request through the official contact page. We will assess the request against applicable legal retention obligations. We will erase data that is no longer required to be retained, and explain which data cannot be erased and why.

Erasure requests cannot be fulfilled where retention is required by AML/CTF law, financial regulation, tax law, a court order, active fraud investigation, or active legal proceedings.

5. Immutable records

Certain records are stored as immutable audit logs: transaction agreement versions, audit events, and compliance decisions. These records cannot be altered or deleted even by Platform administrators, as they constitute the integrity record of the Platform. This is an intentional design control, not an error.

6. Data portability

You may request a copy of your personal data in a structured, machine-readable format through the official contact page. Where technically feasible, we will provide data within applicable legal timeframes. Transaction records and documents can also be downloaded from the transaction workspace while your account is active.