← Back to Trust Center

Privra

Retention policy

Version 1

## Data Retention and Erasure Policy

**Company Name:** testcmp **Policy Owner:** Shreyas Jain, Data Protection Contact (DPC) **Effective Date:** [Date of Policy Adoption] **Version:** 1.0

---

### 1. Introduction and Purpose

This Data Retention and Erasure Policy ("Policy") outlines testcmp's commitment to responsibly managing personal data collected, stored, and processed in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025.

The purpose of this Policy is to ensure that personal data is: * Retained only for as long as necessary to fulfil the purposes for which it was collected. * Erased or anonymised securely when it is no longer needed or when a Data Principal exercises their right to erasure. * Managed in a manner that respects Data Principal rights and testcmp's legal and contractual obligations.

This Policy is a core component of testcmp's overall data protection framework and aligns with Section 8(7) of the DPDP Act, 2023.

### 2. Scope

This Policy applies to all personal data processed by testcmp, whether in digital or physical format, including data collected from Data Principals during service delivery, payment processing, and website usage. It covers all employees, contractors, and third-party vendors (Processors) who handle personal data on behalf of testcmp.

### 3. Key Principles

testcmp adheres to the following principles regarding data retention and erasure:

* **Purpose Limitation (Section 5):** Personal data is collected for specific, clear, and lawful purposes. It will not be retained for longer than is necessary to fulfil those stated purposes. * **Consent (Section 6(1)):** Where processing is based on consent, personal data will be erased upon withdrawal of consent by the Data Principal, unless there is another legal basis for its continued retention. Consent requests are available in English or any language in the Eighth Schedule to the Constitution (Section 6(3)). * **Necessity (Section 8(7)):** Data will not be retained for longer than is necessary for the purposes for which it was collected, or for compliance with legal obligations. * **Legal & Contractual Obligations (Section 8(7)):** Notwithstanding the above, personal data may be retained for longer periods where required by applicable laws (e.g., tax laws, consumer protection laws), contractual obligations, or for the establishment, exercise, or defence of legal claims. * **Security (Section 8(5)):** All personal data, throughout its lifecycle from collection to erasure, is protected by reasonable security safeguards to prevent personal data breaches. Erasure methods are designed to render data irrecoverable. * **Transparency (Section 8(9)):** Contact details for grievance redressal and data queries are published and accessible to Data Principals.

### 4. Data Retention Periods and Erasure Triggers

Personal data held by testcmp will be retained for specific periods based on its category, processing purpose, and the legal or business requirements. Data will be erased or anonymised when:

* The purpose for which the data was collected is no longer served. * The Data Principal withdraws their consent, and no other legal basis for retention exists. * A legal or contractual obligation for retention expires. * A valid request for erasure is received from a Data Principal, and no overriding legal obligation for retention applies.

#### 4.1 Data Category Schedule

The following table outlines typical data categories, their retention periods, the basis for retention, and general erasure methods. This is a general guide and specific retention periods may vary based on evolving legal requirements or specific contractual terms.

| Data Category | Processing Purpose | Retention Period | Basis for Retention | Erasure Method | Backup/Lag for Erasure | | :------------ | :----------------- | :--------------- | :------------------ | :------------- | :--------------------- | | **User Account Data** (Name, Email, Phone, Address, User ID) | Service Delivery | Account closure + 90 days | Contractual obligation (service terms), Legitimate interest (dispute resolution, account reactivation grace period) | Secure deletion from active systems | Up to 90 days in backups | | **Service Usage Data** (Log files, feature usage, activity logs) | Service Delivery | 1-3 years from collection | Legitimate interest (service improvement, troubleshooting, security monitoring) | Anonymisation or secure deletion | Up to 90 days in backups | | **Payment Transaction Records** (Transaction ID, Amount, Date, Payment Status) | Payment Processing | 7 years from transaction date | Legal requirement (e.g., applicable tax laws, financial regulations), Contractual obligation | Secure deletion from active systems | Up to 90 days in backups | | **Website Usage Data** (IP address, device info, pages visited, session duration - via Google Analytics) | Service Delivery (Analytics) | 26 months (Google Analytics default) | Consent (for non-essential cookies), Legitimate interest (website improvement, aggregated analytics) | Anonymisation, Pseudonymisation, or secure deletion by Processor (Google Analytics) | As per Google Analytics policy (typically within 30 days post-retention period) | | **Communication Records** (Support tickets, email correspondence) | Service Delivery | Account closure + 1 year | Legitimate interest (customer support history, dispute resolution) | Secure deletion from active systems | Up to 90 days in backups |

*Note:* Actual payment card details (e.g., full credit card numbers) are typically processed by third-party payment gateways and are not retained by testcmp. Only transaction records and tokens are stored.

### 5. Roles and Responsibilities

* **Data Protection Contact (DPC) - Shreyas Jain:** * Overall owner of this Policy and responsible for its implementation and compliance. * Oversees the establishment and maintenance of data retention schedules. * Acts as the primary point of contact for Data Principal requests regarding erasure. * Ensures regular review and updates of this Policy. * **IT and Operations Team:** * Responsible for implementing and maintaining technical controls for data retention and secure erasure. * Executes automated and manual data deletion processes according to defined schedules. * Ensures that backups are managed in line with retention policies and that data is securely erased from backups within the specified lag period. * **Business Units / Data Owners:** * Responsible for identifying the specific purposes for which personal data is collected and the associated retention needs within their respective areas. * Collaborate with the DPC to define and update data retention schedules for their data categories. * **Third-Party Processors (e.g., Google Analytics):** * Responsible for processing personal data strictly in accordance with testcmp's instructions and contractual agreements. * Must adhere to testcmp's retention and erasure instructions and provide assurances of secure data handling and deletion.

### 6. Erasure Process

#### 6.1 Automated Erasure

Where feasible, testcmp implements automated systems to identify and securely erase personal data that has reached the end of its defined retention period. These systems are regularly monitored and audited to ensure effectiveness.

#### 6.2 Manual Erasure

For data categories not covered by automated processes, or in response to specific Data Principal requests, manual erasure procedures are followed. These procedures ensure: * Identification of all relevant data across active systems and backups. * Secure deletion methods are applied. * Confirmation of erasure where technically feasible.

#### 6.3 Data Principal Requests (Sections 11-14)

Data Principals have the right to request the correction, completion, updating, or erasure of their personal data (Right to Erasure, Section 13). * **Request Submission:** Data Principals can submit erasure requests via the contact details published by testcmp (Section 8(9)) or through designated channels. * **Verification:** testcmp will verify the identity of the Data Principal making the request. * **Processing:** Requests will be processed within the timelines specified in the DPDP Rules, 2025. * **Exceptions:** Erasure requests may be denied if testcmp has a legal obligation to retain the data, if the data is necessary for the establishment, exercise, or defence of legal claims, or for other legitimate reasons permitted by the DPDP Act. The Data Principal will be informed of the reason for denial. * **Notification to Processors:** Where personal data has been shared with third-party Processors (e.g., Google Analytics), testcmp will communicate the erasure request to them to ensure deletion across all relevant systems.

#### 6.4 Erasure Methods

testcmp employs methods designed to render personal data irrecoverable, including: * **Overwriting:** Replacing data with random characters. * **Degaussing:** Eliminating magnetic fields from storage media. * **Physical Destruction:** Shredding or pulverising physical documents and storage media. * **Anonymisation/Pseudonymisation:** Transforming data so it can no longer be attributed to a specific Data Principal without the use of additional information, or cannot be identified at all.

### 7. Security of Data During Retention and Erasure (Section 8(5))

Throughout its retention period, personal data is protected by reasonable security safeguards, including technical and organisational measures, to prevent personal data breaches. This includes access controls, encryption, and regular security assessments. When data is erased, these same security principles apply to ensure the deletion process itself does not compromise data integrity or confidentiality.

### 8. Policy Review

This Policy will be reviewed at least annually, or more frequently if there are significant changes to testcmp's data processing activities, legal requirements, or industry best practices.

### 9. Disclaimer

This document is intended for informational purposes only and serves as an internal operational policy for testcmp. It does not constitute legal advice, nor does it imply any government certification or endorsement. For specific legal guidance regarding the Digital Personal Data Protection Act, 2023, and its Rules, please consult with qualified legal counsel.