§ ESearchCy.com

Data Retention and Deletion Notice

ESearchCy — Cyprus Company Records Service

DRAFT TEMPLATE — NOT LEGAL ADVICE. Review by qualified legal counsel required before launch. Retention periods below are indicative placeholders — set them to match your actual legal obligations and business needs.

Effective date: 27 August 2026 · Last updated: 27 August 2026 · Version: 1.0

This notice supplements section 6 of the Privacy Notice.

1. Principles

We keep personal data only as long as needed for the purposes it was collected, to comply with legal obligations (e.g. tax and company law), and to establish, exercise, or defend legal claims. When retention ends, data is securely deleted or irreversibly anonymised.

2. Retention schedule

Category Examples Retention period Reason
Account data profile, settings, credentials Active account + 12 months after closure Service provision; reactivation window
Orders & billing orders, invoices, payment metadata 6 years from end of financial year Cyprus tax/company law obligations
Delivered documents Document bundles available for re-download 30 days after delivery, then deleted from active storage Service provision
Uploaded content files/text you submit Until deletion by you or account closure + 30 days Service provision
Policy acceptances & cookie consents acceptance logs, consent records Account lifetime + 6 years Demonstrating compliance; limitation periods
Privacy request records DSAR correspondence & outcomes 3 years after closure of the request Accountability
Security & server logs IP logs, auth events, error logs 12 months Security, abuse prevention
Support correspondence emails, tickets 24 months after resolution Service quality, claims
Analytics data usage statistics Not applicable — no analytics in use Improvement (consent-based)
Marketing consents & lists subscription status Until withdrawal + suppression record kept 3 years Consent management

3. Deletion on request and on account closure

4. Backups

We do not currently operate a backup or point-in-time-recovery schedule of our own, so a deletion we carry out is not shadowed by a copy of your data in a backup of ours. Deleted data may persist briefly in our hosting provider's internal replication and log systems before being overwritten in the ordinary course. If we introduce our own backups, this section will be updated first with the schedule, the retention period, and how deletions are re-applied to restored data. [[TO CONFIRM: whether a Firestore backup / PITR schedule is to be enabled before launch — see the Security Overview]]

5. Anonymised data

We may retain aggregated or anonymised data (which no longer identifies any person) without time limit, e.g. for statistics.

Contact: info@esearchcy.com