LEGAL · RETENTION
How long we keep your data
The retention period, legal basis, and deletion method for every category of data we hold.
Draft, pending legal review. This document is published for transparency and is being finalised with counsel. For a binding agreement, contact support@cyphertree.com.
Purpose and scope
This schedule sets out how long Cyphertree Technologies keeps each category of personal data, why we keep it, and how we dispose of it once the retention period ends. We keep personal data only as long as we need it for the purpose it was collected, plus any period required by Indian tax, labour, and company law or by dispute-limitation rules.
This document is classified internal (Document ID CT-GDPR-003). It supports the storage-limitation principle under GDPR Art. 5(1)(e) and India's Digital Personal Data Protection Act 2023 (DPDP). It is reviewed every 12 months.
Master retention schedule
Each row lists a data category, the retention period, the point the clock starts from, the legal basis, and the deletion method we apply.
| # | Data category | Retention period | Starts from | Legal basis | Deletion method |
|---|---|---|---|---|---|
| 1 | Employee identity (name, DOB, gender, contact) | Duration + 3 years | Termination date | Indian Limitation Act | Anonymise |
| 2 | Identity documents (PAN, Aadhaar, passport) | Duration + 8 years | Termination date | Indian IT Act (tax audit) | Hard delete (encrypted) |
| 3 | Payroll records (salary slips, payment history) | 8 years post-employment | Last employment date | Indian IT Act / Payment of Wages Act | Anonymise |
| 4 | TDS records (Form 16, tax computation) | 8 years post-assessment year | End of assessment year | Income Tax Act Sec. 149 | Anonymise |
| 5 | Bank details (account, IFSC) | Duration + 8 years | Termination date | IT Act (linked to payroll) | Hard delete (encrypted) |
| 6 | EPF records (UAN, contributions) | 5 years post-employment | Termination date | EPF & MP Act, 1952 | Anonymise |
| 7 | ESI records | 5 years post-employment | Termination date | ESI Act, 1948 | Anonymise |
| 8 | Employment contracts | Duration + 3 years | Termination date | Indian Limitation Act | Archive then delete |
| 9 | Electronic signatures (signed docs + timestamps) | 7–10 years | Date of signing | Indian IT Act, 2000 / eIDAS | Archive then delete |
| 10 | Performance reviews | Duration + 3 years | Termination date | Dispute limitation | Anonymise |
| 11 | Leave & attendance | Duration + 3 years | Termination date | Shops & Establishments Act | Delete |
| 12 | Health insurance records | Duration + 2 years | Termination/policy end | Insurance regulations | Delete |
| 13 | Nominee/emergency contacts | Duration + 3 years | Termination date | Linked to PF/insurance | Delete |
| 14 | Disciplinary records | Duration + 3 years | Termination date | Dispute limitation | Delete |
| 15 | Offboarding (FnF, exit) | 8 years post-termination | Termination date | Indian IT Act (FnF is taxable) | Anonymise |
| 16 | Applicant data (hired) | Merged into employee record | Hire date | Contract | N/A — becomes employee data |
| 17 | Applicant data (rejected) | 24 months from rejection | Rejection date | GDPR proportionality | Hard delete |
| 18 | Applicant data (talent pool) | 24 months, renewable with consent | Consent date | Consent (Art. 6(1)(a)) | Hard delete if consent not renewed |
| 19 | Applicant ID docs (not hired) | 30 days from rejection | Rejection date | Data minimisation | Hard delete |
| 20 | AI assessment scores | 24 months from assessment | Assessment date | GDPR proportionality | Anonymise (keep aggregate stats) |
| 21 | Client company data | Duration of contract + 3 years | Contract end | Indian Limitation Act | Anonymise |
| 22 | Client billing/invoices | 8 years | Invoice date | Indian IT Act / Companies Act | Archive |
| 23 | User account data | Duration + 30 days after deletion request | Deletion request | Contract / GDPR Art. 17 | Hard delete |
| 24 | Google OAuth tokens | Duration of active account | Account deletion | Functional necessity | Revoke + delete |
| 25 | Google Calendar data | N/A — real-time API access | N/A | N/A | N/A — not stored |
| 26 | Audit logs | 5 years | Log entry date | Regulatory compliance | Delete |
| 27 | Cookie consent records | Duration of consent + 1 year | Consent withdrawal | GDPR accountability | Delete |
| 28 | Marketing consent | Duration of consent + 1 year | Unsubscribe date | GDPR accountability | Delete |
| 29 | Platform session data | 24 hours | Session creation | Functional | Auto-expire |
| 30 | Experience letters | Indefinite (available on request) | Issue date | Standard practice | Available permanently |
Statutory minimums
Several periods above are set by statute, not by choice. We cannot delete this data earlier without breaching the law:
- Income Tax Act Sec. 149 — TDS records (Form 16, tax computation) are kept 8 years past the end of the assessment year.
- Indian IT Act (tax audit) — identity documents, bank details, payroll, and final-settlement records tied to taxable income are kept up to 8 years.
- Payment of Wages Act — payroll records are kept 8 years post-employment.
- EPF & MP Act, 1952 — EPF records (UAN, contributions) are kept 5 years post-employment.
- ESI Act, 1948 — ESI records are kept 5 years post-employment.
- Companies Act — client billing and invoices are kept 8 years.
- Indian Limitation Act — employee identity, contracts, and client company data are kept for the contract duration plus 3 years to cover the dispute-limitation window.
- Indian IT Act, 2000 / eIDAS — electronic signatures and their timestamps are kept 7–10 years.
- Shops & Establishments Act — leave and attendance records are kept for the duration plus 3 years.
Where no statute applies, we default to the GDPR proportionality and data-minimisation principles — for example, rejected-applicant data is deleted after 24 months and their ID documents after 30 days.
Deletion process
When a retention period ends, we apply one of five deletion methods depending on the data category:
| Method | Description | When we use it |
|---|---|---|
| Hard delete | Permanently remove from the database | Sensitive identity docs, rejected candidate data, expired tokens |
| Anonymise | Replace personal data with irreversible anonymous values | Payroll records, employee records (structure preserved for reporting) |
| Archive | Move to cold storage, then delete after the archive period | Contracts, invoices, signatures |
| Auto-expire | Automatic TTL-based deletion | Sessions, temporary tokens |
| Revoke + delete | Revoke external access, then delete the local record | OAuth tokens, API keys |
Anonymisation is irreversible: identifying fields (name, email, phone, PAN, Aadhaar, bank account, IFSC, address, date of birth) are overwritten with redacted placeholders, and the record is flagged as anonymised with a timestamp. The structure is kept so aggregate reporting still works, but the individual can no longer be identified.
Deletion is intended to run automatically. A set of daily jobs is planned to delete rejected candidates past 24 months, remove candidate ID documents 30 days after rejection, anonymise terminated employees once their retention period ends, delete audit logs older than 5 years, clean up expired sessions, remove expired cookie and marketing consent records, and revoke stale OAuth tokens for deleted accounts. Until this automation is fully live, we run manual quarterly reviews to enforce these periods, in line with GDPR Art. 5(1)(e).
Backups and non-stored data
Some data is never stored, so no retention period applies. Google Calendar data is accessed in real time through the API and is not held on our systems. Platform sessions live for 24 hours and expire automatically.
This schedule does not set out separate backup-retention periods; those are governed by our internal backup and infrastructure procedures. Anonymisation and hard deletion apply to the live production data described above.
Related documents
This schedule sits alongside our Privacy policy, our Employee privacy notice, and our Applicant privacy notice, and is backed by our internal Record of Processing Activities (ROPA). Where a specific period is set by an internal record rather than by this schedule, that record governs.
Contact
For questions about how long we keep your data or to request deletion, email support@cyphertree.com.