§8 · DATA RETENTION · POLICY

Retain only what's required. Delete the rest.

Retention windows are configurable per tenant within regulatory floors and ceilings. Default windows are listed below. Tenants can request shorter windows in writing.

§01 · DEFAULT RETENTION WINDOWS

What we keep. For how long.

Data typeDefault retentionConfigurable rangeReason
Camera frames (raw)Never persisted0 (always)Privacy-by-design
Embedding (encrypted)Until /delete called0–7 yearsUser authentication continuity
Verify audit log7 years1–10 yearsRegulatory (BSA, AML)
JWT (server-side)Not persisted server-side0 (always)Token is client-held
Server logs (request metadata)90 days30–365 daysOperational debugging
Aggregate metrics2 years6 months–5 yearsCapacity planning
§02 · DELETION

Two paths. Both verifiable.

  • User-initiatedDELETE /v1/delete zeros the embedding within 24 hours and returns a signed deletion proof.
  • Tenant-initiated bulk — submit a deletion list via the dashboard. Bulk deletions complete within 7 days. Per-user proofs returned for audit.
§03 · LEGAL HOLDS

One exception. Documented.

Lorica may retain data beyond the windows above if legally required (subpoena, court order, regulatory investigation). In that case the affected tenant is notified within 5 business days unless prohibited by law. Held data is segregated and access-logged.

§04 · END OF SERVICE

If a tenant leaves. 30-day window.

On contract termination, all tenant embeddings and audit logs are deleted within 30 days. Aggregate metrics (no PII) may be retained for capacity planning. A final deletion certificate is issued.