Back to Help Centre

Data Retention Policy

Last Updated: 30 June 2025
4 min read

Secure Data Management

This policy outlines how long we retain your data, why we keep it, and how we securely dispose of it when no longer needed.

1. Overview

At iDecide, we are committed to responsible data management and privacy protection. This Data Retention Policy outlines how long we retain your personal data, the reasons for retention, and our secure disposal procedures.

This policy applies to all personal data collected and processed by iDecide through our platform, services, and interactions with users. We retain data only as long as necessary to provide our services, comply with legal obligations, and protect our legitimate business interests.

Our retention practices are designed to balance user privacy with business needs, ensuring we maintain data security while respecting your rights to data deletion and portability.

2. Retention Principles

Our data retention practices are guided by the following principles:

Data Minimization

We collect and retain only the data necessary for our legitimate business purposes and service provision.

Purpose Limitation

Data is retained only for the specific purposes for which it was collected and processed.

Legal Compliance

Retention periods comply with applicable legal and regulatory requirements.

Secure Disposal

Data is securely and permanently deleted when retention periods expire.

3. Data Categories

We classify data into different categories based on sensitivity and purpose:

Highly Sensitive Data

Requires the highest level of protection and specific retention periods:

  • Legal documents and wills
  • Medical records and health information
  • Financial account details and investment records
  • Government identification documents
  • Insurance policies and claims

Personal Information

Standard personal data requiring careful handling:

  • Contact information (name, email, phone, address)
  • Emergency contact details
  • Family member information
  • Digital asset inventories
  • Uploaded personal documents

Account & Technical Data

Platform usage and technical information:

  • Account credentials and authentication data
  • Platform usage logs and analytics
  • Support communications and tickets
  • Payment and billing information
  • Device and browser information

4. Retention Periods

Specific retention periods apply to different types of data:

Data TypeRetention PeriodReason
Account InformationActive account + 7 yearsService provision, legal compliance
Legal DocumentsAs specified by user or indefinitelyLegacy planning, user preference
Financial Records7 years after last updateTax compliance, audit requirements
Medical InformationAs required by healthcare lawsHealthcare compliance
Usage Analytics2 yearsService improvement, fraud prevention
Support Communications3 yearsQuality assurance, dispute resolution
Payment Information7 yearsFinancial record keeping, tax compliance
Marketing DataUntil consent withdrawnMarketing communications (with consent)

6. Data Disposal

When data reaches the end of its retention period, we follow secure disposal procedures to ensure complete and irreversible deletion:

Secure Deletion Process

  1. Review and Verification: Confirm data is eligible for deletion based on retention schedule
  2. Legal Hold Check: Verify no legal holds or ongoing investigations require preservation
  3. User Notification: Notify users before deletion of important documents (where applicable)
  4. Secure Deletion: Use cryptographic erasure and multiple-pass overwriting
  5. Backup Removal: Remove data from all backup systems and archives
  6. Verification: Confirm complete removal and document the process

Technical Deletion Methods

  • Cryptographic key destruction for encrypted data
  • Multiple-pass secure overwriting (DoD 5220.22-M standard)
  • Physical destruction of storage media when decommissioned
  • Database record purging with confirmation

Disposal Documentation

  • Maintain logs of all disposal activities
  • Document disposal methods and verification procedures
  • Record responsible personnel and dates
  • Retain disposal records for audit purposes

7. User Rights

You have several rights regarding the retention and deletion of your personal data:

Right to Deletion

You can request deletion of your personal data, subject to legal and contractual obligations. We will honor deletion requests unless we have a legitimate reason to retain the data.

Data Portability

You can request a copy of your data in a portable format before deletion or when switching services.

Retention Information

You can request information about how long specific types of your data will be retained and the reasons for retention.

Objection to Processing

You can object to certain types of data processing, which may affect retention periods and our ability to provide certain services.

Important: Some data may need to be retained despite deletion requests due to legal obligations, ongoing legal proceedings, or legitimate business interests. We will inform you if this applies to your request.

8. Exceptions

In certain circumstances, we may need to retain data beyond normal retention periods:

Legal Holds

Data subject to litigation, investigations, or regulatory requests will be preserved until the matter is resolved.

Security Incidents

Data related to security incidents or fraud investigations may be retained longer for protective purposes.

User-Requested Preservation

Important documents designated by users for long-term preservation (such as wills or legal documents) may be retained indefinitely.

Backup Systems

Data in backup systems may persist beyond primary deletion until the next backup cycle completion.

9. Monitoring & Review

We regularly monitor and review our data retention practices to ensure compliance and effectiveness:

Regular Reviews

  • Annual review of retention policies and procedures
  • Quarterly assessment of disposal activities
  • Monthly monitoring of automated retention processes
  • Ongoing compliance monitoring

Policy Updates

  • Updates based on legal and regulatory changes
  • Improvements based on operational experience
  • User feedback integration
  • Industry best practice adoption

Compliance Audits

  • Internal audits of retention practices
  • External compliance assessments
  • Documentation and record keeping reviews
  • Process improvement recommendations

10. Contact Information

If you have questions about our data retention practices or wish to exercise your rights regarding data retention:

Data Protection Team: compliance@idecide.co

Business Hours: Monday-Friday, 9:00 AM - 5:00 PM AEST

Response Time: We will respond to requests within 30 days

For urgent data retention matters or if you believe your data is being retained inappropriately, please mark your inquiry as "URGENT - Data Retention" in the subject line.

iDecide Data Retention Policy - Version 1.0
Last Updated: 30 June 2025
Effective Date: 30 June 2025