Skip to document
English
Back to RedPatron

RedPatron legal

Data Retention Schedule

The published retention periods and disposal triggers for RedPatron records.

Effective date: 4 August 2026
Document version: 1.0

The period below runs from the event stated. A shorter period applies where the purpose ends and no law, dispute, provider rule or legal hold requires retention. A longer period is used only for a documented legal obligation or active claim. Backups expire through the stated cycle and are not restored for ordinary use.

Record Default period Trigger / disposal
Unverified registration attempt 30 days Delete or irreversibly de-identify after abandonment
Basic account and contract acceptance Account life + 3 years Delete/de-identify after limitation and dispute period
Security/session logs 12 months Rolling deletion; extend only for a documented incident
Raw identity document held by RedPatron 30 days after successful review Delete; retain verification result/reference instead
Biometric template held by RedPatron Not retained Verification provider must follow its disclosed schedule
Creator/performer verification result Relationship/content life + 5 years Restricted deletion after recordkeeping, claim and safety period
Performer release and asset linkage Content availability + 5 years Restricted deletion unless 2257 or other law requires longer
Rejected/quarantined ordinary upload 30 days Secure deletion after appeal window
Confirmed or suspected CSAM/trafficking evidence Legal reporting/preservation period Never placed in ordinary backups; access restricted; delete only on authorised legal instruction
Published content Until deletion/termination + 90 days Paid-access wind-down, then deletion; legal holds override
Deleted content backups Maximum 90 days Expire automatically and remain unavailable to users
Messages Account life; user-deleted copy up to 90 days Legal/safety cases retain only relevant evidence
Reports, moderation and appeals Closure + 5 years De-identify/delete unless active claim or legal duty
Transaction, refund, chargeback and payout ledger 10 years Accounting/tax deletion review after period
DAC7 due-diligence/reporting records 5 years, extended only to the national lawful maximum Measured from end of reportable period/relationship as applicable
DSA trader traceability records, where applicable 6 months after relationship ends Secure deletion after statutory period
Cookie consent record 5 years Renew when purpose/vendor/version changes
Support tickets Closure + 3 years Delete attachments sooner where no longer necessary
Authority request log Closure + 5 years Restricted legal archive

Privacy must review the schedule annually and after a legal, provider or architecture change. Every production datastore requires an owner, deletion job, exception code, legal-hold flag and deletion evidence. Romanian accounting/tax counsel must confirm whether a shorter mandatory period permits reduction before launch; the conservative 10-year ledger period must not be silently extended.