RedPatron legal
Data Retention Schedule
The published retention periods and disposal triggers for RedPatron records.
Effective date: 4 August 2026
Document version: 1.0
The period below runs from the event stated. A shorter period applies where the purpose ends and no law, dispute, provider rule or legal hold requires retention. A longer period is used only for a documented legal obligation or active claim. Backups expire through the stated cycle and are not restored for ordinary use.
| Record | Default period | Trigger / disposal |
|---|---|---|
| Unverified registration attempt | 30 days | Delete or irreversibly de-identify after abandonment |
| Basic account and contract acceptance | Account life + 3 years | Delete/de-identify after limitation and dispute period |
| Security/session logs | 12 months | Rolling deletion; extend only for a documented incident |
| Raw identity document held by RedPatron | 30 days after successful review | Delete; retain verification result/reference instead |
| Biometric template held by RedPatron | Not retained | Verification provider must follow its disclosed schedule |
| Creator/performer verification result | Relationship/content life + 5 years | Restricted deletion after recordkeeping, claim and safety period |
| Performer release and asset linkage | Content availability + 5 years | Restricted deletion unless 2257 or other law requires longer |
| Rejected/quarantined ordinary upload | 30 days | Secure deletion after appeal window |
| Confirmed or suspected CSAM/trafficking evidence | Legal reporting/preservation period | Never placed in ordinary backups; access restricted; delete only on authorised legal instruction |
| Published content | Until deletion/termination + 90 days | Paid-access wind-down, then deletion; legal holds override |
| Deleted content backups | Maximum 90 days | Expire automatically and remain unavailable to users |
| Messages | Account life; user-deleted copy up to 90 days | Legal/safety cases retain only relevant evidence |
| Reports, moderation and appeals | Closure + 5 years | De-identify/delete unless active claim or legal duty |
| Transaction, refund, chargeback and payout ledger | 10 years | Accounting/tax deletion review after period |
| DAC7 due-diligence/reporting records | 5 years, extended only to the national lawful maximum | Measured from end of reportable period/relationship as applicable |
| DSA trader traceability records, where applicable | 6 months after relationship ends | Secure deletion after statutory period |
| Cookie consent record | 5 years | Renew when purpose/vendor/version changes |
| Support tickets | Closure + 3 years | Delete attachments sooner where no longer necessary |
| Authority request log | Closure + 5 years | Restricted legal archive |
Privacy must review the schedule annually and after a legal, provider or architecture change. Every production datastore requires an owner, deletion job, exception code, legal-hold flag and deletion evidence. Romanian accounting/tax counsel must confirm whether a shorter mandatory period permits reduction before launch; the conservative 10-year ledger period must not be silently extended.