Data retention policy
Last updated:
Issuing entities: REtelligent Pty Ltd (ABN 87 694 108 613; ACN 694 108 613) and REtelligent EU S.R.L. (CUI 54685957) Applies to: the REtelligent Sync application (https://app.retelligent.co) and supporting systems Read with: the Privacy Policy, Cookie Policy, Privacy Collection Notice, the applicable Data Processing Agreement, and the Incident Response Plan
1. Purpose
This Data Retention Policy (“Policy”) establishes how REtelligent Pty Ltd (ABN 87 694 108 613; ACN 694 108 613) and REtelligent EU S.R.L. (CUI 54685957) (collectively, “REtelligent”, “we”, “us”, or “our”) retains, archives and disposes of personal data and business records. It implements the storage-limitation principle (GDPR Article 5(1)(e)), the Australian Privacy Principle 11.2 requirement to destroy or de-identify personal information once it is no longer needed, and the tax, employment and evidentiary retention obligations applicable to both group entities.
It sits alongside, and is cross-referenced by, the Privacy Policy, Cookie Policy, Privacy Collection Notice, the applicable Data Processing Agreement, and the Incident Response Plan.
2. Scope
This Policy applies to all personal data processed by REtelligent as controller or processor in either jurisdiction (whether held in production systems, analytics, backups or archives); all business records generated in operating the platform (including contracts, invoices, audit trails and AI decision artefacts); and all employees, contractors and sub-processors with access to REtelligent data. It does not extend to data held by a property operator as an independent controller; where REtelligent processes such data on the operator’s behalf, retention is governed by the operator’s instructions and the applicable DPA, with this Policy as the minimum floor.
3. Controllers and Applicable Law
Australian entity | EU entity | |
Legal name | REtelligent Pty Ltd | REtelligent EU S.R.L. |
Registration | ABN 87 694 108 613 / ACN 694 108 613 | CUI 54685957 |
Registered address | Unit 2, 8A Judith Street, Carnegie VIC 3163, Australia | Bucureşti Sectorul 1, Bulevardul G-ral Gheorghe Magheru, Nr. 31, Biroul 2, Etaj 5 |
Primary legal anchor | Privacy Act 1988 (Cth) APP 11.2; Income Tax Assessment Act 1936 s.262A; Fair Work Act 2009 Reg 3.44; Corporations Act 2001 s.286-288 | GDPR Articles 5(1)(e), 17, 30; Romanian Law 190/2018; Romanian Accounting Law 82/1991; Romanian Fiscal Code (Law 227/2015) art.25 |
Regulator | Office of the Australian Information Commissioner (OAIC) | ANSPDCP (Romania) |
Retention contact | privacy@retelligent.co | privacy@retelligent.co |
4. Guiding Principles
Storage limitation (GDPR Article 5(1)(e); APP 11.2): personal data is kept only as long as necessary for the purpose collected, or for legal, regulatory or evidentiary obligations. Data minimisation (GDPR Article 5(1)(c); APP 3): the narrowest necessary category is retained. Purpose limitation (GDPR Article 5(1)(b); APP 6): retained data is not re-purposed without separate authorisation. Integrity and confidentiality (GDPR Article 5(1)(f); APP 11.1): retention media apply encryption at rest, least-privilege access and tamper-evident logging. Accountability (GDPR Article 5(2)): retention decisions, deletions and holds are logged. Harmonised floor-and-ceiling: where AU and EU rules diverge, REtelligent applies the stricter floor and the lower ceiling per category so neither regime is breached.
5. Definitions
Retention Period — the total time data or a record is kept from the start of the retention clock to authorised disposition.
Retention Clock Trigger — the event that starts the period (for example work-order closure, contract termination, last login).
Disposition — the authorised action at end of retention: destruction, cryptographic shredding, de-identification, or archival transfer.
Legal Hold — a suspension of scheduled disposition where litigation, regulatory inquiry or investigation makes preservation obligatory (Section 10).
De-identification — processing under which data no longer relates to an identifiable individual (OAIC De-identification Decision-Making Framework; EDPB Guidelines 04/2024).
Cryptographic Shredding — destruction of encryption keys so that ciphertext is unrecoverable (NIST SP 800-88 Rev. 1 “Purge”).
6. Roles and Responsibilities
Data Protection Officer (REtelligent EU S.R.L.) — owns this Policy in the EU and is the escalation point for retention conflicts involving GDPR rights.
Privacy Officer (REtelligent Pty Ltd) — owns APP compliance, OAIC liaison and routine updates in AU.
Head of Engineering — owns technical implementation: automated lifecycle rules in the Postgres database and object storage on the Lovable/Supabase stack (hosted in AWS eu-central-1, Frankfurt), deletion tooling, and evidence of disposition.
Head of Finance — owns retention of tax, invoice and contract records.
People and Culture — owns employee-record retention.
All staff — must not create undocumented copies of personal data, must use platform-sanctioned storage, and must raise any legal-hold trigger to the Privacy Officer or DPO within 24 hours of awareness.
7. Retention Schedule
Data category | AU retention | EU retention | Legal basis | Retention clock | Disposition |
Tenant contact details (name, email, phone, address) | Active tenancy + 24 months | Active tenancy + 12 months | APP 11.2; GDPR Art. 5(1)(e); tenancy-dispute limitation (Limitation of Actions Act (Vic) s.5) | Termination of tenancy as recorded by the operator | Secure deletion; residual audit metadata per maintenance record |
Tenant maintenance request content | 7 years from request closure | 7 years from request closure | Building Act 1993 (Vic) s.232; EU Directive 85/374/EEC art.10; insurance evidence; GDPR Art. 6(1)(c) and (f) | Request marked closed | Soft delete then cryptographic shredding; de-identify if analytics value retained |
Tenant platform communications (in-app messages) | 5 years from last message | 3 years from last message | APP 11.2; GDPR Art. 5(1)(e); dispute evidence | Date of last message on the thread | Secure deletion |
Vendor / trade business contact details | Engagement + 5 years | Engagement + 3 years | Corporations Act s.286(2); Romanian Fiscal Code art.25(1); GDPR Art. 6(1)(b) and (f) | Deactivation of vendor profile | Secure deletion; contract records held separately |
Vendor invoices and payment records | 7 years | 10 years | ITAA 1936 s.262A; GST Act s.70-1; Romanian Accounting Law 82/1991 art.25 | End of the fiscal year of issue | Tax-locked archival; destroy after period |
Vendor qualifications, licences, insurance certificates | Engagement + 7 years | Engagement + 7 years | State building evidentiary retention; GDPR Art. 6(1)(c) and (f) | Vendor deactivation or document expiry, whichever is later | Secure deletion |
Vendor job history and performance metrics | Engagement + 3 years | Engagement + 3 years | APP 11.2; GDPR Art. 5(1)(e); performance evidence | Vendor deactivation | De-identify for analytics; delete identifying fields |
Property records (address, floor plans, manuals) | Operator engagement + 12 months | Operator engagement + 12 months | Operator contract (processor role); GDPR Art. 28; APP 11.2 | Termination of operator agreement | Return to operator, then secure deletion (DPA exit) |
Maintenance history (per property / asset) | 7 years from completion | 7 years from completion | Building Act 1993 (Vic) s.232; EU Directive 85/374 art.10; insurance | Work order marked completed | Secure archival; destroy after period |
Safety and compliance records | 10 years | 10 years | State OHS/WHS Acts; EU Regulation 305/2011 art.11(2); product-liability limitation | Date of certificate/inspection | Tamper-evident storage; destroy after period |
Geo-stamped photographs on maintenance records | Linked to parent record (7 years) | Linked to parent record (7 years) | EXIF GPS = personal data (EDPB Guidelines 3/2019); GDPR Art. 5(1)(e) | Work order marked completed | Cryptographic shredding at the object-storage level |
SMS / WhatsApp vendor follow-up logs | 24 months | 24 months | Spam Act 2003 s.16; Romanian Law 506/2004 art.12 | Date message sent/received | Secure deletion; excluded from analytics |
AI triage decision logs | 24 months | 24 months | GDPR Art. 22(3) and 5(1)(e); APP 11.2; bias monitoring and human review | Date of triage decision | De-identify or delete; aggregated metrics retained |
AI prompts and inputs (user-submitted free text) | 12 months | 12 months | GDPR Art. 5(1)(c); EDPB Opinion 28/2024; APP 3 | Date prompt submitted | Secure deletion; no retention in training datasets without opt-in |
Workflow audit trails | 7 years | 7 years | SOC 2 CC6.3/CC7.2; ISO 27001 A.8.15; GDPR Art. 32; APP 11.1 | Date of event | Write-once storage; destroy after period |
Authentication and access logs | 12 months (13 for forensics buffer) | 12 months (13 for forensics buffer) | SOC 2 CC6.6/CC7.2; ISO 27001 A.8.15-16; GDPR Art. 32(1)(b); APP 11.1 | Date of log entry | Automated rotation and secure deletion |
Security incident records | 7 years | 7 years | SOC 2 CC7.3/7.4; ISO 27001 A.5.24-28; GDPR Art. 33(5); Privacy Act Part IIIC | Date of incident closure | Tamper-evident archive |
Personal data breach register | 7 years | 7 years | GDPR Art. 33(5); Privacy Act NDB evidentiary retention | Date of breach discovery | Tamper-evident archive |
Cookie and marketing consent records | 5 years from consent or withdrawal | 5 years from consent or withdrawal | GDPR Art. 7(1); ePrivacy Art. 5(3); Spam Act 2003 s.16 | Date consent given, changed or withdrawn | Secure deletion from the consent store |
Website contact form submissions | 3 years | 3 years | GDPR Art. 5(1)(e); APP 11.2; pre-contractual limitation | Date of submission | Secure deletion |
Product analytics (user-level) | 14 months | 14 months | Analytics minimum retention; GDPR Art. 5(1)(e); Consent Mode configured | Event date | Automated expiry; purge aggregates annually |
Product analytics (aggregated, non-identifying) | Indefinite while business need persists | Indefinite while business need persists | Not personal data if de-identified (EDPB 04/2024; OAIC framework) | Date of aggregation | Periodic review; delete if re-identification risk increases |
Newsletter / direct marketing consent | 5 years after unsubscribe | 5 years after unsubscribe | Spam Act 2003 s.16; GDPR Art. 7(1); ePrivacy | Date of opt-out | Retain suppression-list hash only |
Employee records (active and former) | 7 years post-termination | 5 years post-termination | Fair Work Act 2009 Reg 3.44; Romanian Labour Code art.34 (payroll certificates may require longer) | Employment end date | Secure deletion except statutorily retained payroll |
Recruitment records (unsuccessful candidates) | 12 months | 12 months | GDPR Art. 5(1)(e); AU discrimination limitation periods | Date of recruitment decision | Secure deletion unless candidate consents to talent-pool retention |
Executed customer / operator contracts and DPAs | Contract term + 7 years | Contract term + 10 years | Corporations Act s.286-288; Romanian Fiscal Code art.25 | Contract expiry or termination | Archival in e-signature vault; destroy after period |
Sub-processor / vendor contracts | Contract term + 7 years | Contract term + 10 years | As above; GDPR Art. 28 evidencing | Contract expiry or termination | Archival |
Privacy request case files (access, correction, complaints) | 3 years from closure | 3 years from closure | GDPR Art. 5(2); APP 1.3 | Case marked closed | Secure deletion; anonymised metrics retained |
Operational backups (encrypted, point-in-time) | 35 days (rolling) | 35 days (rolling) | GDPR Art. 32(1)(c) vs 5(1)(e); SOC 2 A1.2; ISO 27001 A.8.13 | Backup creation timestamp | Automated rotation; on-demand erasure per Section 9 |
Disaster-recovery snapshots | Quarterly, 12 months | Quarterly, 12 months | SOC 2 A1.3; ISO 27001 A.8.14 | Snapshot creation | Automated rotation |
8. AI decision artefacts
AI triage decision logs and the user-submitted inputs to those decisions are retained as set out in Section 7 to support the right to contest an automated decision, human review, and bias monitoring. User inputs are not retained in training datasets without opt-in. Aggregated, de-identified model metrics may be retained indefinitely.
9. Backups and Disaster Recovery
Operational backups retain residual copies of personal data beyond the primary retention period. Backups are retained on a rolling 35-day basis and are encrypted at rest with AWS-managed keys (AWS KMS); customer-managed keys are not used on the current stack. Where a data subject exercises the right to erasure (GDPR Article 17) or requests destruction under APP 11.2, primary deletion is executed immediately; backups are not individually edited but expire on the rolling cycle, and the record is not restored on any restore. Backup destruction is by cryptographic shredding (NIST SP 800-88 Rev. 1 “Purge”). Backups within a legal hold are moved to segregated, immutable hold storage on hold activation and are not rotated until release.
10. Legal Hold
On a legal hold: all scheduled dispositions within the hold scope are suspended, including automated lifecycle rules and backup rotation; in-scope objects are tagged with hold metadata in immutable hold storage; lifecycle expiry and scheduled purges are disabled on in-scope records in the Postgres database; and in-scope backups are copied to immutable hold storage. Cryptographic shredding (per-object or per-bucket encryption keys destroyed) applies to object-storage-resident objects and to backups per Section 9. Holds are released only by the issuing officer, and the release is logged.
11. Disposition and review
At end of retention, data is disposed of by the method stated in Section 7. De-identification lifts data outside the retention clock but must be documented. This Policy is reviewed at least annually and on any material change to the platform, the processing activities, or the law.RETENTION SCHEDULE
16. Contact
Retention queries: privacy@retelligent.co.