Data retention policy

Last updated:

Issuing entities: REtelligent Pty Ltd (ABN 87 694 108 613; ACN 694 108 613) and REtelligent EU S.R.L. (CUI 54685957) Applies to: the REtelligent Sync application (https://app.retelligent.co) and supporting systems Read with: the Privacy Policy, Cookie Policy, Privacy Collection Notice, the applicable Data Processing Agreement, and the Incident Response Plan

1. Purpose

This Data Retention Policy (“Policy”) establishes how REtelligent Pty Ltd (ABN 87 694 108 613; ACN 694 108 613) and REtelligent EU S.R.L. (CUI 54685957) (collectively, “REtelligent”, “we”, “us”, or “our”) retains, archives and disposes of personal data and business records. It implements the storage-limitation principle (GDPR Article 5(1)(e)), the Australian Privacy Principle 11.2 requirement to destroy or de-identify personal information once it is no longer needed, and the tax, employment and evidentiary retention obligations applicable to both group entities.

It sits alongside, and is cross-referenced by, the Privacy Policy, Cookie Policy, Privacy Collection Notice, the applicable Data Processing Agreement, and the Incident Response Plan.

2. Scope

This Policy applies to all personal data processed by REtelligent as controller or processor in either jurisdiction (whether held in production systems, analytics, backups or archives); all business records generated in operating the platform (including contracts, invoices, audit trails and AI decision artefacts); and all employees, contractors and sub-processors with access to REtelligent data. It does not extend to data held by a property operator as an independent controller; where REtelligent processes such data on the operator’s behalf, retention is governed by the operator’s instructions and the applicable DPA, with this Policy as the minimum floor.

3. Controllers and Applicable Law


Australian entity

EU entity

Legal name

REtelligent Pty Ltd

REtelligent EU S.R.L.

Registration

ABN 87 694 108 613 / ACN 694 108 613

CUI 54685957

Registered address

Unit 2, 8A Judith Street, Carnegie VIC 3163, Australia

Bucureşti Sectorul 1, Bulevardul G-ral Gheorghe Magheru, Nr. 31, Biroul 2, Etaj 5

Primary legal anchor

Privacy Act 1988 (Cth) APP 11.2; Income Tax Assessment Act 1936 s.262A; Fair Work Act 2009 Reg 3.44; Corporations Act 2001 s.286-288

GDPR Articles 5(1)(e), 17, 30; Romanian Law 190/2018; Romanian Accounting Law 82/1991; Romanian Fiscal Code (Law 227/2015) art.25

Regulator

Office of the Australian Information Commissioner (OAIC)

ANSPDCP (Romania)

Retention contact

privacy@retelligent.co

privacy@retelligent.co

 

4. Guiding Principles

Storage limitation (GDPR Article 5(1)(e); APP 11.2): personal data is kept only as long as necessary for the purpose collected, or for legal, regulatory or evidentiary obligations. Data minimisation (GDPR Article 5(1)(c); APP 3): the narrowest necessary category is retained. Purpose limitation (GDPR Article 5(1)(b); APP 6): retained data is not re-purposed without separate authorisation. Integrity and confidentiality (GDPR Article 5(1)(f); APP 11.1): retention media apply encryption at rest, least-privilege access and tamper-evident logging. Accountability (GDPR Article 5(2)): retention decisions, deletions and holds are logged. Harmonised floor-and-ceiling: where AU and EU rules diverge, REtelligent applies the stricter floor and the lower ceiling per category so neither regime is breached.

5. Definitions

  • Retention Period — the total time data or a record is kept from the start of the retention clock to authorised disposition.

  • Retention Clock Trigger — the event that starts the period (for example work-order closure, contract termination, last login).

  • Disposition — the authorised action at end of retention: destruction, cryptographic shredding, de-identification, or archival transfer.

  • Legal Hold — a suspension of scheduled disposition where litigation, regulatory inquiry or investigation makes preservation obligatory (Section 10).

  • De-identification — processing under which data no longer relates to an identifiable individual (OAIC De-identification Decision-Making Framework; EDPB Guidelines 04/2024).

  • Cryptographic Shredding — destruction of encryption keys so that ciphertext is unrecoverable (NIST SP 800-88 Rev. 1 “Purge”).

6. Roles and Responsibilities

  • Data Protection Officer (REtelligent EU S.R.L.) — owns this Policy in the EU and is the escalation point for retention conflicts involving GDPR rights.

  • Privacy Officer (REtelligent Pty Ltd) — owns APP compliance, OAIC liaison and routine updates in AU.

  • Head of Engineering — owns technical implementation: automated lifecycle rules in the Postgres database and object storage on the Lovable/Supabase stack (hosted in AWS eu-central-1, Frankfurt), deletion tooling, and evidence of disposition.

  • Head of Finance — owns retention of tax, invoice and contract records.

  • People and Culture — owns employee-record retention.

  • All staff — must not create undocumented copies of personal data, must use platform-sanctioned storage, and must raise any legal-hold trigger to the Privacy Officer or DPO within 24 hours of awareness.

7. Retention Schedule

Data category

AU retention

EU retention

Legal basis

Retention clock

Disposition

Tenant contact details (name, email, phone, address)

Active tenancy + 24 months

Active tenancy + 12 months

APP 11.2; GDPR Art. 5(1)(e); tenancy-dispute limitation (Limitation of Actions Act (Vic) s.5)

Termination of tenancy as recorded by the operator

Secure deletion; residual audit metadata per maintenance record

Tenant maintenance request content

7 years from request closure

7 years from request closure

Building Act 1993 (Vic) s.232; EU Directive 85/374/EEC art.10; insurance evidence; GDPR Art. 6(1)(c) and (f)

Request marked closed

Soft delete then cryptographic shredding; de-identify if analytics value retained

Tenant platform communications (in-app messages)

5 years from last message

3 years from last message

APP 11.2; GDPR Art. 5(1)(e); dispute evidence

Date of last message on the thread

Secure deletion

Vendor / trade business contact details

Engagement + 5 years

Engagement + 3 years

Corporations Act s.286(2); Romanian Fiscal Code art.25(1); GDPR Art. 6(1)(b) and (f)

Deactivation of vendor profile

Secure deletion; contract records held separately

Vendor invoices and payment records

7 years

10 years

ITAA 1936 s.262A; GST Act s.70-1; Romanian Accounting Law 82/1991 art.25

End of the fiscal year of issue

Tax-locked archival; destroy after period

Vendor qualifications, licences, insurance certificates

Engagement + 7 years

Engagement + 7 years

State building evidentiary retention; GDPR Art. 6(1)(c) and (f)

Vendor deactivation or document expiry, whichever is later

Secure deletion

Vendor job history and performance metrics

Engagement + 3 years

Engagement + 3 years

APP 11.2; GDPR Art. 5(1)(e); performance evidence

Vendor deactivation

De-identify for analytics; delete identifying fields

Property records (address, floor plans, manuals)

Operator engagement + 12 months

Operator engagement + 12 months

Operator contract (processor role); GDPR Art. 28; APP 11.2

Termination of operator agreement

Return to operator, then secure deletion (DPA exit)

Maintenance history (per property / asset)

7 years from completion

7 years from completion

Building Act 1993 (Vic) s.232; EU Directive 85/374 art.10; insurance

Work order marked completed

Secure archival; destroy after period

Safety and compliance records

10 years

10 years

State OHS/WHS Acts; EU Regulation 305/2011 art.11(2); product-liability limitation

Date of certificate/inspection

Tamper-evident storage; destroy after period

Geo-stamped photographs on maintenance records

Linked to parent record (7 years)

Linked to parent record (7 years)

EXIF GPS = personal data (EDPB Guidelines 3/2019); GDPR Art. 5(1)(e)

Work order marked completed

Cryptographic shredding at the object-storage level

SMS / WhatsApp vendor follow-up logs

24 months

24 months

Spam Act 2003 s.16; Romanian Law 506/2004 art.12

Date message sent/received

Secure deletion; excluded from analytics

AI triage decision logs

24 months

24 months

GDPR Art. 22(3) and 5(1)(e); APP 11.2; bias monitoring and human review

Date of triage decision

De-identify or delete; aggregated metrics retained

AI prompts and inputs (user-submitted free text)

12 months

12 months

GDPR Art. 5(1)(c); EDPB Opinion 28/2024; APP 3

Date prompt submitted

Secure deletion; no retention in training datasets without opt-in

Workflow audit trails

7 years

7 years

SOC 2 CC6.3/CC7.2; ISO 27001 A.8.15; GDPR Art. 32; APP 11.1

Date of event

Write-once storage; destroy after period

Authentication and access logs

12 months (13 for forensics buffer)

12 months (13 for forensics buffer)

SOC 2 CC6.6/CC7.2; ISO 27001 A.8.15-16; GDPR Art. 32(1)(b); APP 11.1

Date of log entry

Automated rotation and secure deletion

Security incident records

7 years

7 years

SOC 2 CC7.3/7.4; ISO 27001 A.5.24-28; GDPR Art. 33(5); Privacy Act Part IIIC

Date of incident closure

Tamper-evident archive

Personal data breach register

7 years

7 years

GDPR Art. 33(5); Privacy Act NDB evidentiary retention

Date of breach discovery

Tamper-evident archive

Cookie and marketing consent records

5 years from consent or withdrawal

5 years from consent or withdrawal

GDPR Art. 7(1); ePrivacy Art. 5(3); Spam Act 2003 s.16

Date consent given, changed or withdrawn

Secure deletion from the consent store

Website contact form submissions

3 years

3 years

GDPR Art. 5(1)(e); APP 11.2; pre-contractual limitation

Date of submission

Secure deletion

Product analytics (user-level)

14 months

14 months

Analytics minimum retention; GDPR Art. 5(1)(e); Consent Mode configured

Event date

Automated expiry; purge aggregates annually

Product analytics (aggregated, non-identifying)

Indefinite while business need persists

Indefinite while business need persists

Not personal data if de-identified (EDPB 04/2024; OAIC framework)

Date of aggregation

Periodic review; delete if re-identification risk increases

Newsletter / direct marketing consent

5 years after unsubscribe

5 years after unsubscribe

Spam Act 2003 s.16; GDPR Art. 7(1); ePrivacy

Date of opt-out

Retain suppression-list hash only

Employee records (active and former)

7 years post-termination

5 years post-termination

Fair Work Act 2009 Reg 3.44; Romanian Labour Code art.34 (payroll certificates may require longer)

Employment end date

Secure deletion except statutorily retained payroll

Recruitment records (unsuccessful candidates)

12 months

12 months

GDPR Art. 5(1)(e); AU discrimination limitation periods

Date of recruitment decision

Secure deletion unless candidate consents to talent-pool retention

Executed customer / operator contracts and DPAs

Contract term + 7 years

Contract term + 10 years

Corporations Act s.286-288; Romanian Fiscal Code art.25

Contract expiry or termination

Archival in e-signature vault; destroy after period

Sub-processor / vendor contracts

Contract term + 7 years

Contract term + 10 years

As above; GDPR Art. 28 evidencing

Contract expiry or termination

Archival

Privacy request case files (access, correction, complaints)

3 years from closure

3 years from closure

GDPR Art. 5(2); APP 1.3

Case marked closed

Secure deletion; anonymised metrics retained

Operational backups (encrypted, point-in-time)

35 days (rolling)

35 days (rolling)

GDPR Art. 32(1)(c) vs 5(1)(e); SOC 2 A1.2; ISO 27001 A.8.13

Backup creation timestamp

Automated rotation; on-demand erasure per Section 9

Disaster-recovery snapshots

Quarterly, 12 months

Quarterly, 12 months

SOC 2 A1.3; ISO 27001 A.8.14

Snapshot creation

Automated rotation

8. AI decision artefacts

AI triage decision logs and the user-submitted inputs to those decisions are retained as set out in Section 7 to support the right to contest an automated decision, human review, and bias monitoring. User inputs are not retained in training datasets without opt-in. Aggregated, de-identified model metrics may be retained indefinitely.

9. Backups and Disaster Recovery

Operational backups retain residual copies of personal data beyond the primary retention period. Backups are retained on a rolling 35-day basis and are encrypted at rest with AWS-managed keys (AWS KMS); customer-managed keys are not used on the current stack. Where a data subject exercises the right to erasure (GDPR Article 17) or requests destruction under APP 11.2, primary deletion is executed immediately; backups are not individually edited but expire on the rolling cycle, and the record is not restored on any restore. Backup destruction is by cryptographic shredding (NIST SP 800-88 Rev. 1 “Purge”). Backups within a legal hold are moved to segregated, immutable hold storage on hold activation and are not rotated until release.

10. Legal Hold

On a legal hold: all scheduled dispositions within the hold scope are suspended, including automated lifecycle rules and backup rotation; in-scope objects are tagged with hold metadata in immutable hold storage; lifecycle expiry and scheduled purges are disabled on in-scope records in the Postgres database; and in-scope backups are copied to immutable hold storage. Cryptographic shredding (per-object or per-bucket encryption keys destroyed) applies to object-storage-resident objects and to backups per Section 9. Holds are released only by the issuing officer, and the release is logged.

11. Disposition and review

At end of retention, data is disposed of by the method stated in Section 7. De-identification lifts data outside the retention clock but must be documented. This Policy is reviewed at least annually and on any material change to the platform, the processing activities, or the law.RETENTION SCHEDULE

16. Contact

Retention queries: privacy@retelligent.co.