Legal

Data Retention Policy

Last updated: August 2026

Version 1.0 · Review cycle: annually, or following any material change to data processing.

1. Purpose

This policy defines how long Vault47 retains data and when that data is deleted, so that personal data is not held for longer than is necessary for the purposes for which it was collected.

2. Scope

This policy applies to all data processed by the Vault47 platform, including data belonging to subscribing dealers ("Customers"), personal data processed on their behalf, and records generated by the platform itself.

3. Governing principle

Customer business records. Dealers use Vault47 to run their business. Their operational records, including inventory, transactions, purchase records, consignments, service records, production work, and their own client directory, are retained for as long as their account remains active. The Customer is the controller of this data; Vault47 is the processor. Retention of these records is the service being provided, and Vault47 does not unilaterally delete them.

Platform records. Security, audit and operational records generated by the platform itself. Vault47 is the controller of this data and applies defined retention periods to it.

Retention is determined by account status, not by usage activity. Periods of inactivity by an account holder do not trigger deletion of any data.

4. Retention periods

CategoryRetention
Customer business records, including personal data processed on the Customer's behalfDuration of the active subscription, then deleted per §5
Security and audit recordsNo longer than 24 months
Operational and diagnostic recordsNo longer than 12 months
Temporary processing artefacts (generated exports, queued jobs, transient files)Deleted on completion or shortly thereafter; no longer than 30 days
Opt-out and suppression recordsRetained indefinitely, as deletion would defeat the opt-out
Records required for legal, tax or accounting purposesAs required by applicable law, in the minimum form necessary

Retention periods are maximums. Data is deleted sooner where it is no longer required.

5. Account closure and deletion

  • A Customer may request account deletion at any time from within the platform.
  • The account enters a 30-day grace period, during which it can be fully restored.
  • After the grace period, an automated process permanently removes the account and its associated records.
  • Records subject to a legal or regulatory retention obligation are preserved in the minimum form necessary and deleted at the end of that obligation.
  • Customers may export their data at any time prior to deletion using the platform's export function.

6. Dormant accounts

Where a subscription has ended and the account has not been accessed for 12 consecutive months, Vault47 will contact the account holder in writing on at least two occasions, at least 30 days apart, before closing the account under §5. An active subscription always takes precedence. Inactivity alone never results in deletion.

7. Individual rights

Where an individual whose personal data is held within a Customer's records exercises a right of erasure, Vault47 will action the request within 30 days, or direct the request to the relevant Customer where the Customer is the controller. Customers may delete individual records from their own directories at any time.

8. Backups

Backups are encrypted and retained on a rolling window not exceeding 35 days. Data deleted from live systems remains present in backups until it ages out of that window. Backups are not searched, mined, or selectively restored to recover deleted personal data.

9. Connected platforms

Where a Customer connects a third-party commerce platform, Vault47 does not retain end-customer personal data received from that platform. Only platform identifiers, transaction references, amounts and internal Vault47 references are stored. Compliance and erasure requests received from connected platforms are recorded and actioned in accordance with that platform's requirements.

10. Enforcement

Retention periods are enforced by automated deletion processes. Deletions performed outside those processes are recorded in the platform's audit trail.

11. Exceptions

Retention may be extended where required by law, to give effect to a legal hold, or to investigate a security incident. Any extension is documented with a stated reason and is lifted once that reason no longer applies.

12. Contact

Enquiries regarding this policy:

Vault47 Tech LLC

23W 47th Street
Manhattan Diamond District, New York, NY

(516) 908-9007 · support@vault47.cloud

© 2026 Vault47 Tech LLC. 23W 47th Street, Manhattan Diamond District, New York, NY. (516) 908-9007.