Skip to main content

Retention policy

DRAFT — requires legal review

This document is a working draft prepared by the engineering team to describe how the platform is designed to support compliance. It is not legal advice and has not yet been reviewed by counsel. Do not rely on it as a final policy until this banner is removed.

Retention periods below are proposed defaults. Where the law prescribes a longer period, or a record is subject to a legal hold (e.g. medico-legal case), the longer period applies. Providers may configure longer periods for their tenant.

Entity classExamplesProposed retentionBasis / note
Clinical recordsEncounters, vitals, diagnoses, prescriptions, clinical documents, attachmentsLife of the provider account; after offboarding, until the provider's export is confirmed + 90 days; provider remains responsible for statutory retention (minimum 3 years; longer under state rules)Indian Medical Council (Professional Conduct) Regulations 2002 §1.3; state Clinical Establishments rules
Records of minorsPediatric recordsUntil the patient reaches majority + 3 years, or the clinical-records period if longerCommon medico-legal practice (legal review)
Medico-legal case (MLC) recordsMLC flagged encountersUntil final disposal of the caseLegal hold
PCPNDT recordsForm F, registers (from R2)Minimum 2 yearsPCPNDT Act s.29
Billing & taxInvoices, credit notes, payments72 months from the due date of the annual GST return for the yearCGST Act s.36
Audit & access logsWho viewed/changed whatMinimum 1 year; clinical document events kept with the documentDPDP Rules 2025 security safeguards; CERT-In Directions 2022 (180 days, in India)
Consent recordsConsent artefacts, withdrawalsLife of the related data + 3 yearsEvidence of lawful processing
Communication logsWhatsApp/email/SMS delivery records1 yearOperational
Staff/user accountsLogins, membershipsWhile active + 1 year after deactivationSecurity investigations
Leads & enquiriesContact forms, demo requests12 months after last interactionPurpose limitation
BackupsFirestore PITR7 days (rolling)Platform DR
BackupsFirestore daily backups7 daysPlatform DR (infra/modules/firestore)
BackupsFirestore weekly backups8 weeksPlatform DR (infra/modules/firestore)
BackupsFirestore exports in DR bucket30 days, then deleted by lifecyclePlatform DR (infra/modules/storage)
De-identified aggregatesBenchmarksIndefiniteNot personal data (k-anonymity ≥ 10)

End of retention​

Data is deleted (or irreversibly anonymised). Backups age out on their own schedule — deleted data can persist in backups until they expire (maximum 8 weeks) and is never restored into production except for disaster recovery. For Bridge/Silo tenants, crypto-shredding (destroying the tenant key) renders remaining ciphertext unreadable.