Retention policy
This document is a working draft prepared by the engineering team to describe how the platform is designed to support compliance. It is not legal advice and has not yet been reviewed by counsel. Do not rely on it as a final policy until this banner is removed.
Retention periods below are proposed defaults. Where the law prescribes a longer period, or a record is subject to a legal hold (e.g. medico-legal case), the longer period applies. Providers may configure longer periods for their tenant.
| Entity class | Examples | Proposed retention | Basis / note |
|---|---|---|---|
| Clinical records | Encounters, vitals, diagnoses, prescriptions, clinical documents, attachments | Life of the provider account; after offboarding, until the provider's export is confirmed + 90 days; provider remains responsible for statutory retention (minimum 3 years; longer under state rules) | Indian Medical Council (Professional Conduct) Regulations 2002 §1.3; state Clinical Establishments rules |
| Records of minors | Pediatric records | Until the patient reaches majority + 3 years, or the clinical-records period if longer | Common medico-legal practice (legal review) |
| Medico-legal case (MLC) records | MLC flagged encounters | Until final disposal of the case | Legal hold |
| PCPNDT records | Form F, registers (from R2) | Minimum 2 years | PCPNDT Act s.29 |
| Billing & tax | Invoices, credit notes, payments | 72 months from the due date of the annual GST return for the year | CGST Act s.36 |
| Audit & access logs | Who viewed/changed what | Minimum 1 year; clinical document events kept with the document | DPDP Rules 2025 security safeguards; CERT-In Directions 2022 (180 days, in India) |
| Consent records | Consent artefacts, withdrawals | Life of the related data + 3 years | Evidence of lawful processing |
| Communication logs | WhatsApp/email/SMS delivery records | 1 year | Operational |
| Staff/user accounts | Logins, memberships | While active + 1 year after deactivation | Security investigations |
| Leads & enquiries | Contact forms, demo requests | 12 months after last interaction | Purpose limitation |
| Backups | Firestore PITR | 7 days (rolling) | Platform DR |
| Backups | Firestore daily backups | 7 days | Platform DR (infra/modules/firestore) |
| Backups | Firestore weekly backups | 8 weeks | Platform DR (infra/modules/firestore) |
| Backups | Firestore exports in DR bucket | 30 days, then deleted by lifecycle | Platform DR (infra/modules/storage) |
| De-identified aggregates | Benchmarks | Indefinite | Not personal data (k-anonymity ≥ 10) |
End of retention
Data is deleted (or irreversibly anonymised). Backups age out on their own schedule — deleted data can persist in backups until they expire (maximum 8 weeks) and is never restored into production except for disaster recovery. For Bridge/Silo tenants, crypto-shredding (destroying the tenant key) renders remaining ciphertext unreadable.