Legal

Data Retention Policy

Last updated: April 13, 2026

Data retention policy document metadata
DocumentData Retention Policy
Version1.0
Effective date2026-04-13
Legal entityMaiguard Sentinel Limited (trading as MaiGuard)
Parent companyLyrisoft Technologies Limited — Maiguard Sentinel Limited is a registered subsidiary
Operating regionAfrica — primary operations, hosting strategy, and regulatory alignment are oriented to African markets and cross-border flows involving African tenants
OwnerSecurity & Compliance (Maiguard Sentinel Limited / Lyrisoft Technologies Limited group)
Review cadenceAt least annually, or after material product, regulatory, or infrastructure change

1. Purpose and scope

This policy defines how Maiguard Sentinel Limited (trading as MaiGuard), a registered subsidiary of Lyrisoft Technologies Limited, retains, restricts access to, and disposes of customer and platform data processed in connection with MaiGuard’s multi-tenant fraud detection, transaction risk scoring, and related B2B SaaS platform.

MaiGuard operates within Africa; retention and legal obligations may vary by African country (and by tenant contract). Tenants remain responsible for local law where they are licensed or established.

In scope: data stored or processed by MaiGuard on behalf of tenants (business customers) and their end users, including transaction scoring data, configuration, audit trails, operational logs, backups, and support artefacts.

Out of scope: data processed solely on a tenant’s own systems unless MaiGuard explicitly stores or logs it. Jurisdiction-specific legal advice remains the tenant’s responsibility where they are the regulated entity.


2. Definitions

TermMeaning
TenantA business customer account using MaiGuard under a subscription or contract.
End userAn individual or entity whose activity is described in data sent to MaiGuard (e.g. transacting customer).
Personal dataInformation relating to an identified or identifiable natural person, as defined under applicable privacy law.
Retention periodThe maximum time data is kept in production systems, archives, or backups before deletion or irreversible anonymisation, unless a legal hold or contractual exception applies.
Legal holdA suspension of deletion required for litigation, regulatory inquiry, or statutory obligation.
Plan retention windowA visibility or retention limit tied to subscription plan features (e.g. retentionDays), where enforced—see tenant-facing documentation and order form.

3. Principles

  1. Purpose limitation — Data is retained only as long as needed for service delivery, security, abuse prevention, billing, legal obligation, or documented legitimate interest.
  2. Data minimisation — Tenants should send the minimum fields required for their use case; MaiGuard avoids retaining unnecessary sensitive data.
  3. Tenant isolation — Retention and access controls respect tenant boundaries (multi-tenancy).
  4. Secure disposal — Deletion or anonymisation uses industry-appropriate methods for the storage medium (logical deletion, crypto-shredding where applicable, backup expiry).
  5. Transparency — Material retention rules are documented here and, where relevant, in the Privacy Policy, Data Processing Agreement (DPA), and order form or Service Level Agreement (SLA).

4. Roles and responsibilities

RoleResponsibility
Maiguard Sentinel Limited (MaiGuard)Implements this policy; operates deletion and backup lifecycle; documents subprocessors; responds to legal holds and regulated requests within the law.
Tenant administratorConfigures product settings allowed by plan; ensures lawful basis and notices for data sent to MaiGuard; coordinates end-user rights requests as agreed in the DPA.
Engineering / OperationsExecutes technical retention (jobs, storage TTLs, backup rotation) per approved procedures.
Security & ComplianceMaintains this policy, exceptions register, and evidence for audits.

5. Data categories and default retention periods

Default periods apply unless a signed contract, DPA exhibit, or law requires otherwise. Periods are measured from the latest relevant event (e.g. record creation, account closure, or log timestamp) unless stated otherwise.

CategoryExamples (non-exhaustive)Default retentionNotes
Transaction and scoring recordsStored transactions, risk scores, decisions, case metadataPer subscription plan or contract; baseline up to 7 years where required for financial crime or dispute patterns in the tenant’s jurisdictionShorter plan-limited visibility (e.g. retentionDays) may apply to API/UI access even if archival policy differs—see §5.1.
Raw scoring payloads / metadataJSON sent to scoring APIs, enrichment snapshotsAligned with transaction record retention or shorter if minimisation is appliedMay be redacted or truncated in logs.
Tenant user accountsPortal users, roles, preferencesLife of contract + 90 days after offboarding, unless law requires longerDeletion/anonymisation after final billing and dispute window where applicable.
Tenant configurationRules, rule sets, lists, webhooks, API keys (hashed), integrationsLife of contract + 90 daysSecrets stored hashed or encrypted; key rotation encouraged.
Audit logsAdministrative and security-relevant actionsAt least 1 year; up to 7 years for regulated tenants or by contractSupports integrity and investigations.
Application and security logsRequest/error logs, WAF, IDS, auth events30–90 days typical; up to 1 year for security investigationsMay be shorter in non-production.
Webhook and integration tracesDebug payloads, delivery logs30–90 days unless needed for incidentMinimise PII in payloads.
Support tickets and emailSupport platform / email threads with tenant contacts2 years after ticket closure, unless contract says otherwiseAttachments follow same category as primary data.
BackupsDatabase and object-store snapshotsAligned with production; typically 30–90 days rollingRestoration may temporarily revive deleted data until next backup cycle expires (§7).
Export jobsGenerated CSV/JSON exports, presigned URLsURL expiry + 7 days for artefacts, or 30 days maximum unless tenant deletes soonerTenants should download promptly.
File importsUploaded CSV/JSON for batch processing90 days after import completion, unless tenant deletes soonerS3/object lifecycle.
Billing and invoicesInvoices, payment metadata7 years or per tax/accounting requirementStatutory periods vary by African jurisdiction and tenant location.
Marketing / websiteCookies, analytics where usedPer Cookie Policy and consentTypically shorter; not tenant transaction data.

5.1 Plan-based visibility vs physical deletion

MaiGuard may enforce a plan retention window (e.g. features such as retentionDays) that limits read access to historical data via standard APIs and UI, without immediately purging underlying storage. Physical deletion of aged data may be implemented via scheduled jobs as described in product documentation. Where read restriction and purge differ, the stricter of the two applies to customer-facing commitments in the order form.


6. Deletion and anonymisation

  1. Routine deletion — Automated jobs or manual procedures remove or anonymise data when the retention period ends, subject to legal hold.
  2. Tenant offboarding — Upon contract end, MaiGuard deletes or returns data per the DPA and offboarding checklist, within 90 days unless law or dispute requires retention.
  3. Anonymisation — Where full deletion is impractical (e.g. aggregated metrics), MaiGuard may retain non-identifying statistics only.
  4. Cryptographic erasure — Where data is encrypted with tenant-specific keys, key destruction may constitute erasure after documented procedures.

7. Backups and restoration

  • Backups exist for availability and disaster recovery, not indefinite retention.
  • When production data is deleted, residual copies may persist until backup rotation completes (typically ≤ 90 days).
  • Restores are logged and limited to authorised personnel.

8. Legal and regulatory holds

If MaiGuard is notified of litigation, investigation, or statutory freeze:

  1. Relevant data is preserved beyond normal retention until cleared by Legal.
  2. Routine deletion for affected datasets is suspended for the hold scope.
  3. A hold register records matter ID, scope, and release date.

9. Data subject and tenant requests

  • Access, rectification, erasure, restriction, portability — Handled per Privacy Policy and DPA, within statutory timelines. Erasure may be limited where MaiGuard must retain data for legal obligation or legitimate security purposes.
  • Tenants must route end-user requests through agreed channels; MaiGuard assists the tenant as processor where applicable.

10. International transfers

MaiGuard’s primary operations are in Africa; tenants may be in one African country and use infrastructure or subprocessors in others or outside the continent. Transfers across borders (including outside the tenant’s country or outside Africa) follow DPA mechanisms and applicable African data-protection laws (e.g. adequacy, binding corporate rules, or Standard Contractual Clauses where recognised), as described in subprocessors documentation and regional exhibits.

Retention periods in this policy apply unless a regional exhibit or African jurisdiction-specific requirement states a shorter or longer period for a specific deployment.


11. Exceptions

Any deviation from default periods requires:

  • Written approval from Security & Compliance and Legal, and
  • Entry in the retention exceptions register (scope, duration, reason).

12. Policy review

This policy is reviewed at least annually and upon major product changes (new data types, regions, or subprocessors), material security or privacy incident learnings, or new regulatory requirements affecting MaiGuard or its customer base.

Approvals: Security & Compliance lead and executive sponsor.


13. Related documents

  • Privacy Policy
  • Data Processing Agreement (DPA) and subprocessor list
  • Information Security Policy
  • Incident Response Plan
  • Compliance and governance documentation (internal reference)

This document supports governance and customer transparency. Tenants should align their own AML, bookkeeping, and privacy obligations with their regulators and counsel.