Data Retention Policy

Platinum Health Equipment Pty Ltd
Version 2.0 | Effective: April 24, 2026 | Updated: Privacy-First Zero-Retention Policy

1. Purpose

This Data Retention Policy defines how long different types of data are stored by AegisGates Vision AI and the procedures for data deletion. This policy ensures compliance with GDPR, CCPA, Australian Privacy Principles, and industry best practices.

2. Scope

This policy applies to all data collected, processed, and stored by the AegisGates Vision AI platform, including:

3. Data Categories and Retention Periods

Privacy-First Policy

AegisGates does NOT store raw video footage on our servers. All uploaded video clips are processed in real-time and immediately deleted after AI analysis. Only text-based narratives (descriptions) are retained for the periods specified below. This ensures maximum privacy protection for all monitored individuals.

AI Training Use: Prior to deletion, video footage (within its processing window) and AI-generated narratives (within their 90-day retention period) may be used to train and improve our AI detection models. This does not extend any retention period.

3.1 Video Footage

Processing Stage Retention Period Details
Raw Video Clips ZERO (0 seconds) Deleted immediately after AI processing completes (typically within 2-30 seconds of upload)
Processing Frames (temporary) During inference only Extracted keyframes exist in memory only during AI analysis, never written to disk
Failed Clips (debug) 7 days Clips that fail AI processing are quarantined for debugging, then auto-deleted
Why This Matters:

3.2 AI-Generated Narratives and Metadata

Important: Narratives are text-only descriptions of what was observed in video clips. They do NOT contain any video footage, images, or biometric data.

Data Type Retention Period Storage Location
Narratives (text descriptions) 90 days PostgreSQL database (encrypted)
Alert records 90 days PostgreSQL database
Timestamps Same as narratives PostgreSQL database
Motion detection events 90 days Redis + PostgreSQL
Narrative Retention:

All subscribers retain AI-generated narratives and alert records for 90 days from the date of capture. Narratives are automatically deleted when the 90-day period expires. Users can request early deletion at any time.

3.3 Account and User Data

Data Type Retention Period Deletion Trigger
Active account information Duration of subscription + 90 days Account deletion + 90 days
Deleted account data 30 days (soft delete), 90 days (hard delete) Immediate upon deletion request
Email addresses Subscription + 12 months Opt-out or deletion request
Password hashes Subscription only Immediate upon account deletion
Login history 12 months Rolling 12-month window

3.4 Billing and Payment Records

Data Type Retention Period Legal Requirement
Invoices 7 years Australian tax law (ATO requirements)
Payment transactions 7 years Financial record keeping
Failed payment attempts 3 months Fraud prevention
Stripe payment IDs 7 years Payment processor requirements

Note: We do NOT store complete credit card numbers. Stripe securely tokenizes payment information.

3.5 System Logs and Analytics

Log Type Retention Period Purpose
Access logs (web/API) 90 days Security monitoring, debugging
Error logs 90 days Troubleshooting, service improvement
Security logs (failed logins, suspicious activity) 12 months Security investigations
Aggregated analytics (anonymized) Indefinite Product improvement, trends
Redis task queue logs 7 days Operational monitoring

3.6 Communications

Communication Type Retention Period Storage
Support tickets 24 months after resolution Help desk system
Transactional emails (sent) 12 months Email service provider logs
Marketing emails (if opted in) Until opt-out Email marketing platform
SMS alerts (sent) 90 days Twilio logs

4. Deletion Procedures

4.1 Automated Deletion

4.2 Manual Deletion Requests

Users may request early deletion by:

  1. Emailing [email protected]
  2. Using self-service deletion feature (if available)
  3. Contacting customer support
Response Time:

4.3 Secure Deletion Methods

5. Backup Retention

5.1 Backup Schedule

Backup Type Frequency Retention Period
Database (full) Daily 30 days
Database (incremental) Every 6 hours 7 days
Configuration files Weekly 90 days
Disaster recovery snapshot Monthly 12 months

5.2 Backup Deletion

6. Legal Hold and Preservation

6.1 When Legal Hold Applies

Data is retained beyond standard periods when:

6.2 Legal Hold Procedure

  1. Legal team issues preservation notice
  2. Automated deletion is suspended for affected data
  3. Data is copied to secure legal hold repository
  4. Hold is documented with case number and expiration criteria
  5. Hold is lifted only upon legal team authorization

7. Third-Party Data Retention

Service Provider Data Type Their Retention Our Control
Google Gemini API Image analysis requests 30 days (per Google policy) None (processed on-the-fly)
Stripe Payment transactions Indefinite (compliance) Limited (can request deletion)
Twilio SMS logs 6 months Can request deletion
Resend Email logs 30 days Can request deletion
Cloudflare CDN cache, logs 7-30 days Can purge cache
GCP Server infrastructure Duration of contract Full control (encryption keys)

8. Data Subject Rights

Users have the right to:

  1. Access: Request a copy of all data we hold about them
  2. Rectification: Correct inaccurate or incomplete data
  3. Erasure: Request deletion (subject to legal obligations)
  4. Portability: Receive data in machine-readable format
  5. Restriction: Limit processing of their data
  6. Objection: Object to processing based on legitimate interests

How to Exercise Rights: Email [email protected] with subject line "Data Subject Request"

9. Children's Data

10. Data Breach Retention

10.1 Incident Data

10.2 Notification Timeline

11. Retention Schedule Review

This policy is reviewed:

Last Review: April 23, 2026
Next Review: April 2027
Responsible: Chief Privacy Officer / Legal Team

12. Exceptions and Overrides

12.1 Regulatory Requirements

If law requires longer retention (e.g., financial records, subpoenas), regulatory requirements supersede this policy.

12.2 User Requests for Longer Retention

Enterprise customers may negotiate custom retention periods via contract addendum.

12.3 Anonymized Data

Aggregated, anonymized data (no personal identifiers) may be retained indefinitely for analytics and research.

13. Contact Information

Data Retention Inquiries: [email protected]
Legal Hold Requests: [email protected]
General Support: [email protected]

Mailing Address:
Platinum Health Equipment Pty Ltd
7 Eden Park Drive, Unit 5 Suite #1061
Macquarie Park, NSW 2113
Australia

14. Policy History

Version Date Changes
2.0 April 24, 2026 Privacy-First Update: Implemented zero-retention policy for raw video footage. All video clips now deleted immediately after AI processing. Only text narratives retained.
1.0 April 23, 2026 Initial policy release

Next Review Date: April 2027