VERI-TRUST

Privacy & data protection

Data Retention Policy

The retention periods applied to account, search, community feedback, moderation, subscription, security, and privacy-request data processed through Veri-Trust.

Last updated: July 2026

Retention principles

Veri-Trust does not intend to retain personal data indefinitely. Data is kept in active systems only for the period required for the relevant purpose. Where continued retention is justified by a legal obligation, security requirement, dispute, fraud-prevention need, or limitation period, selected information may be moved to a restricted archive before being deleted or irreversibly anonymized.

Retention schedule

Data categoryActive retentionRestricted archiveFinal action
Active user account dataFor the duration of the active account and service relationship.Up to 30 days after account closure to complete deletion, cancellation, security, and reconciliation operations.Deletion or irreversible anonymization, except for data subject to a separate legal or justified retention period.
Closed or deleted account recordRemoved from normal account access following confirmed closure.A minimal record of the account identifier, closure date, status, and necessary compliance information may be retained for 3 years after closure.Deletion or irreversible anonymization unless a legal claim or obligation remains active.
Authentication and session dataFor the duration of the active session or authentication process.Authentication events and relevant security records may be retained for up to 12 months.Automatic deletion or irreversible anonymization.
Password-reset and email-confirmation tokensUntil the token expires, is used, or is replaced.No ordinary archive. Limited technical evidence of the event may remain in security logs for up to 12 months.Deletion or cryptographic invalidation.
Registered-user search logsUp to 90 days from the search date for usage management, support, security, and investigation of abuse.Relevant records may be isolated for up to 12 months where required for a documented security investigation, dispute, or abuse case.Deletion or irreversible anonymization.
Guest search and rate-limit recordsOrdinarily 24 hours for daily limits. Technical anti-abuse records may be retained for up to 30 days.Relevant records may be isolated for up to 12 months only where associated with a documented security or abuse investigation.Deletion or irreversible anonymization.
IP addresses and technical request recordsUp to 30 days for routine rate limiting, incident detection, and technical troubleshooting.Up to 12 months where retained as part of security, access, or audit logs.Deletion or irreversible anonymization.
Published community feedbackFor as long as the feedback remains published and relevant to the purpose of the service.Each published review should be reassessed at least every 24 months. Reviews that are removed may be retained in restricted form for up to 3 years after removal where necessary for disputes, abuse prevention, or legal claims.Deletion, irreversible anonymization, or continued publication following documented reassessment.
Rejected or unpublished community feedbackUp to 90 days after the moderation decision to allow correction, reconsideration, or appeal.Up to 3 years where required to document repeated abuse, enforce platform rules, handle disputes, or defend legal rights.Deletion or irreversible anonymization.
Community feedback removed following a requestRemoved from public or user-facing access as soon as the applicable decision is implemented.A restricted copy or minimal evidence may be retained for up to 3 years after removal where necessary for accountability, dispute handling, legal claims, or repeated-abuse prevention.Deletion or irreversible anonymization unless a legal proceeding requires continued retention.
Trust Score and aggregated indicatorsRecalculated from currently eligible published feedback whenever the relevant underlying data changes.Historical score values may be retained for up to 12 months for audit, malfunction investigation, and calculation verification.Deletion or irreversible aggregation that no longer relates to an identifiable person.
Reports submitted by usersFor the duration of the investigation and moderation process.Up to 3 years after the report is closed. Records connected to active legal proceedings or serious repeated abuse may be retained until final resolution and expiry of the applicable limitation period.Deletion or irreversible anonymization.
Moderation decisions and audit recordsFor the duration of the relevant moderation, account, or content action.Up to 3 years after closure of the matter. Serious fraud, malicious activity, or active legal claims may justify retention for up to 5 years or until final resolution.Deletion, irreversible anonymization, or restricted legal archive where required.
Account warnings, suspensions, and bansFor the duration of the warning, suspension, restriction, or ban.Up to 3 years after the restriction ends. A minimal permanent-ban record may be retained for up to 5 years where necessary to prevent circumvention and repeated serious abuse.Deletion or irreversible anonymization unless continued restricted retention remains demonstrably necessary.
Cached comment translationsFor as long as the original eligible comment remains available and the translation feature remains enabled.No separate archive is normally required. A translation may remain temporarily in backups after deletion of the source comment.Deleted with the original comment or within the ordinary backup-deletion cycle.
Subscription and access-status dataFor the duration of the subscription and account relationship.Operational subscription identifiers and status history may be retained for up to 3 years after the end of the subscription for support, chargeback, dispute, and contractual evidence.Deletion or minimization, except for accounting and tax records subject to the 10-year period.
Invoices, accounting records, and payment evidenceFor the duration required to manage the transaction, subscription, refund, or payment issue.10 years from the end of the relevant accounting period or creation of the relevant accounting document, in accordance with applicable French accounting obligations.Secure deletion after expiry of the applicable legal period.
Stripe customer and subscription identifiersFor the duration of the subscription and related billing management.Up to 3 years after termination for operational disputes, or 10 years where the information forms part of a required accounting record.Deletion, minimization, or retention only within legally required accounting documentation.
Support correspondenceFor the duration necessary to process and close the request.Up to 3 years after closure where required for service history, dispute management, contractual evidence, or legal claims.Deletion or irreversible anonymization.
Privacy and data-subject rights requestsFor the duration necessary to verify, process, and respond to the request.Up to 3 years after the final response to demonstrate compliance and manage disputes. Identity-verification documents, where exceptionally required, should be deleted as soon as verification is completed unless a dispute justifies limited retention.Deletion, minimization, or irreversible anonymization.
Removal, correction, objection, and appeal requestsFor the duration of the investigation, decision, implementation, and applicable appeal period.Up to 3 years after the final decision to document the request, reasoning, outcome, and compliance action.Deletion or irreversible anonymization unless connected to an active legal claim.
Legal notices, claims, and litigation filesFor the duration of the claim, investigation, negotiation, proceeding, or enforcement action.Until final resolution and expiry of the applicable legal limitation or appeal period, ordinarily up to 5 years unless a longer mandatory period applies.Secure deletion or irreversible anonymization.
Standard application and access logsOrdinarily between 6 and 12 months, according to the security purpose and content of the log.Longer retention is permitted only where a specific incident, legal requirement, or documented investigation justifies isolation of selected records.Automatic deletion or irreversible anonymization.
Security-incident recordsFor the duration of detection, containment, investigation, remediation, and notification.Up to 5 years after closure where necessary to document the response, defend legal rights, meet security obligations, or manage repeated incidents.Deletion, minimization, or irreversible anonymization.
BackupsAccording to the rolling backup schedule required for service recovery.Ordinarily no more than 35 days after deletion from the active system, unless a backup is isolated because of an active security incident or legal hold.Automatic overwrite or secure deletion.
Cookie and consent recordsFor the duration specified for the relevant cookie or storage mechanism.Evidence of consent or refusal may be retained for up to 6 months after the preference expires or is replaced, unless a longer period is needed to establish compliance.Deletion, renewal request, or replacement with a new preference record.

1. Purpose and scope

This Data Retention Policy describes the principal periods during which Veri-Trust retains personal data and related operational records.

It applies to registered users, guest users, individuals concerned by community feedback, subscribers, requesters, moderators, and other persons whose information may be processed through the platform.

This public policy must be read together with the Privacy Policy, GDPR Information, Cookie Policy, Moderation Policy, and Data & Review Removal Requests procedure.

2. Active database and restricted archive

Data retained in the active database remains accessible to the personnel, systems, or service providers that require it for the ordinary operation of the platform.

Restricted archival retention means that information is removed from ordinary operational access and made available only to specifically authorized persons for a defined legal, security, compliance, dispute, accounting, or abuse-prevention purpose.

Archival retention is not automatic. Veri-Trust must be able to identify and document the reason for retaining the information beyond its active-use period.

3. Starting point for each retention period

A retention period may begin from account closure, subscription termination, completion of a search, submission or removal of feedback, closure of a report, final response to a request, completion of a transaction, or closure of an investigation.

Where several retention rules apply to the same record, Veri-Trust applies the longest period that remains legally or operationally justified while limiting the retained data to what is necessary.

The existence of a potential future use is not, by itself, sufficient to justify indefinite retention.

4. Review of published community feedback

Published community feedback must not remain online indefinitely without review merely because it was once considered eligible for publication.

Veri-Trust should perform a relevance and necessity reassessment at least every 24 months, taking account of the age of the feedback, the number of reports, subsequent moderation information, the continued relevance of the identifier, and the rights of the person concerned.

A review may result in continued publication, restriction, correction, removal, anonymization, or renewed moderation.

A person concerned may request an earlier review through the Data & Review Removal Requests procedure.

5. Data relating to non-users

The same retention-limitation principles apply where community feedback concerns a person who does not have a Veri-Trust account.

The absence of an account does not justify retaining information indefinitely.

Protected identifiers, feedback, scores, reports, and moderation records concerning non-users must be reviewed, deleted, restricted, or anonymized according to the same necessity, proportionality, and rights-protection requirements.

6. Deleted accounts

Closing an account removes access to the account and initiates the deletion workflow.

Account closure does not necessarily require immediate deletion of every associated record where separate legal, accounting, moderation, security, fraud-prevention, or dispute-related grounds apply.

Records retained following account closure must be limited, access-restricted, and linked to a documented retention purpose.

Community feedback submitted through a deleted account may be removed, retained, or reassessed depending on its status, the rights of the contributor, the rights of the reviewed person, platform integrity, and applicable law.

7. Legal holds and disputes

Deletion may be temporarily suspended where specific information is reasonably necessary for an active complaint, legal claim, court proceeding, regulatory request, fraud investigation, security incident, or defence of legal rights.

A legal hold must concern identified information and a documented matter. It must not be used to suspend deletion of unrelated data.

When the hold ends, the applicable retention period must be reassessed and the information deleted, anonymized, or returned to its ordinary schedule.

8. Backups and delayed deletion

Deletion from active systems may not immediately remove every copy contained in encrypted or rolling backups.

Backup copies are not intended for routine access and are retained only for disaster recovery, resilience, and restoration.

Data deleted from active systems will ordinarily disappear from rolling backups through automatic overwrite within 35 days.

Where a backup is restored, previously deleted records must be removed again where technically and reasonably possible.

9. Anonymization

Where Veri-Trust retains statistics or product metrics after the personal-data retention period, the information must be irreversibly anonymized so that an individual can no longer reasonably be identified.

Replacing a direct identifier with a hash does not, by itself, constitute irreversible anonymization.

Pseudonymized or hashed data remains subject to this retention policy where re-identification or singling out remains reasonably possible.

10. Automatic deletion and periodic review

Where technically possible, Veri-Trust should implement automatic deletion, expiry, anonymization, or archival rules directly within its database and infrastructure.

Retention jobs should be logged and periodically tested to verify that expired records are processed correctly.

Records that cannot be managed automatically must be included in a documented manual review process.

The retention schedule should be reviewed at least annually and whenever the platform introduces a new data category, provider, functionality, legal obligation, or material risk.

11. Service providers

Veri-Trust requires relevant service providers to retain and delete personal data according to the services provided, contractual instructions, their applicable legal obligations, and their documented retention schedules.

Deletion by Veri-Trust may require deletion or expiry within systems operated by Supabase, Vercel, Stripe, Cloudflare, Google Workspace, OpenAI, or another enabled provider.

Some providers may retain limited information as independent controllers or to comply with their own legal obligations. Those periods are governed by the provider’s applicable documentation and law.

12. Requests for early deletion or restriction

A person may request deletion, restriction, correction, objection, or review before the ordinary retention period expires.

Veri-Trust will assess the request according to the applicable legal basis, the rights of the requester and other persons, legal obligations, platform security, moderation requirements, fraud prevention, and the establishment, exercise, or defence of legal claims.

Where complete deletion cannot lawfully be granted, Veri-Trust may restrict access, minimize the retained information, remove public visibility, or explain the applicable retention ground.

Requests may be submitted through the Data & Review Removal Requests page or by email to privacy@veri-trust.app.

13. Changes to this policy

Veri-Trust may update this policy when its processing activities, technical systems, legal obligations, providers, risks, or operational requirements change.

A reduction in a retention period may be applied to existing records where technically and legally possible.

A material increase in a retention period must be documented, justified, proportionate, and reflected in the relevant privacy information.

14. Contact

Privacy and data-retention requests: privacy@veri-trust.app

Legal and compliance requests: legal@veri-trust.app

General support: support@veri-trust.app

Data and review requests: https://veri-trust.app/legal/removal-request