← Back

Data Retention Policy

DataStored?Retention
Document image / selfie framesNoDiscarded immediately after scoring
Face embeddings / pose dataNoIn-memory only
Over-threshold result + coded outcomeYesDefault 12 months, then auto-purged
Dispute scores (match/liveness)YesDefault 30 days, then nulled
Consent receipt (hashes)YesWith the session record
Audit log (no PII)YesRetained for accountability

Automated purge runs daily (npm run gdpr:purge / POST /api/jobs/purge). Customers can trigger erasure for any subject reference at any time.

This template is provided as engineering scaffolding and is not legal advice. Have your DPO / counsel review before going live, and complete a DPIA.