Retention

Data Retention and Deletion Policy

How long each category of record is kept, and what happens when it is no longer needed.

Version
2.0
Effective
26 July 2026
Applies to
Records Shasam Technologies holds in its own right
Scope

This is a general, company-level document. It covers this website and the way Shasam Technologies handles information as a company. No Shasam Technologies product is currently available to the public, so nothing here describes a consumer app. When a product ships it will publish its own notice, which will add to this document and override it only where it says so explicitly.

Website enquiries
24 months from the last message, or sooner on request.
Verified erasure
Completed within 30 days.
Cannot be deleted
Tax and accounting records - 8 financial years by law.
Client system data
Retention set by the client, not by us.

01The principles we apply

The Digital Personal Data Protection Act, 2023 requires personal data to be erased once the purpose it was collected for is served and no law requires it to be kept. This policy is how we meet that obligation in practice.

  • Collect less. The cheapest data to protect is the data we never took. Our forms ask for the minimum that lets us reply.
  • Keep it for a stated reason. Every category below has a period and a reason. If we cannot state the reason, we delete it.
  • Delete or anonymise at the end. Where a record retains analytical value once the personal element is gone, we strip the personal element rather than keep the whole record.
  • Statutory minimums win. Where the law requires a record to be kept, we keep it for that period even if you ask for deletion - and we tell you which record and why.

02The retention schedule

Periods run from the trigger stated in the middle column, not from the date of collection.

RecordKept forWhy
Website enquiries24 months from the last message in the threadTo keep the thread of a conversation and recognise a returning enquirer. Deleted sooner on request.
Data-rights requests and our responses3 years from closureTo evidence that we handled the request properly, which the DPDP Act expects us to be able to show.
Identity material supplied to verify a data requestDeleted as soon as the request is closedIt exists only to confirm who you are. Keeping it afterwards would create the risk it was meant to prevent.
Unsuccessful job applications12 months from the decisionTo answer questions about the decision and to contact you about a later opening. Deleted sooner on request.
Client project records, correspondence, and documentationDuration of the engagement, then 3 yearsTo support the delivered system, honour warranties, and respond to questions after handover.
Signed contracts and their variations3 years after the contract ends, longer if a dispute is liveLimitation periods for contractual claims.
Invoices, accounting, and tax records8 financial yearsStatutory minimum. This overrides a deletion request.
Access and audit logs for systems we operate12 months, or the period the client contract specifiesSecurity investigation and accountability for administrative actions.
Personal data inside a client system we operateSet by the client, in its contract with usThe client is the Data Fiduciary and decides. We apply what the contract says.
IP addresses used for form rate limitingHeld in memory for minutes, then discardedAbuse prevention only. Never written to disk.

03Obligations that override a deletion request

Indian law requires certain records to be retained for a fixed minimum. We cannot delete these on request, and any organization that tells you otherwise is not being straight with you.

RecordMinimum periodRequirement
Books of account, invoices, and financial records8 financial yearsCompanies Act, 2013 (s.128) and Income-tax Act, 1961
GST invoices and related records72 months from the annual-return due dateCentral Goods and Services Tax Act, 2017 (s.36)
Signed contracts and their variations3 years after the contract ends, or longer where a dispute is liveLimitation Act, 1963

We may also need to suspend deletion of specific records where a legal claim, investigation, or regulatory request is live. Where that applies to your request we will tell you which records are affected and why, and delete them once the hold lifts.

04Data inside systems we operate for clients

Where we operate a system for a client, the retention periods for the personal data inside it are the client's decision, set in the contract between us. We implement what it says; we do not set the period ourselves and we do not keep the data for our own purposes.

At the end of an engagement we return or delete the client's data as the contract directs, and we remove our administrative access. Because the client holds the repository, the database, and the cloud accounts in its own name throughout, ending the engagement does not require us to hand anything back - it requires us to withdraw.

If you are an individual whose data sits in a client's system, the retention period is theirs to set and theirs to change. Direct the request to them. See section 2 of the Privacy Policy.

05Backups and why deletion is not instant

Deleting a record from a live system does not immediately remove it from encrypted backups, which exist so that data can be recovered after a failure or an attack. Rewriting backup history on demand would defeat that purpose and is not something any responsible operator does.

Deleted records therefore persist in backups until those backups age out on their normal cycle. While a record remains in a backup it is not used, not restored to live systems, and not accessible in the ordinary course. If a backup is ever restored, deletions already applied are re-applied to the restored data.

06How deletion actually works

  1. You ask. Through Manage my data or by writing to support@shasamtechnologies.com.
  2. We verify it is you. Using the minimum information needed to be confident.
  3. We identify what we hold, across mailboxes, project records, and any system we operate on our own behalf.
  4. We separate what must be kept, apply the deletion to everything else, and tell you specifically what was retained and under which obligation.
  5. We confirm in writing, within 30 days of verifying the request.

We keep a minimal record that a deletion request was made and completed - the date, the type of request, and the outcome. That record is how we can demonstrate we honoured it. It is not used to re-identify you or to rebuild what was deleted.

07Grievances and how to reach a person

If anything in this document, or anything we have done with your information, is not right, raise it with our Grievance Officer. You do not need to use any particular form of words.

We acknowledge grievances within 48 hours and aim to resolve them within 15 days, in line with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

If you are not satisfied with our response on a personal-data matter, you may complain to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023. Approaching us first is not a precondition, but it is usually faster.

Have a question or an idea worth moving?