EIFS.ca policy

Data Retention Policy

Lifecycle principles for account, marketplace, file and operational records.

Version
2026-08-02-beta.1
Last updated
2026-08-02
Status
Beta draft
Legal review
Required
This operational draft reflects implemented private-beta controls. Canadian legal counsel must approve the final commercial policy before launch.

Retention principles

EIFS.ca retains data only while needed for an active workflow, security, audit, dispute, legal obligation or documented business purpose. Automated cleanup covers eligible temporary files, analytics events, contact payloads and rate-limit buckets.

Quarantined files are limited to seven days, malicious files are scheduled for prompt purge, and deleted files use a thirty-day recovery period unless legal or incident hold applies.

Deletion and holds

Deletion requests are evaluated against membership, active Project, billing, fraud, security and legal-hold obligations. Approved deletion uses secure removal or anonymization and creates only the minimum necessary audit evidence.