Data Retention Policy
| Data Category | Retention Period | Reason |
|---|---|---|
| Visitor logs & IP records | 24 months | Security monitoring |
| Audit / activity logs | 36 months | Security & legal compliance |
| User account data | Active + 12 months post-deletion | Contract fulfilment |
| Veterinary case records | Indefinite (institution-controlled) | Conservation records |
| Uploaded documents | Active + 6 months post-deletion | Data integrity |
| Session cookies | Session / 30 days (remember-me) | Authentication |
| API keys | Until regenerated or account closure | API access |
| Password reset tokens | 1 hour | Security |
| Financial / billing records | 7 years | Legal / tax compliance |
After expiry, data is permanently deleted from all systems and backups within 90 days. Anonymised aggregate statistics may be retained indefinitely.