Product: VettiGuard Product owner and provider: Ikemba Tech (ABN 82 565 415 510) Effective date: 25 September 2026 Version: 1.3
1. Principle
VettiGuard retains information only for as long as reasonably required for the purpose for which it was collected, security and fraud prevention, configured customer requirements, contractual obligations, disputes or applicable law. Retention should be shorter for high-sensitivity evidence where continued storage is not necessary.
2. Retention classes
VettiGuard may use the following retention classes rather than a single period for every record:
- Transient capture data: kept only long enough to complete the active verification and any immediate governed finalisation or troubleshooting requirement;
- Biometric enrolment data: retained while an authorised enrolment remains active, subject to revocation, replacement, inactivity or customer policy;
- Identity verification evidence: retained according to the configured identity policy and any lawful customer requirement, with evidence minimisation after finality where configured;
- Verification outcomes and consent evidence: may be retained longer than raw evidence to support auditability, dispute handling and policy governance;
- Security and API logs: retained for a period proportionate to investigation, abuse prevention and operational needs;
- Account and contractual records: retained while the account is active and for a reasonable period afterwards where needed for legal, tax, dispute or security purposes; and
- Backups: retained according to backup rotation and disaster-recovery requirements, with access restricted and deletion occurring through normal expiry or secure sanitisation.
3. No invented universal period
Unless a specific product page, customer policy, order form or law states a period, VettiGuard does not represent that every category is retained for a fixed number of days or years. The configured retention applicable to an identity journey should be captured with the policy version where supported.
4. Deletion and de-identification
When personal information is no longer required, VettiGuard will take reasonable steps to destroy it or de-identify it, taking account of sensitivity, technical feasibility and legal requirements. Deletion should apply to copies under VettiGuard's control, including backups through normal rotation where immediate deletion is not technically practicable.
5. Biometric revocation
Revocation prevents future authorised use of an enrolment. Where the underlying biometric reference is no longer required, it should also be deleted or rendered unusable according to the applicable retention and backup process.
6. Legal holds
An authorised legal hold may temporarily suspend scheduled deletion where information is reasonably required for litigation, a regulator, law enforcement, a legal obligation or a preserved dispute. Legal holds must be limited to the information and period reasonably required and access must remain restricted.
7. Customer deletion requests
Customers may request deletion of eligible Customer Data. VettiGuard may require identity or authority verification before performing a destructive request. VettiGuard will explain where information cannot immediately be deleted because of lawful retention, security, backup or dispute requirements.
8. Individual requests
An individual seeking deletion, access or correction should contact VettiGuard or, where the relevant information was submitted by a VettiGuard customer, the requesting customer. VettiGuard will coordinate with the customer where appropriate.
9. Secure disposal
VettiGuard should use appropriate technical and organisational deletion controls, such as cryptographic or database deletion, secure file removal, access revocation, backup expiry, provider deletion processes and documented lifecycle jobs. Sensitive identity evidence must not be left in ordinary support tickets, email attachments or debug logs.