Personal Data Retention and Destruction Policy
Owner: RUCONN management / legal / information security
1. Purpose
This policy aims to ensure that personal data is deleted, destroyed, or anonymized when its processing purpose ends and that backups and legal-hold processes are controlled.
2. Principles
- Purpose-bound, limited, and proportionate retention.
- Separation of active data from backups, traffic records, and legal holds.
- Communication of deletion requests to service providers.
- Provable recording of destruction activities.
- Automatic blocking of access to data whose retention period has expired.
3. Retention Schedule
| Data/activity | Active retention | Deletion/backup period | Basis/note |
|---|---|---|---|
| Account and profile | While the account is active | Without delay from active systems after account deletion; backups within no more than 30 days | Performance of the contract |
| Email and phone verification code | During code validity and security checks | Within 24 hours; failed-attempt logs for the security period | Account security |
| Raw location and background history | For as long as the feature requires | No more than 30 days from collection | User instruction; data minimization |
| Event distance result | For as long as a current result is required | Old results are updated/deleted as soon as possible | No permanent route profile should be created |
| Active group message | While the chat/account is active or until deletion | Deleted-message backups within no more than 30 days | Group context, user request |
| Active photo/media | While the content is active or until deletion | Deleted-content backups within no more than 30 days | Visibility and content service |
| Report/moderation file | Throughout review and appeal | Recommended 3 years after closure; until completion if litigation/review is pending | Legitimate interest/establishment of rights |
| Super-admin access log | For audit purposes | Recommended 2 years | Unauthorized-access audit |
| Security and error log | For the risk and technical-need period | Recommended 1 year; critical-incident files may be kept longer | Information security |
| Law No. 5651 traffic information | Where a legal obligation applies | For the period under Article 5/3 of Law No. 5651 and applicable secondary legislation; separate from product logs | Role confirmation required |
| Explicit-consent and version record | While consent is valid and the evidentiary need continues | Limited to the relevant limitation period | Burden of proof |
| KVKK request file | Throughout the request and complaint | Recommended 3 years after closure | Legal obligation/establishment of rights |
| Contract and user-acceptance record | Throughout the contractual relationship | For the relevant legal limitation period | Establishment of rights |
| Age-verification document | At the time of verification | Delete without delay after obtaining the result; retain only the 18+ outcome | Data minimization |
4. Periodic Destruction
Data that cannot be deleted automatically is reviewed in a periodic destruction cycle at least every six months. Automated short periods, such as the 30-day location and backup periods, are applied without waiting for the periodic destruction date.
5. Deletion Methods
- Secure deletion or anonymization in the database,
- removal of files and previous versions from object storage,
- clearing search indexes and caches,
- revocation of access authorization and destruction of cryptographic keys,
- deletion through a service-provider API or instruction,
- final removal within 30 days through backup rotation.
6. Legal Hold
For litigation, an official request, a data breach, or a serious complaint, a legal hold is opened for the relevant record. The hold must be limited to the necessary record, access-restricted, and time-bound. When its reason ends, the normal destruction schedule applies.
7. Records and Audit
For each destruction activity, the data category, system, date, method, responsible person, and result are recorded. The service provider’s deletion confirmation is added to the file. The policy is reviewed at least annually and whenever a new feature or provider is introduced.