KiTech Software legal
Data Retention Policy
How KiTech Software determines retention periods and securely disposes of information.
1. Purpose
This policy explains the principles KITECH SOFTWARE LTD uses to determine how long personal information and business records are retained.
It applies to information controlled by KiTech Software. Product-specific notices, customer agreements, and self-hosted deployments may define different operational periods.
2. Retention principles
We retain information only for as long as reasonably necessary to:
- provide and administer a requested service;
- maintain security, integrity, auditability, and service continuity;
- meet contractual commitments;
- comply with legal, regulatory, tax, accounting, and reporting obligations;
- investigate abuse, fraud, incidents, and disputes;
- establish, exercise, or defend legal claims; and
- protect the rights and safety of users, KiTech, partners, and the public.
We consider the nature, sensitivity, volume, purpose, legal requirements, user expectations, technical constraints, and potential harm associated with continued retention.
3. General retention categories
The following categories describe the normal approach. A product-specific notice or contract may provide more precise periods.
Account and profile information
Retained while the account or relevant relationship remains active and for a limited period afterwards to complete deletion, resolve disputes, prevent abuse, and meet legal obligations.
User content
Retained while required to provide the service and according to user, organisation, workspace, retention, deletion, legal-hold, and backup settings applicable to the product.
Security, audit, and access records
Retained for a period proportionate to the security and compliance risk. High-risk or regulated services may require longer audit periods than the public website.
Support and communications
Retained while an enquiry, incident, or support relationship remains active and afterwards where needed for service history, quality, security, dispute resolution, or legal obligations.
Billing, tax, and company records
Retained for the periods required by applicable tax, accounting, corporate, anti-fraud, and financial-record laws.
Website preference data
The public website’s theme preference remains in the visitor’s browser until the visitor removes it. KiTech does not receive the stored theme value as a separate account record.
4. Deletion and anonymisation
When information is no longer required, we delete it, irreversibly anonymise it, or securely isolate it pending disposal.
Deletion from active systems may not immediately remove every backup copy. Backups are protected, rotated, and deleted or overwritten according to the relevant backup schedule. Information restored from a backup remains subject to the original deletion requirement.
5. Legal holds and exceptions
Deletion may be delayed where information must be preserved for:
- a legal or regulatory obligation;
- litigation, investigation, audit, or dispute;
- fraud, abuse, security, or safeguarding purposes;
- protection of another person’s rights or safety; or
- another lawful and proportionate reason.
Only the information required for that purpose will be retained, and access will be restricted appropriately.
6. Customer-managed and self-hosted deployments
An organisation operating a customer-managed or self-hosted deployment normally determines its own retention periods and is responsible for configuring and enforcing them.
KiTech may retain limited support, licensing, security, or contractual records relating to that organisation even when KiTech cannot access the deployment’s user content.
7. Reviews
Retention schedules are reviewed when legal requirements, product architecture, security risks, contractual commitments, or business purposes materially change.
8. Contact
Questions about retention or a request concerning information controlled by KiTech may be sent to hello@kitechsoftware.com.