MVIN Data Retention & Deletion Policy
1. Purpose
This policy defines how MVIN retains, archives and securely deletes data throughout its lifecycle.
The objectives are to:
- Protect user privacy.
- Meet legal obligations.
- Reduce unnecessary data storage.
- Improve security.
- Maintain operational efficiency.
- Support responsible data governance.
2. Scope
This policy applies to all data processed by MVIN, including:
- User accounts
- Property listings
- Messages
- Verification records
- Transaction records
- Audit logs
- Analytics
- Uploaded documents
- Backup data
- System logs
3. Data Lifecycle
Data generally moves through the following stages:
- Collection
- Active use
- Update
- Archive (where applicable)
- Secure deletion
Each stage should be managed according to this policy.
4. Retention Principles
MVIN will retain data only for as long as necessary to:
- Deliver platform services.
- Meet contractual obligations.
- Comply with applicable laws.
- Resolve disputes.
- Prevent fraud.
- Protect platform security.
- Support legitimate business operations.
Data should not be retained indefinitely without justification.
5. Retention Schedule
User account information
Retained while the account is active and for a reasonable period after closure, subject to legal requirements.
Property listings
Retained while active, with archival where appropriate.
Messages
Retained according to operational needs and applicable law.
Verification records
Retained as required for trust, compliance and fraud prevention.
Audit logs
Retained based on security and operational requirements.
System logs
Retained according to operational monitoring requirements.
Backup data
Retained in accordance with the backup and disaster recovery policy.
Support records
Retained as required for customer support and legal obligations.
Retention periods may be adjusted where required by law or operational necessity.
6. User Requests
Where permitted by applicable law, users may request:
- Access to their data.
- Correction of inaccurate information.
- Deletion of personal information.
- Restriction of certain processing activities.
MVIN may decline requests where retention is legally required or necessary for legitimate business purposes.
7. Secure Deletion
When data reaches the end of its retention period, MVIN should take reasonable steps to:
- Permanently delete digital records where appropriate.
- Remove associated metadata where feasible.
- Delete redundant copies where practical.
- Ensure deleted information cannot be easily reconstructed.
Deletion methods should be appropriate to the sensitivity of the data.
8. Backups
Backup systems may temporarily retain deleted information until backup rotation cycles are completed.
Backups should:
- Be encrypted where appropriate.
- Be access-controlled.
- Follow the Disaster Recovery Policy.
- Be securely destroyed when no longer required.
9. Legal Holds
Where required by law, regulation or legal proceedings, deletion may be suspended.
Legal holds take precedence over normal retention schedules.
Once the legal hold is removed, normal retention procedures resume.
10. Data Archival
Information that is no longer actively used but must be retained may be archived.
Archived data should:
- Remain secure.
- Be access-controlled.
- Be recoverable when required.
- Be deleted when retention requirements expire.
11. Roles and Responsibilities
Platform Management
Responsible for:
- Policy oversight
- Governance
- Compliance monitoring
Engineering
Responsible for:
- Implementing retention controls
- Secure deletion processes
- Backup management
- Access controls
Operations
Responsible for:
- Operational compliance
- Record management
- Incident reporting
All personnel handling data are expected to follow this policy.
12. Policy Review
This policy should be reviewed:
- Before major platform releases.
- Following significant legal changes.
- After security incidents involving data.
- During periodic governance reviews.
Updates should be documented and approved.
Guiding Principle
Data should be retained only for as long as it provides legitimate value or is required by law.
Responsible data lifecycle management strengthens user trust, improves security and supports long-term platform sustainability.
Approved by:
MVIN Management
Version 1.0