Legal Document

Data Retention & Deletion Policy

ApprovedVersion 1.0·Effective 2026-07-25·MVIN-LEGAL-006

MVIN Data Retention & Deletion Policy

1. Purpose

This policy defines how MVIN retains, archives and securely deletes data throughout its lifecycle.

The objectives are to:

  • Protect user privacy.
  • Meet legal obligations.
  • Reduce unnecessary data storage.
  • Improve security.
  • Maintain operational efficiency.
  • Support responsible data governance.

2. Scope

This policy applies to all data processed by MVIN, including:

  • User accounts
  • Property listings
  • Messages
  • Verification records
  • Transaction records
  • Audit logs
  • Analytics
  • Uploaded documents
  • Backup data
  • System logs

3. Data Lifecycle

Data generally moves through the following stages:

  1. Collection
  2. Active use
  3. Update
  4. Archive (where applicable)
  5. Secure deletion

Each stage should be managed according to this policy.

4. Retention Principles

MVIN will retain data only for as long as necessary to:

  • Deliver platform services.
  • Meet contractual obligations.
  • Comply with applicable laws.
  • Resolve disputes.
  • Prevent fraud.
  • Protect platform security.
  • Support legitimate business operations.

Data should not be retained indefinitely without justification.

5. Retention Schedule

User account information

Retained while the account is active and for a reasonable period after closure, subject to legal requirements.

Property listings

Retained while active, with archival where appropriate.

Messages

Retained according to operational needs and applicable law.

Verification records

Retained as required for trust, compliance and fraud prevention.

Audit logs

Retained based on security and operational requirements.

System logs

Retained according to operational monitoring requirements.

Backup data

Retained in accordance with the backup and disaster recovery policy.

Support records

Retained as required for customer support and legal obligations.

Retention periods may be adjusted where required by law or operational necessity.

6. User Requests

Where permitted by applicable law, users may request:

  • Access to their data.
  • Correction of inaccurate information.
  • Deletion of personal information.
  • Restriction of certain processing activities.

MVIN may decline requests where retention is legally required or necessary for legitimate business purposes.

7. Secure Deletion

When data reaches the end of its retention period, MVIN should take reasonable steps to:

  • Permanently delete digital records where appropriate.
  • Remove associated metadata where feasible.
  • Delete redundant copies where practical.
  • Ensure deleted information cannot be easily reconstructed.

Deletion methods should be appropriate to the sensitivity of the data.

8. Backups

Backup systems may temporarily retain deleted information until backup rotation cycles are completed.

Backups should:

  • Be encrypted where appropriate.
  • Be access-controlled.
  • Follow the Disaster Recovery Policy.
  • Be securely destroyed when no longer required.

9. Legal Holds

Where required by law, regulation or legal proceedings, deletion may be suspended.

Legal holds take precedence over normal retention schedules.

Once the legal hold is removed, normal retention procedures resume.

10. Data Archival

Information that is no longer actively used but must be retained may be archived.

Archived data should:

  • Remain secure.
  • Be access-controlled.
  • Be recoverable when required.
  • Be deleted when retention requirements expire.

11. Roles and Responsibilities

Platform Management

Responsible for:

  • Policy oversight
  • Governance
  • Compliance monitoring

Engineering

Responsible for:

  • Implementing retention controls
  • Secure deletion processes
  • Backup management
  • Access controls

Operations

Responsible for:

  • Operational compliance
  • Record management
  • Incident reporting

All personnel handling data are expected to follow this policy.

12. Policy Review

This policy should be reviewed:

  • Before major platform releases.
  • Following significant legal changes.
  • After security incidents involving data.
  • During periodic governance reviews.

Updates should be documented and approved.

Guiding Principle

Data should be retained only for as long as it provides legitimate value or is required by law.

Responsible data lifecycle management strengthens user trust, improves security and supports long-term platform sustainability.

Approved by:

MVIN Management

Version 1.0