This policy sets out how long Rebota retains different categories of personal and business data, and the deletion process that follows. It exists to reconcile two obligations that can otherwise conflict: your right to request erasure under the Digital Personal Data Protection Act, 2023, and Rebota's own statutory record-keeping obligations under tax, company and cyber-security law. Where a specific record is subject to a statutory retention period, that period takes precedence over a general erasure request for that record — but only for that record, and only until the statutory period expires.
| Data category | Examples | Retention period | Statutory basis |
|---|---|---|---|
| Account data | Name, email, phone, password hash, company | Duration of account + 90 days after closure | Contractual necessity / dispute defence window |
| Session & security logs | Login logs, IP address, device info, rate-limit records | 180 days minimum, stored in India | CERT-In Directions, 2022 |
| OTP / verification codes | OTP hash, verification tokens | Until used or expired (typically 10 minutes), then purged | Data minimisation — no ongoing purpose |
| Financial / GST records | Invoices, bills, purchase orders, payment records | 6 years from the end of the relevant financial year | GST Act, 2017 |
| Company books of account | Ledgers, subscription billing records | 8 years | Companies Act, 2013, Section 128 |
| Vendor bank/PAN details | Bank account, IFSC, PAN (encrypted at rest) | Duration of vendor relationship + statutory financial-record period above | GST/financial record-keeping + ongoing vendor relationship |
| Worker/labour records | Name, trade, wage, attendance, Aadhaar (last 4 digits) | Duration of engagement + applicable state labour-law period | State Shops & Establishments / labour law record-keeping |
| Project & site-execution data | BOQ, site logs, photos, QC/safety records | Duration of account, or per your own project-closeout policy | Contractual necessity; configurable by account owner |
| Marketing / notification consent | WhatsApp/email opt-in status | Until consent is withdrawn | Consent-based — DPDP Act |
| Deleted ("soft-deleted") records | Any record you delete in-app | 30 days recoverable, then permanently purged | Accidental-deletion recovery window |
| Backups | Full database backups | Rolling 90-day backup window | Disaster recovery |
Most records (a task, a document, a BOQ line) support in-app deletion, which soft-deletes the record — hidden from normal use, recoverable — for 30 days before permanent purge, protecting against accidental deletion.
When a business account is closed, we delete the account's operational data (projects, workers, vendors, site records) within 90 days, except for the record categories in Section 2 that carry an independent statutory retention period (financial/GST records, company books, and any security logs still within their 180-day window).
Where an individual (e.g. a worker or vendor whose data a business entered) requests erasure directly from us, we identify which business account the data belongs to and either refer the request to that Data Fiduciary, or action it ourselves where Rebota is the Data Fiduciary for that record. Any portion of the data subject to a statutory retention period in Section 2 is retained only for that category, ring-fenced from normal use, until that period lapses — we will tell you which parts were deleted immediately and which are retained under statutory hold, and why.
Deleting a record from the live system does not immediately remove it from existing backups; it is purged from backups on the next rotation, within the 90-day window in Section 2.