Skip to content
Publisher
WiseWave Limited
Category
Privacy & Data
Effective date
Effective 2026-07-01
Last updated
Updated 2026-07-17

Data Retention Policy

Reading note. This Policy owns the retention periods. Where a period is fixed in the platform it is stated; where it is set by law or pending an assessment it is described as such and flagged for counsel. The at-a-glance table is in §6; per-category detail follows.

1. Purpose

Purpose. To set out how long WiseWave Limited keeps personal data on Tirvea, when and how it is deleted, how archival and legal holds work, and how data is securely disposed of. This Policy is the single source of retention periods for the platform.

2. Scope

Purpose. To state what this Policy covers. It applies to all personal data processed through the Service and to every retention, deletion, archival, legal-hold, and disposal decision. It references, but does not restate, how data is processed (Privacy Policy, /legal/privacy) or the lifetimes of cookies (Cookie Policy, /legal/cookies).

3. Definitions

Purpose. To define retention terms. Data-protection terms are defined in the Privacy Policy (/legal/privacy).

  • "Retention period" - the length of time we keep a category of personal data.
  • "Legal hold" - a suspension of normal deletion where data must be preserved for a legal or safety reason.
  • "Tombstone" - an anonymised account shell that remains after deletion, pending final cleanup.
  • "Secure disposal" - deletion or irreversible anonymisation so that data can no longer be recovered or attributed.

4. Retention Principles

Purpose. To state the principles that govern retention. We keep personal data only for as long as necessary for the purpose for which it was collected (storage limitation); we minimise what we keep; we delete or anonymise data when it is no longer needed; we retain data longer only where the law requires it or a legal hold applies; and we dispose of data securely. These principles reflect the GDPR and are applied consistently across the categories below.

Purpose. To connect retention to a lawful basis. We retain data on the bases set out in the Privacy Policy (/legal/privacy): performance of the contract (while your account is active), compliance with legal obligations (for example, tax and accounting records), our legitimate interests (for example, security, fraud prevention, and safety), and consent (for example, biometric data). Retention beyond the active life of an account is limited to what a legal obligation, a legal hold, or a compelling legitimate interest requires.

6. Retention Matrix

Purpose. The canonical, at-a-glance retention periods. Where a period is fixed in the platform it is shown; "while active" means for the life of the account; "as required by law" and "pending assessment" are flagged for counsel.

Data categoryRetention periodBasis
Account and profile dataWhile active; erased within 30 days of deletionContract; storage limitation
Authentication dataWhile active; abandoned/unconfirmed rows swept after 24 hoursContract; security
Profile photos and uploadsWhile active; removed on deletionContract
MessagesWhile active; removed on deletion, subject to safety/legal holdsContract; legitimate interests
Identity verification (outcomes + opaque reference)While relevant to the account; no documents storedContract; legal obligation
Photo verification (outcome + opaque reference)While relevant; provider media transientConsent; legitimate interests
Biometric face referenceWhile verification valid; rotated periodically; destroyed on withdrawal or deletion. Exact periods pending DPIAExplicit consent (Art. 9)
Moderation and safety recordsRetained as long as necessary to enforce rules and meet obligations. Exact period to be set by counselLegitimate interests; legal obligation
ReportsRetained as long as necessary. Exact period to be set by counselLegitimate interests
Appeals recordsRetained to handle appeals and for accountability. Exact period to be set by counselLegitimate interests
Audit records (auth/verification/admin events)Append-only; retained for accountability. Exact period to be set by counselLegitimate interests; legal obligation
Security logsRetained for a limited period for fraud prevention. Exact period to be set by counselLegitimate interests
Payment and billing recordsRetained as required by tax and accounting law. Exact period per law, to be set by counselLegal obligation
Temporary enforcement restrictionsDefault 7 days (auto-expiry)Legitimate interests
Device security identifier (cookie)Up to 12 monthsLegitimate interests
Deleted account shell (tombstone, no personal data)Personal data erased within 30 days of the request; the anonymised shell is retained only while legally required linked records (e.g. payment/tax) demand it, then removedStorage limitation; legal obligation

[Legal review required before publication - set the exact periods marked "to be set by counsel" and confirm the biometric periods after the DPIA.]

7. Account Information

Purpose. Retention of account and profile records. We keep account information while your account is active. On deletion, it is erased within 30 days, except records subject to a legal or safety hold (§24). See the Privacy Policy §8 (/legal/privacy).

8. Authentication Data

Purpose. Retention of authentication records. Authentication data is kept while your account is active. Abandoned or unconfirmed authentication rows are swept after 24 hours by a scheduled cleanup. One-time passcodes are short-lived and managed by our authentication provider; the verification lock window is 15 minutes. Device security identifiers are described in §19.

9. Profile and Photos

Purpose. Retention of profile content and uploaded photos. Profile content and photos are kept while your account is active and removed on deletion. Photo moderation records are covered in §14.

10. Messages

Purpose. Retention of messages. Messages are kept while your account is active and removed on account deletion, subject to safety or legal holds (§24). See the Privacy Policy §13 (/legal/privacy).

11. Identity Verification Data

Purpose. Retention of identity-verification data. In Tirvea's systems we keep only the outcome and an opaque provider reference; we do not store identity documents. This is retained while relevant to the account. Provider-held media is handled under the provider's terms. See the Identity Verification Policy (/legal/identity-verification).

12. Photo Verification Data

Purpose. Retention of photo-verification data. We keep only an opaque provider reference and the outcome; provider-held capture media is transient. This is retained while relevant to the account. See the Photo Verification Policy (/legal/photo-verification).

13. Biometric Information

Purpose. Retention of biometric data. The biometric face reference is kept while your verification is valid, rotated periodically, and destroyed when you withdraw consent or delete your account. The exact rotation and deletion periods are configuration-driven and pending a Data Protection Impact Assessment. Full handling is in the Biometric Information Policy (/legal/biometric-data). [Legal review required before publication - fix the biometric retention and rotation periods after the DPIA.]

14. Moderation and Safety Records

Purpose. Retention of moderation and safety records. Moderation outcomes, cases, and violation records are retained as long as necessary to enforce our rules, handle appeals, and meet legal obligations. Records are append-only and PII-stripped where practicable. Enforcement states are described in the Account Suspension Policy (/legal/account-suspension) and moderation in the Trust & Safety Policy (/legal/trust-safety). [Legal review required before publication - set the exact retention period.]

15. Reports

Purpose. Retention of user reports. Reports and their outcomes are retained as long as necessary to assess them, act on them, and meet legal obligations. Child-safety reports are handled under the Child Safety Policy (/legal/child-safety). [Legal review required before publication - set the exact retention period.]

16. Appeals Records

Purpose. Retention of appeals records. Appeals and their outcomes are retained to handle the appeal, support consistency and quality assurance, and meet obligations. The process is in the Appeals Policy (/legal/appeals). [Legal review required before publication - set the exact retention period.]

17. Audit and Security Logs

Purpose. Retention of audit and security records. Audit records (authentication, verification, moderation, and admin events) are append-only and retained for accountability; human actions are attributed to a human actor. Security logs are retained for a limited period for fraud prevention and security. See the Security Policy (/legal/security). [Legal review required before publication - set the exact audit and security-log retention periods.]

18. Payment and Billing Records

Purpose. Retention of billing records. Payment and billing records are retained as required by tax and accounting law. Card details are held by our payment provider, not by Tirvea. See the Privacy Policy §21 (/legal/privacy). [Legal review required before publication - confirm the exact statutory retention period for billing records.]

19. Cookies and Local Storage

Purpose. Retention of client-side storage. Cookie and local-storage lifetimes are set out in the Cookie Policy (/legal/cookies) and are consistent with this Policy. In particular, the device security identifier cookie lasts up to 12 months, and the theme preference is stored in local storage until you change or clear it.

20. Deactivation and Grace Period

Purpose. How deactivation affects retention. When you deactivate your account, it enters a grace state during which your data is retained so that you can restore the account by signing in. If you do not restore it, the account proceeds to deletion (§21). See the Account Deletion Policy (/legal/account-deletion).

21. Account Deletion

Purpose. How deletion affects retention. On deletion, personal data is hard-deleted promptly and the account shell is fully removed within 30 days, except for records we are required or permitted to retain for legal, tax, safety, or fraud-prevention reasons (§14-§18, §24), which are held for no longer than necessary. The full process is in the Account Deletion Policy (/legal/account-deletion).

22. Abandoned Accounts

Purpose. Retention of incomplete sign-ups. Abandoned or unconfirmed authentication rows (for example, a sign-up that is never completed) are swept after 24 hours by a scheduled cleanup, so incomplete registrations do not persist.

23. Anonymisation and Tombstoning

Purpose. How we anonymise on deletion. After deletion, an account is reduced to an anonymised tombstone shell (a tombstone identifier, no personal profile data) so that platform integrity is preserved while personal data is removed; the shell is cleared within 30 days. Identifiers used for security are stored only as salted hashes.

Purpose. When normal deletion is suspended. Where data must be preserved for a legal obligation, a valid legal request, or a safety or child-safety reason, we place it on a legal hold and retain it beyond the normal period, for no longer than the hold requires. Legal holds are currently a manual, organisational process; there is no dedicated legal-hold system (an implementation gap). Cooperation with authorities is described in the Law Enforcement Guidelines (/legal/law-enforcement). [Legal review required before publication - confirm legal-hold obligations and process.]

25. Backups

Purpose. Retention in backups. Backups are managed by our infrastructure providers on their own cycles; deleted data expires from backups as those cycles roll over. Tirvea does not operate a separate backup archive or a defined backup-retention schedule (an implementation gap). [Legal review required before publication - confirm the backup-retention cycle with the infrastructure providers and document it.]

26. Secure Disposal

Purpose. How we dispose of data. When a retention period ends, data is deleted or irreversibly anonymised so it can no longer be recovered or attributed. Deletion is carried out in our systems and, for provider-held data, under the provider's deletion terms. Security identifiers are retained only as salted hashes, which are destroyed with the account.

27. International Transfers

Purpose. Retention and transfers. Where retained data is processed by a provider outside the EEA, an appropriate transfer mechanism applies, as described in the Privacy Policy §39 (/legal/privacy). This Policy does not repeat that analysis.

28. Data Subject Rights

Purpose. Your rights over retained data. You may request access to, or erasure of, your personal data, subject to the exceptions in this Policy (legal, tax, safety, and hold reasons). Requests are handled as described in the Privacy Policy (/legal/privacy) and GDPR & Your Rights (/legal/gdpr). Erasure requests trigger the deletion process in §21.

29. Policy Updates

Purpose. How this Policy changes. We update this Policy to reflect changes in our practices or the law, including when we fix the periods currently marked for counsel. We update the "Last Updated" date and, for material changes, take reasonable steps to communicate them.

30. Contact

Purpose. How to reach us about retention.

  • Operator: WiseWave Limited (Company Number 762171)
  • Registered office: 39 Cooley Park, Dundalk, Co. Louth, A91 AP2V, Ireland
  • Email: info@tirvea.com

For data-subject requests, see GDPR & Your Rights (/legal/gdpr); for how your data is processed, the Privacy Policy (/legal/privacy).


Version history

  • v1.02026-07-17Initial master draft.