Data Retention Policy
Version: v2-2026-09-18
1. What this policy covers
How long GadVerify keeps different categories of data, and what happens to a business's data after account closure or after a subscription period is not renewed. This page expands on section 9 (Retention) of our Privacy Policy with the specific timeframes for each category of data; where this page and the Privacy Policy differ in detail, this page is the more specific and current statement of our retention practice.
2. Account data, while active
Account data (business and staff profile details, role and permission assignments, subscription and billing metadata) is kept for as long as the account remains active, so the platform can function day to day.
3. Transaction, sales, and payroll records
Payroll records are retained indefinitely, for financial recordkeeping purposes that don't depend on whether the account that generated them is still open.
Sales, inventory movement, and customer transaction records are retained for as long as the account is active, and continue to be retained for at least 5 years after account closure, matching standard financial recordkeeping practice — see section 7 below for exactly what happens at that 5-year point. Changing a price or setting later never rewrites what a past receipt or report actually said, and these records remain available for tax, audit, or dispute purposes for as long as they're retained.
4. Stolen and lost device reports
A device report's core purpose — letting anyone check a device's status by reference number, even without an account — means reports are not deleted simply because time has passed; doing so would silently make a previously-flagged stolen device look clean again.
- Resolved reports (marked recovered, resolved, or rejected on review): kept indefinitely as a historical record, in the same way a resolved dispute or closed case is kept, so the platform's match history stays accurate and auditable.
- Unresolved reports (still active, with no resolution recorded): kept active indefinitely while unresolved — an open report is precisely the thing the check tool exists to surface, and there is no expiry that removes or downgrades an unresolved report purely due to age. What does happen after 6 months unresolved: the report is automatically flagged for internal review by platform staff, so a stale report gets a second look rather than sitting unattended indefinitely. This flag is purely internal — it never hides, changes, or removes the report from the public or business stolen-device check, which keeps working exactly as before. A report may still be updated or closed at any time through the normal recovery and dispute review process described elsewhere on the platform.
5. Audit logs
Security-relevant and stolen-device-relevant audit log entries (who flagged a device, who checked one, who changed a permission, login attempts) are retained indefinitely, to support fraud investigation, account security review, and dispute resolution regardless of how much time has passed. Audit records are also relied on as evidence in disputes, which is part of why they are not subject to any deletion schedule.
6. Backups
Encrypted backups of the platform's database are kept separately from the live data described above, for disaster recovery only, on a rolling 30-day retention schedule — a backup older than 30 days is automatically deleted, and a backup is never used to restore data a business or platform administrator has intentionally and permanently deleted through normal use of the platform.
7. After account closure vs. after non-renewal
Non-renewal: if a business does not renew its subscription at the end of a paid period, operational access (point of sale, inventory, staff management, and related features) ends at the end of that period, exactly as described in our Terms & Conditions, section 6, and our Refund Policy, section 5. The business's data is not deleted or altered by non-renewal; subscribing again restores access to the same data.
Account closure: a business account may be deactivated (by owner request or platform decision) or archived (long-term, treated as effectively closed), as described in our Terms & Conditions. Closure blocks operational access in the same way non-renewal does, but does not immediately delete the business's data.
Once an account has been closed (deactivated or archived) for 5 years, its inventory, sales, and customer records are permanently deleted — matching standard financial recordkeeping retention practice, and consistent with section 3 above. Payroll records, audit logs (section 5), and stolen device reports (section 4) are never deleted by this process, regardless of how long the account has been closed. If a closed account is reactivated before the 5-year point, the clock resets: it only starts counting again from the date of any later closure.
8. Nigeria Data Protection Act 2023
Consistent with the data minimization and storage limitation principles of the Nigeria Data Protection Act 2023, we aim to keep personal data only for as long as necessary for the purposes described above, and no longer than what is required for the legal, financial, security, and dispute-resolution reasons stated on this page. You may request a copy of, correction to, or deletion of personal data we hold about you, subject to the retention reasons described above, using the contact details on our Contact page — see also section 10 of our Privacy Policy.
9. Changes to this policy
We may update this policy, including the specific retention periods above, from time to time as our practices and legal obligations evolve.
10. Governing law
This policy is governed by the laws of the Federal Republic of Nigeria, including the Nigeria Data Protection Act 2023 and other applicable data protection legislation.
This document is a working draft prepared for internal review and has not yet been reviewed or approved by a licensed attorney. It should not be treated as final or legally binding until that review is complete.