Executive summary
WaZoBia Smartech LTD applies storage limitation: we retain personal and business data only for as long as necessary for the purposes collected, plus any period required by law. This standalone Data Retention Policy supplements our Privacy Policy and Data Protection Policy.
When retention ends, we delete, anonymise, or aggregate data using documented procedures. Residual copies in encrypted backups are overwritten on a rolling basis, usually within 90 days of production deletion.
Scope & applicability
This policy applies to personal data and business data processed by WaZoBia Smartech LTD through:
- The WaZoBia-Books marketing website and legal pages
- The WaZoBia-Books cloud accounting Service (SaaS)
- Support, sales, billing, and compliance channels operated by us
- Self-hosted, desktop, or enterprise deployments where we act as processor under a separate agreement
Where you act as an independent data controller for your employees, customers, or vendors inside the Service, you remain responsible for retention periods applicable to that data under your own policies and Nigerian tax law — we provide tools to export, archive, and delete.
Retention principles
Purpose limitation
Data is kept only for identified, documented purposes — not repurposed beyond what we disclosed.
Storage limitation (NDPA s.24)
We define maximum retention targets per category and review them at least annually.
Minimisation
We avoid collecting or keeping fields we do not need for service delivery or legal compliance.
Accountability
Retention decisions are logged; DSAR and deletion workflows are auditable.
Security in retention
Data at rest remains encrypted and access-controlled for the entire retention period.
Transparency
This schedule is published publicly; material changes are reflected with an updated “Last updated” date.
Retention schedule
The table below is our master retention schedule. Periods are targets; we may retain longer where statute, regulator direction, or an active legal hold requires it.
| Data category | Examples | Retention target | Legal basis | End-of-life method |
|---|---|---|---|---|
| Active account & subscription profile | Name, email, role, plan tier, billing status, authentication metadata | Life of contract + up to 90 days wind-down | Contract performance; NDPA s.24 storage limitation | Secure deletion or anonymisation after wind-down unless legal hold applies |
| Business & accounting data (Service) | Invoices, payroll, GL, inventory, bank reconciliation, tax records | Life of account; statutory minimums up to 6+ years where Nigerian tax/company law requires | Contract; legal obligation (tax, audit, NRS-related records) | Export offered before closure; identifiers removed where deletion requested and law permits |
| Verified deletion requests | Personal identifiers linked to a closed account | Target deletion within 30 days of verified request | Data subject rights (NDPA ss. 34–38); GDPR Arts. 17–18 | Production deletion + rolling backup overwrite within ~90 days |
| Website contact & sales enquiries | Contact form name, email, company, message body | Up to 24 months from last interaction | Legitimate interests; consent where marketing follow-up requested | CRM/archive purge or anonymisation |
| DSAR & privacy request records | Request type, verification artefacts, response logs | Up to 36 months after closure of request | Legal obligation; accountability (GDPR Art. 5(2)) | Restricted access; secure deletion after retention window |
| Security, audit & operational logs | Auth events, IP addresses, API abuse signals, admin actions | Typically up to 24 months; longer if investigation requires | Legitimate interests; security; legal obligation | Automated log rotation; encrypted at rest |
| Billing & payment records | Invoices to you, transaction references (not full card PAN) | Up to 7 years where accounting/tax law requires | Legal obligation | Archive with access controls; deletion when statutory period ends |
| Marketing consents & preferences | Opt-in records, unsubscribe events, GPC/opt-out flags | Until withdrawal + up to 24 months evidence of consent | Consent; CCPA/CPRA accountability | Suppression list retention; preference centre update |
| Cookie & consent banner choices | Essential/analytics preference stored locally or server-side | Up to 12 months (renewed on revisit) | Consent / legitimate interests for essential cookies | Browser storage clear; server record deletion |
| Customer-configured cloud backups | Exports to Azure Blob, Google Drive, OneDrive | Defined by customer in their cloud tenant | Customer as controller of backup copy | Customer-managed lifecycle; we provide export/delete tools in-app |
| Disaster-recovery & platform backups | Encrypted database snapshots, file backups | Rolling windows aligned with production deletion (typically ≤90 days) | Legitimate interests; availability | Rolling overwrite; no restore to production after verified erasure except legal hold |
| Legal hold & litigation | Any category subject to dispute, regulator inquiry, or court order | Until hold released or obligation ends | Legal obligation; establishment/defence of legal claims | Isolated preservation; deletion resumes when hold lifts |
Account lifecycle
1. Registration & active use
Data is retained for the full subscription term. Audit logs and backups run continuously with role-based access.
2. Suspension or non-payment
We may restrict access but retain data for up to 90 days to allow reactivation and export, unless you request earlier deletion and no legal obligation prevents it.
3. Termination / cancellation
You receive a wind-down window (typically 90 days) to export ledgers, payroll, and reports. We send reminders where contact details exist.
4. Verified deletion
After identity and ownership checks, personal identifiers are deleted or anonymised within 30 days; backups roll off within ~90 days.
5. Residual legal records
Minimal billing or tax artefacts may remain in sealed archives for statutory periods even after account deletion.
Deletion & anonymisation procedures
Deletion removes personal data from production systems so it cannot be reasonably accessed or reconstructed. Anonymisation irreversibly separates data from identifiers so individuals are no longer identifiable.
- Requests via data subject request form or email to admin@wazobia-books.ng
- Identity verification (account email, business ownership checks for multi-user workspaces)
- Ticket logged with request ID, approver, and completion timestamp
- Production purge scripts or soft-delete with cryptographic erasure of keys where applicable
- Confirmation email when deletion completes, subject to legal exceptions
Backups & disaster recovery
Platform backups exist to ensure availability and recovery from failure — not as an indefinite archive. Encrypted snapshots follow rolling retention aligned with the schedule above. Restoring a backup after you have been deleted in production will not re-expose your data except where a legal hold explicitly requires preservation.
If you configure customer-managed backups (Azure, Google Drive, OneDrive), retention is controlled by your cloud settings. We recommend aligning those settings with your internal records-management policy and Nigerian statutory minimums.
Legal hold & litigation
When we receive a credible legal claim, regulatory inquiry, or court order, we may suspend routine deletion for affected data sets. Legal hold records include matter reference, scope, start date, and release date. Data subject deletion requests may be deferred only where law permits; we will explain the reason and expected timeline.
Customer responsibilities
- Define internal retention rules for payroll, HR, and customer PII you enter into the Service
- Export or delete obsolete records using in-app tools before closing an account
- Remove ex-employees and revoke access promptly when roles end
- Configure backup destinations with appropriate lifecycle rules
- Notify us at admin@wazobia-books.ng if you require a custom data processing or retention addendum (enterprise)
Review & changes
This policy is reviewed at least annually and after material changes to our product, subprocessors, or applicable law (NDPA, NDPR, GDPR). Updates are posted on this page with a revised “Last updated” date. Continued use of the Service after changes take effect constitutes acceptance where permitted by law.
Contact
Privacy lead: admin@wazobia-books.ng
Controller: WaZoBia Smartech LTD
Address: WaZoBia Smartech LTD, Kano, Lagos, and Abuja, Nigeria
Related: Privacy Policy — retention summary · Submit a data subject request