Products
Home/Legal/Data Retention

Data Retention Policy

How long WaZoBia-Books keeps personal and business data, why we keep it, and how we delete or anonymise it — aligned with NDPA s.24 storage limitation and international best practice.

Last updated: (2026-08-10)

Executive summary

WaZoBia Smartech LTD applies storage limitation: we retain personal and business data only for as long as necessary for the purposes collected, plus any period required by law. This standalone Data Retention Policy supplements our Privacy Policy and Data Protection Policy.

When retention ends, we delete, anonymise, or aggregate data using documented procedures. Residual copies in encrypted backups are overwritten on a rolling basis, usually within 90 days of production deletion.

Scope & applicability

This policy applies to personal data and business data processed by WaZoBia Smartech LTD through:

  • The WaZoBia-Books marketing website and legal pages
  • The WaZoBia-Books cloud accounting Service (SaaS)
  • Support, sales, billing, and compliance channels operated by us
  • Self-hosted, desktop, or enterprise deployments where we act as processor under a separate agreement

Where you act as an independent data controller for your employees, customers, or vendors inside the Service, you remain responsible for retention periods applicable to that data under your own policies and Nigerian tax law — we provide tools to export, archive, and delete.

Retention principles

Purpose limitation

Data is kept only for identified, documented purposes — not repurposed beyond what we disclosed.

Storage limitation (NDPA s.24)

We define maximum retention targets per category and review them at least annually.

Minimisation

We avoid collecting or keeping fields we do not need for service delivery or legal compliance.

Accountability

Retention decisions are logged; DSAR and deletion workflows are auditable.

Security in retention

Data at rest remains encrypted and access-controlled for the entire retention period.

Transparency

This schedule is published publicly; material changes are reflected with an updated “Last updated” date.

Retention schedule

The table below is our master retention schedule. Periods are targets; we may retain longer where statute, regulator direction, or an active legal hold requires it.

Data categoryExamplesRetention targetLegal basisEnd-of-life method
Active account & subscription profileName, email, role, plan tier, billing status, authentication metadataLife of contract + up to 90 days wind-downContract performance; NDPA s.24 storage limitationSecure deletion or anonymisation after wind-down unless legal hold applies
Business & accounting data (Service)Invoices, payroll, GL, inventory, bank reconciliation, tax recordsLife of account; statutory minimums up to 6+ years where Nigerian tax/company law requiresContract; legal obligation (tax, audit, NRS-related records)Export offered before closure; identifiers removed where deletion requested and law permits
Verified deletion requestsPersonal identifiers linked to a closed accountTarget deletion within 30 days of verified requestData subject rights (NDPA ss. 34–38); GDPR Arts. 17–18Production deletion + rolling backup overwrite within ~90 days
Website contact & sales enquiriesContact form name, email, company, message bodyUp to 24 months from last interactionLegitimate interests; consent where marketing follow-up requestedCRM/archive purge or anonymisation
DSAR & privacy request recordsRequest type, verification artefacts, response logsUp to 36 months after closure of requestLegal obligation; accountability (GDPR Art. 5(2))Restricted access; secure deletion after retention window
Security, audit & operational logsAuth events, IP addresses, API abuse signals, admin actionsTypically up to 24 months; longer if investigation requiresLegitimate interests; security; legal obligationAutomated log rotation; encrypted at rest
Billing & payment recordsInvoices to you, transaction references (not full card PAN)Up to 7 years where accounting/tax law requiresLegal obligationArchive with access controls; deletion when statutory period ends
Marketing consents & preferencesOpt-in records, unsubscribe events, GPC/opt-out flagsUntil withdrawal + up to 24 months evidence of consentConsent; CCPA/CPRA accountabilitySuppression list retention; preference centre update
Cookie & consent banner choicesEssential/analytics preference stored locally or server-sideUp to 12 months (renewed on revisit)Consent / legitimate interests for essential cookiesBrowser storage clear; server record deletion
Customer-configured cloud backupsExports to Azure Blob, Google Drive, OneDriveDefined by customer in their cloud tenantCustomer as controller of backup copyCustomer-managed lifecycle; we provide export/delete tools in-app
Disaster-recovery & platform backupsEncrypted database snapshots, file backupsRolling windows aligned with production deletion (typically ≤90 days)Legitimate interests; availabilityRolling overwrite; no restore to production after verified erasure except legal hold
Legal hold & litigationAny category subject to dispute, regulator inquiry, or court orderUntil hold released or obligation endsLegal obligation; establishment/defence of legal claimsIsolated preservation; deletion resumes when hold lifts

Account lifecycle

  1. 1. Registration & active use

    Data is retained for the full subscription term. Audit logs and backups run continuously with role-based access.

  2. 2. Suspension or non-payment

    We may restrict access but retain data for up to 90 days to allow reactivation and export, unless you request earlier deletion and no legal obligation prevents it.

  3. 3. Termination / cancellation

    You receive a wind-down window (typically 90 days) to export ledgers, payroll, and reports. We send reminders where contact details exist.

  4. 4. Verified deletion

    After identity and ownership checks, personal identifiers are deleted or anonymised within 30 days; backups roll off within ~90 days.

  5. 5. Residual legal records

    Minimal billing or tax artefacts may remain in sealed archives for statutory periods even after account deletion.

Deletion & anonymisation procedures

Deletion removes personal data from production systems so it cannot be reasonably accessed or reconstructed. Anonymisation irreversibly separates data from identifiers so individuals are no longer identifiable.

  • Requests via data subject request form or email to admin@wazobia-books.ng
  • Identity verification (account email, business ownership checks for multi-user workspaces)
  • Ticket logged with request ID, approver, and completion timestamp
  • Production purge scripts or soft-delete with cryptographic erasure of keys where applicable
  • Confirmation email when deletion completes, subject to legal exceptions

Backups & disaster recovery

Platform backups exist to ensure availability and recovery from failure — not as an indefinite archive. Encrypted snapshots follow rolling retention aligned with the schedule above. Restoring a backup after you have been deleted in production will not re-expose your data except where a legal hold explicitly requires preservation.

If you configure customer-managed backups (Azure, Google Drive, OneDrive), retention is controlled by your cloud settings. We recommend aligning those settings with your internal records-management policy and Nigerian statutory minimums.

Customer responsibilities

  • Define internal retention rules for payroll, HR, and customer PII you enter into the Service
  • Export or delete obsolete records using in-app tools before closing an account
  • Remove ex-employees and revoke access promptly when roles end
  • Configure backup destinations with appropriate lifecycle rules
  • Notify us at admin@wazobia-books.ng if you require a custom data processing or retention addendum (enterprise)

Review & changes

This policy is reviewed at least annually and after material changes to our product, subprocessors, or applicable law (NDPA, NDPR, GDPR). Updates are posted on this page with a revised “Last updated” date. Continued use of the Service after changes take effect constitutes acceptance where permitted by law.

Contact

Privacy lead: admin@wazobia-books.ng

Controller: WaZoBia Smartech LTD

Address: WaZoBia Smartech LTD, Kano, Lagos, and Abuja, Nigeria

Related: Privacy Policy — retention summary · Submit a data subject request