Compliance and Privacy
10. Data Retention
Compliance and Privacy: 10. Data Retention
Device Fingerprint data is retained only for the period necessary for device identification, security analysis, troubleshooting, compliance audit, dispute handling, and service improvement.
Unless otherwise agreed in an order, product configuration, or data processing agreement, the following retention periods apply:
| Data category | Retention period |
|---|---|
| Temporary tokens, online or offline query status | 10 minutes |
| Raw collection signals | No more than 12 months |
fp,risk_code,risk_label,client_ip,client_type,access_list query results | No more than 12 months |
| Security logs, error logs, and audit logs | No more than 12 months |
| Customer application configurations, list configurations, and key metadata | During the customer account term |
| Aggregated, anonymous, or de-identified data | May be retained long-term where it does not identify an individual or customer |
If a customer requests deletion or export of data related to its application, Geelab will assist according to the data processing agreement and available technical capabilities. Backup data will be deleted on a rolling basis according to backup cycles.