Data Retention Policy
Last updated: July 20, 2026
Version: 1.0
Important: This Data Retention Policy outlines how long Birch retains different types of data and the principles governing our retention practices. This policy complies with GDPR Article 5(1)(e) and other applicable data protection laws requiring data minimization and storage limitation.
1. INTRODUCTION AND PURPOSE
28labs Inc. ("Birch", "we", "us", "our") is committed to retaining personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. This Data Retention Policy provides transparency about our data retention practices and helps ensure compliance with applicable laws and regulations.
2. PRINCIPLES OF DATA RETENTION
Our data retention practices are governed by the following principles:
- Purpose Limitation: We retain data only for as long as necessary to fulfill the stated purposes
- Legal Compliance: We comply with all applicable legal retention requirements
- Data Minimization: We retain only the minimum data necessary
- Regular Review: We periodically review and update retention periods
- Secure Deletion: We ensure secure and irreversible deletion when retention periods expire
- Transparency: We maintain clear documentation of retention periods and practices
3. RETENTION PERIODS BY DATA CATEGORY
3.1 Healthcare and Medical Records
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Patient medical records | 10 years from last treatment | Healthcare regulations |
| Pediatric records | Until patient reaches age 25 | Child protection laws |
| Audio recordings | 90 days after processing | Data minimization |
| Clinical notes | 10 years from creation | Medical documentation requirements |
| Prescription records | 5 years from dispensing | Pharmaceutical regulations |
3.2 Account and User Data
| Data Type | Retention Period | Notes |
|---|---|---|
| Active account data | Duration of account + 30 days | Grace period for reactivation |
| Deleted account data | 90 days from deletion request | Recovery period |
| Login history | 12 months | Security monitoring |
| Professional credentials | Duration of account + 7 years | Regulatory compliance |
3.3 Technical and Security Data
| Data Type | Retention Period | Purpose |
|---|---|---|
| Security logs | 24 months | Security analysis and compliance |
| Access logs | 12 months | Audit trail |
| Error logs | 6 months | Debugging and improvement |
| Performance metrics | 3 months | Service optimization |
| Backup data | 30 days | Disaster recovery |
3.4 Communication and Support Data
| Data Type | Retention Period | Justification |
|---|---|---|
| Support tickets | 3 years from resolution | Service improvement |
| Email communications | 2 years | Business records |
| Marketing preferences | Until withdrawn + 3 years | Compliance proof |
| Feedback/surveys | 5 years | Product development |
3.5 Financial and Legal Data
| Data Type | Retention Period | Legal Requirement |
|---|---|---|
| Invoices and receipts | 7 years | Tax regulations |
| Payment records | 7 years | Financial compliance |
| Contracts | 10 years after expiration | Statute of limitations |
| Legal holds | Until released + 1 year | Litigation requirements |
4. FACTORS DETERMINING RETENTION PERIODS
We determine appropriate retention periods based on:
- Legal Requirements: Compliance with healthcare, tax, and data protection laws
- Regulatory Obligations: Medical board and healthcare authority requirements
- Contractual Obligations: Agreements with customers and partners
- Business Needs: Legitimate business purposes and operational requirements
- Risk Management: Protection against legal claims and disputes
- Data Subject Rights: Balancing retention with privacy rights
- Industry Standards: Best practices in healthcare data management
5. LITIGATION HOLD PROCEDURES
5.1 Litigation Hold Implementation:
- Triggering Events: Receipt of legal notice, reasonable anticipation of litigation, regulatory investigation, or subpoena
- Immediate Actions: Suspend automatic deletion, notify relevant personnel, identify and preserve relevant data
- Hold Notice: Written notice sent to all custodians within 24 hours
- Scope Documentation: Clear identification of data subjects, date ranges, and data types to be preserved
5.2 Hold Management:
- Legal Hold Register: Centralized tracking of all active holds
- Quarterly Reviews: Regular assessment of continuing need for holds
- Chain of Custody: Documented preservation of data integrity
- Release Procedures: Formal process for lifting holds when no longer required
- Communication: Regular updates to affected data subjects where permitted
6. BACKUP AND ARCHIVE RETENTION
6.1 Backup Retention Schedule:
| Backup Type | Frequency | Retention Period | Storage Location |
|---|---|---|---|
| Real-time replication | Continuous | N/A | Secondary region |
| Hourly snapshots | Every hour | 24 hours | Primary region |
| Daily backups | Daily at 2 AM UTC | 30 days | Cross-region |
| Weekly backups | Sundays | 12 weeks | Archive storage |
| Monthly archives | First Sunday | 1 year | Cold storage |
| Annual archives | January 1st | 7 years | Glacier storage |
6.2 Archive Management:
- Automated lifecycle policies for transitioning to archive storage
- Encrypted archives with key rotation every 365 days
- Annual verification of archive integrity
- Documented restoration procedures with tested RTOs
7. METADATA RETENTION
7.1 Types of Metadata Retained:
- Transactional Metadata: Creation date, modification history, access logs - retained for 24 months
- System Metadata: File properties, database schemas, relationships - retained with primary data
- Audit Metadata: Who, what, when, where of all data operations - retained for 7 years
- Clinical Metadata: Encounter details, provider information - retained per medical record requirements
- Technical Metadata: Format information, encryption keys references - retained for data lifetime + 1 year
7.2 Metadata Handling:
- Metadata is subject to the same security controls as primary data
- Deletion of primary data triggers corresponding metadata deletion
- Anonymized metadata may be retained longer for analytics
- Metadata backups follow the same retention schedule as primary data
8. SYSTEM LOGS RETENTION
8.1 Log Categories and Retention:
| Log Type | Content | Retention | Justification |
|---|---|---|---|
| Application logs | Errors, warnings, info | 90 days | Debugging |
| Security logs | Auth attempts, failures | 24 months | Security analysis |
| Audit logs | Data access, changes | 7 years | Compliance |
| Performance logs | Metrics, latency | 30 days | Optimization |
| Infrastructure logs | System events | 180 days | Troubleshooting |
| API logs | Requests, responses | 60 days | Integration support |
8.2 Log Management Practices:
- Automated log rotation and compression
- Centralized log aggregation with search capabilities
- Real-time alerting for critical events
- Regular log analysis for security threats
- Secure deletion after retention period expires
9. DISASTER RECOVERY TIMELINES
9.1 Recovery Objectives:
- Recovery Time Objective (RTO): Maximum 4 hours for critical services
- Recovery Point Objective (RPO): Maximum 1 hour of data loss
- Recovery Time Actual (RTA): Typical recovery within 2 hours based on drills
- Maximum Tolerable Downtime (MTD): 8 hours before significant business impact
9.2 Data Restoration Priorities:
- Tier 1 (0-2 hours): Authentication systems, current patient records, active conversations
- Tier 2 (2-4 hours): Recent medical records (last 30 days), user accounts, configuration data
- Tier 3 (4-8 hours): Historical records (30 days - 1 year), analytics data, training data
- Tier 4 (8-24 hours): Archived data, logs, non-critical backups
9.3 Disaster Recovery Testing:
- Quarterly DR drills with full restoration testing
- Annual third-party DR audit and certification
- Documented lessons learned and improvements
- Regular updates to DR runbooks and procedures
10. EXCEPTIONS TO STANDARD RETENTION PERIODS
5.1 Extended Retention May Apply When:
- Legal hold or litigation requires preservation
- Regulatory investigation is ongoing
- Patient safety concerns necessitate retention
- Specific legal requirements mandate longer periods
- Data subject provides explicit consent for extended retention
5.2 Early Deletion May Occur When:
- Data subject exercises right to erasure (where applicable)
- Data is no longer necessary for original purpose
- Consent is withdrawn (for consent-based processing)
- Data is found to be inaccurate or unlawfully processed
11. DATA DELETION PROCEDURES
6.1 Automated Deletion:
- Automated processes flag data reaching retention limits
- Scheduled jobs perform deletion after verification
- Deletion logs maintained for audit purposes
- Backup systems synchronized with retention policies
6.2 Manual Deletion Requests:
- Verified through identity confirmation
- Processed within 30 days of request
- Confirmation provided to requester
- Exceptions documented and communicated
6.3 Secure Deletion Methods:
- Cryptographic erasure for encrypted data
- Multiple overwriting passes for unencrypted data
- Physical destruction for hardware disposal
- Third-party certification for media destruction
12. ANONYMIZATION AND PSEUDONYMIZATION
Where possible, we employ data minimization techniques:
- Anonymization: Irreversibly removing identifying information for research and analytics
- Pseudonymization: Replacing identifiers with pseudonyms while maintaining data utility
- Aggregation: Combining data to prevent individual identification
- Data Masking: Obscuring sensitive fields while preserving data structure
Anonymized data may be retained indefinitely as it no longer constitutes personal data under GDPR.
13. CROSS-BORDER CONSIDERATIONS
Retention periods may vary by jurisdiction:
- European Union: GDPR requirements and member state specific laws
- United States: HIPAA and state-specific medical record laws
- United Kingdom: UK GDPR and NHS guidelines
- Other Jurisdictions: Local healthcare and privacy regulations
We apply the longest applicable retention period when multiple jurisdictions are involved.
14. RETENTION POLICY GOVERNANCE
9.1 Responsibilities:
- Data Protection Officer: Overall policy oversight and compliance
- Legal Team: Determining legal retention requirements
- IT Department: Implementing technical retention controls
- Department Heads: Ensuring team compliance
9.2 Policy Review:
- Annual review of retention periods
- Updates for new legal requirements
- Adjustment based on business changes
- Stakeholder consultation process
15. DATA SUBJECT RIGHTS
Regarding data retention, you have the right to:
- Know how long we retain your data
- Request deletion (subject to legal obligations)
- Object to extended retention
- Receive notification before deletion
- Export your data before deletion
- Lodge complaints with supervisory authorities
16. TRAINING AND AWARENESS
We ensure proper implementation through:
- Regular training on retention requirements
- Clear guidance for all staff
- Automated reminders for manual processes
- Compliance monitoring and audits
- Consequences for policy violations
17. THIRD-PARTY DATA PROCESSORS
We ensure our data processors:
- Comply with our retention requirements
- Delete data upon instruction
- Maintain appropriate security measures
- Provide deletion confirmations
- Support data portability requirements
18. BREACH AND INCIDENT MANAGEMENT
In case of incidents affecting retention:
- Immediate assessment of impact
- Preservation of affected data
- Notification to authorities and affected parties
- Documentation of incident and response
- Review and update of retention practices
19. CONTACT INFORMATION
For questions about our data retention practices:
Data Protection Officer:
Email: support@getbirch.com
Privacy Team:
Email: support@getbirch.com
Support:
Visit: /support
Important Notice
This Data Retention Policy is subject to change based on legal requirements and business needs. We will notify users of material changes through our Services or via email. Your continued use of Birch after such notifications constitutes acceptance of the updated policy.
Legal Compliance: This policy complies with GDPR Article 5(1)(e) (storage limitation), Article 13(2)(a) (retention period information), Article 17 (right to erasure), and other applicable data protection laws. Retention periods are determined based on legal requirements, legitimate interests, and the principle of data minimization.