Data Retention Policy

Last updated: July 20, 2026

Version: 1.0

Important: This Data Retention Policy outlines how long Birch retains different types of data and the principles governing our retention practices. This policy complies with GDPR Article 5(1)(e) and other applicable data protection laws requiring data minimization and storage limitation.

1. INTRODUCTION AND PURPOSE

28labs Inc. ("Birch", "we", "us", "our") is committed to retaining personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. This Data Retention Policy provides transparency about our data retention practices and helps ensure compliance with applicable laws and regulations.

2. PRINCIPLES OF DATA RETENTION

Our data retention practices are governed by the following principles:

  • Purpose Limitation: We retain data only for as long as necessary to fulfill the stated purposes
  • Legal Compliance: We comply with all applicable legal retention requirements
  • Data Minimization: We retain only the minimum data necessary
  • Regular Review: We periodically review and update retention periods
  • Secure Deletion: We ensure secure and irreversible deletion when retention periods expire
  • Transparency: We maintain clear documentation of retention periods and practices
3. RETENTION PERIODS BY DATA CATEGORY

3.1 Healthcare and Medical Records

Data Type Retention Period Legal Basis
Patient medical records 10 years from last treatment Healthcare regulations
Pediatric records Until patient reaches age 25 Child protection laws
Audio recordings 90 days after processing Data minimization
Clinical notes 10 years from creation Medical documentation requirements
Prescription records 5 years from dispensing Pharmaceutical regulations

3.2 Account and User Data

Data Type Retention Period Notes
Active account data Duration of account + 30 days Grace period for reactivation
Deleted account data 90 days from deletion request Recovery period
Login history 12 months Security monitoring
Professional credentials Duration of account + 7 years Regulatory compliance

3.3 Technical and Security Data

Data Type Retention Period Purpose
Security logs 24 months Security analysis and compliance
Access logs 12 months Audit trail
Error logs 6 months Debugging and improvement
Performance metrics 3 months Service optimization
Backup data 30 days Disaster recovery

3.4 Communication and Support Data

Data Type Retention Period Justification
Support tickets 3 years from resolution Service improvement
Email communications 2 years Business records
Marketing preferences Until withdrawn + 3 years Compliance proof
Feedback/surveys 5 years Product development

3.5 Financial and Legal Data

Data Type Retention Period Legal Requirement
Invoices and receipts 7 years Tax regulations
Payment records 7 years Financial compliance
Contracts 10 years after expiration Statute of limitations
Legal holds Until released + 1 year Litigation requirements
4. FACTORS DETERMINING RETENTION PERIODS

We determine appropriate retention periods based on:

  • Legal Requirements: Compliance with healthcare, tax, and data protection laws
  • Regulatory Obligations: Medical board and healthcare authority requirements
  • Contractual Obligations: Agreements with customers and partners
  • Business Needs: Legitimate business purposes and operational requirements
  • Risk Management: Protection against legal claims and disputes
  • Data Subject Rights: Balancing retention with privacy rights
  • Industry Standards: Best practices in healthcare data management
5. LITIGATION HOLD PROCEDURES

5.1 Litigation Hold Implementation:

  • Triggering Events: Receipt of legal notice, reasonable anticipation of litigation, regulatory investigation, or subpoena
  • Immediate Actions: Suspend automatic deletion, notify relevant personnel, identify and preserve relevant data
  • Hold Notice: Written notice sent to all custodians within 24 hours
  • Scope Documentation: Clear identification of data subjects, date ranges, and data types to be preserved

5.2 Hold Management:

  • Legal Hold Register: Centralized tracking of all active holds
  • Quarterly Reviews: Regular assessment of continuing need for holds
  • Chain of Custody: Documented preservation of data integrity
  • Release Procedures: Formal process for lifting holds when no longer required
  • Communication: Regular updates to affected data subjects where permitted
6. BACKUP AND ARCHIVE RETENTION

6.1 Backup Retention Schedule:

Backup Type Frequency Retention Period Storage Location
Real-time replication Continuous N/A Secondary region
Hourly snapshots Every hour 24 hours Primary region
Daily backups Daily at 2 AM UTC 30 days Cross-region
Weekly backups Sundays 12 weeks Archive storage
Monthly archives First Sunday 1 year Cold storage
Annual archives January 1st 7 years Glacier storage

6.2 Archive Management:

  • Automated lifecycle policies for transitioning to archive storage
  • Encrypted archives with key rotation every 365 days
  • Annual verification of archive integrity
  • Documented restoration procedures with tested RTOs
7. METADATA RETENTION

7.1 Types of Metadata Retained:

  • Transactional Metadata: Creation date, modification history, access logs - retained for 24 months
  • System Metadata: File properties, database schemas, relationships - retained with primary data
  • Audit Metadata: Who, what, when, where of all data operations - retained for 7 years
  • Clinical Metadata: Encounter details, provider information - retained per medical record requirements
  • Technical Metadata: Format information, encryption keys references - retained for data lifetime + 1 year

7.2 Metadata Handling:

  • Metadata is subject to the same security controls as primary data
  • Deletion of primary data triggers corresponding metadata deletion
  • Anonymized metadata may be retained longer for analytics
  • Metadata backups follow the same retention schedule as primary data
8. SYSTEM LOGS RETENTION

8.1 Log Categories and Retention:

Log Type Content Retention Justification
Application logs Errors, warnings, info 90 days Debugging
Security logs Auth attempts, failures 24 months Security analysis
Audit logs Data access, changes 7 years Compliance
Performance logs Metrics, latency 30 days Optimization
Infrastructure logs System events 180 days Troubleshooting
API logs Requests, responses 60 days Integration support

8.2 Log Management Practices:

  • Automated log rotation and compression
  • Centralized log aggregation with search capabilities
  • Real-time alerting for critical events
  • Regular log analysis for security threats
  • Secure deletion after retention period expires
9. DISASTER RECOVERY TIMELINES

9.1 Recovery Objectives:

  • Recovery Time Objective (RTO): Maximum 4 hours for critical services
  • Recovery Point Objective (RPO): Maximum 1 hour of data loss
  • Recovery Time Actual (RTA): Typical recovery within 2 hours based on drills
  • Maximum Tolerable Downtime (MTD): 8 hours before significant business impact

9.2 Data Restoration Priorities:

  1. Tier 1 (0-2 hours): Authentication systems, current patient records, active conversations
  2. Tier 2 (2-4 hours): Recent medical records (last 30 days), user accounts, configuration data
  3. Tier 3 (4-8 hours): Historical records (30 days - 1 year), analytics data, training data
  4. Tier 4 (8-24 hours): Archived data, logs, non-critical backups

9.3 Disaster Recovery Testing:

  • Quarterly DR drills with full restoration testing
  • Annual third-party DR audit and certification
  • Documented lessons learned and improvements
  • Regular updates to DR runbooks and procedures
10. EXCEPTIONS TO STANDARD RETENTION PERIODS

5.1 Extended Retention May Apply When:

  • Legal hold or litigation requires preservation
  • Regulatory investigation is ongoing
  • Patient safety concerns necessitate retention
  • Specific legal requirements mandate longer periods
  • Data subject provides explicit consent for extended retention

5.2 Early Deletion May Occur When:

  • Data subject exercises right to erasure (where applicable)
  • Data is no longer necessary for original purpose
  • Consent is withdrawn (for consent-based processing)
  • Data is found to be inaccurate or unlawfully processed
11. DATA DELETION PROCEDURES

6.1 Automated Deletion:

  • Automated processes flag data reaching retention limits
  • Scheduled jobs perform deletion after verification
  • Deletion logs maintained for audit purposes
  • Backup systems synchronized with retention policies

6.2 Manual Deletion Requests:

  • Verified through identity confirmation
  • Processed within 30 days of request
  • Confirmation provided to requester
  • Exceptions documented and communicated

6.3 Secure Deletion Methods:

  • Cryptographic erasure for encrypted data
  • Multiple overwriting passes for unencrypted data
  • Physical destruction for hardware disposal
  • Third-party certification for media destruction
12. ANONYMIZATION AND PSEUDONYMIZATION

Where possible, we employ data minimization techniques:

  • Anonymization: Irreversibly removing identifying information for research and analytics
  • Pseudonymization: Replacing identifiers with pseudonyms while maintaining data utility
  • Aggregation: Combining data to prevent individual identification
  • Data Masking: Obscuring sensitive fields while preserving data structure

Anonymized data may be retained indefinitely as it no longer constitutes personal data under GDPR.

13. CROSS-BORDER CONSIDERATIONS

Retention periods may vary by jurisdiction:

  • European Union: GDPR requirements and member state specific laws
  • United States: HIPAA and state-specific medical record laws
  • United Kingdom: UK GDPR and NHS guidelines
  • Other Jurisdictions: Local healthcare and privacy regulations

We apply the longest applicable retention period when multiple jurisdictions are involved.

14. RETENTION POLICY GOVERNANCE

9.1 Responsibilities:

  • Data Protection Officer: Overall policy oversight and compliance
  • Legal Team: Determining legal retention requirements
  • IT Department: Implementing technical retention controls
  • Department Heads: Ensuring team compliance

9.2 Policy Review:

  • Annual review of retention periods
  • Updates for new legal requirements
  • Adjustment based on business changes
  • Stakeholder consultation process
15. DATA SUBJECT RIGHTS

Regarding data retention, you have the right to:

  • Know how long we retain your data
  • Request deletion (subject to legal obligations)
  • Object to extended retention
  • Receive notification before deletion
  • Export your data before deletion
  • Lodge complaints with supervisory authorities
16. TRAINING AND AWARENESS

We ensure proper implementation through:

  • Regular training on retention requirements
  • Clear guidance for all staff
  • Automated reminders for manual processes
  • Compliance monitoring and audits
  • Consequences for policy violations
17. THIRD-PARTY DATA PROCESSORS

We ensure our data processors:

  • Comply with our retention requirements
  • Delete data upon instruction
  • Maintain appropriate security measures
  • Provide deletion confirmations
  • Support data portability requirements
18. BREACH AND INCIDENT MANAGEMENT

In case of incidents affecting retention:

  • Immediate assessment of impact
  • Preservation of affected data
  • Notification to authorities and affected parties
  • Documentation of incident and response
  • Review and update of retention practices
19. CONTACT INFORMATION

For questions about our data retention practices:

Data Protection Officer:

Email: support@getbirch.com

Privacy Team:

Email: support@getbirch.com

Support:

Visit: /support

Important Notice

This Data Retention Policy is subject to change based on legal requirements and business needs. We will notify users of material changes through our Services or via email. Your continued use of Birch after such notifications constitutes acceptance of the updated policy.

Legal Compliance: This policy complies with GDPR Article 5(1)(e) (storage limitation), Article 13(2)(a) (retention period information), Article 17 (right to erasure), and other applicable data protection laws. Retention periods are determined based on legal requirements, legitimate interests, and the principle of data minimization.