Data Retention Policy

Effective: 1 January 2025 ยท Last reviewed: June 2026

1. Overview

This policy describes how long seeID retains personal data and when it is deleted or anonymized, in compliance with POPIA (Protection of Personal Information Act, 2013).

2. Retention Periods

Account Data

User account information is retained while the account is active. Upon account deletion, PII is anonymized within 30 days. Full removal from backups occurs within 90 days.

Verification Records

Verification results (ID numbers, match scores, lineage data) are retained for 2 years from the date of verification. After 2 years, records are automatically purged.

Search History

Search queries and history are retained for 90 days.

Session Data

Session tokens expire after 24 hours (or 30 days if "remember me" is selected). Expired sessions are purged daily.

Email/Password Reset Tokens

Email verification tokens expire after 7 days. Password reset tokens expire after 24 hours.

Biometric Data

Selfie images and fingerprint templates are retained for the duration of the verification session only. They are deleted within 72 hours of session expiry unless required for fraud investigation.

Audit Logs

Admin action logs are retained indefinitely for compliance purposes. They do not contain unmasked ID numbers or PII.

3. Data Subject Rights

Under POPIA, you have the right to:

To exercise these rights, email privacy@seeid.co.za.

4. Automated Cleanup

Data retention rules are enforced automatically. Expired records are purged by scheduled jobs. Administrators can trigger manual cleanup via the admin panel.