Data Retention Policy
Effective: 1 January 2025 ยท Last reviewed: June 2026
1. Overview
This policy describes how long seeID retains personal data and when it is deleted or anonymized, in compliance with POPIA (Protection of Personal Information Act, 2013).
2. Retention Periods
Account Data
User account information is retained while the account is active. Upon account deletion, PII is anonymized within 30 days. Full removal from backups occurs within 90 days.
Verification Records
Verification results (ID numbers, match scores, lineage data) are retained for 2 years from the date of verification. After 2 years, records are automatically purged.
Search History
Search queries and history are retained for 90 days.
Session Data
Session tokens expire after 24 hours (or 30 days if "remember me" is selected). Expired sessions are purged daily.
Email/Password Reset Tokens
Email verification tokens expire after 7 days. Password reset tokens expire after 24 hours.
Biometric Data
Selfie images and fingerprint templates are retained for the duration of the verification session only. They are deleted within 72 hours of session expiry unless required for fraud investigation.
Audit Logs
Admin action logs are retained indefinitely for compliance purposes. They do not contain unmasked ID numbers or PII.
3. Data Subject Rights
Under POPIA, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Object to processing
- Lodge a complaint with the Information Regulator
To exercise these rights, email privacy@seeid.co.za.
4. Automated Cleanup
Data retention rules are enforced automatically. Expired records are purged by scheduled jobs. Administrators can trigger manual cleanup via the admin panel.