Data Retention Statement
Last updated: 14 June 2026
We keep personal data only as long as needed for the purpose it was collected, plus any period required by insurance, tax, or anti-fraud regulation. Where retention is mandated by regulators (e.g. the Information Regulator (South Africa)), those minimums take precedence over deletion requests.
1. Retention schedule
| Data category | Default retention | Trigger |
|---|---|---|
| Account profile | Account life + 24 months | Account closure |
| Incident records (incl. GPS, media) | 7 years | Incident date |
| Claims, payouts, audit log | 10 years | Claim closed |
| FNOL PDFs (all versions) | 10 years | Claim closed |
| Witness statements | 7 years | Statement date |
| Roadside requests | 3 years | Request closed |
| Driver documents (licence, ID copies) | Validity + 24 months | Document expiry |
| In-app notifications | 24 months | Notification created |
| API access logs | 13 months | Request time |
2. Deletion requests
To request deletion of your account email privacy@claimbeacon.app from the address on your account. We will:
- Verify your identity (we may ask for a recent claim reference or device confirmation).
- Remove account data and de-identify incident/claim records that we are legally required to keep.
- Confirm completion within 30 days.
3. Anonymised data
After the retention window we may keep aggregated, de-identified statistics (counts of claims, severity histograms, fraud-score distributions) indefinitely. Such data cannot be linked back to an individual.
4. Backups
Encrypted backups roll off on a 35-day cycle. Deletion of an account propagates to backups no later than 35 days after the deletion confirmation.
Placeholders such as {{COMPANY_LEGAL_NAME}}, {{REGISTERED_ADDRESS}}, {{DPO_EMAIL}} and {{REGULATOR_NAME}} must be filled in before going live. This document is a starting point and is not a substitute for legal advice.