Data Retention Policy
Section 1
Legal Status of Published Passports
Published Digital Product Passports are acknowledged as legal and regulatory records. These records are immutable; they are never deleted or modified. Retention is justified under GDPR Article 17(3) (legal obligation exemption).
Section 2
Tenant / Organization Deletion
A tenant or organization may be deleted from the system at any time upon request (GDPR Right to Erasure).
Deleted Data
- User Accounts
- Personally Identifiable Information (PII)
- API Access Keys
- UI Dashboard Access
- Shopify Connections
Retained Data
- Published passports (Immutable)
- Cryptographic proofs
Section 3
Orphan Passport Policy
It is an intentional design choice that passports remain verifiable and cryptographically valid even if the issuing tenant is deleted. This ensures long-term regulatory compliance beyond the lifespan of the issuing entity.
Verification Logic
- Integrity:Refers to cryptographic authenticity and immutable proof.
- Commercial Validity:Refers to the authorization for commercial use.
Section 4
Commercial Validity (Lease Model)
At Publish Time
The passport is issued as an immutable record. The field commercial_valid_until is set to the end of the first billing period. This field is explicitly excluded from all hash calculations.
Recurring Extension
While the tenant is active and paid, the validity period is extended. This operation does not alter the legal record; it serves only to extend commercial usage rights.
Expiration
When payment stops or the tenant is deleted, commercial validity expires. Verification will return:
Section 5
Demo / Free Tenant Rules
Demo and Free tenants may create drafts, preview data, and generate runtime projections; however, publishing and issuance are not permitted. This policy is enforced to prevent abuse of the platform.
Section 6
Binding Policy Summary
- Published Digital Product Passports are immutable legal records and are never deleted.
- Retention is justified under GDPR Article 17(3).
- Tenant deletion is permitted; PII and access keys are deleted/anonymized.
- Orphaned passports remain cryptographically verifiable.
- Verification distinguishes between Integrity and Commercial Validity.
- The validity date is not hashed and extends only with active payment.
- Expired commercial validity does not invalidate cryptographic integrity.
- Demo tenants cannot publish.
This section is binding.
© 2025 UnicodeVision Ltd. All rights reserved.