Retention approach
SoftNSM does not keep personal data indefinitely by default. Retention depends on why the information was collected, whether an account or service remains active, contractual and accounting needs, security and fraud prevention, dispute periods, backup cycles and applicable legal requirements.
Typical records
Enquiries that do not become engagements are reviewed and removed when no longer operationally useful. Active account, project and support records are kept while needed to provide and secure the service. Transaction, invoice, consent and contractual records may be retained longer where needed for accounting, evidence or law. Security logs and backups are retained for limited operational cycles unless an incident requires preservation.
Project files and third parties
Project materials are retained during delivery and for a reasonable handover or support period. Clients should keep their own final copies. Domains, hosting, payment, communications and storage providers retain information according to their own schedules, and deletion from SoftNSM systems may not immediately remove provider backups or records they must retain independently.
Deletion requests
You may request deletion through SoftNSM's published contact channels and should identify the relevant account, project or communication. We may verify identity before acting. We may deny or limit deletion where data is needed to perform an active agreement, protect security, document transactions, resolve disputes, establish legal claims or comply with law.
Deletion process
Approved requests are applied to active systems within a reasonable operational period. Residual copies may remain in access-restricted backups until the normal backup cycle expires. Instead of deletion, information may be irreversibly anonymised where appropriate. We will explain any material limitation when responding to a verified request.