Back to Secret Community legal hub
Data Retention and Deletion Notice
Describes configurable retention for Secret Community record types. Exact periods are placeholders to be set by authorised privacy counsel.
This text is a draft for counsel review. Screens alone do not make Picom “KVKK compliant” or “GDPR certified”.
Controller information
This notice cannot be published as active until required controller fields are configured. Missing: legalName, registeredAddress, tradeRegistry
- Legal name
- —
- Registered address
- —
- Trade registry
- —
- General contact
- info@picom.gg
- KVKK contact
- info@picom.gg
- GDPR contact
- info@picom.gg
- DPO
- —
- EU representative
- —
- TR representative
- —
Summary
- Retention periods are configurable and must be approved by authorised legal and privacy personnel.
- This notice lists record types; exact day counts are marked as to be set by authorised privacy counsel.
- When a period expires, data is securely deleted or irreversibly anonymised unless a legal hold or legal obligation requires continued storage.
- Expired invitation secrets and raw tokens are deleted or irreversibly hashed as soon as operationally possible.
- Deletion jobs produce auditable completion records.
- “Stored as long as necessary” is not used as the sole retention statement.
Full notice
Configurable periods
The Picom data controller (see Controller information) maintains configurable, documented retention periods. Exact periods must be approved and entered by authorised legal/privacy personnel. Until set, periods below are marked accordingly and must not be treated as final schedules.
Record types
Retention schedules cover at least the following Secret Community-related record types. Period for each: to be set by authorised privacy counsel.
- Telephone verification records — period to be set by authorised privacy counsel
- Voice-call verification records — period to be set by authorised privacy counsel
- Creator interview records — period to be set by authorised privacy counsel
- Invitation records — period to be set by authorised privacy counsel
- Expired invitation tokens — period to be set by authorised privacy counsel (secrets/raw tokens deleted or irreversibly hashed as soon as operationally possible)
- Membership records — period to be set by authorised privacy counsel
- Rule acceptance records — period to be set by authorised privacy counsel
- Security logs — period to be set by authorised privacy counsel
- Moderation records — period to be set by authorised privacy counsel
- Trust Score history — period to be set by authorised privacy counsel
- Reports — period to be set by authorised privacy counsel
- Appeal records — period to be set by authorised privacy counsel
- Root access logs — period to be set by authorised privacy counsel
- Legal-hold records — retained while the hold or legal obligation remains active; period thereafter to be set by authorised privacy counsel
Expiry actions
When a period expires, Picom will delete the data securely or irreversibly anonymise it, unless a documented legal obligation or active legal hold requires continued storage. Deletion jobs must produce auditable completion records.