تخطٍ إلى المحتوى
DrAxis
الميزات الأمان قانوني
EN FR AR
الميزات الأمان قانوني
→ العودة إلى الفهرس القانوني

قانوني

DrAxis — Data Retention Policy

How long DrAxis retains personal data, and the procedures for secure deletion.

آخر تحديث: 2026-08-23
⚠ مسودة — للمراجعة الداخلية. ليست استشارة قانونية.

DrAxis — Data Retention Policy

Status: DRAFT v1 — for internal team review. Not legal advice.
Must be reviewed by qualified legal counsel before publication.
Last updated: 2026-08-23

Document control

FieldValue
Document ownerDrAxis DPO / engineering
Version0.1 (DRAFT)
Effective date[to be set at publication]
Review cycleAnnual, or upon material change in processing
Languages (target)English, French, Arabic
Public URLhttps://draxis.app/legal/data-retention-policy
Internal implementationdraxis-be retention jobs (to be implemented)

1. Purpose

This Data Retention Policy ("Policy") defines how long DrAxis retains personal data, and the procedures for secure deletion. It implements the data minimization and storage limitation principles of:

  • GDPR Art. 5(1)(c) and (e) (EU).
  • Tunisian DPA (Law 2004-63) — proportionality and purpose limitation.
  • KSA PDPL Art. 9 (data minimization) and Art. 13 (destruction).
  • UAE PDPL Art. 8 (data minimization) and Art. 17 (deletion).

2. Retention schedule

2.1 Account data

DataRetentionTrigger for deletionBasis
Phone number (auth)While account active + 30 daysAccount deletion requestContract; user rights
Full nameWhile account active + 30 daysAccount deletion requestContract
Email (if provided)While account active + 30 daysAccount deletion requestContract
Profile photoWhile account active + 30 daysAccount deletion requestConsent
Specialty / seniority / hospital / countryWhile account active + 30 daysAccount deletion requestVerification
License numberWhile account active + 30 daysAccount deletion requestVerification

2.2 Verification data

DataRetentionTrigger for deletionBasis
Verification documents (license scans, ID, affiliation letters)12 months after verification decisionScheduled purgeAudit; risk management
Verification decision (approved/rejected + reason)10 yearsScheduled purgeAudit; Tunisian medical ethics (Art. 64)
Admin reviewer identity + timestamp10 yearsScheduled purgeAudit

2.3 Clinical & messaging data

DataRetentionTrigger for deletionBasis
Calculator inputs (transient)Not persistedImmediate (in-memory only)Data minimization
Saved Calculator results (output only)While account active + 30 daysAccount deletion requestContract
Messages (text)While account active; deleted with accountAccount deletion requestContract
Attachments (files)While account active + 30 daysAccount deletion requestContract
ATB suggestion inputsNot persistedImmediate (in-memory only)Data minimization

2.4 Security & operational data

DataRetentionTrigger for deletionBasis
Audit logs (user ID, action, timestamp, IP)10 yearsScheduled purgeTunisian medical ethics (Art. 64); GDPR Art. 32 security
Server access logs (SSH, admin)12 monthsScheduled purgeSecurity
API request logs (IP, route, status)90 daysScheduled purgeSecurity; abuse prevention
Rate-limit counters24 hoursRolling purgeSecurity
Crash reports (if/when integrated)90 daysScheduled purgeStability
Firebase auth tokensPer Firebase defaults (max 1 hour for ID tokens)AutomaticAuthentication

2.5 Backend technical data

DataRetentionTrigger for deletionBasis
Database backups (full)30 days rollingScheduled purgeDisaster recovery
Database backups (weekly)12 weeks rollingScheduled purgeDisaster recovery
Object storage (attachments)Tied to account + 30 daysAccount deletion requestContract
PM2 logs (application)30 days rollingScheduled purgeOperations

3. Deletion procedures

3.1 User-initiated deletion

When a User requests account deletion (in-app or via dpo@draxis.app):

  1. T+0: Mark account as pending_deletion; revoke Firebase tokens; block new logins.
  2. T+24h: Soft-delete account data in the database (set deleted_at timestamp).
  3. T+30 days: Hard-delete:
- User row in users table. - Profile data. - Saved Calculator results. - Messages authored by the user (recipient copies remain until recipient deletes their account). - Attachments in object storage.
  1. Retained: Audit log entries referencing the user (anonymized to user ID only) for 10 years.

3.2 Scheduled purge jobs

The backend (draxis-be) will implement cron jobs:

JobFrequencyAction
purge-verification-docsDailyDelete verification documents older than 12 months post-decision
purge-api-logsDailyDelete API request logs older than 90 days
purge-server-access-logsDailyDelete SSH/admin access logs older than 12 months
purge-pm2-logsDailyRotate PM2 logs older than 30 days
purge-backupsDailyDelete database backups beyond retention window
purge-deleted-accountsDailyHard-delete accounts past 30-day soft-delete window
purge-audit-logsMonthlyDelete audit log entries older than 10 years

3.3 Secure deletion

  • Database: DELETE (hard delete), not UPDATE to a null value. For sensitive fields, the row is deleted entirely.
  • Object storage: Permanently delete the object (no versioning retention for user-uploaded attachments).
  • Backups: Backups containing deleted data are not specially purged; they expire per the backup retention schedule. Restoring a backup does not restore deleted user data without explicit DPO approval.
  • Firebase: User account in Firebase Auth is deleted via the Admin SDK at T+24h.

4. Legal hold

If DrAxis receives a legal hold notice or litigation hold request:

  • Deletion of the specified data is suspended for the duration of the hold.
  • The DPO maintains a register of active holds.
  • Once the hold is lifted, normal retention rules resume.

5. Data subject rights and retention

  • Right to erasure (GDPR Art. 17): Honored per §3.1, except where retention is required by law (audit logs).
  • Right to object (GDPR Art. 21): May result in restriction of processing rather than deletion.
  • KSA PDPL Art. 13 (destruction): Honored per §3.1.
  • UAE PDPL Art. 17 (deletion): Honored per §3.1.

Where a deletion request cannot be fully honored due to legal retention obligations, we will inform the User of the reasons and the expected deletion date.


6. Backups and recovery

  • Backups are retained for disaster recovery only, not for routine data access.
  • A User who has deleted their account will not be restored from backup unless required by law and approved by the DPO.
  • Backup restoration is logged in the audit log.

7. Implementation status

ComponentStatus
users.deleted_at columnTo be added (migration)
DELETE /api/me routeTo be implemented
GET /api/me/export routeTo be implemented
Cron jobs (§3.2)To be implemented
Firebase Auth deletion on account deletionTo be implemented
Object storage deletion on account deletionTo be implemented
⚠️ Until the above are implemented, account deletion is a manual operation performed by an admin. The 30-day window starts once the manual deletion is initiated.

8. Contact

  • DPO: dpo@draxis.app
  • Engineering: engineering@draxis.app
→ العودة إلى الفهرس القانوني
DrAxis

ذكاء سريري للأطباء المعتمدين.

صُنع في تونس للعالم.

المنتج

الميزاتالأمان

قانوني

سياسة الخصوصية شروط الخدمة إخلاء المسؤولية الطبية الاستخدام المقبول الاحتفاظ بالبيانات ملحق المعالجة سياسة ملفات تعريف الارتباط

الشركة

legal@draxis.appdpo@draxis.appالدعم

© DrAxis. جميع الحقوق محفوظة.