Data Retention Summary
1. Purpose
1.1. This Data Retention Summary describes the main retention periods and deletion practices for personal data and business data processed by Grant Fund.
1.2. This Summary is informational and should be read together with the Privacy Policy, Terms and Conditions, DPA, KYC/KYB Privacy Notice, and applicable law.
2. General retention principle
2.1. Grant Fund retains data only for as long as necessary for the relevant purpose unless longer retention is required or permitted for legal, tax, accounting, security, audit, dispute, compliance, anti-fraud, backup, legitimate business, or legal-defence reasons.
2.2. Retention periods may vary by data category, jurisdiction, product feature, legal hold, dispute status, payment status, compliance status, security incident, or technical limitation.
3. Account closure archive
3.1. Grant Fund provides an archive at the point of Account closure, where technically and legally possible. The User is prompted to download it before the Account is closed, and a copy is sent to the registered email address. Access to the Service ends immediately on closure.
3.2. The archive may include Passport data, available reports, and available exports in JSON or PDF where technically available and not restricted by law, compliance, payment status, security, third-party rights, or technical limitations.
3.3. Ninety (90) days after closure, User Data is deleted or anonymised unless longer retention is required or permitted.
4. Default retention matrix
4.1. Account data: retained for the life of the Account and then deleted or anonymised after the ninety (90) day archive period unless longer retention is required or permitted.
4.2. Passport data and company profile data: retained for the life of the Account and then included in the archive where technically possible; deleted or anonymised after the archive period unless longer retention is required or permitted.
4.3. Reports, Outputs, exports, readiness reports, negative-match memos, and radar updates: retained while the Account is active and then included in the archive where technically possible; deleted or anonymised after the archive period unless longer retention is required or permitted.
4.4. Uploaded files and support attachments: retained while needed for the Service, support, or account use; deleted or anonymised after the archive period unless longer retention is required or permitted.
4.5. Billing, invoice, VAT, payment, refund, and tax records: retained for the period required or permitted by tax, accounting, audit, payment, chargeback, and legal-defence obligations.
4.6. KYC/KYB, sanctions, export-control, AML, UBO, compliance, fraud-prevention, and risk records: retained for the period required or permitted for legal, regulatory, compliance, audit, anti-fraud, sanctions, payment-risk, and legal-defence purposes.
4.7. Security logs, access logs, audit logs, abuse-prevention logs, and incident records: retained for security, investigation, audit, abuse prevention, compliance, and legal-defence purposes for as long as reasonably necessary or legally required.
4.8. AI logs, prompt logs, model inputs, model outputs, confidence metadata, review logs, and system traces: retained where necessary or useful for safety, auditability, debugging, legal defence, quality control, abuse prevention, compliance, fraud prevention, product improvement, or performance monitoring.
4.9. Marketing communication records: retained until opt-out, withdrawal of consent, account deletion, or until no longer necessary, subject to suppression-list retention needed to respect opt-outs.
4.10. Cookie and consent records: retained for the period necessary to evidence consent choices, comply with ePrivacy/cookie rules, and manage cookie preferences.
4.11. Aggregated, de-identified, or anonymised data: may be retained indefinitely where it no longer identifies the User or any individual.
4.12. Backups: backup copies may persist for a limited period after deletion in accordance with backup and disaster-recovery procedures.
5. Legal holds and exceptions
5.1. Grant Fund may suspend deletion, retain data longer, or restrict access where necessary for legal holds, disputes, investigations, audits, sanctions, AML/KYC/KYB, fraud prevention, security incidents, chargebacks, tax obligations, regulatory requirements, or legal defence.
5.2. Grant Fund may refuse deletion or restrict deletion where deletion would conflict with legal obligations, security obligations, dispute needs, compliance obligations, or rights of third parties.
6. Deletion and anonymisation
6.1. Data may be deleted, anonymised, aggregated, or de-identified when it is no longer required.
6.2. Anonymisation is irreversible where reasonably implemented. Anonymised data may be used for analytics, statistics, research, product improvement, fraud prevention, security, market insights, and business operations.
7. User export
7.1. User Data may be exportable in JSON or PDF where technically available, subject to plan limitations, security controls, compliance restrictions, payment status, and technical availability.
7.2. Users should export required data before closing their Account.
Questions about your data?
For any privacy request or question, contact us at privacy@grant.fund.
Data Protection Officer / EU representative: Ivan Petrakov

