BeneVets, Inc. - Data Retention Schedule (Document 14)
| Field | Value |
|---|---|
| Document number | 14 |
| Document title | Data Retention Schedule |
| Document owner (officer) | Secretary (Harish), supported by Treasurer (Callie) |
| Operational owner (engineering) | Chief Executive Officer and Executive Director (Walter), with Lead Engineer (Ian) |
| Effective date | July 4, 2026 |
| Last revised | 2026-06-02 |
| Review cadence | Annual; out-of-cycle on material schema change or new regulatory obligation |
| Approval authority | Board of Directors (changes affecting permanent or 7+ year categories); Secretary (clarifying changes that do not alter retention durations or triggers) |
| Cross-referenced by | Document 02 (Privacy Policy); Document 09 (Donor Privacy Policy); Document 18 (Whistleblower / Document Retention Policy); Document 07 (Helper / Account-Linking Terms); Document 13 (Security and Vulnerability Disclosure Policy) |
§ 1. In Plain English
In plain English: This schedule says how long BeneVets keeps each kind of information, why we keep it that long, and what causes us to delete it. Most personal data tied to a user account is kept while the account is active and for a short window afterward, then either deleted or stripped of identifying details. Some categories must be kept longer because federal or state law requires it (for example, audit logs and donation records). A few categories you can ask us to delete right away (for example, your DD-214, your symptom log, and your tracked conditions), and we will, unless a court order or legal hold requires us to keep them. Backups are not searched and edited; they age out and overwrite on their own rotation. When we cannot delete a record (because a law requires us to keep it), we anonymize it instead, so the audit chain stays intact but the personal connection to you is broken.
This schedule is the single source of retention truth for BeneVets. The Privacy Policy, Donor Privacy Policy, and Document Retention Policy all defer to this document for specific durations.
§ 2. Defined Terms (Schedule-Specific)
Capitalized terms not defined here have the meaning given in Document 02 (Privacy Policy) or Document 01 (Terms of Service).
- "Account Closure Event" means the moment at which the User clicks "Delete my account" in the Profile surface, the moment at which a verified Privacy Request requesting deletion is approved, or the moment at which the Board of Directors directs deletion under a documented administrative-closure procedure.
- "Active" means, as to an account, that the account has not been the subject of an Account Closure Event and that the account is not in the 30-day soft-delete window. As to a Helper link, that the link has not been revoked. As to a donation appeal, that the appeal cycle has not closed.
- "Anonymization" means the one-way transformation of a record so that it can no longer be associated, directly or through reasonable means, with a particular User. The technique applied at BeneVets is described in § 7 below.
- "Calendar Day" means a 24-hour period beginning at 00:00:00 UTC. Where a period is stated in calendar days, weekends and federal holidays are counted.
- "Business Day" means Monday through Friday, excluding U.S. federal holidays as listed in 5 U.S.C. § 6103, in the Pacific Time Zone.
- "Hard Deletion" means irreversible removal from all live application databases and live object storage such that the record cannot be reconstituted by ordinary application or operator action. Hard Deletion does not, by itself, reach into immutable backup media; see § 8.3.
- "Legal Hold" means a documented directive from the CEO, Secretary, or retained counsel suspending normal deletion for a defined scope of records pending litigation, audit, investigation, regulatory inquiry, or subpoena response.
- "Soft-Delete Window" means the 30 Calendar Day period immediately following an Account Closure Event, during which the User may recover the account by re-authenticating.
- "WORM" means write-once, read-many storage in which records cannot be modified or deleted by ordinary operator action prior to expiry of the retention period.
§ 3. Scope
This schedule applies to all Personal Information and operational records held by BeneVets, Inc. in connection with the Service, including but not limited to:
- Every Prisma model defined in the production schema, current and future (see § 5 for the model-by-model treatment).
- All session and authentication state.
- All audit log entries.
- All application telemetry, route-level analytics, and error monitoring data.
- All file storage envelopes (DD-214 envelopes, profile photos, generated PDFs).
- All transactional and marketing email logs.
- All donor and donation records once donation processing activates.
- All corporate governance records of BeneVets, Inc.
This schedule does not apply to:
- Records held by subprocessors under their own retention policies, except to the extent those policies are constrained by the Data Processing Agreement between BeneVets and the subprocessor. Subprocessor-side retention is enumerated in Document 04 (Sub-processor List).
- VA-side records held by the U.S. Department of Veterans Affairs as a third-party recipient and source. VA retention is governed by VA records schedules, not by this document.
§ 4. Legal-Basis Taxonomy
Every retention period in the master table in § 5 is justified by one (and sometimes more than one) of the following legal bases. The shorthand label is used in the "Legal basis" column.
| Shorthand | Basis | Source |
|---|---|---|
| Contract | Performance of a contract with the User (the Terms of Service) | Cal. Civ. Code § 1798.140(e) ("business purpose"); GDPR Art. 6(1)(b) analog (not directly applicable, used as drafting frame) |
| Legal-Federal | Compliance with U.S. federal recordkeeping requirements | 26 U.S.C. § 6033 (annual return), § 6104 (public inspection); IRS Form 990 instructions; 18 U.S.C. § 1519 (Sarbanes-Oxley document destruction) |
| Legal-State | Compliance with California regulatory requirements | Cal. Civ. Code § 1798.130(a)(2) (12 months minimum, 24 months SPI record retention for verified-request handling); Cal. Code Regs. tit. 11, § 7101 (recordkeeping for at least 24 months); Cal. Corp. Code § 6320 (nonprofit records) |
| Legal-WA | Compliance with Washington consumer-health-data law | Wash. Rev. Code § 19.373.030(2) (right to delete and propagation to backups) |
| Legitimate-Interest | Operation and security of the Service | Cal. Civ. Code § 1798.140(e)(2)-(8) (enumerated business purposes including security, debugging, fraud prevention) |
| Donor-Relationship | Ongoing donor stewardship and IRS-substantiation obligation | 26 U.S.C. § 170(f)(8) (contemporaneous written acknowledgment); IRS Form 990, Schedule B; AFP Donor Bill of Rights |
| User-Request | The User has affirmatively requested deletion or limitation under Cal. Civ. Code § 1798.105 or § 1798.121; or under Wash. Rev. Code § 19.373.030(2) | Statutory rights of the User |
| Audit-Requirement | Internal or external audit, SOC 2 readiness, board-fiduciary obligation, or anti-fraud documentation | Sarbanes-Oxley § 802 (18 U.S.C. § 1519); AICPA Trust Services Criteria; nonprofit fiduciary duty under Cal. Corp. Code § 5231 |
Where two bases compete (for example, a User-Request deletion against a Legal-Federal recordkeeping obligation), the longer-retention basis prevails and the affected record is anonymized at the User-Request trigger if anonymization preserves the underlying purpose. See § 7.
§ 5. Master Retention Table
Conventions used in the table:
- "Life of account" means the period from account creation through the Account Closure Event.
- "+N years" means N calendar years measured from the Account Closure Event.
- "On request" means the User may, by exercising rights under Cal. Civ. Code § 1798.105 or Wash. Rev. Code § 19.373.030, accelerate deletion of the row regardless of the default trigger. "On request - same as account" means the User cannot accelerate deletion below the default while the account is Active because the data is core to providing the Service.
- Sensitivity tiers: T1 Public, T2 Internal-Operational, T3 Personal Information, T4 Sensitive Personal Information, T5 Government-ID / Financial-Account.
§ 5.1 User Identity and Profile
| Data category | Prisma model(s) | Sensitivity tier | Retention period | Trigger to delete | Legal basis | Cross-reference |
|---|---|---|---|---|---|---|
| User account record | User | T3 | Life of account + 24 months, then Anonymized | 24-month anniversary of Account Closure Event | Legal-State (Cal. Civ. Code § 1798.130(a)(2)); Audit-Requirement | Privacy Policy § 7 |
| Personal information record (name, contact, DOB) | PersonalInfo | T3 | Life of account + 24 months, then Hard Deletion | 24-month anniversary of Account Closure Event | Contract; Legal-State | Privacy Policy § 3.1 |
| Service information record (branch, era, separation status, disability rating) | ServiceInfo | T4 (SPI per Cal. Civ. Code § 1798.140(ae)(1)(B) for disability rating; otherwise T3) | Life of account + 24 months, then Hard Deletion | 24-month anniversary of Account Closure Event | Contract; Legal-State | Privacy Policy § 3.2 |
| Password hash (bcrypt / argon2id) | User.passwordHash | T3 | Life of account; rehash on policy upgrade | Account Closure Event (Hard Deletion at end of Soft-Delete Window) | Contract; Legitimate-Interest (auth security) | Document 13 § 5 |
| Email verification token | EmailVerificationToken | T2 | 24 hours from issuance OR on use, whichever first | Token use or 24-hour expiry | Legitimate-Interest | Document 13 § 5 |
| Password reset token | PasswordResetToken | T2 | 1 hour from issuance OR on use, whichever first | Token use or 1-hour expiry | Legitimate-Interest | Document 13 § 5 |
| Google OAuth federated identity binding | OAuthAccount (or equivalent) | T3 | Life of account | Account Closure Event (Hard Deletion at end of Soft-Delete Window) | Contract | Privacy Policy § 4 |
§ 5.2 Authentication and Sessions
| Data category | Prisma model(s) | Sensitivity tier | Retention period | Trigger to delete | Legal basis | Cross-reference |
|---|---|---|---|---|---|---|
| MFA TOTP secret (AES-256-GCM encrypted) | MfaSecret | T3 | Life of MFA enrollment | User-disable of MFA | Contract; Legitimate-Interest | Document 13 § 5 |
| MFA backup codes (hashed) | MfaBackupCode | T3 | Life of MFA enrollment; individual code deleted on use | User-disable of MFA; code use | Contract; Legitimate-Interest | Document 13 § 5 |
| Session record (token hash, last-seen timestamp, truncated IP, user-agent class) | Session | T3 | 7 calendar days from last refresh; idle timeout 30 minutes; absolute lifetime 12 hours | Earliest of: refresh+7d, idle+30m, absolute+12h, sign-out, account closure | Legitimate-Interest; NIST SP 800-63B § 7.2 AAL2 | Privacy Policy § 4; Document 13 § 6 |
| Active-Perspective state (current Helper view) | ActivePerspective (or in-memory session attribute) | T2 | Length of session | Session end | Legitimate-Interest | Helper Terms § 4 |
| Anti-abuse rate-limit counters | RateLimitBucket (Redis/edge) | T2 | 24 hours rolling | Bucket window expiry | Legitimate-Interest | Document 13 § 6 |
§ 5.3 Documents and Files
| Data category | Prisma model(s) | Sensitivity tier | Retention period | Trigger to delete | Legal basis | Cross-reference |
|---|---|---|---|---|---|---|
| DD-214 file (AES-256-GCM encrypted envelope in ProfileVault) | ProfileVaultEnvelope (type=DD214); blob in B2/Vercel Blob | T5 | Life of account + 1 year; Deletable on User-Request immediately, subject only to active Legal Hold | User-Request deletion (immediate, ≤30 calendar days) OR 1-year anniversary of Account Closure Event | Contract; User-Request; Legal-State (Cal. Civ. Code § 1798.105) | Privacy Policy § 6.3 |
| Profile photo | User.profilePhotoUrl; blob storage object | T3 | Life of account; Deletable on User-Request immediately | User-Request deletion (immediate, ≤30 calendar days) OR Account Closure Event | Contract; User-Request | Privacy Policy § 3.1 |
| Form submission record (VA Form 21-526EZ, 21-0966, 21-22, others) | FormSubmission | T4 | Life of account + 7 years | 7-year anniversary of Account Closure Event | Contract; Audit-Requirement; federal claim recordkeeping context (38 C.F.R. § 3.155, § 3.400) | Pro Se Filing Attestation § 6 |
| VA Lighthouse Benefits Intake transmission metadata (submission UUID, status callbacks) | LighthouseSubmission | T3 | Life of account + 7 years | 7-year anniversary of Account Closure Event | Contract; Audit-Requirement | Pro Se Filing Attestation § 6 |
| C&P-prep generated PDFs (symptom-log summary, post-exam adequacy audit) | GeneratedPdf | T4 | Life of account + 7 years | 7-year anniversary of Account Closure Event | Contract; Audit-Requirement | Privacy Policy § 6.4 |
| Pro Se Filing Attestation server-locked record | ProSeAttestation | T3 | Life of account + 7 years | 7-year anniversary of Account Closure Event | Contract; Audit-Requirement; 38 C.F.R. § 14.626 non-representation evidence | Pro Se Filing Attestation § 7 |
§ 5.4 Health and Crisis
| Data category | Prisma model(s) | Sensitivity tier | Retention period | Trigger to delete | Legal basis | Cross-reference |
|---|---|---|---|---|---|---|
| Symptom log entries (AES-256-GCM encrypted) | SymptomLog | T4 | Life of account; Deletable on User-Request immediately | User-Request deletion (immediate, ≤30 calendar days) OR Account Closure Event | Contract; User-Request (Cal. Civ. Code § 1798.105; Wash. Rev. Code § 19.373.030(2)(c)) | Privacy Policy § 6.2; Document 15 § 4 |
| Tracked condition record | TrackedCondition | T4 | Life of account; Deletable on User-Request immediately | User-Request deletion (immediate, ≤30 calendar days) OR Account Closure Event | Contract; User-Request (Cal. Civ. Code § 1798.105; Wash. Rev. Code § 19.373.030(2)(c)) | Privacy Policy § 6.2 |
| Crisis-keyword scanner trigger (the fact a scan fired and which surface presented resources) | CrisisTrigger (audit subset of AuditLog) | T4 | 30 calendar days, then Anonymized to aggregate statistics | Day-30 from event | Legitimate-Interest (safety follow-up window); Audit-Requirement | Document 15 § 5 |
| Crisis-keyword scanner inference (the textual evidence that produced the inference) | CrisisInference | T4 | 24 hours from triggering event; longer only if safety follow-up is in progress and documented | 24-hour expiry OR documented closure of safety follow-up | User-Request (Cal. Civ. Code § 1798.121 right to limit SPI); Legitimate-Interest | Document 15 § 5 |
| User opt-out of crisis-keyword inference per Cal. Civ. Code § 1798.121 | UserPrivacyPreference.crisisInferenceLimit | T3 | Life of account + 24 months (record of having honored the request) | 24-month anniversary of Account Closure Event | Legal-State (Cal. Civ. Code § 1798.130(a)(2)) | Document 15 § 5 |
§ 5.5 Claims and Intent-to-File
| Data category | Prisma model(s) | Sensitivity tier | Retention period | Trigger to delete | Legal basis | Cross-reference |
|---|---|---|---|---|---|---|
| Intent-to-File (ITF) record | IntentToFile | T3 | Life of account + 7 years | 7-year anniversary of Account Closure Event | Contract; Audit-Requirement; 38 C.F.R. § 3.155 evidentiary context | Privacy Policy § 6.4 |
| Claim record | Claim | T4 | Life of account + 7 years | 7-year anniversary of Account Closure Event | Contract; Audit-Requirement | Privacy Policy § 6.4 |
| ProfileVault financial / government-ID envelope (encrypted SSN, bank account, routing) | ProfileVaultEnvelope (type=SSN, type=BANK) | T5 | Life of account + 1 year; Deletable on User-Request immediately, subject only to active Legal Hold | User-Request deletion (immediate, ≤30 calendar days) OR 1-year anniversary of Account Closure Event | Contract; User-Request; Legal-State | Privacy Policy § 6.3 |
| Claim status callback from VA Lighthouse | ClaimStatusCallback | T3 | Life of account + 7 years | 7-year anniversary of Account Closure Event | Contract; Audit-Requirement | Privacy Policy § 6.4 |
§ 5.6 Account-Linking ("Helpers")
| Data category | Prisma model(s) | Sensitivity tier | Retention period | Trigger to delete | Legal basis | Cross-reference |
|---|---|---|---|---|---|---|
| AccountLink (Active) | AccountLink where status = ACTIVE | T3 | Life of link | Revocation by either party; Account Closure of either party | Contract | Helper Terms § 3 |
| AccountLink (Revoked) | AccountLink where status = REVOKED | T3 | 24 months from revocation, then Anonymized | 24-month anniversary of revocation | Legal-State (Cal. Civ. Code § 1798.130(a)(2)); Audit-Requirement; abuse-investigation window | Helper Terms § 8 |
| Scammer / abuse report against a Helper or alleged accredited representative | ScammerReport | T4 | 7 years from filing | 7-year anniversary of filing | Audit-Requirement; legitimate interest in abuse-evidence chain; potential Legal-Federal in 38 C.F.R. § 14.633 referral context | Helper Terms § 9 |
| Cross-account profile read event (a Helper viewed the Veteran's data) | CrossAccountRead (subset of AuditLog) | T3 | Life of link + 7 years from link end | 7-year anniversary of link end | Audit-Requirement; legitimate interest in user trust | Helper Terms § 4 |
| Helper acceptance attestation | HelperAttestation | T3 | Life of link + 7 years from link end | 7-year anniversary of link end | Contract; Audit-Requirement | Helper Terms § 2 |
§ 5.7 Communications
| Data category | Prisma model(s) | Sensitivity tier | Retention period | Trigger to delete | Legal basis | Cross-reference |
|---|---|---|---|---|---|---|
| Email transmission metadata (Resend message ID, to-address hash, bounce/complaint status) | EmailTransmissionLog | T2 | 90 calendar days; extended only under Legal Hold | Day-90 from transmission | Legitimate-Interest (deliverability operations); CAN-SPAM 15 U.S.C. § 7704 compliance demonstration | Privacy Policy § 8.1 |
| Email content (the rendered body of a sent email) | n/a - not retained server-side beyond transmission | T2 | Not retained beyond the dispatch transaction (Resend may retain per its DPA; see Document 04) | Dispatch completion | Legitimate-Interest | Document 04 |
| User communication preferences (transactional, newsletter, donor stream, opt-outs) | CommunicationPreference | T3 | Life of account | Account Closure Event (Hard Deletion at end of Soft-Delete Window). Unsubscribe records preserved per CAN-SPAM. | Contract; Legitimate-Interest; 15 U.S.C. § 7704(a)(4) | Privacy Policy § 8 |
| CAN-SPAM unsubscribe ledger (suppression list) | EmailSuppression | T2 | Permanent (suppression list must outlive account to honor opt-out for the email address) | Never. Address may be re-hashed on policy upgrade. | Legal-Federal (15 U.S.C. § 7704(a)(4)); Legitimate-Interest | Privacy Policy § 8.2 |
§ 5.8 Analytics and Telemetry
| Data category | Prisma model(s) | Sensitivity tier | Retention period | Trigger to delete | Legal basis | Cross-reference |
|---|---|---|---|---|---|---|
| First-party route-pattern usage event | UsageEvent | T2 | 13 months | 13-month anniversary of event | Legitimate-Interest | Privacy Policy § 5 |
| First-party route-level analytics aggregation | RouteAnalyticsAgg (rollup) | T2 | 13 months at row level; aggregate counts retained indefinitely | 13-month anniversary of row | Legitimate-Interest | Privacy Policy § 5 |
| Google Analytics 4 event store (subprocessor side) | n/a (subprocessor) | T3 (with GA4 identifiers) | 2 months (GA4 minimum) per BeneVets configuration | GA4-side expiry | Legitimate-Interest; honored Global Privacy Control sitewide | Document 04; Privacy Policy § 5 |
| Sentry error event (PII-scrubbed) | n/a (subprocessor) | T2 | 30 calendar days | Day-30 from event | Legitimate-Interest (debugging per Cal. Civ. Code § 1798.140(e)(8)) | Document 04 |
| Edge proxy / DDoS-mitigation logs (Cloudflare) | n/a (subprocessor) | T2 | Per subprocessor default, capped at 30 calendar days | Subprocessor expiry | Legitimate-Interest (security) | Document 04 |
§ 5.9 Audit and Compliance
| Data category | Prisma model(s) | Sensitivity tier | Retention period | Trigger to delete | Legal basis | Cross-reference |
|---|---|---|---|---|---|---|
| Hash-chained audit log entry | AuditLog | T3 (Anonymized at Account Closure for entries tied to closed accounts) | 7 years; WORM-mirrored upon SOC 2 readiness | 7-year anniversary of entry; entries tied to closed accounts are Anonymized at the deletion event (§ 7) | Audit-Requirement; Legal-Federal (18 U.S.C. § 1519); Legal-State (Cal. Code Regs. tit. 11, § 7101); Cal. Corp. Code § 6320 | Document 13 § 7; Document 18 |
| Privacy request record (intake, identity verification, response, fulfillment evidence) | PrivacyRequest | T3 | 4 years per Cal. Civ. Code § 1798.130(a)(2) (24-month minimum) extended to 4 years for audit defense | 4-year anniversary of request closure | Legal-State (Cal. Civ. Code § 1798.130(a)(2)); Audit-Requirement | Privacy Policy § 12 |
| Privacy request supporting documents (identity proof, authorized-agent letters) | PrivacyRequestAttachment | T3 | 4 years | 4-year anniversary of request closure | Legal-State; Audit-Requirement | Privacy Policy § 12 |
| Compliance obligation tracker (regulatory inquiries, breach notifications, attestations) | ComplianceObligation | T2 | 7 years from closure | 7-year anniversary | Audit-Requirement; Legal-Federal (18 U.S.C. § 1519) | Document 18 |
| Staff role grant / role revocation | UserStaffGrant | T3 | 7 years from revocation | 7-year anniversary of revocation | Audit-Requirement (privileged-access review) | Document 13 § 4 |
| Security incident record | SecurityIncident | T3 | 7 years from closure | 7-year anniversary of closure | Audit-Requirement; Legal-Federal (18 U.S.C. § 1519); Cal. Civ. Code § 1798.82 (breach notice evidence) | Document 13 § 9 |
| Data subject right-to-limit-SPI election | UserPrivacyPreference.spiLimit | T3 | Life of account + 24 months | 24-month anniversary of Account Closure Event | Legal-State (Cal. Civ. Code § 1798.121, § 1798.130(a)(2)) | Privacy Policy § 11 |
§ 5.10 Donor (When Donation Processing Activates)
These rows reflect the forward-state when on-site donation processing or off-platform donor stewardship begins. Until donation processing activates, the only donor records BeneVets holds are those of donors who arrived via external channels and elected to receive donor email.
| Data category | Prisma model(s) | Sensitivity tier | Retention period | Trigger to delete | Legal basis | Cross-reference |
|---|---|---|---|---|---|---|
| Donor record | Donor | T3 | 7 years from last activity | 7-year anniversary of last donation, last communication-engagement, or formal unsubscribe (whichever is latest) | Donor-Relationship; Legal-Federal (26 U.S.C. § 6033 audit-preparedness; IRS Form 990 instructions) | Donor Privacy Policy § 5 |
| Donation transaction record | DonationTransaction | T3 | 7 years from transaction date | 7-year anniversary of transaction | Legal-Federal (26 U.S.C. § 6033); Audit-Requirement | Donor Privacy Policy § 5 |
| Donor communication preferences | DonorCommunicationPreference | T3 | Life of donor relationship + 2 years | 2-year anniversary of relationship close | Donor-Relationship; Legitimate-Interest | Donor Privacy Policy § 6 |
| § 170(f)(8) contemporaneous written acknowledgment | DonationAcknowledgment | T3 | 7 years from issuance | 7-year anniversary | Legal-Federal (26 U.S.C. § 170(f)(8)) | Donor Privacy Policy § 5 |
| Payment-processor token (Stripe customer ID, no PAN, no full card) | DonorPaymentToken | T5 | Life of donor relationship + 1 year, or sooner on User-Request | Earliest of: User-Request, 1-year anniversary of relationship close | Donor-Relationship; User-Request | Donor Privacy Policy § 5 |
| State charitable-solicitation registration evidence | CharitableRegistrationFile | T2 | Permanent | Never | Legal-State (varies by state); Audit-Requirement | State Disclosures (Document 11) |
§ 5.11 Governance and Corporate
| Data category | Sensitivity tier | Retention period | Trigger to delete | Legal basis | Cross-reference |
|---|---|---|---|---|---|
| Articles of Incorporation | T1 | Permanent | Never | Legal-State (Cal. Corp. Code § 6320); Legal-Federal | Document 18 |
| Bylaws (all amendments) | T1 | Permanent | Never | Legal-State (Cal. Corp. Code § 6320); Legal-Federal | Document 18 |
| IRS Form 1023 application | T1 | Permanent | Never | Legal-Federal (26 U.S.C. § 6104(d) public inspection) | Document 18 |
| IRS determination letter | T1 | Permanent | Never | Legal-Federal (26 U.S.C. § 6104(d)) | Document 18 |
| EIN assignment letter | T1 | Permanent | Never | Legal-Federal | Document 18 |
| Form 990 / Form 990-N filings | T1 | Permanent | Never | Legal-Federal (26 U.S.C. § 6033, § 6104(b), (d)) | Document 18 |
| Board minutes | T1 | Permanent | Never | Legal-State (Cal. Corp. Code § 6320); Audit-Requirement | Document 18 |
| Board resolutions | T1 | Permanent | Never | Legal-State (Cal. Corp. Code § 6320); Audit-Requirement | Document 18 |
| Annual Conflict-of-Interest disclosures (board, officers, key employees) | T3 | 7 years from disclosure year | 7-year anniversary | Legal-Federal (Form 990, Part VI); Audit-Requirement | Document 17 |
| Whistleblower report and investigation file | T3 | 7 years post-resolution | 7-year anniversary of resolution | Legal-Federal (18 U.S.C. § 1519); Audit-Requirement | Document 18 |
| Vendor / subprocessor DPAs and BAAs (if any) | T2 | Term of contract + 7 years | 7-year anniversary of contract end | Audit-Requirement; Legal-Federal | Document 04 |
| Insurance policies and claims | T2 | Term of policy + 7 years | 7-year anniversary of policy end | Legitimate-Interest; Audit-Requirement | Document 18 |
§ 6. Retention Exceptions
A retention period stated in § 5 may be extended, but not shortened, by any of the following.
§ 6.1 Legal Hold
When BeneVets reasonably anticipates or is on notice of litigation, audit, regulatory inquiry, government investigation, or any other matter under which a duty to preserve evidence has attached, the CEO, the Secretary, or retained counsel will issue a written Legal Hold notice. The hold suspends the deletion triggers in § 5 for the defined scope until the hold is released in writing.
The destruction-of-evidence prohibition in 18 U.S.C. § 1519 (Sarbanes-Oxley § 802) applies to any record in the scope of a contemplated federal investigation, audit, or proceeding. Operationally:
- Holds are documented in the
LegalHoldregister and propagated as deletion-suppression flags on affected rows. - Holds are reviewed at least every 180 calendar days for continued necessity.
- Hold release is also documented; on release, the affected records resume their normal § 5 trigger calculus.
- Records placed under hold while they would otherwise be in the 30-day Soft-Delete Window are preserved past the window; Hard Deletion is deferred until the hold is released, at which point the original deletion proceeds within 30 calendar days.
§ 6.2 Subpoena, Court Order, or Law-Enforcement Preservation Request
A duly served subpoena, court order, search warrant, or preservation request under 18 U.S.C. § 2703(f) extends retention of the scoped records for the period stated in the instrument, or for the period required by applicable law, whichever is longer. BeneVets logs the request in the LegalHold register with a lawEnforcementRequest flag and routes the request through retained counsel.
§ 6.3 Active Claim or Dispute
While a claim, dispute, complaint, or BBB / state-attorney-general inquiry involving the User remains open, all records reasonably related to the claim are retained until 90 calendar days after final resolution, including the period for filing any appeal.
§ 6.4 Active Fundraising Appeal or Annual Reporting Cycle
Donor data scheduled to expire mid-appeal or mid-Form-990-cycle is retained through the close of the appeal or the filing of the Form 990 covering that fiscal year, whichever applies.
§ 6.5 Active Safety Follow-Up
A crisis-keyword scanner trigger or inference scheduled to expire while an active safety follow-up is documented in CrisisTrigger.safetyFollowupOpen = true is retained for the duration of the follow-up plus 30 calendar days, then expires.
§ 7. Anonymization Versus Deletion
§ 7.1 When Anonymization Is Used
Where a regulatory or operational basis forbids deletion (notably the hash-chained AuditLog), or where deletion would destroy a record that BeneVets must retain to defend the integrity of the platform (notably revoked AccountLink audit trail and scammer reports), the personal nexus of the record is severed at the user-deletion event while the operational record is preserved.
§ 7.2 Anonymization Technique
The User identifier embedded in a record subject to Anonymization is replaced with a one-way hash:
anonymized_user_id = HMAC-SHA-256(per-record-salt, original_user_id)
where per-record-salt is a random 256-bit value generated at the moment of anonymization and stored only with the anonymized record. The mapping (anonymized_user_id, original_user_id) is not retained: the original identifier is overwritten with NULL and the row's anonymizedAt timestamp is set. Because the salt is unique per anonymization event and the original identifier is destroyed, the hash cannot be reversed by BeneVets, by a subprocessor, or by anyone with read access to the database.
Records anonymized in this way:
- preserve the audit chain (the hash-chained log remains intact because the hashed identifier still satisfies the hash chain),
- preserve the row count for compliance reporting,
- cannot be re-associated with the User after anonymization, even by BeneVets,
- and, per Cal. Civ. Code § 1798.140(o), constitute "deidentified" information when the technical and administrative safeguards in this section are also enforced.
§ 7.3 Records Subject to Anonymization Rather Than Hard Deletion
- Hash-chained
AuditLogentries that reference the deleted User. AccountLinkrecords inREVOKEDstatus referencing the deleted User (after the 24-month abuse-investigation window).ScammerReportrecords in which the deleted User is the reporter (the reported party's identity is preserved unchanged).CrossAccountReadaudit entries beyond the 7-year link-end window if SOC 2 readiness requires longer.
§ 7.4 Records Subject to Hard Deletion (Not Anonymization)
All records in § 5 not listed in § 7.3 are subject to Hard Deletion on their stated trigger. In particular, ProfileVault envelopes (DD-214, SSN, bank), SymptomLog entries, TrackedCondition entries, and profile photos are always Hard Deleted, never anonymized.
§ 8. Deletion Mechanics
§ 8.1 User-Initiated Deletion
- User clicks "Delete my account" in the Profile surface and confirms.
- An Account Closure Event is recorded. The account immediately enters the 30-Calendar-Day Soft-Delete Window. Sessions are revoked. The User cannot sign in by password. The User can recover the account by completing a recovery flow that requires email re-verification.
- On day 31, a scheduled job performs Hard Deletion on the categories listed in § 5 whose trigger is "Account Closure Event," and starts the longer retention clocks (e.g., the 7-year FormSubmission clock, the 24-month AuditLog anonymization clock).
- The User receives a confirmation email at the address of record at the time of the Account Closure Event. The email contains the date of Hard Deletion and the categories preserved under longer retention.
§ 8.2 Privacy-Request Deletion (Cal. Civ. Code § 1798.105, § 1798.130(b); Wash. Rev. Code § 19.373.030)
- The request is received through the Profile surface, the privacy@benevets.org mailbox, or the toll-free intake line if and when activated.
- Identity verification is performed per Cal. Code Regs. tit. 11, § 7060.
- Receipt is acknowledged in writing within 10 Business Days per Cal. Civ. Code § 1798.130(a)(2)(A).
- The substantive response and deletion are completed within 45 Calendar Days of receipt, extendable once by an additional 45 Calendar Days when reasonably necessary per Cal. Civ. Code § 1798.130(b), with notice to the User.
- The User-Request deletion accelerates the "User-Request" trigger rows in § 5 (DD-214, ProfileVault SSN/bank, SymptomLog, TrackedCondition, profile photo) regardless of any otherwise applicable longer trigger, subject only to active Legal Hold under § 6.1, regulatory exception under Cal. Civ. Code § 1798.105(d), or law-enforcement preservation under § 6.2.
- Where a User requests deletion of a record subject to a longer regulatory retention that cannot be honored (for example, an
AuditLogentry), BeneVets performs Anonymization under § 7 at the request resolution and communicates that anonymization, not deletion, is the available remedy.
§ 8.3 Backups, Archives, and Replicas
Deletion of a record from the live application database propagates immediately to read replicas through ordinary replication.
Backup tapes, snapshots, and archival object-storage versions that contain the record at the moment they were captured are not edited. Backups age out and are overwritten on the documented backup rotation:
- Daily snapshots: rolling 14 calendar days, then overwrite.
- Weekly snapshots: rolling 8 weeks, then overwrite.
- Monthly snapshots: rolling 12 months, then overwrite.
- Annual snapshots: rolling 7 years, then overwrite. (Required to satisfy the AuditLog and FormSubmission retention floors.)
A User-Request deletion does not trigger a search-and-destroy operation against the backup set, except where Wash. Rev. Code § 19.373.030(2)(c)(iv) requires it for consumer health data. For SymptomLog and TrackedCondition records, BeneVets will, upon a verified User-Request deletion, place a deletion-on-restore flag on the relevant record ID such that if the affected backup is ever restored, the record is re-deleted before the restore is opened to application traffic. This satisfies the "extraordinary procedure" contemplated by Wash. Rev. Code § 19.373.030(2)(c)(iv) while preserving the integrity of the backup chain.
§ 8.4 Subprocessor Propagation
When a record subject to Hard Deletion exists at a subprocessor (for example, an email transmission log at Resend, or a Sentry error event), BeneVets issues a deletion-propagation request through the subprocessor's documented mechanism within 30 calendar days of the originating deletion. Subprocessor expiry on the subprocessor side is also relied upon. The Sub-processor List (Document 04) reflects each subprocessor's confirmed propagation latency.
§ 9. Cross-References
This schedule is cross-referenced by, and operates in concert with, the following BeneVets documents:
- Document 02 - Privacy Policy §§ 3-11 (retention column entries defer to this schedule).
- Document 04 - Sub-processor List (subprocessor-side retention durations and propagation latency).
- Document 07 - Helper / Account-Linking Terms § 3, § 4, § 8 (AccountLink retention and cross-account read audit).
- Document 09 - Donor Privacy Policy § 5, § 6 (donor and donation retention).
- Document 13 - Security and Vulnerability Disclosure Policy § 5-§ 9 (session, audit, incident retention).
- Document 15 - Automated Decision-Making and AI Notice § 4, § 5 (crisis-keyword retention and right-to-limit).
- Document 17 - Conflict of Interest Policy (annual disclosure retention).
- Document 18 - Whistleblower and Document Retention Policy (corporate-governance and whistleblower retention).
To the extent any other document states a retention period that conflicts with this schedule, this schedule controls and the other document is to be conformed.
§ 10. Schedule Maintenance
- Annual review. The Secretary, supported by the Treasurer and the operational owner, reviews this schedule no later than the second board meeting of each calendar year.
- Out-of-cycle review. Required upon any of: (a) a material change to the Prisma schema introducing a new data category, (b) activation of donation processing, (c) activation of SMS, (d) a new regulatory obligation (state privacy law expansion, IRS or VA regulatory change), (e) onboarding or offboarding of a subprocessor, (f) a security incident touching retention.
- Board ratification. Changes that lengthen or shorten any retention period at or above 7 years, that touch a "Permanent" row, or that change the deletion trigger on a T4 or T5 row require Board ratification. Other changes (clarifications, new T2 rows added under existing trigger logic, citation updates) may be approved by the Secretary with notice to the Board at the next meeting.
- Version control. Each revision increments the document version. The prior version is preserved in the
Legal-Drafts/_archive/directory. - Audit log of revisions. Each revision is logged in
AuditLogwith the actor, the section changed, and the rationale.
§ 11. Forward-State Items to Update
The following rows are written to be activated, not removed, at the listed milestones. They are listed here so the reviewer knows what to look for.
- Donation processing activation: § 5.10 rows shift from "forward-state" to active. Add
DonorPaymentTokenpropagation row to Document 04. Confirm Stripe DPA retention. - SMS activation: Add a new sub-table in § 5.7 for SMS transmission metadata (carrier handoff logs, opt-in-evidence record). The prior-express-written-consent evidence record must be set to "Life of opt-in + 4 years" per 47 U.S.C. § 227 statute-of-limitations practice.
- SOC 2 readiness: Activate the WORM mirror on
AuditLog. AddAuditLogMirrorrow and confirm 7-year minimum on the WORM device. - HIPAA business-associate posture (if ever): Add a new sub-table with PHI categories; conform to 45 C.F.R. § 164.530(j) (6-year retention of HIPAA policies, procedures, and disclosure accountings).
End of Document 14 - Data Retention Schedule.