CoreID

Data Retention, Storage & Archiving Policy

Last updated: 21/04/2026

This Data Retention, Storage & Archiving Policy explains how Velari Protocol Pty Ltd stores, retains, archives, and provides access to customer data across the lifecycle of an account, including after cancellation or suspension. This policy applies to all customers unless otherwise agreed in writing.

Data Retention, Storage & Archiving Policy

Last updated: 21/04/2026

This Data Retention, Storage & Archiving Policy explains how Velari Protocol Pty Ltd stores, retains, archives, and provides access to customer data across the lifecycle of an account, including after cancellation or suspension. This policy applies to all customers unless otherwise agreed in writing.

1. Overview

CoreID governs each AI system as a secure, auditable system-of-record. Data is retained and stored in accordance with operational requirements, contractual obligations, and applicable legal and regulatory standards.

Data handling practices may vary depending on account status, subscription state, and applicable laws.

This policy should be read together with our Privacy Policy, Terms of Service, and Subscription & Billing Policy.

2. Data Categories

Data stored by CoreID may include:

  • AI system records
  • Compliance and governance records
  • Operational and audit logs
  • Model metadata and configuration data
  • Historical activity and validation records
  • Organizational verification records (including status classifications such as Attested, Registry Validated, or Inherited)
  • Authority attestation confirmations (including timestamps and associated IP address logs)
  • Uploaded corporate registration or incorporation documentation
  • Registry validation results and cross-referencing records
  • Verification history, status changes, and inheritance relationships
  • Activity monitoring signals used to detect abnormal, excessive, or automated platform behavior

This data is retained to support platform functionality, auditability, and regulatory compliance, and organizational verification integrity.

3. Active Data Storage

While an account is active:

  • Data is stored in active operational storage
  • Full access is provided in accordance with the subscribed plan
  • Data is available for normal platform operations, validation, and auditing

Active storage supports ongoing usage, monitoring, and compliance activities.

4. Data Retention After Cancellation

Following cancellation or account restriction:

  • Your account moves to a read-only archived state
  • Your data and records remain in secure operational storage
  • Access is restricted through platform access controls. Modifications, uploads, and new submissions are disabled
  • Reactivation is available where eligible, restoring full access to your existing records

If you wish to permanently remove your account, you may submit a deletion request from your account settings. Deletion requests follow the process described in Section 8.

Verification documentation, attestation records, registry validation logs, verification status history, and related audit data may be retained beyond account cancellation where necessary to preserve audit integrity, prevent fraud, support dispute resolution, or comply with legal and regulatory obligations.

5. Account Archival and Data Preservation

When an account is archived (for example, following subscription cancellation or prolonged inactivity), data is preserved to maintain integrity and auditability.

When an account is archived:

  • Data remains in secure operational storage with access controls applied
  • Modifications, updates, or new submissions are disabled
  • Data remains preserved for audit, legal, or review purposes

CoreID currently operates a single storage tier. Data lifecycle management and tiered storage may be introduced as the platform scales.

6. Long-Term Regulatory Retention

Certain data may be retained for extended periods to meet statutory, legal, or regulatory requirements.

In these cases:

  • Data is retained in secure operational storage for the required retention period
  • Access is limited and controlled
  • Retrieval is available to authorized personnel as required

Retention periods are determined by applicable laws, contractual obligations, and compliance obligations, and may vary based on jurisdiction and the nature of the data involved.

This may include verification-related audit logs and platform integrity monitoring records.

7. Data Access & Export

Depending on account status and applicable policies:

  • Access to data may be limited or restricted
  • Customers may request data exports where permitted
  • Export availability may depend on legal, regulatory, or contractual constraints

CoreID reserves the right to limit or deny export requests where required by law or policy.

8. Data Deletion

CoreID supports user-initiated account deletion. When you submit a deletion request from your account settings:

  • Your account is immediately scheduled for deletion and a confirmation email is sent
  • A 30-day grace period applies, during which you may cancel the request by signing in
  • At the end of the grace period, your personal data is permanently deleted or irreversibly anonymized within CoreID systems. You will receive a confirmation email when deletion is complete

What is deleted: Your user profile, login activity, and personal identifiers associated with your account.

What is retained: Audit records, attestation records, verification history, compliance evidence, and related governance data may be retained where required by legal, regulatory, or contractual obligations. Where records are retained, your identity is anonymized within those records wherever possible, so the underlying compliance trail remains intact without preserving personal identifiers.

Organizational records (such as registered models, governance configurations, and shared compliance documentation) belong to the organization and are not removed by an individual user's deletion request. Organization-level deletion is handled separately and may be requested by an organization administrator through support.

CoreID currently operates a single storage tier. Tiered storage and additional retention automation may be introduced as the platform scales.

9. Enterprise Accounts

Enterprise customers may be subject to additional data retention, storage, and archiving terms, including custom arrangements for large data volumes or regulated environments.

10. Policy Updates

This Data Retention, Storage & Archiving Policy may be updated from time to time. Any changes will be posted on this page and take effect from the date shown above.

11. Contact

If you have questions about data retention or storage practices, please contact: