Back to Mission Control

Retention Schedule

Full Text Document

1stProtect Retention Schedule
Effective Date: July 19, 2026
Last Updated: July 19, 2026
Version: 1.0

This Retention Schedule describes standard retention periods for records processed through the 1stProtect Platform. It is referenced by the 1stProtect End User License Agreement (EULA), the Data Processing Addendum (DPA), and applicable product documentation.

Retention periods below are default periods and may be adjusted where:
- customer subscription tier, product configuration, or Order Form specifies a different period;
- legal, regulatory, litigation hold, or law-enforcement requirements require longer retention;
- customer-directed deletion is required under applicable law or contract.

1. Scope
This schedule applies to records maintained by 1stProtect in connection with platform delivery, security operations, support, and contractual compliance, including:
- account and tenant administration records;
- endpoint telemetry and security data;
- operational, support, and audit records;
- agreement acceptance and legal evidence records.

2. Standard Retention Periods
2.1 EULA Acceptance and Legal Evidence Records
- Retention: Duration of customer relationship plus 7 years.
- Records may include acceptance timestamps, account owner identity, EULA version/hash, source IP, and related session metadata.

2.2 Account, Organization, and Administrative Configuration Records
- Retention: Duration of active subscription plus 24 months.
- Includes organization/account/tenant metadata, role assignments, policy state, and administrative action logs.

2.3 Authentication, Session, and Access Security Logs
- Retention: 12 months.
- Includes authentication events, session activity, access decisions, and security-significant login metadata.

2.4 Endpoint Telemetry (Operational/Security Telemetry)
- Retention: 90 days by default.
- Includes endpoint event telemetry required for detections, investigations, and service operations.

2.5 Security Alerts, Detections, Incidents, and Remediation Records
- Retention: 12 months by default.
- Includes alerts, incident timelines, response actions, and analyst-generated investigation outcomes.

2.6 File/Artifact Collection and Investigation Materials (Where Enabled)
- Retention: 30 days by default.
- Includes collected suspicious files, command output, forensic artifacts, and investigation attachments.

2.7 Support and Troubleshooting Records
- Retention: 24 months after case closure.
- Includes support tickets, diagnostic logs provided for support, and resolution notes.

2.8 Billing, Invoicing, and Payment Records
- Retention: 7 years.
- Maintained for financial reporting, tax, accounting, and contractual compliance obligations.

3. Deletion and Post-Termination Handling
3.1 Standard Deletion Timeline
- Upon termination or expiration, customer data is deleted according to contractual terms and this schedule unless legal retention obligations apply.

3.2 Export Window
- Unless otherwise agreed in writing, customer data export may be available for up to 60 days after termination.

3.3 Backup and Recovery Systems
- Deleted records may persist in encrypted backups for a limited rotation period and are removed during normal backup lifecycle expiry.

4. Exceptions and Overrides
Retention may be extended where reasonably required for:
- legal holds, dispute resolution, or regulatory inquiries;
- fraud prevention, abuse prevention, or security investigations;
- compliance with applicable laws, court orders, or lawful government requests.

5. Customer Controls and Configuration
Where product capabilities support configurable retention, customer-selected retention settings may apply, subject to minimum system safeguards and contractual limits.

6. Contact
Questions about this Retention Schedule may be directed to:
[email protected]