DRAFT — COUNSEL REVIEW REQUIRED

These documents were drafted from what Covio's own systems actually do. They have not been reviewed by a lawyer, they are not a contract, and no part of them should be relied on as legal advice or as Covio's final position. Open questions for counsel are listed at the end of each document.

How long

Data Retention Statement

DRAFT — COUNSEL REVIEW REQUIRED

Covio's six retention categories: the three that are settled, the three that are not, and what Covio keeps permanently by decision.

Drafted 21 September 2026

1 · Retention is a policy object, not a habit

Covio answers every "how long do we keep this" question from one place. There are six named categories. Each carries a number of days or an explicit "no expiry", the source the value came from, and — the part that matters — whether the value is ratified or is still a proposal.

The policy in force today is stamped with the version 2026-08-fd2-pending, so any certificate Covio issues under it says on its face that it was issued under an unsettled policy.

2 · The three settled categories

CategoryPeriodWhat it governs
Export download link72 hoursHow long an authenticated link to a company's export bundle stays valid. A new link can be issued
Backup set age-out30 daysWhen the last backup set containing a departed company expires. A company is not truly gone until the backups holding it are, and the purge certificate states that date
Platform audit evidenceKept permanently, by decisionThe append-only ledger of what was done to a company's account, and the certificate recording that an export and a purge happened. A ledger that could erase its own record of a deletion would be the one operation nobody could ever verify

"Kept permanently" here means kept by an explicit decision, not kept because nobody chose a number. Covio's own policy object distinguishes the two and does not let a reader guess which is which.

3 · The three that are not yet fixed

Not settled / not in placeThese are unratified proposals. Covio publishes them as proposals because publishing a proposal as policy would be Covio inventing a legal position on its customers' behalf.

CategoryStatus todayWhat it governs
Delay after termination before a purge is permittedNot fixed. An internal proposal of 90 days exists and has not been ratifiedHow long a terminated company's data is held before it may be destroyed. Too short and a customer cannot get their data back; too long and Covio holds what it should not
Statutory holds that outlive a companyNot fixed. No period is recordedWhether Indian factory-compliance records and documents must be kept even after the company that produced them has left Covio. Purging a record the law requires kept cannot be corrected afterwards
Raw telemetry horizonNot fixed. The proposal is unlimited at launchHow long raw machine telemetry is kept for a company that is still a customer

The first two of these gate destruction. Because they are unratified, Covio's software refuses every production purge today and says why. That refusal is deliberate: it is the system declining to destroy customer data under a policy nobody has ratified.

4 · What deliberately survives a purge

Sixteen tables are declared as retained rather than purged, and every one of them carries a written basis. There is no third state: a table is declared purge or declared retain, and an undeclared table fails Covio's build. Grouped, they are:

  • The evidence that the export and the purge happened: the run record, the per-module record, and the certificate. Deleting these would erase the proof of the deletion.
  • The append-only ledger of platform actions taken on the account, and the lifecycle row the certificate points at.
  • Evidence about Covio's own conduct rather than the customer's business: which Covio staff member opened which screen, the grant that authorised it, and which companies were told about a platform incident.
  • Billing records, on the basis of statutory financial record retention.
  • Rows that are not any one company's: the plan catalogue, firmware images published for a hardware model, connector builds published for a version, and Covio's certification of what a given TallyPrime version was proven to do.
  • The relationship recording which Covio partner onboarded the company — two identifiers and a timestamp, carrying no customer content.

The purge certificate reports what was retained and why, so what survives is on the record rather than merely absent from the deletion counts.

5 · The honest state of retention today

Not settled / not in placeCovio's own review of this area records the finding plainly: a "retain" declaration currently means "forever", with no mechanism to mean anything else. The declaration structure can carry a period as text, but nothing reads it, nothing schedules against it, and no job has ever deleted a retained row.

Concretely: billing records state a period of eight financial years and nothing deletes them at eight years; the support-access and grant records state a basis and no period at all, so they are retained indefinitely by default rather than by decision. Covio is not going to describe that as a retention schedule.

What counsel must rule on before this stops being a draft

Covio drafted this document from its own systems rather than from a template, so what follows are the points where engineering cannot decide and a lawyer must.

  1. 1Are there statutory obligations on Indian factory-compliance records and documents that survive a customer's termination? If so, which record classes and for how long? Everything about compliance records and documents depends on this answer, and the shape of the answer changes what Covio has to build — a hold that survives termination means a purge that deletes part of a table and still issues a truthful certificate, which nothing in the current design does.
  2. 2Is 90 days after termination, before a purge is permitted, acceptable?
  3. 3Is a 30-day backup age-out an acceptable true-erasure horizon, given a company's data survives in encrypted backups for that window after the purge?
  4. 4Must every "retain" declaration carry an enforced period rather than a basis alone? A stated period that nothing enforces is a commitment to delete that is not being kept, which is a different exposure from having no period at all.
  5. 5Is indefinite retention of the support-access log and its authorisation record defensible, and does an erasure request reach them? If they must expire, what period?
  6. 6Does the Companies Act 2013 s.128(5) eight-financial-year books-of-account period apply to Covio's entity and to its billing records? Covio recorded it as the governing obligation and cannot confirm it.
  7. 7Is there an upper bound Covio should place on raw machine telemetry for a live customer?