Home / Trust Centre / Data Retention Policy

Asanya Data Retention Policy

Principles and guidelines for the retention, storage and disposal of data within Asanya, ensuring appropriate compliance, accountability and security.

Version: 1.0 Effective: 17 September 2026 Updated: 15 September 2026 NDPA 2023 Compliant

1. Purpose

This Data Retention Policy establishes the principles and guidelines for the retention, storage and disposal of data within Asanya, which is operated by Urhere Solutions Ltd. It supports compliance with applicable Nigerian data protection laws, regulatory requirements and reasonable business, audit and security needs.

2. Scope

This Policy applies to employees, contractors and third-party service providers who handle, store or process data on behalf of Asanya or Urhere Solutions Ltd in connection with Asanya. It covers personal, financial, operational, attribution, programme, transactional, commission, settlement, support and other records processed through or for Asanya.

3. Data Retention Principles

  • Data shall be retained only for as long as reasonably necessary to fulfil legal, regulatory, contractual, security, audit, dispute-resolution and legitimate business requirements.
  • Retention periods shall be determined having regard to applicable law, the nature of the record, the relevant Business or Partner relationship and the purposes for which the data is processed.
  • Secure disposal methods shall be used when data is no longer required.
  • Personal data shall be deleted, anonymised or securely archived when continued identifiable retention is no longer necessary.
  • Termination of a Business or Partner account does not necessarily require immediate deletion of attribution, commission, settlement, audit, security, dispute or other records that Asanya is lawfully required or reasonably entitled to retain.

4. Data Retention Schedule

The following schedule outlines the designated retention periods and lawful rationales across core platform data classifications:

Data Category Retention Period Justification
Business and Partner Account Records 10 years from account closure Regulatory, audit, legal, dispute and account-history purposes
Employee Records 3 years after termination Employment administration and applicable legal requirements
Financial, Transactional, Commission and Settlement Records 7 years Accounting, audit, tax, reconciliation and dispute-resolution purposes
Attribution, Milestone, Qualifying Outcome and Programme Activity Records 7 years from end of programme / last material activity Attribution integrity, audit, commercial reconciliation and dispute-resolution purposes
Legal and Compliance Records As required by law / legal need Regulatory and legal requirements
Marketing and Communications Data 2 years (unless longer lawful basis) Business needs, communications history and user preferences
IT and Security Logs 1 year (subject to investigation extension) Security monitoring and forensic investigations
Customer / User Support Logs 2 years Service improvement, support history and dispute resolution
Contractual Agreements Duration of contract + 6 years Legal, contractual and audit purposes

5. Data Storage and Security

  • Data shall be stored in secure, appropriately access-controlled environments.
  • Appropriate encryption and other technical or organisational safeguards will be applied where required by the nature and risk of the information.
  • Periodic reviews may be conducted to assess compliance with retention and storage requirements.

6. Data Disposal

  • Data that is no longer required shall be permanently deleted, anonymised or securely destroyed as appropriate.
  • Electronic data shall be disposed of using appropriate data-sanitisation methods.
  • Physical records, where any exist, shall be securely destroyed when no longer required.
  • Disposal records may be maintained where reasonably necessary to demonstrate accountability.

7. Roles and Responsibilities

  • The Data Protection Officer or designated privacy lead shall oversee compliance with this Policy.
  • IT and security personnel shall support appropriate storage, access control, backup and secure disposal of electronic data.
  • Relevant Business owners and department heads shall apply the retention schedule to the records within their responsibility.
  • Third-party service providers handling Asanya data shall comply with applicable contractual retention and deletion obligations.

8. Compliance and Review

Non-compliance with this Policy may result in disciplinary, contractual or other appropriate action.

This Policy shall be reviewed at least annually or earlier where required by material product, legal, regulatory or operational changes.

Retention periods may be adjusted where applicable law, a regulatory requirement, litigation hold, active dispute, security investigation or other lawful requirement requires a longer or shorter period.
Need more information?

Contact Asanya / Urhere Solutions Ltd for any questions regarding data retention schedules or disposal procedures.

Urhere Solutions Ltd
100A Apapa-Oshodi Expressway
Lagos, Nigeria