Cridenty
FR / EN

Data retention policy

Cridenty Platform

Current version: V1

English translation provided for convenience. In case of discrepancy, the French version shall prevail.

1. Purpose

This policy describes the retention periods and retention methods for data processed by the Cridenty platform, in accordance with GDPR principles, and the evidence, security and audit requirements of professional use cases.

Cridenty applies a controlled retention policy based on data minimization and the purpose of evidence.

2. General principles

Cridenty undertakes to:

Data retention is determined by:

3. Categories of retained data

3.1 Data not retained

Cridenty does not retain:

Content is processed strictly for technical and transient purposes, only to generate a cryptographic proof.

3.2 Retained data

Cridenty retains exclusively the following categories of data:

Category Description Retention period
Cryptographic proofs Hashes, signatures, timestamps, short identifiers and minimized technical identifiers for export 120 months (10 years)
Technical identifiers Tenant/customer identifier, agent identifier, campaign identifier Duration of the contractual relationship
Audit logs Critical events (authentication, validation, security) with minimized representations of technical targets 12 months by default, or a documented contractual period where security, audit or compliance needs justify it
Configuration data Tenant security settings Duration of the contract

3.3 Cridenty Guard / Agent Guard specific retention

Guard technical signals may include sensitive execution-related information (processes, paths, reduced commands, policy decisions). Their retention is therefore framed by category and may be configured contractually per customer.

Category Examples Indicative retention period
Raw Guard technical signals Process events, AI tool actions, normalized paths, reduced commands, policy decisions Short customer-configurable period, for example 7 to 30 days by default
Aggregated signals / facts / summaries Event counts by policy, machine, AI tool, action type, aggregated score Contractual period or duration necessary for security audit
Alerts / incidents Blocked action, out-of-scope action, required validation, confirmed incident According to contractual obligation or customer policy
Exportable cryptographic proofs Signed proofs, hashes, timestamps and minimized identifiers when the evidentiary purpose justifies it 120 months (10 years)

4. Justification of retention periods

The retention period for cryptographic proofs (120 months) is justified by:

This period helps preserve evidentiary value over time without retaining original content or republishing full technical identifiers in clear form when a minimized and verifiable representation is sufficient.

The 120-month period is also consistent with evidentiary needs and limitation periods applicable to commercial relationships, including general commercial limitation periods and certain long-term retention needs for supporting documents.

5. Location and security

Data retained by Cridenty is:

When the customer requires enhanced localization, France-based hosting or a dedicated instance may be contractually agreed.

Cridenty is bound by an obligation of means to ensure confidentiality, integrity and availability of data.

6. Deletion and purge

At the end of applicable retention periods:

Technical backups may temporarily retain deleted data until the end of their rotation cycle. These backups are protected, access-restricted, and used only for restoration, business continuity or security purposes.

Where anonymization is used, Cridenty seeks reasonable irreversibility through aggregation, generalization or removal of re-identifying elements, in line with CNIL and EDPB best practices.

7. Enhanced retention (optional)

For certain customers or specific regulatory contexts, Cridenty may offer, on a contractual basis:

These options are subject to specific conditions.

8. Policy evolution

This retention policy may be amended to reflect:

The applicable version is the one published on the Cridenty website.

9. Contact

For any question regarding data retention: contact@cridenty.com