Data Retention Policy

Effective Date: 1 August 2026

1. Purpose

This Data Retention Policy explains how ArayaPRO (“ArayaPRO”, “we”, “our”, or “us”) retains, manages and securely disposes of personal information and business data processed through our platform.

Our objective is to retain information only for as long as it is required to deliver our services, meet legal and contractual obligations, protect the security of our platform, and resolve disputes where necessary.

This policy applies to all customers, authorised users, suppliers whose information is stored within the platform, and visitors who interact with ArayaPRO.

2. Customer Data Ownership

Customer data remains the property of the customer.

ArayaPRO processes and stores customer data solely for the purpose of providing the Services, maintaining platform security, supporting customers, and complying with applicable legal and regulatory obligations.

3. Data Retention Schedule

Unless otherwise required by law or agreed with a customer, ArayaPRO retains information in accordance with the following schedule.

Data Category Retention Period
Customer account information For the duration of the subscription and up to 90 days following termination
Supplier records and uploaded documents For the duration of the customer’s subscription and up to 90 days following termination
User account details While the user account remains active and up to 90 days after removal
Billing and financial records Seven (7) years, or longer where required by law
Customer support requests Two (2) years after closure
Audit logs Two (2) years
Security and system logs Two (2) years, or longer where required for security investigations
Platform backups Thirty (30) days

Retention periods may be extended where required by applicable legislation, regulatory obligations, legal proceedings, or ongoing security investigations.

4. Account Termination

Following termination of a customer’s subscription, customer data will generally be retained for up to ninety (90) days to allow for account recovery, data export, or resolution of outstanding matters.

After this period, customer data will be securely deleted or permanently anonymised unless ArayaPRO is legally required to retain it.

Customers requiring a copy of their data prior to deletion should contact ArayaPRO before the retention period expires.

5. Secure Deletion

When information is no longer required, ArayaPRO securely deletes or anonymises the data using industry-standard processes designed to prevent unauthorised recovery or access.

Backups are managed separately and are automatically removed in accordance with our backup retention schedule.

6. Data Security During Retention

While information is retained, ArayaPRO implements appropriate technical and organisational security measures, including:

  • Encryption of data in transit and at rest where appropriate.
  • Role-based access controls.
  • Multi-factor authentication for privileged access.
  • Continuous monitoring of platform security.
  • Secure backup and recovery processes.

7. Exceptions

ArayaPRO may retain information beyond the standard retention periods where reasonably necessary to:

  • comply with applicable laws or regulatory requirements;
  • establish, exercise or defend legal claims;
  • investigate fraud, misuse or security incidents;
  • enforce contractual rights; or
  • protect the integrity and security of the platform.

8. Changes to this Policy

We may update this Data Retention Policy from time to time to reflect changes in our services, legal obligations, or business practices. The most current version will always be available at www.arayapro.com.

9. Contact Us

If you have any questions about this policy or wish to request the deletion or export of your data, please contact:

ArayaPRO

Email: info@arayapro.com

Address: Level 26, 1 Bligh Street, Sydney NSW 2000, Australia