Eunifi Data Retention Policy
Effective Date: May 11, 2026 Last Updated: May 11, 2026
1. Purpose
This Data Retention Policy (“Retention Policy”) establishes how Ramsey Theory Group (“RTG”) and the Eunifi platform (“Eunifi” or the “Service”) retain and dispose of personal information, business records, and system data. It supports our commitments under the Eunifi Privacy Policy and applicable laws, including the FTC Safeguards Rule, the FTC Red Flags Rule, the USA PATRIOT Act, the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), Washington RCW 19.375, the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and analogous state privacy and biometric statutes.
This Retention Policy is incorporated by reference into the Eunifi Privacy Policy and any applicable Data Processing Addendum entered into with a Dealer Customer.
2. Scope
This Retention Policy applies to all personal information and business records collected, processed, or stored by Eunifi, including but not limited to:
- Consumer personal information submitted through the Platform by Dealer Customers
- Biometric identifiers and biometric information processed for identity verification, Red Flags screening, and duplicate detection
- Identity verification results and supporting evidence
- Dealer Customer and Dealer User account information
- System logs, security logs, and audit trails
- Marketing and CRM records for prospective and active Dealer Customers
- Support tickets and customer communications
- Backups and archival copies
3. Guiding Principles
- Purpose limitation. Personal information is retained only as long as necessary to fulfill the purpose for which it was collected, or as required by law.
- Data minimization. We collect only what is necessary, and we delete or de-identify data when retention is no longer justified.
- Statutory and contractual compliance. Retention periods reflect the longer of the period required by applicable law and the period required by Dealer Customer contracts.
- Defensibility. Each retention period is documented, reviewable, and tied to a specific purpose.
- Secure disposal. When a retention period expires, data is permanently and irreversibly destroyed or de-identified.
4. Roles and Responsibilities
- Privacy Office ([email protected]) — owns this Retention Policy and reviews it at least annually.
- Security / Engineering Lead — implements technical controls that enforce retention schedules and oversees secure disposal.
- Customer Success / Operations — coordinates retention exceptions tied to Dealer Customer requests, investigations, and legal holds.
- Legal Counsel — approves legal holds, retention exceptions, and any deviation from the schedules in Section 5.
- All Personnel — are responsible for complying with this Retention Policy and reporting any non-compliance.
5. Retention Schedules
The schedules below describe the maximum retention period for each category. Data is deleted or de-identified earlier where reasonably practicable.
5.1 Identity Verification and Biometric Data
| Data Category | Description | Retention Period | Trigger / Notes |
|---|---|---|---|
| Raw ID document images | Front/back capture of driver’s license, passport, state ID, etc. | 30 days after verification completion | Deleted from primary systems; encrypted backups age out per Section 5.7. |
| Raw selfie / liveness video | Selfie or short video captured during the IDV flow | 30 days after verification completion | Same as above. |
| Facial geometry template | Numeric template derived from selfie and ID photo for biometric match | Service term + 3 years, or until duplicate-detection purpose is satisfied | Required for ongoing duplicate detection (Jumio Biometric Duplicate Handling). Deleted earlier on valid Consumer deletion request that we are not legally required to deny. |
| Duplicate-detection vectors / hashes | Irreversible representation used for cross-tenant fraud detection | Service term + 3 years | Stored separately from identifying records; deletion follows the underlying biometric template. |
| Verification result records | Pass / fail decision, document authenticity result, reason codes, match score | 7 years from verification | Supports FTC Red Flags Rule recordkeeping, dispute resolution, and audit. |
| OFAC / sanctions screening results | Hit / no-hit indicators, list version, screening timestamp | 5 years from screening | Aligned with OFAC recordkeeping expectations. |
| IDV Quiz responses | Knowledge-based question responses and outcomes | 2 years from completion | Quiz items themselves are not retained beyond what is needed to validate the score. |
| Red Flags signals | Indicators generated by Red Flags rules and Web Submission Duplicate Detection | 7 years from generation | Supports FTC Red Flags Rule and dealer audits. |
5.2 Consumer Transactional Information
| Data Category | Description | Retention Period | Trigger / Notes |
|---|---|---|---|
| Consumer profile data | Name, DOB, address, phone, email, employment, vehicle of interest | Service term + 2 years | After this period, data is deleted or de-identified for analytics. |
| Last 4 SSN | Last four digits of SSN, where collected | Service term + 2 years | Encrypted at rest; minimum-necessary access. |
| Full SSN | Where required by a Dealer Customer’s Red Flags / OFAC program | 5 years from collection | Strict access controls; deleted from primary systems at end of term and purged from backups within the next backup cycle. |
| Co-applicant information | Information about co-signers, co-applicants, or joint customers | Same as primary Consumer profile | — |
| Signed disclosures and consents | Privacy notices, biometric consent forms, e-signature evidence | 7 years from signature | Supports defense of consent. |
5.3 Dealer Customer and Dealer User Records
| Data Category | Description | Retention Period | Trigger / Notes |
|---|---|---|---|
| Dealer Customer account record | Dealership entity record, billing, configuration | Service term + 7 years | Aligns with general business / tax recordkeeping. |
| Dealer User account | Individual employee credentials, role, profile | Active term + 12 months after deactivation | Deactivated users are anonymized in audit logs only as required by law. |
| Authentication and session logs | Login events, MFA challenges, session metadata | 24 months | Security investigations. |
| Support tickets and communications | Email, chat, call notes between Eunifi and dealership personnel | 5 years | Supports ongoing customer relationships and dispute resolution. |
| Contracts, MSAs, DPAs, order forms | Executed commercial agreements | Service term + 7 years | Standard contract recordkeeping. |
5.4 Security, Audit, and System Logs
| Data Category | Description | Retention Period | Trigger / Notes |
|---|---|---|---|
| Application audit logs | User actions inside the Platform (who did what, when) | 24 months in hot storage; up to 7 years in cold/archival storage where required for Dealer Customer compliance | Cold storage is encrypted and access-restricted. |
| Security event logs | IDS / WAF / authentication anomalies, access violations | 24 months | Incident response and forensics. |
| Infrastructure logs | Cloud, network, container, and service logs | 90 days in hot storage; 13 months in cold storage | Operational and security purposes. |
| Vulnerability scan / pentest reports | Internal and third-party security testing artifacts | 5 years | Compliance and continuous-improvement evidence. |
| Incident response records | Investigations, root-cause analyses, notification records | 7 years from incident closure | Regulatory defensibility. |
5.5 Marketing and CRM
| Data Category | Description | Retention Period | Trigger / Notes |
|---|---|---|---|
| Business-contact records for prospective dealerships | Name, business email, role, dealership, engagement history | Until opt-out or 3 years of inactivity, whichever comes first | B2B contact data only. |
| Email marketing engagement | Open, click, and conversion events | 2 years | Aggregated thereafter. |
| Website analytics | Aggregate visit data, conversion events | 26 months | Generally not tied to identified individuals. |
5.6 De-identified and Aggregated Data
De-identified or aggregated data that cannot reasonably be linked to an identified or identifiable individual may be retained indefinitely for analytics, benchmarking, and product-improvement purposes. We do not attempt to re-identify such data and we contractually prohibit our subprocessors from doing so.
5.7 Backups
Backups are retained on a rolling cycle:
- Daily backups: 35 days
- Monthly backups: 13 months
- Annual archival snapshots: up to 7 years for systems supporting financial, legal, or regulatory records
Personal information identified for deletion is removed from the primary systems immediately; backup copies are overwritten or expired through the normal backup rotation. We do not selectively restore backups to delete individual records.
6. Legal Holds
When RTG receives a litigation, regulatory, or governmental inquiry that may require preservation of information, Legal Counsel will issue a legal hold that suspends the routine deletion of relevant data. Legal holds:
- Are documented in writing
- Identify the data, custodians, and time period subject to hold
- Override the retention schedules in Section 5 for the duration of the hold
- Are released in writing once the matter is resolved, after which normal retention resumes
7. Dealer Customer–Directed Retention
Dealer Customers may, in their service contract or by written instruction, request:
- A shorter retention period for data they submit to the Platform — RTG will honor reasonable requests that do not conflict with our legal obligations.
- A longer retention period for verification records or audit evidence — RTG will accommodate where consistent with applicable law and our security posture; biometric retention extensions require a documented, lawful purpose.
In no case will Dealer Customer instructions override mandatory legal minimums or the biometric maximums set out in Section 5.1.
8. End-of-Service Data Handling
When a Dealer Customer’s subscription terminates:
- Read-only access to data is offered for up to 30 days to allow export.
- Active records for that Dealer Customer are placed into a quarantine state for 90 days to support reactivation or dispute resolution.
- Deletion of Dealer Customer–specific data from production systems occurs within 120 days of termination, subject to Section 5 (where longer retention is required by law) and Section 6 (legal holds).
- Backups age out per the rolling cycle in Section 5.7.
- RTG will provide written confirmation of deletion upon request.
9. Consumer Rights Requests
When a Consumer exercises a deletion, correction, or access right under applicable law:
- For information collected by Eunifi as a service provider to a Dealer Customer, RTG will work with the Dealer Customer to execute the verified request within the legally required timeframe.
- For information collected by Eunifi as the controller / business (for example, Dealer User accounts), RTG will respond directly.
- Deletion requests are honored unless an exception applies (for example, ongoing fraud investigation, legal recordkeeping obligation, defense of legal claims). Exceptions are documented and the requester is informed.
10. Secure Disposal
When the retention period for personal information ends, RTG securely disposes of the data:
- Electronic data: cryptographic erasure of encryption keys, overwriting, or deletion through automated tooling that confirms removal from the primary data store. Removal from backups occurs through normal rotation.
- Biometric data: permanent destruction such that the data cannot be reconstructed. Destruction events for biometric data are logged with timestamp, system, and operator.
- Physical media: disks and removable media that may have stored personal information are degaussed or physically destroyed at end of life by a vetted vendor; certificates of destruction are retained.
11. Policy Review
The Privacy Office reviews this Retention Policy at least annually, and more frequently in response to:
- New or amended laws or regulations
- Material changes to the Service
- Significant security incidents or audit findings
- Changes in Dealer Customer or industry expectations
Material changes are communicated to Dealer Customers and reflected in the published version of this document.
12. Contact
Questions about this Retention Policy may be directed to:
- Email: [email protected]
- Mail: Ramsey Theory Group — Attn: Privacy Office, 2125 Center Avenue, Fort Lee, NJ 07024, United States
- Web: eunifi.com/retention

