Data Retention Schedule
This Schedule supplements the CDN.MN Privacy Policy and describes the standard retention periods or criteria used by NicNames, Inc.
A shorter period may apply where a Customer deletes data or where data is no longer necessary. A longer period may apply where required for law, tax, accounting, payment disputes, security, fraud prevention, abuse investigation, litigation, legal hold, or protection of rights.
Deletion from distributed systems may require reasonable propagation and backup rotation.
Standard retention
| Data category | Standard retention |
|---|---|
| One-time email sign-in code | Valid for 10 minutes; invalidated immediately after successful use or after 5 failed attempts. Cryptographic code records are deleted through routine database retention. |
| Human Account session | Valid until revocation, 7 days of inactivity, or 30 days after creation, whichever occurs first. Revoked and expired-session metadata may be retained for up to 90 days for security investigation. |
| Pending Agent device claim | 15 minutes, followed by expiration. Expired claim metadata may be retained for up to 90 days for security and abuse prevention. |
| Agent access token | 24 hours unless revoked earlier. Only a cryptographic hash is stored. Token-use and revocation metadata may be retained with audit records. |
| Account and profile data | While the Account is active and ordinarily for 30 days after confirmed deletion, subject to billing, security, abuse, audit, and legal exceptions. |
| Workspace, Site, Origin, and domain configuration | While active and ordinarily for 30 days after confirmed deletion or termination, subject to restoration, audit, security, and legal exceptions. |
| Customer Content at the Origin | Not stored by CDN.MN as the authoritative original. Retention is controlled by Customer at its Origin. |
| Optimized cache variants in origin cache storage | Until purge, expiry, eviction, Site deletion, Account closure, or operational cleanup. Deletion initiated by Site or Account closure is ordinarily completed from active cache storage within 30 days. |
| Edge-cached optimized variants | Subject to cache expiry, invalidation, and eviction. The standard cache lifetime is 30 days and may be as long as 365 days for an eligible object, but a purge or suspension may invalidate access sooner. |
| Raw CDN access logs | 90 days. |
| Aggregated daily usage, billing measurement, and invoice support data | Up to 7 years where needed for billing, tax, accounting, dispute, and legal records. Aggregated or deidentified operational statistics may be retained longer. |
| Application and infrastructure operational logs | 30 days unless a security or incident record is preserved longer. |
| Audit events for user, Agent, billing, domain, configuration, purge, and security actions | 24 months after the event, unless a longer period is required for dispute, security, abuse, or legal purposes. |
| Analyzer run records and machine-readable reports | Up to 30 days after the scan. |
| Analyzer optimized preview files | Up to 30 days after creation or earlier deletion. |
| Free compressor uploads and outputs | Up to 24 hours after processing. |
| Support communications | 3 years after the matter closes. |
| Privacy requests and identity-verification records | 3 years after completion, or longer where required by law. |
| Abuse, infringement, vulnerability, and security cases | 3 years after closure, or longer for repeated abuse, active risk, litigation, law-enforcement preservation, or legal claims. |
| Billing, tax, payment, invoice, refund, and dispute records | 7 years after the transaction or longer where required by law. |
| Payment-card data | CDN.MN does not store full payment-card numbers. The payment processor retains payment information under its own policy and legal obligations. |
| Marketing consent and suppression records | For the duration of consent and as long as necessary to honor an unsubscribe or legal obligation. |
| Legal acceptance records | 7 years after Account closure or the end of the applicable agreement. |
| Database and service backups | Rotated and ordinarily deleted or overwritten within 90 days. Data in a backup is not restored to active use except for disaster recovery, and deletion requests are reapplied following restoration. |
| Security telemetry preserved for an active incident | For the incident and as long as reasonably necessary for remediation, fraud prevention, legal claims, or law. |
| Deidentified or aggregated data | May be retained without a fixed limit where it cannot reasonably identify an individual and is maintained as deidentified. |
Deletion and purge behavior
Customer purge
A cache purge invalidates the selected cached variants. Propagation is not instantaneous. A purge does not delete the original at the Customer's Origin.
Site deletion
Site deletion:
- unpublishes active delivery configuration;
- revokes Site-specific Agent access where applicable;
- initiates deletion of Site configuration and optimized variants;
- preserves required billing, audit, security, and legal records; and
- does not delete the Customer's Origin content.
Account or Workspace deletion
Account or Workspace deletion may require cancellation of subscriptions and ownership checks. After confirmation, NicNames initiates deletion of active Account data and Customer-controlled resources, subject to the periods and exceptions above.
Legal hold
Where NicNames reasonably anticipates litigation, receives lawful preservation process, or must preserve evidence of fraud, abuse, infringement, or a security incident, affected data may be retained until the hold ends.
Customer-selected longer retention
A paid plan or Order may provide longer log, audit, or reporting retention. The selected period will be shown in the Account or Order and supersedes a shorter standard period for that category.
Contact
Questions or requests concerning retention may be sent to privacy@cdn.mn.