Legal
Data Retention Policy
Systematic Data Lifecycle Management
Purpose and Scope
This Data Retention Policy ("Policy") establishes the principles, schedules, and procedures for the retention and destruction of all personal data, business records, and other information processed by ZenVisa International ("ZenVisa"), operated by Zenway International FZ-LLC.
This Policy applies to all data regardless of format (electronic, physical, or other) and all personnel who handle such data. It supplements our Privacy Policy and is designed to ensure compliance with UAE Personal Data Protection Law (PDPL), UAE Anti-Money Laundering Law, tax regulations, and other applicable legal requirements.
Definitions
"Archival Data": Data retained for historical, research, or reference purposes beyond active operational use.
"Destruction": The complete and irreversible elimination of data in all forms.
"Legal Hold": A suspension of normal retention and destruction practices due to litigation, investigation, or regulatory requirement.
"Retention Period": The length of time data must be maintained before authorized destruction.
Retention Principles
ZenVisa's data retention practices are guided by the following principles: (a) Data is retained only as long as necessary for the purposes for which it was collected; (b) Retention periods comply with all applicable legal and regulatory requirements; (c) Data is destroyed securely when no longer needed; (d) Data subjects are informed of retention periods at the time of collection; (e) Retention schedules are reviewed regularly and updated as necessary; (f) Legal holds supersede normal destruction schedules; (g) Retention practices are documented and auditable.
Retention Schedule
ZenVisa maintains the following retention periods: Client case files: 7 years from case completion (UAE Civil Code limitation period). AML/KYC records: 6 years from end of business relationship (UAE AML Law). Financial/tax records: 7 years from transaction date (UAE Tax Procedures Law). Communication records: 3 years from date of communication. Website logs: 1 year from date of collection. Consent records: Duration of consent plus 3 years. Complaint records: 6 years from resolution. Employee records: 10 years from employment end. Contract records: 10 years from termination. Backup data: Aligned with source data retention.
Client File Retention
Client case files are retained for 7 years from the date of case completion or termination of the client relationship, whichever is later. This includes: application forms and supporting documents; correspondence and communication records; case notes and consultant assessments; government submissions and responses; and invoices and payment records.
After the retention period, files are reviewed for any ongoing legal hold obligations before destruction. Where a client requests early deletion, such requests are evaluated against legal retention obligations.
Financial Records Retention
All financial records, including invoices, receipts, payment confirmations, bank statements, and accounting records, are retained for 7 years from the date of the transaction, in accordance with UAE Federal Decree-Law No. 28 of 2022 on Tax Procedures.
Communication Records
Email correspondence, chat transcripts, and call records are retained for 3 years from the date of communication, unless they relate to an active case (in which case the longer case file retention period applies) or a legal hold.
AML/KYC Records
Anti-money laundering and know-your-customer records are retained for 6 years from the end of the business relationship, as required by UAE Cabinet Decision No. 10 of 2019 concerning the Implementing Regulation of the AML Law. This includes: identification and verification documents; risk assessments; transaction records; suspicious activity reports; and screening results.
Website and Log Data
Website access logs, server logs, and analytics data are retained for 1 year from the date of collection. Aggregated, anonymized statistics may be retained indefinitely for business analytics purposes.
Backup Data
Backup copies of data are retained in accordance with the retention period of the source data. Backups are destroyed within 30 days after the source data reaches its destruction date, except where a legal hold is in effect.
Special Categories of Data
Personal data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or orientation ("Special Categories") is subject to enhanced protection and retention limits. Such data is retained only for the specific purpose for which it was collected and destroyed immediately upon completion of that purpose, unless longer retention is required by law.
Data Destruction Procedures
When data reaches the end of its retention period and no legal hold applies, it is destroyed using the following methods: (a) Electronic data: Secure deletion using industry-standard wiping software (minimum 3-pass overwrite), followed by verification; (b) Physical documents: Cross-cut shredding to DIN P-4 standard or higher, followed by certified disposal; (c) Storage media: Physical destruction or degaussing before disposal; (d) Cloud data: Permanent deletion from all systems and backups, with written confirmation from the cloud provider.
Destruction is documented with: date of destruction; description of data destroyed; method used; and authorized personnel signature.
Early Destruction Requests
Data subjects may request early destruction of their personal data by contacting dpo@zenvisa.ae. Such requests will be honored unless: the data is required for ongoing legal proceedings; retention is required by law or regulation; the data is necessary for establishing, exercising, or defending legal claims; or the request would prejudice our ability to comply with AML/KYC obligations.
Legal Hold and Litigation
When ZenVisa becomes aware of pending or anticipated litigation, investigation, or regulatory proceeding, a legal hold may be issued suspending normal destruction schedules for relevant data. Legal holds remain in effect until formally lifted by the Legal Department. All personnel must comply immediately with legal hold notices.
Cross-Border Data Retention
Data transferred outside the UAE is subject to the same retention periods and destruction procedures as data stored within the UAE. ZenVisa ensures that third-party processors in other jurisdictions comply with these retention requirements through contractual provisions.
Third-Party Processor Retention
Third-party processors handling ZenVisa data are contractually bound to: retain data only for the period specified by ZenVisa; return or destroy data upon contract termination; and provide certification of destruction. ZenVisa audits third-party compliance annually.
Data Subject Rights Impact
Data retention periods are designed to balance: operational needs; legal obligations; and data subject rights (including the right to erasure). Where a data subject exercises the right to erasure, we evaluate the request against our retention obligations. Data that is subject to legal retention requirements will not be deleted, but processing will be restricted to storage only.
Compliance Auditing
The Data Protection Officer conducts annual audits of data retention practices to verify: adherence to retention schedules; proper documentation of destruction; compliance with legal holds; and effectiveness of destruction methods. Audit findings are reported to senior management.
Breach Notification Records
Records of data breaches, including incident reports, investigation findings, notifications sent, and remedial actions, are retained for 6 years from the date of the breach, in accordance with PDPL requirements.
Policy Review and Updates
This Policy is reviewed annually and updated as necessary to reflect changes in: applicable laws and regulations; business operations; data processing activities; and industry best practices. The next scheduled review is 15 July 2026.
Roles and Responsibilities
Data Protection Officer: oversees implementation of this Policy. Department Heads: ensure compliance within their departments. IT Department: implements technical retention and destruction measures. All Staff: follow retention procedures and report violations.
| Data Protection Officer | dpo@zenvisa.ae |
|---|---|
| Legal Department | legal@zenvisa.ae |
| Compliance Officer | compliance@zenvisa.ae |
| Address | RAKEZ Business Centre FZ, Ras Al Khaimah, UAE |
© 2025 Zenway International FZ-LLC (trading as ZenVisa International). All rights reserved. RAKEZ Business Centre FZ, Ras Al Khaimah, UAE.