KYC.me.co.bw

Data Retention Policy

Last updated: 24 July 2026 · Operator: Mobile Enterprises (Pty) Ltd t/a M.E Smart Communications, Botswana

Back to home Privacy Policy Terms of Service Cookie Policy Data Processing Agreement Acceptable Use Policy Refund & Cancellation Policy Security Policy Data Retention Policy Privacy Notice for KYC Respondents

Data Retention Policy

Under the Botswana Data Protection Act, 2024, personal data must not be kept longer than necessary. This policy sets out how long KYC.me.co.bw (Mobile Enterprises (Pty) Ltd) retains each category of data.

1. Retention schedule

Data categoryRetention periodNotes
KYC entries & uploaded documents (active client account) Duration of the client’s subscription The client (data controller) may delete entries earlier from their dashboard and controls their own statutory retention duties.
KYC entries & documents after account cancellation 30-day grace period, then securely deleted Export available on request during the grace period. Where a client is legally required to retain KYC records (commonly 5 years in regulated sectors), the client must export before the grace period ends; we retain only at the client’s documented instruction.
SMS OTP records Up to 12 months OTP codes themselves are hashed and expire within minutes; logs keep the number, timestamp and delivery outcome for fraud prevention and billing.
Audit logs Up to 24 months Logins, views, edits, exports and security events.
Client account & registration data While the account is active; billing records as required by Botswana tax/accounting law Registration-interest leads are reviewed periodically and deleted when no longer needed.
Server & application logs (access, error) Up to 12 months Rotated automatically; used for security and troubleshooting.
Database backups Up to 30 days Deleted data disappears from backups on the normal cycle, never later than 30 days.
Cookie consent records 12 months in the browser Stored in the visitor’s browser; renewed when a new choice is made.

2. Secure deletion

When retention ends, records are deleted from production databases, uploaded files are removed from storage, and residual backup copies are overwritten on the normal backup cycle. Deletion is designed to be irreversible using the tools available in our hosting environment.

3. Legal holds

Where we are required by law, a regulator, or pending litigation to preserve data, the affected records are exempt from deletion until the obligation ends.

4. Controller-instructed retention

Where we process data on a client’s behalf, the client (as data controller) sets the retention period through its instructions and use of the Platform. Clients with statutory KYC retention duties should export their records before closing their account.

Questions: [email protected].

Privacy Policy Terms of Service Cookie Policy DPA Acceptable Use Refunds Security Data Retention Data protection: [email protected]

We use essential cookies to keep you signed in and secure. With your consent we also use analytics cookies (Google Analytics) to understand how our site is used. See our Cookie Policy and Privacy Policy.