법적 고지

Data Retention Policy

발효일: 2026-03-01

회사: Asteria Limited (HK)

This Data Retention Policy explains ASTERIA KYC’s general approach to retaining, deleting, anonymizing, or preserving data processed through the ASTERIA KYC website and services. It applies to data processed in connection with identity verification, document verification, liveness detection, biometric processing, AML screening, fraud prevention, risk scoring, case management, API, SDK, reporting, customer support, security, and operational administration.

Retention requirements may vary depending on Customer instructions, applicable law, service configuration, contractual terms, security needs, fraud prevention requirements, dispute handling, and regulatory obligations.

1. Purpose of Data Retention

ASTERIA KYC retains data only where there is a legitimate purpose, such as:

  • providing verification and compliance-support services
  • maintaining audit trails
  • enabling Customer review and reporting
  • supporting fraud prevention
  • supporting AML and risk workflows
  • troubleshooting technical issues
  • maintaining system security
  • complying with legal obligations
  • resolving disputes
  • enforcing agreements
  • improving service reliability
  • preserving evidence of workflow events where appropriate

2. Categories of Data Subject to Retention

Data subject to retention may include:

  • identity document data
  • document images
  • document metadata
  • selfie images
  • facial images or video frames
  • liveness signals
  • biometric-related processing signals where enabled
  • verification results
  • risk scores
  • AML screening outputs where enabled
  • sanctions, PEP, adverse media, or watchlist indicators where enabled
  • case management records
  • reviewer notes
  • audit logs
  • API logs
  • dashboard activity logs
  • account administrator data
  • support communications
  • security logs
  • cookie preference data
  • website analytics data where enabled

3. Customer-Controlled Data

Where ASTERIA KYC processes data on behalf of a Customer, the Customer may determine the applicable retention period, subject to service capabilities, contractual terms, legal requirements, operational constraints, and security considerations.

Customers are responsible for configuring retention settings where available and for ensuring that retention aligns with their legal obligations and internal policies.

4. Legal and Regulatory Retention

Certain Customers may be subject to AML, KYC, financial crime, tax, gaming, payments, fintech, virtual asset, corporate, consumer protection, or other recordkeeping obligations.

ASTERIA KYC does not determine the Customer’s required legal retention period. Customers must obtain appropriate legal or compliance advice and configure or instruct retention accordingly.

5. Security and Fraud Prevention Retention

ASTERIA KYC may retain certain logs, fraud signals, abuse indicators, security events, device signals, or risk-related metadata for a period reasonably necessary to protect the Services, prevent abuse, investigate incidents, enforce policies, and maintain platform integrity.

Security and fraud prevention data may need to be retained even where other workflow data has been deleted, if permitted by law.

6. Audit Trail Retention

Verification workflows may generate audit trails, including timestamps, status changes, reviewer actions, system events, API events, and case history.

Audit trails support accountability, dispute resolution, compliance review, quality control, and operational integrity.

Retention of audit trails may depend on Customer configuration, contractual terms, legal obligations, and service design.

7. Biometric-Related Data Retention

Where liveness detection or biometric comparison features are used, ASTERIA KYC may process facial images, video frames, biometric-related signals, similarity scores, liveness indicators, or other technical outputs.

Retention of biometric-related data should be limited to what is necessary for the configured verification purpose, legal obligations, fraud prevention, audit, dispute resolution, or Customer instructions.

Customers are responsible for providing required notices, obtaining consent where necessary, and determining lawful retention periods for biometric-related processing.

8. Website and Cookie Data Retention

Website data, cookie preferences, analytics events, and technical logs may be retained for operational, analytics, security, and consent management purposes.

Cookie-related retention is described further in the Cookie Policy.

9. Support and Business Contact Data

Business contact data, customer communications, support tickets, onboarding correspondence, commercial records, and administrative communications may be retained for account management, support history, contractual administration, dispute resolution, and legal compliance.

10. Deletion

Data may be deleted when:

  • it is no longer required for the purpose collected
  • the Customer requests deletion and deletion is legally and technically permissible
  • the applicable retention period expires
  • the account is terminated and no further retention basis applies
  • deletion is required by law
  • the data is no longer necessary for security, fraud prevention, dispute, audit, or operational purposes

Deletion may occur through active deletion, scheduled deletion, anonymization, aggregation, overwriting, or other technically appropriate methods.

11. Anonymization and Aggregation

ASTERIA KYC may anonymize or aggregate data so that it no longer reasonably identifies an individual.

Anonymized or aggregated data may be used for analytics, service improvement, security research, performance measurement, fraud pattern analysis, and operational reporting, where permitted by law.

12. Backup Retention

Deleted data may remain in backups for a limited period until backup cycles expire or restoration points are overwritten.

Backup data is generally not used for active processing unless restoration is necessary for security, continuity, disaster recovery, or legal reasons.

13. Legal Holds and Preservation

ASTERIA KYC may preserve data beyond normal retention periods where necessary for:

  • legal claims
  • regulatory inquiries
  • investigations
  • court orders
  • law enforcement requests
  • security incidents
  • fraud investigations
  • dispute resolution
  • enforcement of agreements
  • protection of rights, safety, or property

14. Customer Requests

Customers may request deletion, export, retention modification, or other data handling actions through available tools or official support channels.

ASTERIA KYC may require verification of authority before acting on such requests.

Requests may be limited by technical feasibility, contractual terms, legal obligations, security needs, fraud prevention requirements, or ongoing disputes.

15. End User Requests

Where ASTERIA KYC processes data on behalf of a Customer, End Users should generally direct access, correction, deletion, or objection requests to the Customer that controls the verification relationship.

ASTERIA KYC may assist Customers in responding to valid requests where required by applicable law or agreement.

16. Retention After Account Termination

After a Customer account is terminated, ASTERIA KYC may retain data for a limited period to support transition, backup, audit, billing, dispute resolution, legal compliance, fraud prevention, and security purposes.

Customer-controlled data may then be deleted, anonymized, or retained only where a valid basis remains.

17. Retention and Service Configuration

Retention capabilities may vary by product, workflow, data category, region, and service plan.

Customers should confirm retention behavior before deploying workflows in regulated or high-risk environments.

18. No Universal Retention Period

Because ASTERIA KYC supports different industries, jurisdictions, and use cases, this public policy does not set a single universal retention period for all Customer data.

Retention must be assessed based on the Customer’s legal obligations, selected workflow, contractual terms, configuration, and risk environment.

19. Updates to This Policy

ASTERIA KYC may update this Data Retention Policy to reflect changes in law, technology, service architecture, security practices, or operational requirements.

문의

이 정책에 대해 궁금한 점이 있으신가요?

본 정책, ASTERIA KYC 서비스, 데이터 처리, 컴플라이언스 워크플로우 또는 문서에 관한 문의 사항이 있으시면 웹사이트의 공식 연락 채널을 통해 Asteria에 문의해 주십시오.

Data Retention Policy | ASTERIA KYC