Data Retention Policy

Last Updated: July 5, 2026  |  Effective Date: July 5, 2026


1. Introduction

This Data Retention Policy outlines how ShambaCare collects, stores, and retains personal data in compliance with the Kenya Data Protection Act, 2019 and other applicable data protection regulations. This policy should be read together with our Privacy Policy.

2. Data Categories and Retention Periods

2.1 User Account Information

Data Type Retention Period Retention Rationale
Name, contact information, login credentials While account is active + 7 years after closure Account management, legal compliance, fraud prevention
Profile information (farm details, location) While account is active + 7 years after closure Service delivery, agricultural advisory
Authentication logs and session data 90 days Security monitoring, incident investigation

2.2 Agricultural Data

Data Type Retention Period Retention Rationale
Crop images and diagnostic results 5 years from diagnostic date Historical analysis, AI model improvement, farmer records
Crop planting and harvest records 7 years from record date Agricultural planning, trend analysis
Field visit reports and recommendations 5 years from visit date Extension officer records, service quality
Pesticide calculation records 3 years from calculation date Regulatory compliance, safety records

2.3 Marketplace Data

Data Type Retention Period Retention Rationale
Product listings and descriptions While listing is active + 2 years after removal Marketplace operation, dispute resolution
Transaction records and communications 7 years from transaction date Financial compliance, dispute resolution
Buyer and seller reviews 5 years from review date Trust system, quality assurance

2.4 Communication Data

Data Type Retention Period Retention Rationale
Email communications 3 years from date of communication Service support, legal compliance
Support tickets and responses 5 years from ticket closure Service improvement, quality assurance
In-app messages and notifications 1 year from message date Service delivery, user support

2.5 Analytics and Technical Data

Data Type Retention Period Retention Rationale
Website usage analytics (aggregated) 2 years Service improvement, business intelligence
Server logs and error reports 6 months System maintenance, security monitoring
IP addresses and access logs 90 days Security, fraud prevention

3. Data Retention Principles

3.1 Purpose Limitation

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

3.2 Data Minimization

We collect and retain only the minimum amount of personal data required to achieve our purposes. When data is no longer needed, it is securely deleted or anonymized.

3.3 Accuracy and Currency

We take reasonable steps to ensure retained data is accurate, complete, and up-to-date. Users may request correction or deletion of their data as outlined in our Privacy Policy.

4. Data Deletion and Disposal

4.1 Automatic Deletion

When retention periods expire, data is automatically deleted or anonymized through:

4.2 User-Requested Deletion

Users may request deletion of their personal data before the end of retention periods by:

We will process deletion requests within 30 days, subject to legal and regulatory requirements.

4.3 Account Closure

When a user closes their account:

5. Legal and Regulatory Retention Requirements

Certain data may be retained longer than standard periods to comply with:

6. Data Archiving

6.1 Archive Criteria

Data that is no longer actively used but must be retained is moved to secure archives when:

6.2 Archive Security

Archived data is stored with enhanced security measures:

7. Data Anonymization

7.1 Anonymization Process

When data is no longer needed in identifiable form but has value for analysis, we:

7.2 Anonymized Data Use

Anonymized data may be used for:

8. Special Categories of Data

8.1 Health and Agricultural Data

Crop health and diagnostic data is treated as sensitive information:

8.2 Biometric Data

We do not currently collect biometric data. If this changes in the future, specific retention policies will be implemented with explicit user consent.

9. Data Breach Retention

In the event of a data breach:

10. Third-Party Data Processors

We use third-party services to process data. We ensure that:

11. Data Subject Rights

Users have the right to:

12. Policy Review and Updates

This Data Retention Policy is reviewed annually and updated as necessary to reflect:

13. Compliance and Monitoring

13.1 Internal Audits

We conduct regular internal audits to ensure:

13.2 Staff Training

All staff with access to personal data receive training on:

14. Contact Information

For questions about data retention or to exercise your data subject rights:

My Crops Diagnostics Field Visits
More
More Options
Home Dashboard Profile Support Tickets Login