# Data Retention and Footprints

## Introduction

The Global Data API prioritizes data privacy and protection. This section details our policies regarding the retention, storage, and access of the data communicated through our API.

> **Important Note**: No Personally Identifiable Information (PII) sent to Global Data as part of an API request is stored or retained unless it's explicitly necessary for processing the request.

## Data Retention Policy

### What We Retain:

1. **Query Data**: This encompasses the data necessary to process the requested query. For instance, a "Person Search" might involve PII like names, addresses, and phone numbers.
2. **Return Data**: Data sent back in response to a query, which might also contain PII.
3. **Local Data**: Details from the local web browser or software agent making the request. Examples include browser versions, operating systems, and screen resolutions.
4. **Network Data**: Captured from internet connections to our API services, primarily the IP address of the requester.

While we retain various data types, PII within Query Data is never stored or retained.

### How We Store Data:

- **Local and Network Data**: Stored in server logs and our service audit database.
- **Query Data**: Stripped of any PII and then stored in the service audit database.
- **Return Data**: Contains PII already known to Global Data and stored in our service audit database.

### Security Measures:

- All data, both in transit and at rest, is encrypted using industry-standard methodologies.
- Access to stored data adheres strictly to the Global Data IT policy, following the principle of least privilege.

### Why We Store Data:

Data storage primarily caters to:

1. **Historic Review**: Enables users to revisit their past API queries or searches.
2. **Audit Purposes**: For refining service performance or addressing service hitches.
3. **Regulatory Compliance**: Meeting requirements like the Australian Privacy Act and Australian Privacy Principles.
4. **Specific Processing**: Particularly when data is added for future access purposes, e.g., in datawashes.

## Data Retention Duration

The period for which data is retained varies:

- **Query Data**: Retained indefinitely from the capture time, stripped of any PII.
- **Return Data**: Retained indefinitely post initial capture.
- **Network and Local Data**: Kept indefinitely if they're devoid of PII.

## Data Erasure

Once the retention period is fulfilled, data is systematically purged and obliterated, aligning with industry best practices and the Global Data's Data Lifecycle policy.

## Access Footprint Policy

It's crucial to highlight that Global Data is not a credit bureau or assessment entity. Therefore, we don't create access footprints or access records on a data record that's discernible to end-users or record proprietors, beyond the scope described in this documentation.
