Privacy, retention and deletion
KolayVisa is built to hold your documents for as short a time as possible. There is no permanent passport vault: documents belong to one application, and deleting that application deletes them.
Retention
Policy version retention-2026-09-01
| Data | While active | After completion | If abandoned |
|---|---|---|---|
| Original documents | Needed for processing | Deleted after 7 days | Deleted after 30 days |
| Extracted values | Needed for the package | Deleted after 7 days | Deleted after 30 days |
| Generated package | Available to download | Deleted after 7 days | Not created |
| Product analytics | Pseudonymous, no values | Aggregated | Aggregated |
| Deletion receipt | Not created yet | Kept as evidence, no values | Kept as evidence, no values |
Delete now
Deletion is a workflow with observable states, not a flag in a database.
- 1. scheduled
- 2. locked
- 3. primary deleted
- 4. derivatives deleted
- 5. provider confirmed
- 6. backup expiry pending
- 7. completed
Every original upload, redacted preview, extracted value, canonical fact, generated output and queued payload is removed, and the encryption key for that application is destroyed so any surviving ciphertext is unreadable. You receive a receipt listing what was deleted and when.
What we do not claim
This deployment keeps no encrypted backups, so the backup stage of the deletion workflow reports not_applicable rather than a window we cannot honour. A hosted deployment must publish its real backup expiry period here.
Never written to logs or analytics
- passport and identity document numbers
- names in a document context
- machine readable zone strings
- bank statement text and balances
- raw extraction payloads
- signed document URLs
- generated form contents
The event ledger records what happened — a document was classified, a check was raised, a package was generated — using a pseudonymous application reference. An automated test fails the build if any sensitive value reaches it.