We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

SigmaTrust Docs · Data Protection & Evidence Handling

Data Protection & Evidence Handling

Retention, deletion and the evidence lifecycle inside the platform.

Evidence with provenance

Evidence items carry their source, collector and timestamps, so an artefact used in an assessment can be traced to where and when it came from.

Deletion that actually deletes

Records removed from operational views are governed by explicit lifecycle handling, and data-subject deletion obligations (DPDP s.8(7)-style duties) are operationally supported rather than left to ad-hoc database work.

Backups and retention

Scheduled, tested backups with defined retention; restoration procedures exercised rather than assumed.

Regional operation

The platform is operated for Indian and Gulf clients with data-residency questions answered per deployment during procurement — see the Trust Center for the current subprocessor register and data-flow statement.

FAQ

How does the platform support DPDP obligations?

Operationally: consent-linked records, retention handling, deletion workflows and audit trails give fiduciaries the machinery their DPDP programme needs; legal obligations remain the customer’s and are supported, not replaced.

Where is our data hosted?

Deployment details, subprocessors and data flows are published in the Trust Center and confirmed per contract — accurate answers beat generic ones.

Explore SigmaTrust →Trust Center