SigmaTrust Docs · Data Protection & Evidence Handling
Data Protection & Evidence Handling
Retention, deletion and the evidence lifecycle inside the platform.
Evidence with provenance
Evidence items carry their source, collector and timestamps, so an artefact used in an assessment can be traced to where and when it came from.
Deletion that actually deletes
Records removed from operational views are governed by explicit lifecycle handling, and data-subject deletion obligations (DPDP s.8(7)-style duties) are operationally supported rather than left to ad-hoc database work.
Backups and retention
Scheduled, tested backups with defined retention; restoration procedures exercised rather than assumed.
Regional operation
The platform is operated for Indian and Gulf clients with data-residency questions answered per deployment during procurement — see the Trust Center for the current subprocessor register and data-flow statement.
FAQ
How does the platform support DPDP obligations?
Operationally: consent-linked records, retention handling, deletion workflows and audit trails give fiduciaries the machinery their DPDP programme needs; legal obligations remain the customer’s and are supported, not replaced.
Where is our data hosted?
Deployment details, subprocessors and data flows are published in the Trust Center and confirmed per contract — accurate answers beat generic ones.
