← Back to home

Data Retention & Protection Policy

Last updated: July 11, 2026

Lumus is a product of Digitaro Private Limited, a company incorporated in Singapore.

This Policy describes how Digitaro Private Limited ("Digitaro") retains, protects, and deletes data processed through Lumus. Lumus is a product of Digitaro Private Limited, Singapore. It should be read with our Privacy Policy and Security Policy.

Contact for retention, deletion, and data protection requests: labs@digitaro.co.

1. Roles

  • Customer (school, academy, organization): typically the controller of student, parent, and staff education records in Lumus
  • Digitaro: processor of Customer Content as instructed by the Customer; controller of account, billing, website, and support data we collect directly

2. Categories of data

  • Account & identity: names, emails, roles, authentication identifiers
  • Education records: enrollments, grades, attendance, submissions, feedback, messages
  • Media & files: videos, PDFs, images, and other uploads (including imported Zoom recordings where configured)
  • Integration data: OAuth tokens, meeting metadata, webhook events from Zoom and similar providers
  • Operational data: logs, diagnostics, security events
  • Commercial data: contracts, invoices, payment metadata

3. Retention principles

We retain data only as long as needed for:

  • Providing the Services to the Customer
  • Legitimate business needs (security, dispute resolution, accounting)
  • Legal, regulatory, or contractual obligations

Customers may set internal retention policies for education records that are stricter than Digitaro's platform defaults; Digitaro will assist with export and deletion requests consistent with the Customer agreement and law.

4. Default retention periods

Exact periods may vary by deployment (SaaS vs dedicated) and Customer contract. Unless otherwise agreed in writing, Digitaro applies the following defaults:

  • Active Customer Content: retained for the duration of the active subscription / deployment
  • After contract termination or written deletion request: Customer Content is scheduled for deletion or return within 30 to 90 days, after a short recovery window, except where retention is required by law or ongoing dispute
  • Backups: may persist for a limited backup cycle (typically up to 30–90 days) after primary deletion, then expire automatically
  • Support tickets / email: typically up to 24 months after closure, unless needed longer for an ongoing matter
  • Security and access logs: typically 6–24 months, longer if needed for investigations
  • Billing and tax records: as required by Singapore and applicable tax law (often 5+ years)
  • Zoom OAuth tokens: retained while the integration remains connected; deleted or invalidated upon disconnect / deauthorization
  • Imported recordings stored in Lumus: treated as Customer Content under the Customer's retention rules; Zoom-hosted recordings remain subject to Zoom's retention settings

5. Deletion and return of data

Customers may request:

  • Export of Customer Content in a reasonable machine-readable format where available
  • Deletion of a tenant, user, or specific records, subject to technical and legal limits

End users (students, parents, teachers) should generally submit access/deletion requests to their institution first. Digitaro will support the Customer in fulfilling data subject requests. Direct requests to Digitaro: labs@digitaro.co with subject "Data Deletion Request" or "Data Subject Request".

6. Protection measures

Data protection measures include encryption in transit, access controls, least-privilege staff access, secure development practices, and vendor due diligence, as described in the Security Policy. Personal data is processed only for documented purposes consistent with the Privacy Policy and Customer instructions.

7. Subprocessors

Digitaro uses subprocessors for hosting, storage, email delivery, monitoring, and payments. Subprocessors process data only to provide services to Digitaro/Lumus and under confidentiality and security obligations. A current list can be provided to Customers on request via labs@digitaro.co.

8. Breach notification

In the event of a personal data breach affecting Customer data, Digitaro will notify the Customer without undue delay as required by applicable law and the Customer agreement, and will cooperate on investigation and remediation.

9. International transfers

Data may be processed in Singapore and other countries where Digitaro or its subprocessors operate. Safeguards for transfers are applied where required by law.

10. Changes

We may update this Policy periodically. Material changes will be reflected in the "Last updated" date and, where appropriate, communicated to Customers.

11. Contact

Digitaro Private Limited (Singapore) — Lumus
labs@digitaro.co