General principle
APEX keeps information only for as long as reasonably needed for education, administration, security, support, legal obligations and institutional record continuity.
Typical categories
- Login/security logs: retained for a limited security/troubleshooting period.
- Support and communication records: retained while relevant to service or disputes.
- Student academic and attendance records: may be retained as institutional records after account access ends.
- Fee/payment records: may be retained for accounting, reconciliation and lawful record-keeping.
- Social-login links and active authentication tokens: removed when the relevant account/link is deleted or revoked, subject to necessary security records.
Deletion requests
Where complete deletion is not appropriate because a record must legitimately be retained, personal data should be minimized or anonymized where feasible and access restricted.
