Tentunit Business — Audit & Record Retention Policy
Version 1.0 (Draft — pending legal review) · Effective Date: July 11, 2026 · Applies to: Tentunit Business
This page is informational. It explains, but does not override, the Data Processing Addendum and the Platform Terms of Service, which control.
1. Overview & Definitions
This policy explains what records Tentunit Business creates and keeps, how long we keep them, how we delete them, and how audits of our practices work. It is a plain-language companion to the binding commitments in the Data Processing Addendum (“DPA”) and the Platform Terms of Service (“Platform ToS”); where this page and those documents differ, the DPA and Platform ToS control.
1.1 Purpose
Tentunit, Inc. (“Tentunit,” “we,” “us”) operates Tentunit Business, a rent collection and property management platform for landlords and property managers in the US, EU, and UK. Operating that platform responsibly requires us to keep certain records — for security, for financial and tax compliance, because the DPA or applicable law requires it, or simply so the product works. This policy describes those records and their lifecycle.
1.2 Definitions
- “Customer” means the business entity (landlord, property manager, or their organization) that subscribes to Tentunit Business under the Platform ToS.
- “Customer Data” means data submitted to the platform by or on behalf of a Customer, including Tenant Data, as defined in the DPA.
- “Tenant Data” means personal data relating to a Customer’s tenants, applicants, or occupants processed through the platform.
- “Audit Logs” means system-generated records of events on the platform, such as logins, permission changes, and payment events, maintained primarily for security, integrity, and dispute-resolution purposes.
- “Records” means Audit Logs together with financial, transactional, support, and e-signature records generated in the course of providing the services.
- “Deletion” means rendering data unrecoverable in the ordinary course, through erasure, cryptographic deletion, or de-identification such that it no longer relates to an identifiable person.
1.3 Roles
For most Customer Data, the Customer is the controller (or “business” under US state privacy laws) and Tentunit is the processor acting on the Customer’s instructions under the DPA. For records Tentunit must keep for its own legal compliance — for example financial, tax, and anti-money-laundering (“AML”) records — Tentunit acts as an independent controller, and retention of those records is governed by law rather than by Customer instruction. This distinction matters throughout this policy.
2. Logging & Record Types
We keep several categories of records, each tied to a specific operational, security, or legal need. This section describes the main categories so Customers know what exists and can answer questions from their own tenants, auditors, or regulators.
2.1 Authentication Logs
We log authentication events, including successful and failed sign-in attempts, multi-factor authentication events, password resets, session creation and termination, and API key usage. These logs typically include timestamps, account identifiers, IP addresses, and device or user-agent metadata. They are used to detect account takeover, enforce access controls, and investigate security incidents.
2.2 Role & Permission Changes
Changes to user roles, permissions, and team membership within a Customer workspace are logged, including who made the change, what changed, and when. These records support the principle of least privilege, allow Customers to reconstruct who had access to what, and are frequently requested during Customer security reviews.
2.3 Payment & Payout Events
We record payment and payout lifecycle events, including rent charge creation, capture, refunds, chargebacks and their outcomes, payout initiation and settlement, and payout holds. Payments are processed through Stripe Connect Connected Accounts by Stripe, Inc. (US), Stripe Payments Europe, Ltd. (regulated by the Central Bank of Ireland), or Stripe Payments UK, Ltd. (regulated by the FCA), and Stripe maintains its own records under its own legal obligations. Tentunit acts as a limited payment collection agent (agent of the payee) and is not a bank or e-money issuer; our payment records exist for reconciliation, dispute resolution, and compliance, as further described in the Payments & Payouts Policy.
2.4 Automation Executions
Where a Customer configures automations — for example scheduled rent reminders, late-fee application, or workflow triggers — we log each execution, its trigger, its outcome, and material errors. These logs allow Customers and Tentunit to verify that automated actions occurred as configured and to troubleshoot failures.
2.5 Support Interactions
We retain support tickets, emails to [email protected] and related addresses, in-product chat transcripts, and internal notes associated with a support case. These records help us resolve issues, meet our support response commitments under the Service Level Agreement, and handle complaints, including EU complaint-handling timelines.
2.6 Document E-Sign Events
For documents signed through the platform’s e-signature features, we maintain an audit trail for each envelope: signer identity information, authentication method, timestamps for each signature event, IP addresses, document hashes, and completion status. These records exist to support the validity and evidentiary weight of electronically signed documents, as described in the E-Sign Consent & Disclosure.
3. Retention Periods
We retain records only as long as there is a live reason to keep them: delivering the service, meeting a legal obligation, or protecting security and legal rights. This section describes our retention approach by lifecycle stage rather than as a rigid table, because different record types carry different obligations.
3.1 Active Accounts
While a Customer account is active, Customer Data and associated Records are retained as needed to deliver the services. Customers control much of this data directly and may edit or delete individual records through the product, subject to the platform’s integrity constraints (for example, financial transaction records cannot be altered after the fact).
3.2 Post-Termination Export Window & Deletion
Following termination or expiration of a Customer’s subscription, the Customer has a 60-day read-only export window during which it may retrieve its Customer Data in commonly used, machine-readable formats. After that window closes, Tentunit deletes or de-identifies Customer Data within a further 30 days, subject to the legal-retention carve-out in Section 3.3 and the backup-rotation lag described in Section 4.2. These timelines mirror the binding commitments in the DPA and the Platform Terms of Service.
3.3 Financial, Tax & AML Records — Legal Retention Carve-Out
Certain records must be retained beyond termination because the law requires it. These include invoices and billing records, tax records, transaction and payout records, chargeback documentation, and records generated in connection with know-your-customer/know-your-business verification, AML monitoring, and OFAC and EU/UN sanctions compliance. Retention periods for these records vary by record type and by the statutes and regulatory frameworks of each jurisdiction where we operate; we retain such records for the period the applicable law requires and no longer. Records retained under this carve-out are restricted from ordinary operational use and kept only for the compliance purpose that justifies their retention.
3.4 Audit Logs
Audit Logs described in Section 2 are retained for security, integrity, and dispute-resolution purposes for a reasonable, documented period appropriate to each log type. That period is set internally based on threat-detection needs, incident-investigation requirements, contractual commitments, and applicable law, and is reviewed periodically. When an Audit Log is subject to an active investigation, litigation hold, or regulator request, retention is extended for the duration of that matter.
3.5 E-Signature Records
E-signature audit trails are retained in accordance with the E-Sign Consent & Disclosure and the DPA so that completed documents remain verifiable. Customers should export completed documents and their audit trails during the post-termination export window if they need them after the account closes.
4. Deletion Standards
When data reaches the end of its retention period, we delete it in a way that is designed to be effective and verifiable. This section explains how deletion works in practice, including the honest caveat that backups take additional time to cycle out.
4.1 Secure Deletion from Production
Deletion from production systems is performed using methods appropriate to the storage medium, including record-level erasure, cryptographic deletion (destruction of encryption keys rendering data unreadable), or de-identification that removes any reasonable means of re-identification. Deletion jobs are logged so that we can demonstrate when and how deletion occurred.
4.2 Backup Rotation Lag
Like most cloud services, Tentunit maintains encrypted backups for disaster recovery. Backups are immutable snapshots and are not selectively edited; instead, deleted data ages out of backups as the backup rotation cycle completes. This means that after data is deleted from production, copies may persist in backups for a limited additional period until those backups expire in the ordinary course. Backup copies are not restored to production except for disaster recovery, and if a restoration occurs, previously deleted data is re-deleted promptly.
4.3 Certification of Deletion
Upon a Customer’s written request following deletion under Section 3.2, Tentunit will provide written certification that Customer Data has been deleted in accordance with the DPA, subject to the legal-retention carve-out and backup-rotation lag described above. Requests may be sent to [email protected].
4.4 Sub-Processors
Our sub-processors are contractually required to delete or return Customer Data on termination of their processing, consistent with the DPA. Changes to our sub-processor list are notified 30 days in advance as described in the DPA and the Privacy Policy.
5. Internal & External Audit Rights
Retention rules only matter if someone checks that they are followed. This section summarizes how Tentunit audits itself and how Customers, regulators, and payment partners may audit Tentunit.
5.1 Tentunit Internal Audits
Tentunit performs periodic internal reviews of its logging, retention, and deletion practices, including sampling deletion jobs, reviewing access to Audit Logs, and validating that retention schedules are applied. Findings are tracked to remediation. Access to Audit Logs is itself restricted and logged.
5.2 Customer Audit Rights Under the DPA
Customers have audit rights as set out in the DPA. In summary: audits may be conducted no more than once per twelve-month period (except following a confirmed personal data breach affecting the Customer or where a supervisory authority requires more), on at least 30 days’ prior written notice, during business hours, subject to confidentiality obligations, and without unreasonable disruption to Tentunit’s operations. If Tentunit obtains third-party security attestations (e.g., SOC 2) in the future, Tentunit may offer such reports in satisfaction of audit requests. The DPA’s terms govern in full.
5.3 Regulator & Payment-Processor Audits
Tentunit cooperates with lawful requests, examinations, and audits from competent supervisory authorities and financial regulators, and complies with audit and information requirements imposed through our payment processor relationships (including Stripe program requirements). Where a regulator’s request concerns a specific Customer’s data, we will notify that Customer where legally permitted, consistent with the DPA and the Law Enforcement & Legal Request Policy, if applicable.
5.4 Questions
Questions about this policy may be directed to [email protected] (data retention and deletion) or [email protected] (logging and audit practices). Because this page is informational, any conflict between it and the DPA or Platform Terms of Service is resolved in favor of those binding documents.