Insurance, Retention, and Escalation Schedule
Version 2026-07-20 · Effective July 20, 2026
Issued by Ohana Capital AG
Effective date
July 20, 2026

Issued by
Ohana Capital AG
1. Status of this document
This Insurance, Retention, and Escalation Schedule is a counsel working draft. It ties complaints escalation and record retention to real platform systems and states the current insurance position honestly.
2. Insurance (current)
| Coverage type | Current status |
|---|---|
| Customer deposit guarantee | Not claimed |
| Investor compensation scheme | Not claimed |
| Professional indemnity / cyber / crime policies | To be confirmed with brokers and listed here once bound |
| Custody / client-asset insurance | Not applicable while no client assets are held |
No insurance coverage should be marketed to customers until a binder or policy schedule is on file and counsel has approved customer-facing wording.
When policies are obtained, record: insurer, policy number, period, limits, deductibles, insured entity, and material exclusions.
3. Complaints escalation path
Operational path (aligned with the Complaints Policy):
- Intake — in-platform support, published support email (including office / CRM inbound mail where configured), or help-center channels.
- First-line support — acknowledge, gather facts, attempt resolution.
- Escalation to operations / compliance — disputes about identity decisions, ledger corrections, suspected fraud, or regulatory issues.
- Senior management / counsel — material loss allegations, legal threats, media risk, or authority requests.
- External body — only where a live regulated product and local scheme apply; details must be added per jurisdiction before go-live.
Target internal clocks (operational goals, not guarantees):
| Stage | Target |
|---|---|
| Acknowledgement | Within 2 business days |
| Substantive update | Within 10 business days |
| Outcome letter | Within 30 calendar days where practicable; complex cases may take longer with notice |
4. Retention schedule (working)
Retention runs from account closure or record creation, whichever rule applies, subject to longer legal holds.
| Record class | Systems of record | Working retention |
|---|---|---|
| Account profile & auth events | Supabase Auth / profiles | Account life + 5–10 years (confirm locally) |
| KYC documents & review decisions | documents bucket + document_uploads + audit logs |
Account life + minimum AML period (often 5–10 years; counsel to set per jurisdiction) |
| Legal acceptances | legal_acceptances / versions |
Account life + 10 years working target |
| Orders, positions, ledger events | Trading / ledger tables | Account life + 5–10 years working target |
| Support / CRM email threads | Resend + CRM inbox tables | 3–7 years working target |
| Complaints files | Support + compliance archive | 5–10 years working target |
| Analytics events (consented) | PostHog | Per analytics retention config / consent withdrawal |
| Cookie consent records | Consent API / storage | 2–5 years working target |
| Server / access logs | Hosting providers | 30–365 days unless security investigation |
Counsel should replace working ranges with jurisdiction-specific mandatory periods before live client-money operations.
5. Legal holds
When litigation, authority request, or investigation is reasonably anticipated, relevant records are preserved beyond normal deletion schedules until released by counsel or compliance.
6. Related documents
Questions about this document?
Contact Ohana Capital AG and include the document title and version in your message.
Contact support