is there any legal restriction of how long you can keep internal systems logs? if it's done right they don't contain PIIs but they _can_ be used to track people if you have enough logs.
I suspect as a payment processor though, being able to look back far when investigating breeches etc would be important.