Skip to content

Legal

Data Retention Policy

How long condition-audit evidence is kept, how legal holds work, and how deletion requests are handled.

Last updated 2026-08-21

1. Current handling

Automatic plan-based file expiry is not active in the current service. Evidence and retained report files are not presently deleted merely because a Free or paid plan time window elapses. They may be removed through an authenticated deletion request, an organization-directed deletion path where one is available, a security or abuse response, or a legal obligation.

2. Planned tiered retention

The approved planned design is 30 days on Free and 365 days on paid plans for original evidence and retained report files. The planned ledger floor is at least three years, with a longer retention snapshot, backup confirmation, grace period, unresolved-job guard, and preservation hold required before cleanup. Those safeguards and the cleanup worker are not active today. AuditIt will update this policy before activating automatic tiered expiry.

3. No silent deletion of signed records

Signed and refused stage records and generated-report ledger entries are not silently deleted through normal product flows. Corrections use void/replace paths so history remains reviewable. Because automated tiered cleanup is not active, a plan limit or billing event does not currently trigger the planned 30/365-day file expiry.

4. Preservation requests and disputes

No self-serve legal-hold control is active. Contact support immediately to request preservation for a dispute, legal process, or contractual requirement and include the relevant workspace and audit identifiers. A saved retention preference or support request is not confirmation of a hold; rely on written confirmation from AuditIt.

5. Export

Export may include report PDFs, verification URLs, manifests, media hash lists, and signature/refusal summaries. Request export via support. Self-serve export may expand over time; manual requests are handled as described on the support page.

6. Deletion requests

A signed-in user can directly initiate account deletion in the AuditIt mobile app from Workspace → Delete account. The authenticated request is recorded immediately and completed within 30 days. Some audit history may need to be preserved or redacted rather than hard-deleted where law or contract requires. Organization closure is a deliberate destructive workflow, not a casual dashboard action.

Back to home