Skip to content

Legal

Data Retention Policy

How long condition-audit evidence is kept, how legal holds work, and how deletion requests are handled.

Last updated 2026-07-09

1. Default retention

Unless your organization configures a different window in settings, the product default retention target is 1,095 days (3 years) for audit evidence and related reports (see product privacy/retention specs). Organizations may choose longer or shorter defaults where the product allows.

2. No silent deletion of signed records

Signed and refused stages and generated reports are not silently deleted through normal product flows. Corrections use void/replace paths so history remains reviewable. Verification of already-generated reports must not be removed solely because of billing failure or plan limits.

3. Legal holds and disputes

Evidence subject to an active dispute, legal hold, or contractual retention requirement must not be auto-deleted without explicit owner/admin action and appropriate process.

4. Export

Export may include report PDFs, verification URLs, manifests, media hash lists, and signature/refusal summaries. Request export via support. Self-serve export may expand over time; manual requests are handled as described on the support page.

5. Deletion requests

Account or data deletion requests are handled through support. Some audit history may need to be preserved or redacted rather than hard-deleted where law or contract requires. Organization closure is a deliberate destructive workflow, not a casual dashboard action.

Back to home