Principles
We minimise collection, define a purpose for retained information, support shorter customer-configured periods where available, and securely delete or anonymise information when its purpose expires. Legal holds override routine deletion only for as long as necessary.
Default schedule
- Lead and unsuccessful beta enquiries: 12 months after last meaningful contact.
- Active account and membership records: subscription or beta term plus 90 days.
- Release metadata and optional evidence files: 365 days by default, configurable by organisation and contract.
- Authentication and customer audit events: 365 days by default.
- Security and internal-admin audit events: 24 months.
- Application logs containing IP addresses or request identifiers: 30 days unless required for an active incident.
- Backups: rolling 35 days, after which expired data ages out through backup rotation.
- Billing, invoice and contract records: 6 years after the relevant financial year or contract end.
- Suppression records needed to honour communication choices: retained while the choice remains relevant.
Deletion
Account closure initiates deletion or return according to the contract and DPA. Data in backups is isolated from normal use and expires through rotation. Secure deletion requests can be sent to arran@cs-code.com.

