Data Retention and Deletion Policy

The lifecycle used for active customer records, exports, deletion requests, and provider backups.

Effective date: July 22, 2026

Last updated: July 22, 2026

Active workspaces

Access to an active workspace continues according to the applicable subscription and account-closure terms. Operational records remain available while the workspace is active unless the customer applies a shorter lawful retention schedule or requests deletion. Customers should export records they wish to retain before access ends and are responsible for selecting retention periods required by their safety and legal obligations.

Account closure

Before access ends, an authorized workspace administrator may request a reasonable export. SafeWorks verifies the deletion scope, identity, and authority before deletion begins.

Deletion timing

SafeWorks begins deletion for verified requests within 30 days. Residual encrypted provider backups expire under applicable provider backup cycles and are not restored except for disaster recovery. Exact backup expiry depends on the applicable provider cycle.

Security and audit records

Limited legal, accounting, security, fraud-prevention, support, and audit records may be retained where necessary to meet legal or accounting duties, prevent fraud, establish legal claims, support security operations, or document authorized deletion.

Deletion may be delayed where preservation is required by law, litigation hold, regulator request, or a documented customer instruction.