Data Retention Policy
Placeholder draft · Last updated 6 July 2026
Placeholder draft — this document has not yet completed legal review and is not legal advice. Final text must be reviewed before client contracting.
1. Customer-controlled retention
Retention is customer-controlled per tenant. Each workspace's retention settings govern its operational records, audit events, attachments and export artifacts. OgmaQ does not impose its own shorter retention on customer workspace content.
2. No automated purge
No automated purge currently runs. Deletion is a reviewed, manual administrative workflow: a deletion request is checked against the tenant's settings and any open obligations before any removal is carried out. Where audit traceability requires it, deletion may currently be effected as anonymisation — personal fields are minimised while the record identifier is retained (see Account lifecycle below).
If prohibited or sensitive data (for example patient data or special-category personal data, which are restricted by default — see the Acceptable Use Policy) is discovered in workspace records, its removal or anonymisation is handled as a reviewed action with the customer as controller. It is not automatically purged, and audit traceability obligations are considered before any change.
3. Account lifecycle
When a user leaves an organisation, their account is deactivated first and may then be anonymised. Historical audit-support records are preserved for record integrity — the trail of who did what remains intact even after the person's account is anonymised.
4. Tenant offboarding
When a customer leaves the service, the standard path is export first, then reviewed deletion of the tenant's data. Where a legal hold or similar obligation applies, the affected records are retained until the hold is lifted.
5. Retention schedule (structured placeholders)
The table below structures the categories a final retention schedule will cover. Where a period is not yet defined, it is deliberately left as a placeholder rather than an invented number.
| Data category | Current handling | Retention period |
|---|---|---|
| Tenant escalation records | Customer workspace content, customer-controlled | Customer-controlled setting, subject to legal and operational review |
| Audit-support records | Preserved for record integrity | Customer-controlled setting; any minimum period to be defined during customer agreement / legal review |
| Attachments | Metadata-led model with a private-storage design | Follows the owning record; to be defined during customer agreement / legal review |
| Export artifacts | Generated on request, short-lived by design | To be defined during legal review |
| Authentication and session logs | Operated via Supabase Auth | To be confirmed per provider configuration and documented during legal review |
| Security logs | Operational security monitoring | To be defined during legal review |
| Support requests | Email-based support | To be defined during legal review |
| Billing records | No billing provider currently in use | To be defined before any paid launch |
| User accounts | Deactivated first; may later be anonymised (identifier retained for audit traceability) | Lifecycle-based — see "Account lifecycle" above |
| Tenant offboarding data | Export first, then reviewed deletion | Subject to legal hold and retention obligations |
6. Contact
Retention questions and deletion requests: the in-app privacy request workflow or [email protected] (general contact: [email protected]). These role-based aliases route to the OgmaQ team; [email protected] is the general contact if you are unsure which to use.