We keep personal data only as long as necessary for the purposes for which it was collected (Art. 5(1)(e) GDPR). At the end of the period, data is securely deleted or anonymized.
Audit (activity) logs use tiered retention based on the importance of the event: routine (informational) events are kept 12 months; noteworthy changes (e.g. role or settings changes) 24 months; and critical events — security, financial, governance (votes) and destructive actions — 5 years. Critical events are never deleted early.
Formular 230 data (including CNP) is automatically deleted by a recurring process after the 5 fiscal years + 1 year archiving period; the records and associated PDF documents are permanently removed. See the 230 DPA.
On account deletion or subscription termination, associated data is deleted per the DPA, except where retention is legally required (e.g. fiscal records). Requests: contact@usequorify.com.