Data Retention

This document explains how long oklido retains different types of data and when it's deleted.

Retention Principles

Our data retention follows these principles:

  1. Purpose limitation - Keep data only as long as needed
  2. Legal compliance - Meet regulatory retention requirements
  3. User control - Honour deletion requests
  4. Security - Secure deletion when retention ends

Retention Schedule

Account Data

Data TypeActive AccountAfter Deletion
Profile informationDuration of account30 days
Authentication dataDuration of accountImmediate
PreferencesDuration of account30 days

Documents

Data TypeRetentionAfter Deletion
Uploaded documentsUntil deleted30 days (soft delete)
Document metadataUntil deleted30 days
Extracted textUntil deleted30 days

Operational Data

Data TypeRetention
Audit logs7 years
Security logs7 years
Error logs30 days
Performance metrics90 days

Billing Data

Data TypeRetentionBasis
Invoices7 yearsUK tax law
Payment records7 yearsUK tax law
Subscription history7 yearsUK tax law

Communication Data

Data TypeRetention
Support tickets3 years
Email communications3 years

Deletion Process

When You Delete Documents

  1. Document moves to "Deleted" (soft delete)
  2. Recoverable for 30 days
  3. After 30 days, permanently deleted
  4. Backups retained for 90 days then purged

When You Delete Your Account

  1. Account deactivated immediately
  2. Documents moved to deletion queue
  3. Data deleted within 30 days
  4. Some data retained per legal requirements

What's Retained After Account Deletion

For legal and security reasons:

DataRetentionReason
Billing records7 yearsUK tax law
Audit logs7 yearsSecurity/compliance
Anonymised analyticsIndefiniteProduct improvement

Data Deletion Rights

Your Rights

Under GDPR, you can request deletion of:

  • Your account and profile
  • Your documents
  • Your activity history

How to Request Deletion

  1. Self-service: Settings → Account → Delete Account
  2. Support: Email privacy@oklido.com

What We Cannot Delete

  • Data required by law (billing, audit logs)
  • Data needed to fulfil legal obligations
  • Anonymised aggregate data

Backup Retention

Backup Schedule

Backup TypeFrequencyRetention
DatabaseDaily30 days
DocumentsReal-time replicationN/A
ConfigurationOn change90 days

Backup Deletion

When data is deleted:

  1. Production data deleted immediately
  2. Next backup cycle excludes deleted data
  3. Old backups expire per retention schedule
  4. Complete purge within 90 days

External User Data

Beneficiary Data

DataRetention
ProfileUntil access revoked + 30 days
Access logs7 years

Guest Data

DataRetention
Access recordsUntil expiration + 30 days
Access logs7 years

Data Subject Requests

Response Times

Request TypeResponse Time
Access request30 days
Deletion request30 days
Rectification30 days

Process

  1. Verify identity
  2. Locate all data
  3. Process request
  4. Confirm completion

Compliance

Our retention practices comply with:

  • GDPR - Data minimisation, storage limitation
  • UK DPA 2018 - Same as GDPR
  • UK tax law - 7 year retention for financial records
  • Cyber Essentials - Security log retention

Changes to This Policy

We review this policy annually. Material changes are communicated via email.

Last updated: January 2026

Questions

For data retention questions: