Data Retention Policy
Last updated: 26 March 2026
This policy explains how long we keep your data, what happens when you delete things, and what happens when you close your account.
Active accounts
While your account is active, your data is retained and available:
| Data type | Retention while active |
|---|---|
| Account information (name, email, organisation) | Retained while account is active |
| ESG facts, questionnaire responses, templates | Retained while account is active |
| Uploaded documents and evidence files | Retained while account is active |
| Audit logs | Depends on subscription tier (see below) |
| Billing records | Retained for the life of the account |
Audit log retention by tier
Audit logs record account actions (logins, data changes, exports, deletions) for security and compliance purposes. Retention periods vary by subscription tier:
| Tier | Audit log retention |
|---|---|
| Starter (£19/mo) | 90 days |
| Professional (£39/mo) | 1 year |
| Business (£59/mo) | 2 years |
When audit logs exceed their retention period, they are excluded from the application and are no longer accessible to users. Expired audit data is periodically purged from the database during scheduled maintenance.
Deleting data within your account
When you delete individual items (facts, documents, questionnaire responses):
- Immediate: The item is soft-deleted and no longer visible or accessible in the application.
- 30-day recovery window: The soft-deleted item is retained in the database in case you need to recover it. Contact support within this period.
- After 30 days: Soft-deleted items become eligible for permanent removal during scheduled maintenance cycles.
Soft-deleted items cannot be accessed via the application but remain in the database during the 30-day window. Contact support@answervault.co.uk if you need to recover a recently deleted item.
Closing your account
When you close your account (from account settings or by requesting deletion):
- Immediate: Your account is marked for deletion. You are logged out and can no longer access the Service.
- 30-day recovery window: Your account and all associated data are retained in a soft-deleted state. During this window, you can contact us to reactivate your account and recover your data.
- After 30 days: Your account and all associated data become eligible for permanent removal during scheduled maintenance. Once removed, data cannot be recovered. This includes:
- Account information
- All ESG data (facts, responses, templates)
- All uploaded documents
- All audit logs
- Organisation membership records
Billing records may be retained for up to 7 years as required by UK tax law, even after account deletion.
Subscription cancellation vs. account deletion
- Cancelling your subscription stops future billing but does not delete your account or data. Your account reverts to a limited state at the end of the billing period. Your data remains accessible.
- Deleting your account initiates the permanent deletion process described above.
Data export
Before closing your account, you can export your data using the data export feature in account settings. We recommend doing this before requesting account deletion.
Backups
Our infrastructure provider (Supabase) maintains encrypted database backups for disaster recovery. Backup retention follows Supabase's standard policies. Deleted data may persist in backups for a limited period but is not accessible or recoverable through AnswerVault.
Contact
Questions about data retention? Contact us at support@answervault.co.uk.