Data Retention Policy

Last updated: 26 March 2026

This policy explains how long we keep your data, what happens when you delete things, and what happens when you close your account.

Active accounts

While your account is active, your data is retained and available:

Data type Retention while active
Account information (name, email, organisation) Retained while account is active
ESG facts, questionnaire responses, templates Retained while account is active
Uploaded documents and evidence files Retained while account is active
Audit logs Depends on subscription tier (see below)
Billing records Retained for the life of the account

Audit log retention by tier

Audit logs record account actions (logins, data changes, exports, deletions) for security and compliance purposes. Retention periods vary by subscription tier:

Tier Audit log retention
Starter (£19/mo) 90 days
Professional (£39/mo) 1 year
Business (£59/mo) 2 years

When audit logs exceed their retention period, they are excluded from the application and are no longer accessible to users. Expired audit data is periodically purged from the database during scheduled maintenance.

Deleting data within your account

When you delete individual items (facts, documents, questionnaire responses):

  1. Immediate: The item is soft-deleted and no longer visible or accessible in the application.
  2. 30-day recovery window: The soft-deleted item is retained in the database in case you need to recover it. Contact support within this period.
  3. After 30 days: Soft-deleted items become eligible for permanent removal during scheduled maintenance cycles.

Soft-deleted items cannot be accessed via the application but remain in the database during the 30-day window. Contact support@answervault.co.uk if you need to recover a recently deleted item.

Closing your account

When you close your account (from account settings or by requesting deletion):

  1. Immediate: Your account is marked for deletion. You are logged out and can no longer access the Service.
  2. 30-day recovery window: Your account and all associated data are retained in a soft-deleted state. During this window, you can contact us to reactivate your account and recover your data.
  3. After 30 days: Your account and all associated data become eligible for permanent removal during scheduled maintenance. Once removed, data cannot be recovered. This includes:
    • Account information
    • All ESG data (facts, responses, templates)
    • All uploaded documents
    • All audit logs
    • Organisation membership records

Billing records may be retained for up to 7 years as required by UK tax law, even after account deletion.

Subscription cancellation vs. account deletion

  • Cancelling your subscription stops future billing but does not delete your account or data. Your account reverts to a limited state at the end of the billing period. Your data remains accessible.
  • Deleting your account initiates the permanent deletion process described above.

Data export

Before closing your account, you can export your data using the data export feature in account settings. We recommend doing this before requesting account deletion.

Backups

Our infrastructure provider (Supabase) maintains encrypted database backups for disaster recovery. Backup retention follows Supabase's standard policies. Deleted data may persist in backups for a limited period but is not accessible or recoverable through AnswerVault.

Contact

Questions about data retention? Contact us at support@answervault.co.uk.