Data Retention
DRAFT — pending review.
- Retention periods are policy-driven per data category and per institution; defaults are conservative and disabled until configured with the Controller.
- End-of-contract: an institution’s data can be exported and then deleted or anonymised on instruction.
- Erasure / retention sweeps are manual and reviewed — there is no automated bulk deletion; runs are gated behind verified backups and explicit approval.
- Audit and AI-processing logs are retained longer for accountability, then deleted per their own policy.
Data-subject erasure requests are tracked and routed to the Controller — see Data Processing.