Last updated:
Data Retention
This page explains how long we retain different types of data, the legal basis for each retention period, and how data is deleted when no longer needed.
Retention Schedule
| Data Type | Retention Period | Legal Basis | Deletion Method |
|---|---|---|---|
| Account data | Active account + 30 days | Contract performance | Automated purge |
| Conversations & documents | Until deleted by user or account closure | Contract performance | Permanent deletion |
| Integration credentials | Until disconnected | Contract performance | Immediate purge on disconnect |
| Payment records | 7 years | UK tax law (HMRC) | Automated after period |
| Audit logs | 90 days (up to 1 year for production) | Legitimate interest | Automated rotation |
| Email delivery logs | 30 days | Legitimate interest | Automated purge |
| Temporary authentication tokens | Minutes | Technical necessity | Automatic expiry |
| Analytics data | 26 months | Consent (GA4 default) | GA4 automatic deletion |
| Backups | 7 days | Legitimate interest | Automated rotation |
| Beta registration data | Until account activation or 12 months | Consent | Manual review |
Your Control
You have direct control over your data retention:
- Delete individual conversations at any time from your workspace
- Disconnect integrations - encrypted credentials are immediately purged
- Request full account deletion - email privacy@projan.ai
- Export your data before deletion - we provide data export on request
All deletion requests are processed within 30 days in accordance with GDPR Article 17 (Right to Erasure).