Security & Privacy
Data retention schedule
What is kept, for how long, and which mechanism enforces each window, including the records for which no automatic deletion exists.
Different things are kept for different periods, and a different mechanism enforces each. So that you can judge it, here is what each actually is.
| Held | Window | Enforced by |
|---|---|---|
| Raw evidence from your environment | 1 day by default | The assessment platform's own artifact expiry. It does not depend on anyone remembering |
| Board pack in the assessment workflow | 7 days by default | The same expiry |
| Assessment snapshot | 90 days by default | The same expiry. This is also the comparison window |
| Board pack in GovIntel storage | A retention window recorded against the pack | The service stops issuing links at expiry; removal is handled by the storage lifecycle policy |
| Enquiry and engagement records, including the onboarding audit trail | For as long as there is a relationship, and afterwards as needed for legal, accounting and tax obligations | Nothing automatic |
| Database backups | Rotated on a short cycle, currently fourteen days | Backup rotation |
The row that deserves emphasis
Nothing in the product deletes enquiry and engagement records automatically. There is no scheduled purge and no expiry rule on them.
That is stated plainly because the alternative — a numeric retention promise that nothing enforces — would be a policy claim with no mechanism behind it. If you want those records removed, ask, and they will be.
Why the evidence expires fastest
It is the most sensitive artefact and the one nobody needs after the assessment.
Why the snapshot can be kept longest
It carries no customer identifiers. That is what makes a longer window defensible when the raw evidence expires in a day.
Your own copy
Download your pack and keep it with your board records. Your licence to it does not depend on GovIntel retaining a copy.
