Data retention

How long your organization keeps the personal data of members who left, and the personal details in its audit log.

For administrators who hold the permission manage configuration, usually together with whoever is responsible for data protection in your organization.

Who decides

Your organization is in charge of its members' personal data and decides how long it is kept, within the range Keel Platform offers. The operators of your Keel Platform site set a default that every organization inherits until it sets its own. The setting is Tenant retention policy, under the heading Compliance on the settings page.

Each period is counted from the moment of the record it applies to, and Keel Platform applies it automatically once an hour. Nothing needs to be started by hand.

The two periods

FieldRangeDefaultWhat happens when it runs out
Deactivated members kept for 1 day to 1 year 14 days A member deactivated that long ago is erased: their name, email address, password and second factor are removed for good. Their account stays as Erased member, so the audit log can still say what they did, but it cannot be reactivated. If the person returns, add them again: they get a new account.
Personal data in audit logs kept for 4 weeks to 12 years 1 year An audit log entry that old loses its source network address and its details. The event, who did it, what it concerned and when stay forever.

Changing the policy

  1. Open Configuration in the administration and choose Tenant retention policy.
  2. Type a period into each field, such as 30d, 6m or 2y. Beside each field you see the value of the level beneath.
  3. If a period is longer than the one inherited, write in Reason for keeping it longer why your organization needs it, for example a legal obligation. The reason is kept with the setting and in the audit log. It is not needed for a shorter or equal period.
  4. Choose Save policy. The next hourly run applies the new periods; a shortened period can erase data at once that the old one still kept.

Periods follow the calendar: 1y after 1 March is the next 1 March. The page explains the notation.

The tenant retention policy: two periods, each with a reason field for keeping data longer.
The tenant retention policy: two periods, each with a reason field for keeping data longer.

Data your organization does not decide on

Some periods belong to the site or to your contract, not to this setting: how long sign-in attempts are kept is set by the site's operators, and how long your organization's data is kept after it closes is part of your plan's terms (see Billing and licenses).