Data retention and deletion
How long information stays, and how it leaves.
Retention is a published schedule, not a guess in a proposal. The same periods drive the deletion job. A legal hold pauses deletion. A signed statement of work may shorten a period; it may not silently extend one without notice.
01 / Section
The schedule.
| Data class | Period | Notes |
|---|---|---|
| Marketing inquiries | 24 months after last meaningful contact | 30 days after a verified deletion request if no legal hold applies. |
| Intake drafts (never submitted) | Link expiry plus 30 days | Answers are deleted. Hashed link metadata is kept 12 months for abuse forensics. |
| Intake submitted, no engagement | 24 months | Deleted or anonymized unless a legal hold or active discussion applies. |
| Intake and workspace records bound to an engagement | Life of the engagement plus 7 years | Contract and tax retention. A statement of work may specify earlier deletion. |
| Auth accounts and access grants | Life of the grant plus 90 days after revoke | Invitation-only. No public signup accounts exist. |
| Session network metadata (IP, user agent) | 90 days | Scrubbed from session rows after 90 days. Sessions themselves expire with Better Auth. |
| Transactional email (SendGrid) | Up to 24 months in provider logs | Message bodies are not kept in Neon. Do not put secrets in mail. |
| SMS one-time codes (Twilio) | Better Auth verification expiry (minutes) | Used only when SMS sign-in is enabled for an invited person. |
| Privacy and deletion requests | 7 years | Kept as evidence that the request was received and completed. |
| Security and incident evidence | 7 years | Access reviews, incident records, and restore-test records. |
| Operational security logs | 12 months | Hosting and application logs needed to operate the system. |
| Backups | Rolling 30 days | Neon point-in-time recovery window. Deleted data may persist in backups until that window closes. |
| Workforce transition records | Engagement plus 7 years, unless the workforce schedule says otherwise | Purpose-limited. Not used for surveillance or automated employment decisions. |
02 / Section
Deletion, export, and holds.
A client offboarding exports workspace records in a reasonable electronic form, then deletes them according to this schedule. Privacy requests are answered within 45 days, or sooner where a shorter statutory period applies. Legal holds override deletion until the hold is released.
Deleted rows may remain in the rolling backup window for up to 30 days. Intake draft answers are removed after the link expires plus 30 days; the hashed link metadata remains for 12 months so we can investigate abuse without reconstructing the URL.
03 / Section
Classification.
Intake free text and workspace documents default to Confidential. Restricted data is prohibited in Xpancom systems. If Restricted data is sent by mistake, we will delete it and notify the sender.
- Public
- Intended for the open web, such as this marketing site.
- Internal
- Xpancom operating information that is not published.
- Confidential
- Client and prospect information, including intake answers and workspace records. Default classification.
- Restricted
- Credentials, payment card data, protected health information, and raw employee files. Prohibited in Xpancom systems including intake free text.