Data Retention and Deletion Schedule

Last updated: 30 August 2026

Status: Revised draft aligned to intended exit workflowDownload approved document (PDF)

1. Principles

Customer-controlled governance records may legitimately be long-lived while the workspace is active.

Derived AI/search data should not outlive its source without a documented reason.

Deletion of an individual user must not delete organisation-owned governance records.

On organisation closure, processor data should be returned/exported or deleted according to customer instruction.

Protected backups can remain beyond live deletion only until the verified backup cycle expires and must remain beyond normal use.

2. Retention schedule

Data classDefault / targetTriggerDisposal / notes
Active organisation Customer ContentCustomer-controlled while contract/workspace activeCustomer deletion or terminationDelete/export under customer instruction; no default age-expiry of active board records.
Derived chunks/search/embeddingsNo longer than sourceSource deletionCascade/delete derived representations.
Transcript text / stored AI outputsSame as related Customer ContentSource/user deletion or customer retention ruleDelete with related governance record.
Browser/OS speech audioNot retained by BoardCue as application audio in managed browser routeSpeech recognition eventThird-party browser/OS provider processing is governed by customer endpoint choice and provider terms.
Organisation exit archive14 days after customer notified export is ready, where Full Exit workflow is enabledTermination/expiryRead-only download, then delete archive as closure process completes.
Terminated active-system Customer ContentTarget completion within 30 days after export window/deletion instructionEnd of export window or immediate deletion instructionDeterministic live-system deletion; retain only narrow controller/legal records.
Supabase protected database backups - enterprise baselineOrdinary Pro daily-backup cycle, current published access window 7 daysLive deletion / backup expiryBeyond normal use; deletion state reapplied if restored. Verify actual plan/settings at go-live.
Security/audit records12 months default unless part of customer governance record or active investigationEvent dateRolling deletion/anonymisation, with extension for legal hold/investigation.
Contracts/billing/legal records6 years after end/relevant accounting period unless law requires longerContract/accounting closeSecure archive then deletion.
Incident/complaint records6 years after closure unless legal holdCase closureMinimise to evidence necessary for accountability.

3. Full Organisation Exit workflow

1. Workspace becomes read-only on the effective termination date.

2. BoardCue generates a complete organisation export for authorised organisation administrators.

3. Customer is notified when the export is ready; the download window lasts 14 calendar days where this workflow is enabled.

4. Customer can request immediate deletion instead of using the export window.

5. At the end of the window, automated deletion of active Customer Content and derived data begins.

6. Deletion should complete within 30 days of the window closing, subject to verified service-specific mechanics.

7. Protected backup copies expire through the ordinary provider cycle and are not restored to ordinary use without reapplying the deletion state.

8. A deletion completion record is retained as narrow accountability evidence.

4. Implementation gate

The 14-day workflow should be made unconditional in public terms only after the Full Organisation Exit Export, read-only closure state, complete database/storage deletion cascade and automated tests have been implemented and verified for the relevant deployment.

Meeting Effectiveness records

Participant eligibility, ratings, optional comments, response-window status and reminder events are organisation Customer Content. The customer must define and document the applicable retention rule. Deletion and organisation-exit handling follow the Customer Content lifecycle, subject to legal hold and protected-backup expiry.