Last updated: May 15, 2026

Data Retention Schedule

This Schedule sets out the periods for which Revsnap retains personal and customer data processed in connection with the service. It supports the Privacy Policy and DPA.

Data categoryActive retentionPost-terminationLegal basis
Account / identity (user records, workspace membership)Lifetime of account90 days after closure (restorable on request), then deletedPerformance of contract
Authentication artefacts (sessions, API key hashes)Lifetime of relevant session / keyDeleted on revocation or account closurePerformance of contract
Salesforce OAuth tokens (Vault)Until customer disconnects orgDeleted within 30 daysPerformance of contract
Snapshots (Storage objects and DB rows)Customer-controlled30 days after subscription end, then deletedPerformance of contract
Test run metadata / resultsCustomer-controlled30 days after subscription end, then deletedPerformance of contract
Billing records, invoicesLifetime of subscription6 years from end of accounting periodUK statutory accounting requirements (HMRC); equivalent under other regimes
Audit log (workspace_audit_log)12 months onlineUp to 24 additional months in cold storage if required for regulator or security responseLegitimate interests (security, regulator response)
Product analytics (PostHog, consent-gated)Up to 12 monthsDeleted on subscription end or consent withdrawalConsent
Server / application logs30 daysDeletedLegitimate interests (security, debugging)
Sub-processor recordsLifetime of relationship3 years after end of relationshipLegitimate interests (audit defence)
Marketing communications opt-in recordsUntil withdrawn3 years after withdrawalDemonstrating consent (PECR)
Security incident records6 yearsn/aDefence of legal claims, regulator response

Deletion procedure

Customer-initiated overrides

Customers may request shorter retention via Enterprise Order Form terms; we will accommodate where technically feasible and not in conflict with statutory retention.