Policy centre
Retention and deletion summary
Last updated: 29 August 2026
How long common Brakan records remain available and what happens when they are deleted.
Current operational periods
- Pilot applications: kept while recruitment and selection are active, then deleted when no longer needed; normally within six months after the relevant recruitment campaign closes.
- Rejected upload objects: removed during the next daily retention run.
- Customer-deleted documents: recoverable for 30 days, then permanently removed unless subject to a legal hold.
- Generated portfolio exports: removed after seven days.
- Email-webhook deduplication evidence: retained for 90 days.
- Expired verification, OAuth and session records: removed automatically.
- Encrypted backups: seven daily and twelve monthly recovery points; backups are for disaster recovery, not ordinary archives.
Customer business records
Active property, tenancy, accounting, tax, compliance and audit records remain while the customer needs the service and may be retained after closure where required for legal obligations, disputes, fraud prevention or security evidence. Before public launch, the commercial closure and export timetable will be stated in the subscription terms.
Legal holds
A documented legal hold pauses deletion of relevant customer documents. It does not provide routine administrator access or permit indefinite retention without review.
Backups
A deletion may remain in an encrypted backup until that recovery point expires. Restored systems must reapply later deletion and hold records. Backup access is restricted to recovery and testing.