Trust
Retention and Deletion Summary
Reform applies purpose-specific retention and restricts retained evidence after account or content deletion.

Short-lived operational data

Privacy export packages expire after 24 hours. Incomplete checkout drafts are deleted after 90 days.

Account, security, and support

After an approved account deletion, the authentication shell and direct profile identifiers are removed immediately. Authentication and security logs are retained for 12 months. Support cases are retained for 36 months after closure.

Privacy and incident evidence

Privacy-request and incident evidence is retained for 5 years after closure and moved out of ordinary operational visibility. Retained evidence is access-restricted, purpose-limited, and pseudonymized where possible.

Contracts and financial records

Legal acceptance evidence, contracts, invoices, accounting documents, and associated delivery evidence are retained for 6 years from the applicable final entry or relationship end. Account deletion does not remove evidence that must remain for these purposes.

Customer content

Organizations, projects, forms, records, media, and invitations use the existing configurable soft-delete and hard-delete lifecycle. The ordinary default reversible period is 30 days; the applicable workspace policy controls.

Backups

EU-jurisdiction rolling server/database backup objects expire after 14 days and manually designated backup objects after 90 days. Infrastructure snapshots are separate, manually retained, and have no automatic expiry; this is an accepted storage-limitation risk and must be reviewed and retired manually. Deleted data is not restored into live service except when necessary for operational recovery and is then re-subjected to deletion.

Requests

For account rights contact privacy@paqu.io. Requests about customer form content should normally be directed to the customer/controller identified on the form. Case-specific preservation is recorded in the relevant privacy, incident, billing, or legal case.