Privacy export packages expire after 24 hours. Incomplete checkout drafts are deleted after 90 days.
After an approved account deletion, the authentication shell and direct profile identifiers are removed immediately. Authentication and security logs are retained for 12 months. Support cases are retained for 36 months after closure.
Privacy-request and incident evidence is retained for 5 years after closure and moved out of ordinary operational visibility. Retained evidence is access-restricted, purpose-limited, and pseudonymized where possible.
Legal acceptance evidence, contracts, invoices, accounting documents, and associated delivery evidence are retained for 6 years from the applicable final entry or relationship end. Account deletion does not remove evidence that must remain for these purposes.
Organizations, projects, forms, records, media, and invitations use the existing configurable soft-delete and hard-delete lifecycle. The ordinary default reversible period is 30 days; the applicable workspace policy controls.
EU-jurisdiction rolling server/database backup objects expire after 14 days and manually designated backup objects after 90 days. Infrastructure snapshots are separate, manually retained, and have no automatic expiry; this is an accepted storage-limitation risk and must be reviewed and retired manually. Deleted data is not restored into live service except when necessary for operational recovery and is then re-subjected to deletion.
For account rights contact privacy@paqu.io. Requests about customer form content should normally be directed to the customer/controller identified on the form. Case-specific preservation is recorded in the relevant privacy, incident, billing, or legal case.