How long Rople keeps data, and what happens when it is deleted. Public-facing and referenced by the Privacy Policy and the DPA. Bracketed values must be confirmed before publication and must match what the system actually does.
1. Principle
We keep personal data only as long as we need it for the purpose we collected it for, or as long as the law requires. Workspace content belongs to the Customer: while the workspace is active, the Customer decides what is kept and what is deleted. Rople does not silently delete Customer Data.
2. Retention schedule
Workspace content — Customer controlled
| Data | Retention |
|---|---|
| Goals, check-ins, feedback, reviews, development and improvement plans | Life of the workspace, or until the Customer deletes it |
| Uploaded files | Life of the workspace, or until deleted |
| Departments, reporting structure, seats | Life of the workspace |
| Custom module data, including CRM-style client records | Life of the workspace, or until deleted |
| After termination | Exportable for [30] days, then deleted from live systems within [30] days |
Identity and membership
| Data | Retention |
|---|---|
| Authentication account and password hash | Life of the account |
| Profile fields | Life of the membership; pseudonymised on erasure (§4) |
| Membership records | Life of the workspace — retained after a member leaves to keep historical records attributable |
| Sessions | [90] days |
Onboarding artefacts
| Data | Retention |
|---|---|
| Owner claim links | Until redeemed or expired, then [90] days for audit |
| Team invite links | Until revoked or expired, then [90] days |
| Invite redemption records — who joined via which link | [24] months |
| Consent records — document, version, timestamp, IP, user agent | Life of the account plus [6] years, as evidence of lawful basis |
Accountability and operations
| Data | Retention |
|---|---|
| Audit log | [24] months |
| Authentication and security events | [90] days |
| Error reports (Sentry) | [90] days |
| Product analytics (PostHog) | [12] months |
| Support conversations | [24] months |
| Marketing contacts | Until consent is withdrawn, or [24] months of inactivity |
Legal and financial
| Data | Retention |
|---|---|
| Invoices, payment records, tax records | 6 years — statutory, cannot be deleted on request |
| Contracts and order forms | 6 years after the end of the term |
| Records of data subject requests | [6] years |
| Anything under legal hold | Until the hold is lifted |
Backups
Encrypted point-in-time backups are retained [35] days. Deleted data persists in backups until they roll off. Backups are not used to restore individual deleted records, only to recover from failure, and any restore reapplies pending deletions.
3. Deleting a workspace
Available to the workspace owner, and promised to every Customer:
- Request — the owner requests deletion in-product or in writing to [PRIVACY EMAIL]. We verify they are the owner.
- Export first — we generate a complete structured export (JSON + CSV, files included) and confirm the owner has it. [30] day window.
- Confirm — explicit second confirmation. The workspace name must be typed. This step is irreversible.
- Suspend — access is cut immediately; a [7] day grace period allows reversal in case of mistake or dispute.
- Delete — workspace, memberships, content and files removed from live systems within [30] days.
- Backups — the data ages out of encrypted backups within a further [35] days.
- Certify — written confirmation of deletion on request, listing what was retained under §2 and why.
Retained after workspace deletion: billing and tax records (6 years), the deletion request record, and any data under legal hold.
4. Deleting one person
When an individual's data is erased — at the Customer's instruction, or on a verified request Rople handles as controller:
Deleted: authentication account and credentials, profile photo, phone number, personal contact details, sessions, analytics identifiers.
Pseudonymised, not deleted: authorship of workspace content. The name is replaced with "Former member" and the identifier is severed from the person. The content — goals, feedback given, review records — remains, because it is the employer's business record and deleting it would corrupt other people's history and the Customer's own compliance position.
Retained: consent records, audit-log entries recording the deletion itself, billing records, and anything under legal hold.
If a Customer instructs full destruction of authored content, we will do it, but we will first put the consequences in writing.
5. How deletion is executed
Deletion means removal of the record, not a hidden flag. Where a soft-delete flag is used for a grace period, a scheduled job performs the hard delete at the end of that period. File objects are removed from storage, not merely unlinked. Each automated deletion job writes to the audit log.
6. Exports
Available to owners and admins for their own workspace, at any time, at no charge. Structured JSON plus CSV, with uploaded files included. Delivered as a password-protected archive, with the password sent separately. Large exports may take up to [72] hours.
7. Requests
Retention or deletion questions: [PRIVACY EMAIL]. Individual rights procedure: SUBJECT_RIGHTS_RUNBOOK.md (internal) and the Privacy Policy (public).