Template — not yet legal advice. These documents are drafts to be reviewed and adapted by a qualified lawyer for your jurisdiction before Canvas Approvals goes live. Bracketed [placeholders] must be completed.

Data Retention Policy

Last updated: [DATE]

This policy describes how long Canvas Approvals retains data and how deletion works. It supplements the Privacy Policy and Terms of Service. Retention periods marked with brackets are defaults to confirm with counsel and align to your customers’ own obligations.

1. Principles

  • We keep data only as long as needed to provide the Service, meet legal and accounting obligations, resolve disputes, and enforce agreements.
  • Approval records are designed to be durable and tamper-evident: values are locked at submission and every action is logged.
  • Records are removed through the product’s own deletion process (a deletion approval chain), and a fully approved record cannot be deleted from within a workspace.

2. Retention periods

  • Live Customer Data (approvals, forms, data tables, variables, attachments, audit logs): retained for the life of the workspace while your subscription is active.
  • Audit logs: retained for at least [12–24 months] to support security and compliance.
  • Account data: retained while the account is active.
  • Email records (verification, notifications, marketing sends): retained for [12 months] for deliverability and compliance.
  • Backups: retained on a rolling [30-day] cycle and then overwritten.
  • Billing/tax records: retained for the period required by law (often [7 years]).

3. Deletion within the product

  • Attachments and approvals can be removed through the workspace where permitted; deletion of an approval runs through its configured deletion chain and can be cancelled by any participant.
  • Deleting a sub-space offers a choice to archive (keep approvals) or permanently delete, with a prompt to export first.
  • Deleting a workspace cascades to its members, sub-spaces, forms, approvals, attachments, and logs.

4. Deletion on account/workspace closure

When a workspace is closed or a contract ends, live Customer Data is deleted or anonymized within [30–90] days, after which it may persist only in backups until they cycle out (see above). You are responsible for exporting anything you need before closure; the product provides PDF and CSV export for approvals and logs.

5. Requests and legal holds

Verified deletion or export requests are handled within [30] days, subject to legal holds, ongoing disputes, and our need to retain certain records (for example, billing). For Customer Data, requests are directed through the workspace administrator (the data controller).

6. Contact

Questions about retention or deletion: [privacy@canvasapprovals.com].