Skip to content
InnovAIte

Discovery Data & Trust

Retention & deletion

Client information is not kept indefinitely just in case it becomes useful.

Last updated: · Version 1.1

These are the requirements for our Discovery engagements, not a claim that every described software capability is already operational. Scope, permissions, providers and retention must be agreed and checked before client evidence is processed.

A schedule for each kind of information

Retention depends on the purpose, engagement terms and applicable legal, security and operational requirements. Recordings, transcripts, source datasets, final reports, correspondence and accounting records may need different periods.

The actual periods and their start points are still being finalised. They must be documented and communicated before the relevant processing begins; this page is not a completed retention schedule.

What happens at the end

The engagement must define return or deletion arrangements, any justified continued retention and who is responsible. Where InnovAIte acts as a processor, the contract must address return or deletion at the controller’s choice, subject to applicable legal retention requirements.

Restricted storage is not an alternative to deletion without a valid reason. Any retained information needs a defined purpose, access restrictions and a review or deletion point.

Include derived copies and backups

Deletion planning must cover relevant transcripts, search indexes, cached processing data and local engagement copies, not only the original upload. This is an architectural requirement to verify, not a claim that automated deletion has already been validated.

If backup data cannot immediately be overwritten, the arrangements must put it beyond use until an established deletion cycle removes it. Backup handling and any restore process must prevent deleted information being reintroduced into ordinary use.