Data retention
Version 1.0 · Effective date: [[OWNER: publication date — stamp the same value into Config\Legal::$publishedAt]]
This page publishes the summary section of our retention schedule, and the categories of data it covers. The full working schedule — the record-by-record detail, what enforces each period, and the gaps we have not yet closed — is held internally for our regulator and our reviewing solicitor. Nothing appears here as a period unless the software enforces it automatically, or a named review that we actually run enforces it.
1. Publishable summary
How long we keep information
Your business records — customers, jobs, quotes, invoices and everything else you enter — are kept for as long as your account is open, because they are your working records and you decide what to remove. Deleting a record in the app moves it to your recycle bin; permanently deleting it from the bin removes the record itself, along with the things attached to it and their files — unless live invoices or payments still depend on it, in which case we refuse, because a tax record may not be destroyed. To remove one person from your account while keeping the financial record, use the erasure action on their customer record: it keeps the invoices and payments in anonymised form and deletes everything else. We do not delete your records on a timetable of our own.
Some things are cleared automatically:
What When Images you attach to the AI assistant Deleted permanently 60 minutes after upload Alerts you have dismissed Deleted permanently after 30 days (you can change this) Your sign-in session Ends after 2 hours of inactivity A password-reset link Stops working after 1 hour A staff invitation link Stops working after 7 days (you can change this) A public payment or quote link you send a customer Stops working 90 days after you send it (you can change this, including to "never"), and you can revoke a single payment or quote link, or all of one customer's links, at once Messages between you and your customers, and between your staff Kept until you set a retention period in Settings, which then clears them permanently Financial records — invoices, payments and the records underlying them — are kept for at least six years, because tax and company law require it, and that requirement overrides a deletion request.
Enquiries you send us through our website are kept for 24 months from your last contact with us, then deleted. We store a one-way fingerprint of the sender's internet address rather than the address itself. Where our website's private storage is configured on the host, expired enquiries are removed automatically each day; otherwise we review and clear them at least twice a year.
Support tickets and their attachments are kept for 24 months after the ticket is closed, or for the life of the account if that is longer, then deleted. Your account record is kept for as long as the account is open and for 6 years afterwards, because it is part of our contractual and accounting record. Both are cleared by a review we run on a diary, not by an automatic process.
Your Account database after the Services end: access ends on cancellation; we hold the database for a 30-day reinstatement grace period; we then write to the account contact giving at least 30 days' notice to take an export; and we delete it 90 days after the Services end unless you have told us to do something else. That deletion is carried out by a person, never on a timer, and the software checks every precondition before it will run — the account cancelled, the grace expired, the ninety days elapsed or a written instruction from you recorded by its reference, a verified export of your database still on file or a recorded reason for proceeding without one, and the database name matching your own account. Your account record, our administrative audit log and our support and agreement history are kept afterwards, as the record that the deletion happened.
Backups. Any backups at the hosting layer are held by our hosting provider, [[OWNER: hosting provider and data-centre location]]. We also take our own encrypted backups and keep them for 30 days, never dropping below one surviving copy of each database. Information you delete stays in a backup until that backup is rotated out. We make no backup or disaster-recovery commitment on the strength of this: no copy is held off-site yet, and we state no recovery time.
⚠ One thing this schedule is not: a single global purge policy. Every period in it is a ceiling — the longest we keep something. Some laws impose a floor instead, and the two point in opposite directions. India's forthcoming rules will require a customer to cause us to retain personal data, traffic data and processing logs for at least ONE YEAR before erasure, while European storage limitation and Singapore's retention-limitation obligation push the other way. Section 17 of the Data Processing Agreement is where that is reconciled: where a customer's own law imposes a floor, it is applied to that customer's data as their instruction, and only for that period. Retention is therefore a per-customer position, not a platform-wide one, and nothing in this schedule should be read as overriding a floor a customer has told us about.
2. Categories of data covered
| Population | Field 2 Service's role | Where it lives |
|---|---|---|
| The tenant's customers, their contacts, leads and portal users | Processor | The tenant's own database (database-per-tenant) |
| The tenant's staff and engineers | Processor | The tenant's own database |
| The tenant's account holder, billing contact and support correspondents | Controller | The platform registry database |
| Marketing-site enquirers | Controller | site/private/contact.csv on the web server |