Skip to content
Adoptiv

Data Retention Schedule

Every category of data Adoptiv holds, where it lives, how long we keep it, what triggers deletion, and which periods you can change yourself.

Adoptiv Inc · Updated 2026-08-03

01What this schedule is

This is the complete retention policy for Adoptiv. Every category of data we hold appears in the table below with a defined period, a defined deletion trigger, and a note saying whether you can change it.

It forms part of the [Terms of Service](/legal/terms) and the [Data Processing Agreement](/legal/dpa). Where an Order Form or a signed addendum sets a different period for your account, that document controls for the categories it names and this schedule controls for everything else.

Two ideas run through the whole schedule. First, a period runs from a trigger, not from the day you happen to ask: a call recording ages from the call, a user profile ages from the day the user is removed. Second, deletion is a process rather than an instant, because a record removed from a live system stays in a backup until that backup rotates. The backups section says exactly how long that takes.

Periods here are maximums. Deleting something yourself, sooner, always works and always wins.

02The schedule

Data categoryWhere it livesRetention periodWhat triggers deletionCan you change it
Account and workspace recordsPrimary database, shared schemaLife of the account, then 30 daysThe retrieval window closes after the subscription endsNo
User profiles and sign-in identitiesPrimary database, shared schema30 days after the user is removedAn administrator removes the user, or the workspace is closedNo. You can remove a user at any time, which starts the clock
Sessions, devices and API keysPrimary database and cacheSession ends 30 days after last use. A registered device is removed 90 days after last useInactivity, sign-out, or the credential being revokedNo. Revoke any session, device or key at any time
Call detail recordsWorkspace schema24 monthsNightly sweep removes records older than the windowYes. Settings, Data retention. 3 to 84 months
Call recordingsRecording storage12 monthsStorage lifecycle rule expires the audio. The call record itself stays for its own periodYes. Settings, Data retention. 30 days to 84 months, extendable in 30-day blocks on the retention add-on
Voicemail audioRecording storage90 daysAge of the message, or deletion from the mailbox, whichever comes firstYes. Settings, Voicemail. 30 to 365 days
Transcripts and AI analysis outputWorkspace schemaFollows the recording it came from, 12 months by defaultThe parent recording expires or is deletedYes. It inherits the call recording setting
CRM records: leads, contacts, accounts, deals, quotesWorkspace schemaLife of the account. No automatic expiryYou delete the record. It sits in the recycle bin for 30 days, then it is purgedYes. Delete any record at any time
Notes, comments and files on a CRM recordWorkspace schema, files in object storageLife of the parent recordThe parent record is purged, or the item is deleted directlyYes
Tasks and activitiesWorkspace schemaLife of the parent record. A standalone activity is purged 36 months after it completesThe parent record is purged, or the 36 months elapseYes. Delete at any time
Email copies synced from a connected mailboxWorkspace schema24 months, or 30 days after the mailbox is disconnected, whichever comes firstAge of the message, or disconnection of the mailboxYes. Settings, Email. 3 to 60 months
Email attachmentsObject storageThe same window as the message it belongs toThe message row is deleted, and the attachment is removed within 7 daysYes. It inherits the email setting
Email open and click eventsWorkspace schema180 daysDaily prune removes events older than the windowNo
Chat messages and chat filesWorkspace schema, files in object storage24 monthsAge of the message, or deletion by a member with permissionYes. Settings, Chat. 30 days to 84 months, or keep until deleted
CRM change historyWorkspace schema24 monthsMonthly prune removes entries older than the windowNo
Audit logsPrimary database, shared schema13 monthsMonthly partition is dropped once it passes 13 monthsNo. Enterprise accounts can extend to 24 months by agreement
Security and access logs: sign-in, MFA, failed attempts, administrative actionsPrimary database, shared schema12 monthsDaily prune removes entries older than the windowNo
Application and infrastructure logsLog store30 daysLog store retention policy expires the entryNo
API request logs and webhook delivery logsWorkspace schema90 daysDaily prune removes entries older than the windowNo
Do-not-call and suppression listsWorkspace schemaLife of the account. Never expired automatically, and never removed when a contact is deletedAn administrator removes an entry, which is written to the audit logYes, by an administrator. Keep entries at least 5 years to meet the Telemarketing Sales Rule
Billing records: invoices, payments, credits, wallet transactionsPrimary database and the payment provider7 years from the end of the tax yearThe statutory period expiresNo. These survive an erasure request while the period runs
Support correspondenceHelpdesk and the support mailbox24 months from the last message on the ticketAge of the ticketNo. Ask us to close and delete a ticket sooner
Marketing contacts, meaning people who give us their details on our own siteMarketing store24 months from the last engagementInactivity, unsubscribe, or an erasure request, whichever comes firstYes. Unsubscribe or write to privacy@adoptiv.com
Data exports you generateObject storage7 daysThe download link expires and the file is deletedNo. Delete an export sooner from the exports list
Import files you uploadObject storage30 days after the import finishesAge of the file. The records it created follow their own categoryNo
Analytics storeAnalytics storeRow-level events 90 days. Aggregated daily and monthly metrics 25 monthsTable time-to-live expires the rowNo
BackupsBackup storage, separate from production35 days, rollingThe backup passes 35 days old and is overwrittenNo
Aggregated, de-identified statisticsAnalytics storeIndefiniteNot applicable. These cannot be linked to a person or an accountNot applicable

03How deletion actually works

Deletion runs in three stages, and knowing all three is the only way to answer the question customers actually ask, which is when the data is really gone.

  • Soft delete. Deleting a CRM record in the app puts it in the recycle bin. It disappears from lists, reports and search immediately, and it can be restored. It stays there for 30 days.
  • Hard delete. After 30 days the record is purged from the live database, along with the notes, files, activities and attachments that hang off it. This is not reversible. Recordings, voicemail and other objects in storage are removed by the storage lifecycle rule for their category.
  • Backup rotation. The purged record still exists in backups taken before the purge. Those backups rotate out over the next 35 days, after which no copy remains.

So the worst case, from the moment you press delete to the moment the last copy is gone, is 65 days: 30 in the recycle bin plus 35 of backup rotation. You can shorten the first 30 by emptying the recycle bin, which triggers the hard delete straight away and leaves only the backup window.

Deleting a parent record deletes its children. Deleting a contact removes its notes, files, tasks, activities and call links. It does not remove the call detail records themselves, which carry their own period, and it does not remove a do-not-call entry, which is the whole point of a do-not-call entry.

04Backups

Backups get their own section because deleting something from a live system does not remove it from a backup. It cannot: a backup is a fixed picture of the data as it stood, and editing one would defeat its purpose.

What we run:

  • A full encrypted backup of the databases every night, plus continuous write-ahead log shipping so any point in the retention window can be restored.
  • A retention of 35 days, rolling. A backup older than 35 days is expired and overwritten.
  • Backups held in storage separate from production, encrypted at rest, with access restricted to the engineers who run recovery.
  • Non-current versions in object storage, which cover recordings and files, expired on the same 35-day rule.

What that means for you. When a record is purged from the live system, copies of it remain in backups for up to 35 more days, and then they are gone. We do not selectively edit a record out of a backup, and no supplier who tells you otherwise is describing a real process.

A backup is used only to restore service. If a restore brings back data that had already been deleted under this schedule, the deletion is reapplied within 24 hours of the restore completing.

05Audit, security and access logs

These logs hold personal data, and we say so plainly rather than filing them under a vague heading. An audit entry records the user, the action, the resource it touched, the value before the change, the IP address, an approximate location derived from that IP address down to city level, the browser, the operating system and the device type.

They exist for three reasons: so you can see who changed what in your workspace, so we can investigate a security incident, and so we can answer a regulator or a court. That is why they are kept longer than most operational data, and why an individual user cannot edit or delete them.

LogPeriodWhy that period
Audit log of changes in your workspace13 monthsOne full year plus a month, so a year-on-year comparison and an annual review both have complete data
Security and access log: sign-ins, MFA events, failed attempts, administrative actions12 monthsLong enough to investigate an incident found late, short enough not to become a standing archive of where your staff were
Application and infrastructure logs30 daysOperational debugging only. They are not a record of anything
API request and webhook delivery logs90 daysLong enough to reconstruct an integration fault and settle a dispute about what was sent

None of these is kept for as long as necessary, which means nothing. They are kept for the period above and then deleted by a scheduled job, and the deletion itself is logged.

Enterprise customers who need a longer audit window for their own obligations can extend the audit log to 24 months by agreement. That is the only extension we offer, and it does not extend the security and access log.

07Exporting before deletion

You can take your data out at any time, on any plan, without asking us.

  • In the app: any list view exports to CSV, and Settings, Export builds a full workspace export in CSV and JSON covering contacts, leads, accounts, deals, activities, tasks, notes, call detail records, transcripts and email metadata.
  • Recordings and voicemail audio export as original audio files with a manifest that maps each file to its call record.
  • The API returns any record type in JSON, with pagination, so you can build a continuous copy rather than a one-off dump.
  • A full workspace export is prepared within 24 hours for most accounts and within 72 hours for the largest. We email the administrator when it is ready.

An export file is available to download for 7 days and is then deleted from our storage. Generate another if you miss it.

If you are leaving, export before the retrieval window closes. We do not restore data from a backup for an account that let the window pass, because by then the deletion is the correct outcome and reversing it would be the breach.

08When your account ends

Whether you cancel or we terminate, the sequence is the same:

StageWhenWhat happens
Access endsEnd of the paid period, or immediately on termination for causeUsers can no longer sign in to work. Administrators keep sign-in for export only
Retrieval window30 days from the day access endsYour data is held read-only. You can sign in as an administrator and export it. Nothing is processed, no calls are placed, no sync runs
Deletion from live systemsWithin 7 days of the window closingThe workspace schema is dropped, storage objects are deleted, cache entries are flushed, and the account record is reduced to what billing law requires
Deletion from backupsWithin a further 35 daysBackups containing the workspace rotate out and are overwritten

So an account is fully gone within 72 days of access ending: 30 days of retrieval, 7 days to delete, 35 days of backup rotation.

What survives, and why. Invoices, payment records and the minimum account identifiers attached to them are kept for 7 years from the end of the tax year, because tax and company law require it. Audit entries recording the closure itself are kept for their normal period. Aggregated statistics that cannot be linked back to you or to any individual are kept indefinitely.

A telephone number on the account is released back to the carrier when the retrieval window closes and cannot be recovered after that. Port it out before then if you want to keep it.

If you come back within the retrieval window, we reinstate the account as it was. After the window, there is nothing to reinstate.

09Asking us to erase something

For data inside your workspace, you are the controller and we are the processor. That means an individual who wants their data erased should ask you, and you delete it, which is faster than anything we could do on your behalf. Delete the record, empty the recycle bin, and the schedule above does the rest.

Where you need our help, or where the request concerns data we control, write to privacy@adoptiv.com from an address we can verify.

  • We acknowledge within 5 business days.
  • We complete the erasure from live systems within 30 days of the request. If the request is complex we tell you why and take up to 60 days, which is the extension the GDPR allows.
  • Backups rotate out over the following 35 days, as described above.
  • We confirm in writing what was deleted, from which systems, and on what date.

We may refuse or narrow a request where the data is under legal hold, where we must keep it for tax, accounting or regulatory reasons, where erasing it would defeat a do-not-call suppression that protects the individual, or where it is aggregated and no longer identifies anyone. We tell you which of those applies rather than declining without a reason.

Erasing a contact does not erase the fact that a call happened, where the call detail record is needed as evidence of consent or of a do-not-call request. In that case we strip the identifying fields and keep the minimum record. We tell you when we do this.

10How deletion reaches our sub-processors

Some data sits with a sub-processor, for example telephony carriage, transcription, email delivery or payment processing. The current list, with what each one holds and where it operates, is at [our sub-processor page](/legal/sub-processors).

When data is deleted here, this is how it clears there:

  • Sub-processors that hold data only in transit, such as carriers and email delivery, hold no copy to delete beyond their own logs, which run on their published retention.
  • Sub-processors that store data on our behalf, such as object storage and transcription, receive the delete instruction through the same API call that removes the object. That is immediate, and their own version and backup expiry follows within 35 days.
  • For anything not deletable through an API, we issue a written deletion instruction within 5 business days of the deletion here, and require completion within 30 days.
  • Our contracts require every sub-processor to delete or return personal data on termination of our agreement with them, and to hold nothing longer than we permit.

Payment records at our payment provider are the exception. Those are kept for the statutory period under the provider's own obligations, and we cannot instruct their deletion sooner.

If you need written confirmation that a specific deletion has propagated, ask privacy@adoptiv.com and we will produce it.

11Aggregated and de-identified data

We keep aggregated statistics indefinitely: counts, totals, averages and trends used to run capacity planning, to bill correctly and to improve the product.

Aggregated means the figure cannot be resolved back to a person, a contact, a call or an account. No identifiers, no free text, no audio, no transcript content. If a figure could be traced back, it is not aggregated data and it follows its own row in the schedule above.

We do not use Customer Data to train AI models, aggregated or otherwise. That commitment is in the [Terms of Service](/legal/terms) and it is absolute.

12Changes to this schedule

We may change this schedule. Shortening a period, or adding a category, takes effect when the updated date at the top of this page changes.

Lengthening a retention period for a category you cannot control yourself is a material change and is announced 30 days in advance to account administrators, under the changes section of the [Terms of Service](/legal/terms).

Questions about this schedule, or a request for a copy tailored to your account, go to privacy@adoptiv.com. Legal hold requests go to legal@adoptiv.com.

Adoptiv Inc, 2810 N Church St STE 88783, Wilmington, DE 19802, United States. Telephone +1 (636) 556 0022.

Adoptiv Inc, 2810 N Church St STE 88783, Wilmington, DE 19802, United States. Questions about this document go to legal@adoptiv.com. Privacy requests go to privacy@adoptiv.com.