Data Retention Schedule
Every category of data Adoptiv holds, where it lives, how long we keep it, what triggers deletion, and which periods you can change yourself.
Adoptiv Inc · Updated 2026-08-03
01What this schedule is
This is the complete retention policy for Adoptiv. Every category of data we hold appears in the table below with a defined period, a defined deletion trigger, and a note saying whether you can change it.
It forms part of the [Terms of Service](/legal/terms) and the [Data Processing Agreement](/legal/dpa). Where an Order Form or a signed addendum sets a different period for your account, that document controls for the categories it names and this schedule controls for everything else.
Two ideas run through the whole schedule. First, a period runs from a trigger, not from the day you happen to ask: a call recording ages from the call, a user profile ages from the day the user is removed. Second, deletion is a process rather than an instant, because a record removed from a live system stays in a backup until that backup rotates. The backups section says exactly how long that takes.
Periods here are maximums. Deleting something yourself, sooner, always works and always wins.
02The schedule
| Data category | Where it lives | Retention period | What triggers deletion | Can you change it |
|---|---|---|---|---|
| Account and workspace records | Primary database, shared schema | Life of the account, then 30 days | The retrieval window closes after the subscription ends | No |
| User profiles and sign-in identities | Primary database, shared schema | 30 days after the user is removed | An administrator removes the user, or the workspace is closed | No. You can remove a user at any time, which starts the clock |
| Sessions, devices and API keys | Primary database and cache | Session ends 30 days after last use. A registered device is removed 90 days after last use | Inactivity, sign-out, or the credential being revoked | No. Revoke any session, device or key at any time |
| Call detail records | Workspace schema | 24 months | Nightly sweep removes records older than the window | Yes. Settings, Data retention. 3 to 84 months |
| Call recordings | Recording storage | 12 months | Storage lifecycle rule expires the audio. The call record itself stays for its own period | Yes. Settings, Data retention. 30 days to 84 months, extendable in 30-day blocks on the retention add-on |
| Voicemail audio | Recording storage | 90 days | Age of the message, or deletion from the mailbox, whichever comes first | Yes. Settings, Voicemail. 30 to 365 days |
| Transcripts and AI analysis output | Workspace schema | Follows the recording it came from, 12 months by default | The parent recording expires or is deleted | Yes. It inherits the call recording setting |
| CRM records: leads, contacts, accounts, deals, quotes | Workspace schema | Life of the account. No automatic expiry | You delete the record. It sits in the recycle bin for 30 days, then it is purged | Yes. Delete any record at any time |
| Notes, comments and files on a CRM record | Workspace schema, files in object storage | Life of the parent record | The parent record is purged, or the item is deleted directly | Yes |
| Tasks and activities | Workspace schema | Life of the parent record. A standalone activity is purged 36 months after it completes | The parent record is purged, or the 36 months elapse | Yes. Delete at any time |
| Email copies synced from a connected mailbox | Workspace schema | 24 months, or 30 days after the mailbox is disconnected, whichever comes first | Age of the message, or disconnection of the mailbox | Yes. Settings, Email. 3 to 60 months |
| Email attachments | Object storage | The same window as the message it belongs to | The message row is deleted, and the attachment is removed within 7 days | Yes. It inherits the email setting |
| Email open and click events | Workspace schema | 180 days | Daily prune removes events older than the window | No |
| Chat messages and chat files | Workspace schema, files in object storage | 24 months | Age of the message, or deletion by a member with permission | Yes. Settings, Chat. 30 days to 84 months, or keep until deleted |
| CRM change history | Workspace schema | 24 months | Monthly prune removes entries older than the window | No |
| Audit logs | Primary database, shared schema | 13 months | Monthly partition is dropped once it passes 13 months | No. Enterprise accounts can extend to 24 months by agreement |
| Security and access logs: sign-in, MFA, failed attempts, administrative actions | Primary database, shared schema | 12 months | Daily prune removes entries older than the window | No |
| Application and infrastructure logs | Log store | 30 days | Log store retention policy expires the entry | No |
| API request logs and webhook delivery logs | Workspace schema | 90 days | Daily prune removes entries older than the window | No |
| Do-not-call and suppression lists | Workspace schema | Life of the account. Never expired automatically, and never removed when a contact is deleted | An administrator removes an entry, which is written to the audit log | Yes, by an administrator. Keep entries at least 5 years to meet the Telemarketing Sales Rule |
| Billing records: invoices, payments, credits, wallet transactions | Primary database and the payment provider | 7 years from the end of the tax year | The statutory period expires | No. These survive an erasure request while the period runs |
| Support correspondence | Helpdesk and the support mailbox | 24 months from the last message on the ticket | Age of the ticket | No. Ask us to close and delete a ticket sooner |
| Marketing contacts, meaning people who give us their details on our own site | Marketing store | 24 months from the last engagement | Inactivity, unsubscribe, or an erasure request, whichever comes first | Yes. Unsubscribe or write to privacy@adoptiv.com |
| Data exports you generate | Object storage | 7 days | The download link expires and the file is deleted | No. Delete an export sooner from the exports list |
| Import files you upload | Object storage | 30 days after the import finishes | Age of the file. The records it created follow their own category | No |
| Analytics store | Analytics store | Row-level events 90 days. Aggregated daily and monthly metrics 25 months | Table time-to-live expires the row | No |
| Backups | Backup storage, separate from production | 35 days, rolling | The backup passes 35 days old and is overwritten | No |
| Aggregated, de-identified statistics | Analytics store | Indefinite | Not applicable. These cannot be linked to a person or an account | Not applicable |
03How deletion actually works
Deletion runs in three stages, and knowing all three is the only way to answer the question customers actually ask, which is when the data is really gone.
- Soft delete. Deleting a CRM record in the app puts it in the recycle bin. It disappears from lists, reports and search immediately, and it can be restored. It stays there for 30 days.
- Hard delete. After 30 days the record is purged from the live database, along with the notes, files, activities and attachments that hang off it. This is not reversible. Recordings, voicemail and other objects in storage are removed by the storage lifecycle rule for their category.
- Backup rotation. The purged record still exists in backups taken before the purge. Those backups rotate out over the next 35 days, after which no copy remains.
So the worst case, from the moment you press delete to the moment the last copy is gone, is 65 days: 30 in the recycle bin plus 35 of backup rotation. You can shorten the first 30 by emptying the recycle bin, which triggers the hard delete straight away and leaves only the backup window.
Deleting a parent record deletes its children. Deleting a contact removes its notes, files, tasks, activities and call links. It does not remove the call detail records themselves, which carry their own period, and it does not remove a do-not-call entry, which is the whole point of a do-not-call entry.
04Backups
Backups get their own section because deleting something from a live system does not remove it from a backup. It cannot: a backup is a fixed picture of the data as it stood, and editing one would defeat its purpose.
What we run:
- A full encrypted backup of the databases every night, plus continuous write-ahead log shipping so any point in the retention window can be restored.
- A retention of 35 days, rolling. A backup older than 35 days is expired and overwritten.
- Backups held in storage separate from production, encrypted at rest, with access restricted to the engineers who run recovery.
- Non-current versions in object storage, which cover recordings and files, expired on the same 35-day rule.
What that means for you. When a record is purged from the live system, copies of it remain in backups for up to 35 more days, and then they are gone. We do not selectively edit a record out of a backup, and no supplier who tells you otherwise is describing a real process.
A backup is used only to restore service. If a restore brings back data that had already been deleted under this schedule, the deletion is reapplied within 24 hours of the restore completing.
05Audit, security and access logs
These logs hold personal data, and we say so plainly rather than filing them under a vague heading. An audit entry records the user, the action, the resource it touched, the value before the change, the IP address, an approximate location derived from that IP address down to city level, the browser, the operating system and the device type.
They exist for three reasons: so you can see who changed what in your workspace, so we can investigate a security incident, and so we can answer a regulator or a court. That is why they are kept longer than most operational data, and why an individual user cannot edit or delete them.
| Log | Period | Why that period |
|---|---|---|
| Audit log of changes in your workspace | 13 months | One full year plus a month, so a year-on-year comparison and an annual review both have complete data |
| Security and access log: sign-ins, MFA events, failed attempts, administrative actions | 12 months | Long enough to investigate an incident found late, short enough not to become a standing archive of where your staff were |
| Application and infrastructure logs | 30 days | Operational debugging only. They are not a record of anything |
| API request and webhook delivery logs | 90 days | Long enough to reconstruct an integration fault and settle a dispute about what was sent |
None of these is kept for as long as necessary, which means nothing. They are kept for the period above and then deleted by a scheduled job, and the deletion itself is logged.
Enterprise customers who need a longer audit window for their own obligations can extend the audit log to 24 months by agreement. That is the only extension we offer, and it does not extend the security and access log.
06Legal hold
A legal hold suspends this schedule for the data it covers. Nothing under hold is deleted, by a scheduled job or by a user, until the hold is lifted.
A hold can be applied by:
- Adoptiv's legal counsel, or an officer of Adoptiv Inc acting on counsel's advice, where we reasonably anticipate litigation, receive a preservation notice, or receive a valid order or lawful request from a court, a regulator or a law enforcement body.
- You, on your own workspace, by written request to legal@adoptiv.com from an account administrator, naming what to preserve and why. We confirm in writing when the hold is in place and what it covers.
While a hold is in place we tell the account administrator that one exists and what categories it covers, unless we are legally prohibited from saying so. We record who applied it, when, on what basis, and when it was lifted.
A hold is reviewed at least every 6 months and lifted as soon as the reason for it ends. When it is lifted, the normal schedule resumes and anything already past its period is deleted at the next scheduled run.
A legal hold does not give anyone extra access to the data. It stops deletion. It does not open a door.
07Exporting before deletion
You can take your data out at any time, on any plan, without asking us.
- In the app: any list view exports to CSV, and Settings, Export builds a full workspace export in CSV and JSON covering contacts, leads, accounts, deals, activities, tasks, notes, call detail records, transcripts and email metadata.
- Recordings and voicemail audio export as original audio files with a manifest that maps each file to its call record.
- The API returns any record type in JSON, with pagination, so you can build a continuous copy rather than a one-off dump.
- A full workspace export is prepared within 24 hours for most accounts and within 72 hours for the largest. We email the administrator when it is ready.
An export file is available to download for 7 days and is then deleted from our storage. Generate another if you miss it.
If you are leaving, export before the retrieval window closes. We do not restore data from a backup for an account that let the window pass, because by then the deletion is the correct outcome and reversing it would be the breach.
08When your account ends
Whether you cancel or we terminate, the sequence is the same:
| Stage | When | What happens |
|---|---|---|
| Access ends | End of the paid period, or immediately on termination for cause | Users can no longer sign in to work. Administrators keep sign-in for export only |
| Retrieval window | 30 days from the day access ends | Your data is held read-only. You can sign in as an administrator and export it. Nothing is processed, no calls are placed, no sync runs |
| Deletion from live systems | Within 7 days of the window closing | The workspace schema is dropped, storage objects are deleted, cache entries are flushed, and the account record is reduced to what billing law requires |
| Deletion from backups | Within a further 35 days | Backups containing the workspace rotate out and are overwritten |
So an account is fully gone within 72 days of access ending: 30 days of retrieval, 7 days to delete, 35 days of backup rotation.
What survives, and why. Invoices, payment records and the minimum account identifiers attached to them are kept for 7 years from the end of the tax year, because tax and company law require it. Audit entries recording the closure itself are kept for their normal period. Aggregated statistics that cannot be linked back to you or to any individual are kept indefinitely.
A telephone number on the account is released back to the carrier when the retrieval window closes and cannot be recovered after that. Port it out before then if you want to keep it.
If you come back within the retrieval window, we reinstate the account as it was. After the window, there is nothing to reinstate.
09Asking us to erase something
For data inside your workspace, you are the controller and we are the processor. That means an individual who wants their data erased should ask you, and you delete it, which is faster than anything we could do on your behalf. Delete the record, empty the recycle bin, and the schedule above does the rest.
Where you need our help, or where the request concerns data we control, write to privacy@adoptiv.com from an address we can verify.
- We acknowledge within 5 business days.
- We complete the erasure from live systems within 30 days of the request. If the request is complex we tell you why and take up to 60 days, which is the extension the GDPR allows.
- Backups rotate out over the following 35 days, as described above.
- We confirm in writing what was deleted, from which systems, and on what date.
We may refuse or narrow a request where the data is under legal hold, where we must keep it for tax, accounting or regulatory reasons, where erasing it would defeat a do-not-call suppression that protects the individual, or where it is aggregated and no longer identifies anyone. We tell you which of those applies rather than declining without a reason.
Erasing a contact does not erase the fact that a call happened, where the call detail record is needed as evidence of consent or of a do-not-call request. In that case we strip the identifying fields and keep the minimum record. We tell you when we do this.
10How deletion reaches our sub-processors
Some data sits with a sub-processor, for example telephony carriage, transcription, email delivery or payment processing. The current list, with what each one holds and where it operates, is at [our sub-processor page](/legal/sub-processors).
When data is deleted here, this is how it clears there:
- Sub-processors that hold data only in transit, such as carriers and email delivery, hold no copy to delete beyond their own logs, which run on their published retention.
- Sub-processors that store data on our behalf, such as object storage and transcription, receive the delete instruction through the same API call that removes the object. That is immediate, and their own version and backup expiry follows within 35 days.
- For anything not deletable through an API, we issue a written deletion instruction within 5 business days of the deletion here, and require completion within 30 days.
- Our contracts require every sub-processor to delete or return personal data on termination of our agreement with them, and to hold nothing longer than we permit.
Payment records at our payment provider are the exception. Those are kept for the statutory period under the provider's own obligations, and we cannot instruct their deletion sooner.
If you need written confirmation that a specific deletion has propagated, ask privacy@adoptiv.com and we will produce it.
11Aggregated and de-identified data
We keep aggregated statistics indefinitely: counts, totals, averages and trends used to run capacity planning, to bill correctly and to improve the product.
Aggregated means the figure cannot be resolved back to a person, a contact, a call or an account. No identifiers, no free text, no audio, no transcript content. If a figure could be traced back, it is not aggregated data and it follows its own row in the schedule above.
We do not use Customer Data to train AI models, aggregated or otherwise. That commitment is in the [Terms of Service](/legal/terms) and it is absolute.
12Changes to this schedule
We may change this schedule. Shortening a period, or adding a category, takes effect when the updated date at the top of this page changes.
Lengthening a retention period for a category you cannot control yourself is a material change and is announced 30 days in advance to account administrators, under the changes section of the [Terms of Service](/legal/terms).
Questions about this schedule, or a request for a copy tailored to your account, go to privacy@adoptiv.com. Legal hold requests go to legal@adoptiv.com.
Adoptiv Inc, 2810 N Church St STE 88783, Wilmington, DE 19802, United States. Telephone +1 (636) 556 0022.
Adoptiv Inc, 2810 N Church St STE 88783, Wilmington, DE 19802, United States. Questions about this document go to legal@adoptiv.com. Privacy requests go to privacy@adoptiv.com.