Trust and vendor file Retention and deletion

Retention and deletion

Last reviewed: [DATE]

This document sets out how long Innorve Academy keeps data and how it is deleted. The schedule is a proposed default called RET-v1. It is not yet adopted and is subject to counsel review. [CONFIRM]

RET-v1 schedule

Data Retention What happens at the end
Institution data (all records belonging to a credit union: memberships, enrollments, learning records, submissions, reviews, pilot and oversight records, evidence-binder links, invitations) 90 days after the engagement ends, unless the contract says otherwise Deleted through an audited database function. A CSV export is available before deletion.
Individual user account (email, display name, notification send records) Deleted after the institution's data is deleted, if the person belongs to no other institution; or earlier on the credit union's written request Deleted through an audited database function, together with everything that person authored [CONFIRM process]
Website leads (form submissions) 24 months after last contact, or deleted on request Deleted by Innorve platform staff [CONFIRM process: manual review or scheduled job]
Audit events 3 years Deleted after 3 years [CONFIRM process]. They hold references only, never content.
Database backups 7 days, rolling [CONFIRM plan before first pilot] Rotated out automatically by the provider
Provider logs (request, sign-in and email logs) Each provider's standard retention [CONFIRM per provider plan] Deleted by the provider
Free-tool answers Never received by Innorve Stay in the visitor's browser until the visitor clears them

Each institution record in the platform carries a reference to the retention policy that applies to it (by default, RET-v1) and the engagement end date.

Before deletion: export

Authorized roles can export cohort records as CSV files at any time during the engagement:

  • assessment records;
  • observations; and
  • progress.

Every export is recorded in the audit log. Innorve recommends that the credit union takes its final export before the engagement ends, and at the latest before the 90-day deletion date.

How deletion works

Deletion is performed by Innorve platform staff using audited database functions. Only platform staff can run them.

  • Deleting an institution requires typing the institution's exact name. The function records an audit event, then deletes the institution. The records that belong to it (memberships, cohorts, enrollments, learning records, submissions, reviews, pilot and oversight records, evidence-binder links and invitations) are deleted with it.
  • Deleting a user account requires typing the person's exact email address. The function records an audit event, then deletes the account and everything the person authored. A staff member cannot delete their own account this way.

These confirmation steps are there to prevent accidental deletion of the wrong institution or person.

User accounts are deleted as a separate step. A person's account (email and display name) is not part of any one institution, because a person can belong to more than one. When an institution is deleted, Innorve then deletes the accounts of its users who no longer belong to any institution, using the user-account function above. [CONFIRM process] Records of which notifications were sent to a user are deleted with that user's account.

What remains after deletion

What remains For how long Why
Audit events Up to 3 years from creation They show that actions, exports and the deletion itself happened. They hold ids, action, record type, version, time and outcome only, never content.
Backups Up to 7 days Deleted data can remain in backups until they rotate out. Innorve will not restore deleted data from a backup except to recover from an incident or error, and would then delete it again.
Provider logs Each provider's standard retention [CONFIRM] Request and sign-in logs, including IP addresses
Exports the credit union downloaded Under the credit union's control Innorve does not keep copies of exports

Requests

  • Credit unions can ask for earlier deletion of institution data or of a specific user account by writing to [PRIVACY CONTACT EMAIL]. [CONFIRM: who at the credit union may authorize a deletion request]
  • Individual platform users should ask their credit union. If they contact Innorve, Innorve passes the request to the credit union.
  • Website visitors can ask Innorve directly to delete their lead record at [PRIVACY CONTACT EMAIL].
  • Written confirmation of deletion is available on request. [CONFIRM]

Legal holds

If the law requires Innorve to keep specific data longer, Innorve will tell the affected credit union (unless the law forbids it), keep protecting the data, and delete it when the requirement ends.