Skip to main content

Overview

Every Vault has a retention policy that governs what happens to its data after deletion. A Vault created without an explicitly assigned policy uses ROOTKey’s default retention policy, described in full below. A custom retention policy can be assigned instead - at creation, or later from the Vault’s options menu - in which case that policy governs instead of the default described on this page.

Default Retention Policy

Every number above is a default, not a fixed rule. A custom retention policy can change the retention period, the size of the notice window, how often the reminder repeats, and who receives it - assign one to the Vault if any of those do not fit your organisation.

Why Three Years

GDPR’s storage limitation principle (Article 5(1)(e)) requires that personal data not be kept longer than necessary for the purpose it was processed for - while permitting longer retention when data is processed solely for archiving, statistical, or research purposes, subject to appropriate safeguards. ROOTKey’s default policy is built around that distinction:
  • During the 3-year window, deleted data is retained in full, supporting recovery, audit, and dispute-resolution needs.
  • After the window closes, sensitive information - anything that could identify a person or expose confidential content - is permanently deleted.
  • Aggregate statistical data that carries no privacy exposure (for example, usage counts or validation totals) is preserved, consistent with GDPR’s statistical-purposes allowance.

Before the Deadline

You are not left to track the date yourself. Once a Vault holds data whose deletion deadline falls inside the notice window - 30 days by default - ROOTKey alerts the organisation’s owners and admins, by email and by in-app notification, and repeats the alert every 7 days until the deadline passes. A custom retention policy can name specific recipients instead. When it does not, or when no custom policy is assigned at all, the alert goes to the organisation’s owners and admins. The deletion itself then happens automatically once the deadline is reached.

Assigning a Different Policy

If the default behavior above does not fit your organisation’s requirements, a Vault can be assigned a custom retention policy:
  • At creation - when configuring a new Vault
  • Afterward - from the Vault’s options menu in the Vaults table
Any Vault with a custom policy assigned follows that policy instead of the default described on this page.

View compliance coverage

See how ROOTKey’s retention and deletion behavior maps to GDPR and other regulatory frameworks.

Manage your Vaults

Sign in to review or change the retention policy on any of your Vaults.