Last updated: 24 May 2026
This policy sets out how long CrowAgent Ltd retains each category of personal and business data we process. Retention periods balance your right to erasure under UK GDPR Article 17 against our legal obligations (tax, company, and regulatory record keeping) and legitimate operational needs.
| Data category | Active-account retention | Post-closure retention | Basis |
|---|---|---|---|
| Account (email, name, auth metadata) | Life of the account | 14 days then hard-deleted | Contract + GDPR Art 17 |
| Social Value contracts + narratives | Life of the account | 14 days then hard-deleted | Contract + GDPR Art 17 |
| Generated reports (PDF archive) | Life of the account | 30 days then purged from storage | Contract |
| Billing records (invoices, VAT, Stripe events) | Life of the account + 7 years | 7 years after closure | UK VAT Act 1994 s58; Companies Act 2006 s388 |
| VIES / VAT validation log | Life of the account + 7 years | 7 years after closure | UK VAT Act 1994 s58 |
| Audit log (admin actions, security events) | 2 years rolling | 2 years from last entry | Legitimate interest; breach notification |
| Error telemetry (Sentry) | 30 days (free-tier default) | Already expired at closure | Legitimate interest |
| Product analytics (PostHog, consented) | 12 months rolling | Deleted on closure | Consent (GDPR Art 6(1)(a)) |
| Marketing emails (Resend logs) | 12 months rolling | Deleted on unsubscribe | Consent (PECR reg 22) |
| Backup snapshots (encrypted) | 35 days rolling | Expires automatically | Legitimate interest (disaster recovery) |
Closing your account via Account → Delete account starts a 14-day grace period. The moment you confirm:
If you do nothing for 14 calendar days, the scheduled hard-delete runs:
Billing records, VAT validation logs and anonymised audit-log entries are retained for the statutory period shown in the schedule above even after closure, but contain no directly identifying personal data after the hard-delete completes.
You can request a portable copy of every record we hold on your account at any time from Account → Data export. We process the request asynchronously and email you a private download link to a ZIP archive (one JSON file per data category) usually within a few minutes. The link is single-tenant-signed and expires after 7 days; you can request a new export at most once every 30 days.
If you prefer a written request, email hello@crowagent.ai and we will respond within one calendar month (UK GDPR Article 12(3)).
Supabase Point-In-Time Recovery snapshots are taken continuously and retained for up to 35 days. Deleted data may persist in these encrypted snapshots until the snapshot itself expires; we do not selectively purge individual rows from backups, consistent with UK ICO guidance on backup retention.
You can request access, correction, deletion, portability, or restriction of your personal data at any time by emailing hello@crowagent.ai. We respond within one calendar month (UK GDPR Article 12(3)).
Material changes to retention periods will be announced at least 30 days in advance via in-app banner and email to the registered account-holder address.