Trust Centre
Legal & privacy

Retention & Deletion Schedule

Retention must be proportionate to purpose and law. Customer-specific clinical retention rules can override a general product default.

Last updated 24 August 2026

Public-launch gate: this product-aligned draft must be reviewed and approved by qualified privacy, healthcare and commercial counsel for each supported jurisdiction before CareFlow accepts real healthcare data or payment under these terms. It is not presented as legal advice or a signed customer agreement.

01

Active workspace records

Account and operational records remain while the workspace is active and as required to provide the service. Customers are responsible for defining lawful clinical and financial retention requirements before production use.

02

Deletion request

An owner must re-enter the current password and exact workspace name. The workspace enters a seven-day deletion-pending period in which the owner can cancel the request.

03

After the grace period

Tenant users, clinical and operational records, subscriptions, documents represented in the database, tokens and tenant-linked configuration are erased by the deletion job.

Audit rows are pseudonymised and stripped of actor identity, target and detail. That minimum is retained for up to 365 days for security and financial accountability, then removed by the same scheduled lifecycle process.

04

Other operational records

Authentication verification/reset tokens expire automatically by purpose. Platform request telemetry is described as a 30-day operational record. Payment providers, email providers, backups and infrastructure logs may have separate configured or legal retention that must be recorded in the production deployment register.

05

Backups

Deletion from live storage does not promise immediate removal from immutable backup media. Backup retention, encryption, restoration restrictions and expiry must be defined in the production runbook and customer agreement.