Skip to content

Search

Search pages, products, sectors, experts and legal documents

All legal documents

Data Retention Policy — Client Portal

Effective date: 11 September 2026

1. Principles

  1. Keep data only as long as needed for the purpose, a legal duty, or the defence of legal claims.
  2. Retention runs per matter (request), from the date the request is closed or delivered, whichever is later.
  3. Deletion is logical first, physical second: a record is marked for deletion, excluded from all Portal views, then purged from storage and database within the grace window.
  4. Legal hold overrides every period below: a matter under hold is not deleted until the hold is lifted by GN in writing.

2. Schedule

DataPeriodTriggerMethod
Released deliverables (files + manifest hash)7 yearsrequest closed/deliveredpurge storage object + row; keep audit event
Client input documents (clean)7 yearsrequest closed/deliveredpurge storage object + row
Draft / candidate / superseded deliverable versions90 days after a later version is released, else with the matterrelease of a newer versionpurge
Quarantined / infected uploads30 daysscan resultpurge object; keep scan receipt
Reserved-but-never-uploaded file rows7 daysreservation timedelete row
Messages (client-visible and internal)with the matter (7 years)request closedpurge
Activity / audit events7 years (10 years if evidence of a claim)event timepurge
Authentication: one-time codes10 minutesissueprovider TTL
Authentication: sessions7 days inactivity / 30 days absolute (authentication-provider default)last activityprovider
Staff TOTP factorsuntil revoked by GN or account removal—admin unenrol
Account (membership)engagement end + retention of that org's last mattermembership removeddelete auth user after last matter purge
Hosting/request logs (Vercel)30 days (hosting-provider retention)—provider
Email delivery logs (Resend)provider default, not longer than 30 days—provider
Backups (Supabase)daily backups, 7-day cycle; purged data ages out with the cycle—provider

3. Procedure

  1. Monthly job (to be implemented) lists matters past their period and produces a deletion manifest.
  2. GN (or a delegated reviewer) approves the manifest; approval is recorded as an audit event.
  3. Purge runs; a purge receipt (counts, ids, hashes) is stored in the audit log for 10 years.
  4. Client organisations receive 30 days' notice before purge of released deliverables and may download them before then.

4. Client requests for early deletion

Handled within 30 days where the Engagement and professional duties permit. Where a professional duty requires retention, the client is told which records are retained and why.

5. Sub-processor alignment

Retention settings at Supabase, Vercel, Resend and Cloudmersive must be reviewed against this schedule at onboarding and annually. Cloudmersive scanning must be configured so submitted content is not retained by the provider.

6. Exceptions and holds

Only GN may approve an exception or place a legal hold. Both are recorded in the audit log with reason and date.


This document combines the firm's advanced AI system with experienced legal expertise, under the close supervision and approval of a senior attorney.