1. Principles
- Keep data only as long as needed for the purpose, a legal duty, or the defence of legal claims.
- Retention runs per matter (request), from the date the request is closed or delivered, whichever is later.
- Deletion is logical first, physical second: a record is marked for deletion, excluded from all Portal views, then purged from storage and database within the grace window.
- Legal hold overrides every period below: a matter under hold is not deleted until the hold is lifted by GN in writing.
2. Schedule
| Data | Period | Trigger | Method |
|---|---|---|---|
| Released deliverables (files + manifest hash) | 7 years | request closed/delivered | purge storage object + row; keep audit event |
| Client input documents (clean) | 7 years | request closed/delivered | purge storage object + row |
| Draft / candidate / superseded deliverable versions | 90 days after a later version is released, else with the matter | release of a newer version | purge |
| Quarantined / infected uploads | 30 days | scan result | purge object; keep scan receipt |
| Reserved-but-never-uploaded file rows | 7 days | reservation time | delete row |
| Messages (client-visible and internal) | with the matter (7 years) | request closed | purge |
| Activity / audit events | 7 years (10 years if evidence of a claim) | event time | purge |
| Authentication: one-time codes | 10 minutes | issue | provider TTL |
| Authentication: sessions | 7 days inactivity / 30 days absolute (authentication-provider default) | last activity | provider |
| Staff TOTP factors | until revoked by GN or account removal | — | admin unenrol |
| Account (membership) | engagement end + retention of that org's last matter | membership removed | delete auth user after last matter purge |
| Hosting/request logs (Vercel) | 30 days (hosting-provider retention) | — | provider |
| Email delivery logs (Resend) | provider default, not longer than 30 days | — | provider |
| Backups (Supabase) | daily backups, 7-day cycle; purged data ages out with the cycle | — | provider |
3. Procedure
- Monthly job (to be implemented) lists matters past their period and produces a deletion manifest.
- GN (or a delegated reviewer) approves the manifest; approval is recorded as an audit event.
- Purge runs; a purge receipt (counts, ids, hashes) is stored in the audit log for 10 years.
- Client organisations receive 30 days' notice before purge of released deliverables and may download them before then.
4. Client requests for early deletion
Handled within 30 days where the Engagement and professional duties permit. Where a professional duty requires retention, the client is told which records are retained and why.
5. Sub-processor alignment
Retention settings at Supabase, Vercel, Resend and Cloudmersive must be reviewed against this schedule at onboarding and annually. Cloudmersive scanning must be configured so submitted content is not retained by the provider.
6. Exceptions and holds
Only GN may approve an exception or place a legal hold. Both are recorded in the audit log with reason and date.
This document combines the firm's advanced AI system with experienced legal expertise, under the close supervision and approval of a senior attorney.