Legal

Retention schedule

The default period or decision rule for each data class. Customer-configured windows and an Order Form may set a different period where the product supports it.

Effective
1 August 2026
Last updated
1 August 2026
Version
2026-08-01

The schedule

DataDefault period or criterionReason
Email sign-in codes10 minutes or five failed attemptsAuthenticate one sign-in. The code is hashed and deleted after successful use.
Signed session7 daysKeep a user signed in. Signing out removes the browser cookie immediately.
Rate-limit counters and pseudonymous source keysUp to 24 hoursPrevent abuse and diagnose short-lived traffic incidents. Sign-in source addresses are HMAC-pseudonymised before storage.
Account, membership and workspace settingsWorkspace lifetimeOperate the account and enforce access. Removed from active systems when the workspace is erased, subject to narrow legal records below.
Build conversations, packages, skills, configurations and uploaded process documentsWorkspace lifetimeBuild, explain, version and operate the Customer’s automations. The Customer may export or erase the workspace.
Run tracesCustomer-configured; workspace lifetime if no window is configuredInvestigate what an automation did. A deployment may set RETENTION_TRACE_DAYS.
Run summariesCustomer-configured; workspace lifetime if no window is configuredOperations, audit and trend analysis. A deployment may set RETENTION_RUN_DAYS, never shorter than trace retention.
Resolved exceptionsCustomer-configured; workspace lifetime if no window is configuredShow how failed or escalated work was resolved. Open exceptions do not expire automatically.
Usage recordsCustomer-configured; normally at least 13 monthsQuotas, billing reconciliation and year-on-year comparison.
Hash-chained audit and legal acceptance receiptsWorkspace lifetimeEvidence of changes and authority. Removed from active tenant systems only through full workspace erasure; a minimal non-personal erasure receipt survives.
Invoices, payment and tax recordsThe period required by Swiss accounting, tax and limitation rulesMeet legal obligations and establish or defend claims. Stripe may retain its independent records under its own notice.
Backups and provider recovery copiesProvider rotation schedule after active-system deletionDisaster recovery. They are isolated from ordinary use and are not restored except for a recovery event; legal holds may extend the period.

How configurable retention works

A hosted or dedicated deployment may configure separate windows for full run traces, run summaries, resolved exceptions and usage records. No history is silently pruned where a window has not been configured. A run summary cannot expire before its trace, open exceptions do not expire automatically, and audit cannot be pruned one entry at a time without invalidating its hash chain.

Customers should choose periods based on their process, statutory recordkeeping, limitation periods, employment or sector rules, and the need to explain automated actions. Shortening a window can permanently remove data as soon as the next retention job runs.

Workspace erasure

Full workspace erasure is separate from routine retention. It clears tenant-scoped active database rows and stored trace objects, including workspace audit and acceptance records. The operation verifies that no tenant rows remain. A minimal erasure receipt survives outside the tenant scope, recording the workspace identifier, counts removed and final audit-chain head rather than Customer content.

Backups and disaster-recovery copies are not available for ordinary use after active deletion and expire under provider rotation schedules. If a recovery temporarily restores deleted data, deletion controls must be reapplied. Narrow tax, billing, legal-hold or security evidence may be retained and isolated for the applicable legal period.

Choosing or asking about a period

Enterprise Order Forms can record a deployment-specific schedule and data-residency design. Contact hello@boundlane.com to request the configured values, discuss a different schedule, or coordinate deletion.