Effective 14 August 2026. Part of the CommonLynk Privacy Policy and Data Processing Agreement.
1. Principle
We keep personal data only as long as necessary for the purposes it was collected for, and as required by applicable law. Different data has different retention periods, set out below. This policy aligns with major data protection frameworks, including the GDPR's storage-limitation principle, and with the data protection laws applicable to your use of the platform.
2. Account lifecycle (tenant workspaces)
A subscription and its workspace move through defined stages:
Active
- Trigger: Subscription paid/current
- What happens to data: Full access; data processed normally.
Grace
- Trigger: Payment lapses
- What happens to data: A limited grace period (target: 30 days), typically read-only; data retained; renewal restores access.
Dormant
- Trigger: Grace ends without renewal
- What happens to data: Workspace suspended for a further period (target: 6 months); data retained but inaccessible; reactivation on payment restores it.
Deletion
- Trigger: Dormant period ends
- What happens to data: Workspace and its data are scheduled for permanent deletion after notice, unless the Organisation has exported it or a legal hold applies.
At the start of the grace period we automatically generate a final, complete, downloadable copy of the workspace (an "offboarding package") and keep it available to the Organisation for download throughout the grace and dormant periods — so the Organisation can retrieve its data before any deletion. Final periods are confirmed in the Terms of Service; we give notice before permanent deletion where required.
3. Organisation (Beneficiary) data
Data about the individuals, households and establishments an Organisation records and serves (each, a "Beneficiary") and its operational data is controlled by the Organisation. The Organisation decides what to collect and how long to keep it, and can correct or delete records at any time while active. On termination, Organisation Data is deleted or returned per the DPA. We do not retain Organisation Data longer than the lifecycle above plus any legally required period.
4. Specific data types (CommonLynk as controller)
- Account/identity: kept for the life of the account; deleted per the lifecycle after closure.
- Billing/invoices: retained for the period required by tax and accounting law (commonly several years), even after account closure, then deleted.
- Payment references / uploaded transfer receipts: retained for reconciliation and the legally required financial-record period.
- Authentication & security logs: retained for a limited period for security and fraud-prevention, then deleted or anonymised.
- Support communications: retained for a reasonable period to handle queries and disputes.
- Marketing/consent records: retained while consent is active and for a period afterwards to evidence the consent.
4a. Diagnostic and fault-report data
When the platform encounters an error, or a user reports a problem or makes a suggestion, we record diagnostic data and the report itself (see Privacy Policy Section 6 and DPA Section 5A). These have their own periods:
Raw error records — technical error details, page address, browser, action trail
- Retention: 180 days. Deletion is currently carried out by a CommonLynk administrator using a built-in deletion tool; it is not yet run on an automatic schedule
- Why: Long enough to see whether a fault recurs across a reporting season; no longer
Fault summaries — the aggregated record of a distinct fault, with counts and dates, containing no personal data
- Retention: Kept while the fault is relevant to the platform's history
- Why: It is the record of what was broken and when it was fixed
Screenshots and files attached to a report
- Retention: Retained with the report they belong to. We do not currently apply an automatic time-based deletion to these files. They are deleted on request at any time, and when a report is deleted; the report keeps a note that an attachment existed
- Why: These carry the highest risk of containing Beneficiary personal data, so we are working towards a shorter, automatically enforced life for them than for the report itself
Reports and their message threads
- Retention: Retained for the life of the account and the lifecycle in Section 2
- Why: They are the record of what was asked and what we answered — needed for disputes, audits and continuity of support
Automated analyses of a fault
- Retention: Deleted with the fault summary they belong to
- Why: No independent purpose
These periods are applied by CommonLynk administrators using a built-in deletion tool, and are configurable only by CommonLynk administrators. They are not yet enforced by an automatic schedule; putting them on one is planned work. Organisations may request earlier deletion of a specific report or attachment at any time, and we act on such requests promptly.
5. Backups
CommonLynk maintains two layers of backup. Both are transferred over encrypted connections (TLS). Encryption at rest differs between the two layers, and is described separately below:
- Tenant backups — the Organisation can generate, schedule and download complete copies of its own workspace (spreadsheets, CSV, original uploaded files, and a technical database copy) from within the platform. Automatic copies are retained on a grandfather-father-son rotation — the most recent 7 daily, 4 weekly and 6 monthly copies — and then automatically pruned; on-demand copies keep the most recent few. Retention counts are automatically verified so copies are neither lost early nor accumulated indefinitely. Each such package is encrypted at rest with AES-256, under a key dedicated to the backup subsystem and separate from the live-data key.
- Infrastructure backups — server-level database snapshots of the whole platform taken nightly and rotated on a short cycle (currently 7 days) for disaster recovery. They are transferred over TLS and held in access-controlled object storage. CommonLynk does not currently apply its own encryption to this layer, and the storage provider does not offer encryption at rest for it. Adding encryption to this layer is planned work.
Data deleted from the live system persists in backup copies only until those copies age out of the rotation, after which it is overwritten. Where a data subject's records are erased, the erasure is honoured on any restore — a restore does not bring erased records back. The Organisation may additionally opt to receive its backup copies in storage it owns and controls (escrow), giving it an independent copy outside CommonLynk's infrastructure. Backup retention is kept to the minimum needed for disaster recovery and continuity.
6. Legal holds
Where data is subject to a legal obligation, investigation, or dispute, we may retain it beyond the periods above for as long as required, after which normal deletion resumes.
7. Deletion method
When data reaches end-of-life it is deleted from live systems and allowed to age out of backups; files are removed from storage. Where complete deletion is not immediately feasible, data is isolated and protected until deletion is possible.
8. Requests & contact
To request deletion of data we hold as controller, contact our Data Protection Officer, Yasmine Ossama — dpo@commonlynk.com. For Beneficiary data, contact the relevant Organisation (we assist as processor).