Data retention schedule
The table below sets out how long Relisend keeps different records and how they are disposed of.
RecordTargetPurpose / disposal⚙ Active account and configurationAccount lifetimeDelete or de-identify after verified closure.✉ Mailbox contentMailbox/customer controlsUser-managed through mail folders and provider.▤ Security/admin audit logs12 monthsSecurity and accountability.▰ Support tickets24 months after closureContinuity and disputes.▭ Payment/tax recordsApplicable statutory period, commonly up to 10 yearsAccounting and tax; card data stays with processors.⌁ Attachment quarantine30 days by defaultIncident review, then secure deletion.▱ BackupsDocumented rotationDeletion propagates through expiry.⚿ Password-reset tokensShort expiryConsumed tokens are invalidated.
How disposal works
When a retention target is reached and no legal hold applies, we follow a structured disposal process.
Our commitments
We apply the following principles to our data retention and disposal practices.
Purpose-limited retentionWe retain records only for legitimate business, legal and operational purposes.
Secure disposalWe use appropriate technical and organisational measures to securely dispose of records.
Documented accountabilityWe maintain documentation to demonstrate compliance with our practices.