Skip to main content

Data retention and deletion lifecycle

How long Konfir keeps verification data and what happens when retention ends.

Jacob avatar
Written by Jacob
Updated over 2 weeks ago

Overview

Konfir retains personal data for defined periods to support service delivery, audits, and legal or regulatory obligations. Retention differs depending on whether the individual has a Konfir account and the context in which verification data is processed.

Disclaimer: This article provides a high-level overview of Konfir’s retention and deletion approach. For the authoritative retention schedule, refer to:https://www.konfir.com/client/security


Standard retention periods

By default, Konfir retains personal data for up to seven (7) years in the following ways. This may vary depending on the type of data and your account status (active, terminated, inactive).

If you do not have a Konfir account - Personal data is typically retained for up to seven (7) years from the date the relevant verification data is provided to (or obtained by) Konfir.

If you have (or set up) a Konfir account - Personal data is typically retained until seven (7) years after your account is terminated or closed.

Inactive accounts - If an account is wholly inactive for at least three (3) years, retention is typically calculated from the end of that inactive period.

Marketing data - Marketing-related data is typically retained for twelve (12) months.

Disclaimer: Formal retention rules are maintained externally in the Retention Schedule. See: https://www.konfir.com/legal/retention-schedule


What happens when retention ends

When the applicable retention period ends, and there is no ongoing lawful basis to keep the data, Konfir will securely delete or anonymise it.

In some cases, deletion may not be immediate (for example where data exists in backup archives). In those situations, Konfir securely isolates the data from further processing until deletion is possible.

When data may be retained longer

Konfir may retain personal data beyond standard periods where there is an ongoing lawful basis to do so, for example:

  • To provide a service you have requested

  • To comply with applicable legal, tax, or accounting requirements

  • To pursue or defend legal claims

Customer responsibilities for exported copies

If your organisation has exported or stored verification outputs outside Konfir, you remain responsible for retention and deletion of those downstream copies. Konfir cannot delete or amend data held in your own systems.

Did this answer your question?