Skip to content

Data retention

Tidehawk keeps data only as long as it is needed for the purpose it was collected for. A daily job enforces the periods below automatically.

Data Kept for
Workspace, users, clients, domains, certificates, findings and alerts The life of the subscription, plus 30 days after cancellation
PSA connection credentials Until you disconnect the integration, or until the workspace is deleted
Support tickets and messages With the workspace
Passkeys, recovery codes and two-factor secrets Until you remove them, or with your user record
Reports, exports and erasure certificates in storage Download links expire; objects are deleted with the workspace
An abandoned trial workspace 30 days after the 7-day grace period following trial expiry

The 30-day windows are the recovery period: reactivate inside them and nothing is lost. See Change plan or cancel and Your trial and upgrading.

Data Kept for
Sign-in session cookie 7 days maximum, and revoked sooner on password reset or removal
Email verification, password reset and invitation tokens Until used or expired, then 3 days
Passkey challenges Expiry plus 1 day
Rate-limit counters The rate-limit window, then 2 days
Data Kept for
Your workspace audit log The life of the workspace, then pseudonymised on erasure
Pseudonymised audit rows left after an erasure 365 days, then deleted
Record of Tidehawk operator access to your workspace 6 years; the IP address and browser details are removed after 90 days
Support session records With the workspace; the IP address is removed after 90 days
Outbound email delivery log 90 days
External look-up log, recording queries made on your behalf 30 days
Stripe webhook payloads 90 days, then replaced with a marker

Your audit log is never edited in place, because every field in an entry feeds the hash chain that makes the evidence report meaningful. That is why it is pseudonymised at erasure rather than trimmed on a schedule. See Audit log.

Data Kept for
Erasure requests, including the certificate reference 6 years from completion
Subject access requests 6 years from completion
Breach incident records 6 years from closure
Billing records and invoices 6 years after the financial year

These are the records that prove a request was handled. Deleting them would remove the evidence that the erasure or the disclosure actually happened.

The managed database keeps seven days of point-in-time recovery data. A workspace erased today is therefore absent from all backups within seven days. Your erasure certificate states this. Backups are encrypted, held in London, and are not restored into a live environment except during a declared disaster-recovery event.

Links to exports and subject access packages expire after 30 days. Links to erasure certificates expire after 90 days. Save the file rather than the link.