Data retention
Tidehawk keeps data only as long as it is needed for the purpose it was collected for. A daily job enforces the periods below automatically.
Your workspace data
Section titled “Your workspace data”| Data | Kept for |
|---|---|
| Workspace, users, clients, domains, certificates, findings and alerts | The life of the subscription, plus 30 days after cancellation |
| PSA connection credentials | Until you disconnect the integration, or until the workspace is deleted |
| Support tickets and messages | With the workspace |
| Passkeys, recovery codes and two-factor secrets | Until you remove them, or with your user record |
| Reports, exports and erasure certificates in storage | Download links expire; objects are deleted with the workspace |
| An abandoned trial workspace | 30 days after the 7-day grace period following trial expiry |
The 30-day windows are the recovery period: reactivate inside them and nothing is lost. See Change plan or cancel and Your trial and upgrading.
Sign-in and security artefacts
Section titled “Sign-in and security artefacts”| Data | Kept for |
|---|---|
| Sign-in session cookie | 7 days maximum, and revoked sooner on password reset or removal |
| Email verification, password reset and invitation tokens | Until used or expired, then 3 days |
| Passkey challenges | Expiry plus 1 day |
| Rate-limit counters | The rate-limit window, then 2 days |
| Data | Kept for |
|---|---|
| Your workspace audit log | The life of the workspace, then pseudonymised on erasure |
| Pseudonymised audit rows left after an erasure | 365 days, then deleted |
| Record of Tidehawk operator access to your workspace | 6 years; the IP address and browser details are removed after 90 days |
| Support session records | With the workspace; the IP address is removed after 90 days |
| Outbound email delivery log | 90 days |
| External look-up log, recording queries made on your behalf | 30 days |
| Stripe webhook payloads | 90 days, then replaced with a marker |
Your audit log is never edited in place, because every field in an entry feeds the hash chain that makes the evidence report meaningful. That is why it is pseudonymised at erasure rather than trimmed on a schedule. See Audit log.
Compliance records
Section titled “Compliance records”| Data | Kept for |
|---|---|
| Erasure requests, including the certificate reference | 6 years from completion |
| Subject access requests | 6 years from completion |
| Breach incident records | 6 years from closure |
| Billing records and invoices | 6 years after the financial year |
These are the records that prove a request was handled. Deleting them would remove the evidence that the erasure or the disclosure actually happened.
Backups
Section titled “Backups”The managed database keeps seven days of point-in-time recovery data. A workspace erased today is therefore absent from all backups within seven days. Your erasure certificate states this. Backups are encrypted, held in London, and are not restored into a live environment except during a declared disaster-recovery event.
Download links
Section titled “Download links”Links to exports and subject access packages expire after 30 days. Links to erasure certificates expire after 90 days. Save the file rather than the link.