Data Retention and Deletion Policy
How long operational, provider, backup, billing, security, and deleted-account records remain.
Effective 1 October 2026
1. Active workspace
Operational agency data remains while the workspace is active so the agency can reuse approved question records, review history, feedback, and cohort evidence. Optional feedback delivery addresses remain encrypted with their student records. Owners can correct or remove an address, delete records where product integrity and billing law permit, or request workspace deletion.
2. Temporary processing data
- Upload originals, normalized pages, approved assessment representations, and compiled marking evidence remain private while needed for marking, review, release, export, support, and an active agency retention choice.
- Mathpix asynchronous PDF artifacts are deleted after OCR and geometry are retrieved. Provider request payloads are not copied into application logs.
- Private Code Interpreter records from earlier service versions (inputs, outputs, hashes, latency, usage, failures, limits, and provenance) are tenant-scoped marking evidence; current marking no longer uses a code sandbox. They follow the associated agency's export, active-account, cancellation, deletion, backup, and legal-hold periods and are never placed in application logs or exposed to another tenant.
- Worker leases, transient renders, signed URLs, non-evidentiary request traces, and staging test data use the shortest operational period practical and are removed by scheduled jobs.
- Anonymous website counters are retained for up to 365 days. Daily workspace activity is retained for up to 90 days and is deleted with the workspace. Completed milestones are calculated from existing operational records and follow those records’ retention periods.
- Redacted application logs are retained for up to 30 days unless a security investigation or legal duty requires a specific record for longer. Privacy-scrubbed Sentry error events and operational alerts follow the configured Sentry project retention and are removed when no longer needed for reliability or incident response.
3. Cancellation without a guarantee claim
At ordinary cancellation, access continues until the end of the paid period. The owner may export records or request workspace deletion. If the owner does not delete the workspace, Axtant may retain operational data for 90 days after access ends to support reactivation and billing reconciliation, then schedule deletion.
4. Refund or deletion request
An approved guarantee claim or verified deletion request removes write access and provides a 14-day read-only export window. Automated deletion of customer operational data begins when that window closes. Encrypted backup copies become inaccessible to normal operations and age out within a further 35 days.
Deletion includes agency content, student rosters and encrypted feedback delivery addresses, source documents, approved assessment representations, compiled marking evidence, marked examples, private sandboxed-computation traces, submissions, document observations, answer mappings, marks, feedback, delivery events, question refinements, cohort briefs, and active links. The process is idempotent and audit-logged. An active legal hold defers operational and storage deletion until the hold is released.
5. Records retained after operational deletion
- Invoice, payment, refund, overage, tax-status, and accounting records for seven years where needed for legal, financial, and dispute purposes.
- The legal-agency identity hash, guarantee outcome, and minimal fraud-prevention record for seven years to enforce the one-claim rule. The hash is not used to restore operational data.
- Security and audit evidence for up to two years where needed to investigate access, deletion, refund, or abuse events.
- A longer period only where law, litigation hold, or a regulator requires it. Axtant restricts retained records to that purpose.
6. Personal accounts
A personal account is separate from a workspace. Deleting a personal account removes that person's sign-in after they have transferred any workspace ownership and left or been removed from every active workspace. It does not delete a workspace or another member's records. Historical membership identity may be anonymised where audit integrity must be preserved.
7. Requests
Owners may request workspace export or deletion from billing settings or privacy@axtant.com. Any user may manage their separate personal account from Account. Axtant verifies identity and agency authority before acting and reports completion or a specific legal exception.