Data retention
This page explains how long information in the building onboarding service is kept, and what is deliberately never removed. It sits alongside the privacy notice.
Kept as a permanent record
The following are the record of what a client told Future Decisions and when. They are not removed by any routine cleanup, because deleting them would destroy the evidence base for decisions made about a building:
- Submitted questionnaires and the answers within them
- The exact template version each building answered, including the question wording
- Audit events — the trail is append-only and is never edited or deleted through the application
- Requests for further information and the responses to them
Kept until deleted by a user
- Uploaded documents. A user with access to the building can delete a file. The file content is then removed from storage, while the record that it existed, who uploaded it and who deleted it remains in the audit trail.
Short-lived by design
- One-time login codes expire after 10 minutes and can be used once. Only a secure hash is ever stored — never the code itself.
- Invitation links expire after 7 days, and are invalidated immediately when an invitation is resent or revoked. Only a hash of the secret half of the link is stored, so a copy of the database does not yield a usable link.
- Sessions end after a period of inactivity, and on sign-out.
Accounts
A user account that is no longer needed is suspended or archived rather than deleted, so that the questionnaire answers, uploads and audit entries attributed to that person remain attributable. Suspended and archived accounts cannot sign in.
Backups
Backups of the database and the file volume are taken together and retained under Future Decisions' operational backup policy. Information removed from the live service may persist in backups until those backups age out.
Questions
For questions about retention, or to request information about data held about you, contact privacy@futuredecisions.ai.