- Nothing is kept "just in case". Data lives while you use the service and for a 30-day safety window after you delete.
- Three delete buttons: one assessment (erased at once), your account (locked now, erased in 30 days), an organisation (hidden now, erased in 30 days).
- Uploaded files are not kept unless an organisation turns retention on, and then only until the expiry it sets.
- What survives erasure: proof that consent was given (without your IP or browser), anonymous benchmark aggregates, and a tombstone user id so audit logs of surviving organisations still make sense.
The three deletions
One assessment · immediate
Your account · two-speed
If you own an organisation that still has other members, the button asks you to transfer ownership first: the workspace belongs to the team, not to the person leaving. Organisations where you are the only member are deleted with the account and restored with it.
An organisation · two-speed
What "erased" means, row by row
When the 30-day account purge runs, this is exactly what happens to each kind of record.
| Record | On account purge | Why not simply deleted |
|---|---|---|
| Login, sessions, linked Google identity | Sessions and linked identities deleted. The user row becomes a tombstone: email replaced with an unusable placeholder, name set to "Deleted user", profile fields blanked. | Audit logs in organisations you belonged to reference your user id. A tombstone lets them keep meaning "someone" without identifying you. |
| Assessments and answers | Answers, email address, IP address and telemetry wiped from each assessment; the assessment is marked deleted. | — |
| Assessment turn log | The raw text of what you typed, the request bodies and IP addresses are removed. The structural log of which question was answered when remains, without content. | The engine's own transcript is erased by an operator with the separate admin key within the same window; see Security. |
| Consent records | IP address and browser removed. The record that consent was given on a date remains, pointing at the tombstone. | Proof of consent is something DPDP expects a data fiduciary to be able to show. |
| Command Center chats | Deleted. | — |
| Notifications | Deleted. | — |
| Usage events | Your user id is removed; the anonymous event stays. | Aggregate product analytics; nothing identifies you once the id is gone. |
| Organisation memberships and invitations | Deleted. | — |
| Newsletter subscription, contact-form and report-delivery records under your email | Deleted. | — |
| Sole-member organisations | Purged on their own 30-day clock, which started when you deleted the account. | — |
| Record | On organisation purge |
|---|---|
| Uploaded files | Deleted from storage first. |
| Every table with an organisation column | All rows for that organisation deleted: assessments, evidence, initiatives, risks, decisions, policies, tasks, members, invitations, API keys, integrations, notifications, audit log. |
| The organisation itself | Deleted last. |
| Case-engine cases linked to it | Erased by an operator with the admin key inside the window. |
Retention schedule
| Data | Kept for | Then |
|---|---|---|
| Account and profile | While the account exists | Tombstoned 30 days after deletion |
| Assessments, reports, answers | While the account or organisation exists | Erased with it; individual assessments at once on request |
| Uploaded evidence files | Not retained by default. If retention is on: until the organisation's expiry setting (365 days unless changed) or its storage cap | Raw file deleted by a daily job; the confirmed facts extracted from it remain as the evidence register |
| Extracted-fact proposals not yet confirmed | Proposals awaiting review are swept periodically; interrupted extractions are marked failed | Re-upload to retry |
| Workspace records | While the organisation exists | Erased with it |
| Command Center chats | While the account exists | Deleted with it |
| Audit log | While the organisation exists | Deleted with it (an organisation that no longer exists has nothing for its log to protect) |
| Consent records | Indefinitely, pseudonymised after erasure | — |
| Contact-form and assurance-pilot submissions | Until we close the conversation, or on request | Deleted |
| Newsletter subscription | Until you unsubscribe or your account is erased | Deleted |
| Usage events | Indefinitely, without user id after erasure | — |
| Application logs (hosting provider) | Short rolling window set by Render | Aged out |
| Database backups (hosting provider) | Render's backup retention window | Aged out; not restored except to recover from an outage |
| Aggregate benchmark statistics | Indefinitely | Never identify an organisation or person |
If you cannot press the button
Assessments taken without an account, data entered about you by someone else's organisation, or anything else you cannot reach from a profile page: email klaritiq@gmail.com with "Erase" in the subject line and enough detail for us to find the records. We confirm within 7 days and complete within 30.
Related
Privacy Notice · Security · Data processing terms
Questions about anything on this page: klaritiq@gmail.com. We write these pages ourselves, in plain language, to match what the product actually does; they are not a substitute for legal advice to you.

