Retention Policy
What expires automatically, what remains today, and how customers or signers can request a retention review.
The rule we apply today
Pactlyra retains only information needed to operate, secure, bill for and prove the service, but the current production system does not yet run automatic lifecycle deletion for agreements, documents, evidence, workspace records or support tickets. Those records remain until Pactlyra applies a lawful deletion, anonymisation or customer-specific contractual process. This policy states that limitation plainly instead of promising a deletion schedule the product does not enforce.
Current schedule
| Data class | Current period or criterion |
|---|---|
| Uploaded source documents and drafts | No automatic expiry; retained with the workspace until a lawful deletion process is applied |
| Sent and completed agreements, field values and evidence | No automatic expiry; retained to preserve the transaction and verifiable evidence, subject to law and an applicable order |
| Recipient names and addresses | Retained with the agreement; reviewed with any verified rights request and the customer's instructions |
| Append-only audit events | No automatic expiry; retained to preserve integrity, with personal data minimised to identifiers and hashes where the product supports it |
| Customer accounts, workspaces and memberships | Retained while the account is active and afterwards until closure, legal, billing and deletion requirements can be applied |
| Customer console sessions | Expire after their configured authentication window; expired records may remain as security metadata |
| Signing links and one-time codes | Expire according to the link or challenge window; tokens are stored as hashes |
| API-key records | Retained while active and after revocation as security and audit metadata; plaintext keys are not stored |
| Hard-bounce and complaint suppression | Retained while needed to prevent repeat contact, unless the address is lawfully reviewed and lifted |
| Support and security tickets | No automatic expiry; retained while needed to resolve, audit and defend the request |
| Abuse-prevention counters | Expire after their fixed operational window and are not joined to a signer record |
| Billing and tax records | Retained by Pactlyra and Stripe for the period required by accounting, tax, fraud and payment-dispute obligations |
| Neon snapshots | Follow the configured production snapshot schedule and provider deletion behavior; snapshot deletion may lag primary-record changes |
Customer choices
Customers should set appropriate document expiry before sending where available, export completed evidence, avoid uploading unnecessary personal data, revoke unused credentials and remove integrations no longer needed. Envelope expiry stops an unfinished transaction; it does not delete the underlying document or evidence.
An enterprise order may set a different retention, export, legal-hold or data-residency requirement only when Pactlyra confirms that the control is implemented for that workspace. A sales statement or requested setting does not override this policy by itself.
Requests and legal holds
Send retention, closure or deletion requests to [email protected] with enough non-sensitive information to identify the account, workspace or agreement. Do not email the document, a signing link, password or API key. Pactlyra will verify the requester, identify whether the customer or Pactlyra controls the data, and explain the available action and any legal, evidentiary, security or backup exception.
Pactlyra may preserve records required for a legal claim, fraud investigation, payment dispute, regulatory duty or customer-directed legal hold. Restricted records are used only for that purpose. When the reason ends, the record returns to the applicable retention rule.
Future controls
Pactlyra intends to add verified workspace closure, configurable retention, deletion or anonymisation, backup propagation and legal-hold controls. They are not represented as available until production and tests enforce them. This page will be updated when those controls change the real schedule.
Effective and last updated 2026-09-21. These pages describe Pactlyra's current production practices. Contact [email protected] with questions or rights requests.