Data Retention Policy

Effective date: June 8, 2026 · Last updated: June 8, 2026

1. Purpose

inSpring TalentOS stores credentials, work authorization documents, communications, and financial records. Indefinite retention enlarges the breach impact surface, violates data-minimization principles under applicable privacy laws, and serves no operational purpose past the candidate’s placement window.

This policy defines how long each category of data is kept, when it is deleted or de-identified, and how the periods are enforced.

2. Retention periods by category

CategoryPeriodTrigger eventNotes
Active account profileWhile the account existsAccount closure or 24 months of inactivityActive = any login or staff-side update in the last 24 months
Communications history2 years post-placementFinal pipeline stage = placed or withdrawnIncludes email, WhatsApp, SMS bodies and metadata
Documents — activeWhile the candidate is activeAccount closureMost credentials stay relevant for the duration of the engagement
Documents — expired credentials90 days past expiryDocument marked expiredTest scores, certifications, visa stamps, etc.
Documents — visa/immigration filings7 years post-filingFiling dateRequired for I-9 / immigration audit response
Audit logs1 yearLog entry timestampLong enough to investigate incidents within a reasonable detection window
Authentication logs90 daysEvent timestampLogin / logout / password reset events
Course progressWhile active + 90 daysAccount closureHelps re-onboarding if a candidate returns
Payment records7 yearsTransaction dateUS tax / financial record-keeping requirement
AI resume-parsing outputsLifetime of the parsed documentDocument deletionStored as structured fields on the candidate profile
AI report queries1 yearQuery timestampAudit trail for prompt-injection investigation
Staff internal notes2 years post-placementSame as communicationsTreated as part of the candidate’s record
Stage history2 years post-placementSame as communicationsUsed for funnel analytics; can be de-identified before deletion
Backups and snapshots7 days PITR; 30 days dailyBackup creationSupabase Pro defaults

Where two categories conflict (e.g., a document is both an audit artifact and an active credential), the longer period applies.

3. Account deletion

When a user requests deletion of their account, we:

  1. Mark the profile inactive within 24 hours.
  2. Within 30 days, delete or de-identify: profile, candidate profile, communications, documents, course progress, internal notes, reminders, and scheduled meetings.
  3. Retain only the categories that have a longer required period:
    • Payment records (7 years) — kept for tax and audit.
    • Visa/immigration filings (7 years) — kept for I-9 / immigration audit.
    • Audit logs (1 year from query, not from deletion).
  4. Backups containing the deleted data persist up to 30 days after deletion before being overwritten on the standard rotation.

4. Legal holds

If we are required by law to preserve specific records — subpoena, litigation hold, regulatory investigation — those records are exempt from this policy until the hold is lifted. Holds are tracked and reviewed quarterly by the operations team.

5. Disposal procedures

When a record reaches its retention limit:

6. Review cadence

This policy is reviewed: