Data retention
The rule of thumb: check-in information exists to support a person’s first months, so it is kept for the program and a short tail, then removed. Nothing is kept “just in case”. The CCPA requires us to tell you how long we keep each kind of information rather than leave it open-ended, so here it is.
| What | Kept for | Why |
|---|---|---|
| Check-in replies, notes, follow-up records | The onboarding program (about six months), then 12 months | The tail lets a people team look back over a full cycle before it goes |
| Starter, manager and buddy contact details | While the organization’s subscription is live | Needed to send the check-ins at all |
| Private-word requests | The onboarding program, then 12 months | Same as check-ins; only ever visible to the head of people |
| Signal snapshots (calibration) | While the linked starter record exists | Pseudonymised, not deidentified: still personal information under the CCPA, see below |
| Email delivery log | 24 months | Append-only record that a message was sent, for support and dispute |
| Account and billing records | As long as tax and company law require | Statutory |
On the calibration snapshots
Accolgo stores a periodic snapshot of each starter’s signal so the thresholds behind it can be checked and corrected over time. Those rows carry an internal reference to the starter and the organization rather than a name, but the reference points at a live record, so an individual could still be identified through it. That makes the snapshots pseudonymised, not deidentified, and the CCPA continues to treat them as personal information for as long as that link exists. They are deleted with the starter record.
Deletion on request
An organization may ask for its data to be deleted at any time, and an individual may exercise their right to deletion under the CCPA or their own state’s law. Deletion is real deletion, not archival, save for anything the law requires us to keep.