Data Retention
This page defines how long AB-Labz retains each category of data. Retention periods are set to be proportionate to the purpose for which data was collected, subject to any legal obligations requiring longer retention. These periods are consistent with the Privacy Policy and DPA.
Retention Schedule
| Data category | Retention period | Basis |
|---|---|---|
|
CSV uploads (Experiment Data)
Files uploaded via the CSV import interface
|
Session only | Deleted immediately after the analysis is complete or the session ends. Raw files are never persisted. |
|
API datasets (Experiment Data)
Data submitted via the API for analysis
|
Up to 14 days | Automatically purged 14 days after ingestion. No manual action required. |
|
Runner data
Data processed by the self-hosted Runner component
|
Never received | Runner data never leaves the Customer's infrastructure. AB-Labz receives only analysis results, not raw data. |
|
Workspace data
Experiment configurations, analyses, results, AI insights
|
Active license + 30-day read-only window | Retained throughout the License Period. After expiry, a 30-day read-only window for export. Permanently deleted after 30 days. |
|
Account and profile data
Name, email, organization, settings
|
Duration of account + 30 days | Deleted 30 days after account deletion request or license expiry, whichever is later. |
|
Support communications
Email threads, support tickets
|
3 years | Legitimate interest in resolving disputes and providing continuity of support. |
|
Access and security logs
Authentication events, API calls, admin access logs
|
12 months | Security monitoring and incident investigation. Logs are retained separately from production data. |
|
Billing records and invoices
Payment records, invoice history, tax documents
|
7 years | Legal obligation under Serbian and EU tax and accounting law. |
|
Database backups
Daily encrypted snapshots of all database data
|
30-day rolling window | Backups older than 30 days are automatically purged. This means deleted data persists in backups for up to 30 days after deletion from active systems. |
Notes on Backup Retention
When data is deleted from active systems (e.g., at account deletion or after the 14-day API dataset window), the data may continue to exist in encrypted database backups for up to 30 days. Backup copies are not accessible during normal operations and are used only for disaster recovery. Backup data is purged according to the 30-day rolling schedule.
Requesting Early Deletion
Customers may request early deletion of data (subject to legal retention requirements) by contacting [email protected]. See Data Deletion for the full process.